aboutsummaryrefslogtreecommitdiff
path: root/tests/result/trickbot.pcap.out
blob: ca8bb203e17035adf2ae6254b6b9dd62da0c8f2f (plain)
1
2
3
4
5
6
7
8
Guessed flow protos:	0

DPI Packets (TCP):	8	(8.00 pkts/flow)
Confidence DPI              : 1 (flows)

HTTP	74	62002	1

	1	TCP 10.12.29.101:61318 <-> 82.118.225.196:7080 [proto: 7/HTTP][ClearText][Confidence: DPI][cat: Web/5][28 pkts/2801 bytes <-> 46 pkts/59201 bytes][Goodput ratio: 46/96][8.40 sec][Hostname/SNI: 82.118.225.196][bytes ratio: -0.910 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 327/167 1000/1000 339/292][Pkt Len c2s/s2c min/avg/max/stddev: 54/54 100/1287 982/1514 182/426][URL: 82.118.225.196:7080/OK21pqJAtyyGBEo00sk][StatusCode: 200][Req Content-Type: application/x-www-form-urlencoded][Content-Type: text/html][User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E)][Risk: ** Known Protocol on Non Standard Port **** HTTP Numeric IP Address **** HTTP Suspicious Content **][Risk Score: 160][PLAIN TEXT (POST /OK21p)][Plen Bins: 0,0,0,0,0,0,0,2,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,2,0,0,0,0,4,0,0,6,2,0,35,0,0,44,0,0]