blob: 035f0aecba09fdf4073c55345a97ba0123c21d61 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
|
ntop 80 36401 4
TLS 26 3245 7
Facebook 22 10202 2
Google 62 15977 1
QUIC 3 502 1
JA3 Host Stats:
IP Address # JA3C
1 2a00:d40:1:3:7aac:c0ff:fea7:d4c 1
1 UDP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:45931 <-> [2a00:1450:4001:803::1017]:443 [proto: 188.126/QUIC.Google][cat: Web/5][33 pkts/7741 bytes <-> 29 pkts/8236 bytes][Host: www.google.it][pktlen c2s avg(stddev)/entropy: 4.6(234.6)/285.7][pktlen s2c avg(stddev)/entropy: 4.2(284.0)/300.8][bytes ratio: -0.03][PLAIN TEXT (www.google.it)]
2 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:37506 <-> [2a03:b0c0:3:d0::70:1001]:443 [proto: 91.26/TLS.ntop][cat: Network/14][14 pkts/3969 bytes <-> 12 pkts/11648 bytes][pktlen c2s avg(stddev)/entropy: 3.0(283.5)/323.7][pktlen s2c avg(stddev)/entropy: 3.3(970.7)/538.6][bytes ratio: -0.49][TLSv1][client: www.ntop.org][JA3C: d3e627f423a33ea41841c19b8af79293]
3 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:37486 <-> [2a03:b0c0:3:d0::70:1001]:443 [proto: 91.26/TLS.ntop][cat: Network/14][11 pkts/1292 bytes <-> 8 pkts/5722 bytes][pktlen c2s avg(stddev)/entropy: 3.3(117.5)/67.4][pktlen s2c avg(stddev)/entropy: 2.4(715.2)/607.6][bytes ratio: -0.63][TLSv1][client: www.ntop.org][JA3C: d3e627f423a33ea41841c19b8af79293]
4 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:37494 <-> [2a03:b0c0:3:d0::70:1001]:443 [proto: 91.26/TLS.ntop][cat: Network/14][10 pkts/1206 bytes <-> 8 pkts/5722 bytes][pktlen c2s avg(stddev)/entropy: 3.1(120.6)/69.9][pktlen s2c avg(stddev)/entropy: 2.4(715.2)/607.6][bytes ratio: -0.65][TLSv1][client: www.ntop.org][JA3C: d3e627f423a33ea41841c19b8af79293]
5 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:37488 <-> [2a03:b0c0:3:d0::70:1001]:443 [proto: 91.26/TLS.ntop][cat: Network/14][10 pkts/1206 bytes <-> 7 pkts/5636 bytes][pktlen c2s avg(stddev)/entropy: 3.1(120.6)/69.9][pktlen s2c avg(stddev)/entropy: 1.9(805.1)/929.1][bytes ratio: -0.65][TLSv1][client: www.ntop.org][JA3C: d3e627f423a33ea41841c19b8af79293]
6 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:53132 <-> [2a02:26f0:ad:197::236]:443 [proto: 91.119/TLS.Facebook][cat: SocialNetwork/6][7 pkts/960 bytes <-> 5 pkts/4227 bytes][pktlen c2s avg(stddev)/entropy: 2.6(137.1)/82.6][pktlen s2c avg(stddev)/entropy: 1.3(845.4)/1077.9][bytes ratio: -0.63][TLSv1.2][client: s-static.ak.facebook.com][JA3C: d3e627f423a33ea41841c19b8af79293][server: *.ak.fbcdn.net][JA3S: b898351eb5e266aefd3723d466935494][organization: Facebook, Inc.][Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256]
7 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:53134 <-> [2a02:26f0:ad:197::236]:443 [proto: 91.119/TLS.Facebook][cat: SocialNetwork/6][6 pkts/874 bytes <-> 4 pkts/4141 bytes][pktlen c2s avg(stddev)/entropy: 2.4(145.7)/86.4][pktlen s2c avg(stddev)/entropy: 0.7(1035.2)/1503.0][bytes ratio: -0.65][TLSv1.2][client: s-static.ak.facebook.com][JA3C: d3e627f423a33ea41841c19b8af79293][server: *.ak.fbcdn.net][JA3S: b898351eb5e266aefd3723d466935494][organization: Facebook, Inc.][Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256]
8 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:41776 <-> [2a00:1450:4001:803::1017]:443 [proto: 91/TLS][cat: Web/5][7 pkts/860 bytes <-> 7 pkts/1353 bytes][pktlen c2s avg(stddev)/entropy: 2.7(122.9)/61.5][pktlen s2c avg(stddev)/entropy: 2.4(193.3)/171.9][bytes ratio: -0.22]
9 UDP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:55145 <-> [2a00:1450:400b:c02::5f]:443 [proto: 188/QUIC][cat: Web/5][2 pkts/359 bytes <-> 1 pkts/143 bytes][pktlen c2s avg(stddev)/entropy: 0.8(179.5)/80.5][pktlen s2c avg(stddev)/entropy: 0.0(143.0)/0.0][bytes ratio: 0.43]
10 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:33062 <-> [2a00:1450:400b:c02::9a]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
11 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:40308 <-> [2a03:2880:1010:3f20:face:b00c::25de]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
12 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:40526 <-> [2a00:1450:4006:804::200e]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
13 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:58660 <-> [2a00:1450:4006:803::2008]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
14 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:59690 <-> [2a00:1450:4001:803::1012]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
15 TCP [2a00:d40:1:3:7aac:c0ff:fea7:d4c]:60124 <-> [2a02:26f0:ad:1a1::eed]:443 [proto: 91/TLS][cat: Web/5][1 pkts/86 bytes <-> 1 pkts/86 bytes][pktlen c2s avg(stddev)/entropy: 0.0(86.0)/0.0][pktlen s2c avg(stddev)/entropy: 0.0(86.0)/0.0][bytes ratio: 0.00]
|