diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2023-11-09 19:50:29 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2023-11-09 19:52:36 +0100 |
commit | dcb595e16153caa1600b64adea6af20009ea8419 (patch) | |
tree | 91259a9cba95a47e354eeec65485b9c007dd98d4 /test/results/flow-info | |
parent | b667f9e1daa913acddb0bf2117651481d788fdf8 (diff) |
bump libnDPI to b08c787fe267053afdea82701071f3878c09244b
* fix ndpi data anylsis struct min/max issue
* py-flow-info cosmetics in printing some information
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/flow-info')
444 files changed, 15297 insertions, 15285 deletions
diff --git a/test/results/flow-info/caches_cfg/ookla.pcap.out b/test/results/flow-info/caches_cfg/ookla.pcap.out index deae2b3f6..d441591d7 100644 --- a/test/results/flow-info/caches_cfg/ookla.pcap.out +++ b/test/results/flow-info/caches_cfg/ookla.pcap.out @@ -1,27 +1,27 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] + new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] detected: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] - new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] + new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] detected: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] detection-update: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] RISK: HTTP Obsolete Server - new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] + new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] detected: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] guessed: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] [Ookla][Unknown][Network][Safe] - idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] idle: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 1|detection-updates: 1|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] detection-update: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] idle: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] end: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe] RISK: HTTP Obsolete Server - new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] + new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] detected: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] RISK: Known Proto on Non Std Port detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] diff --git a/test/results/flow-info/caches_cfg/teams.pcap.out b/test/results/flow-info/caches_cfg/teams.pcap.out index 407badd2d..5fbd73a71 100644 --- a/test/results/flow-info/caches_cfg/teams.pcap.out +++ b/test/results/flow-info/caches_cfg/teams.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] + new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] detected: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][tl-sg116e] ERROR-EVENT: Unknown packet type [1/16] - new: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [MIDSTREAM] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] ERROR-EVENT: Unknown packet type [4/16] ERROR-EVENT: Unknown packet type [5/16] ERROR-EVENT: Unknown packet type [6/16] - new: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] detection-update: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] - new: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] - new: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] + new: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] + new: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] detected: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detection-update: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detected: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -33,7 +33,7 @@ detection-update: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [7/16] - new: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] + new: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] detected: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] detection-update: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] analyse: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] @@ -48,10 +48,10 @@ [ENTROPIES...: 4.4,5.2,4.9,5.6,7.3,7.3,4.9,7.7,4.9,5.9,5.5,4.9,7.9,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.1,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.1,7.9,7.9,7.9] detection-update: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] + new: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] detected: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] + new: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] detected: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detection-update: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] analyse: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] @@ -66,17 +66,17 @@ [ENTROPIES...: 4.3,5.2,5.0,6.0,7.3,7.7,5.1,7.3,5.0,6.0,5.7,5.1,7.8,7.9,7.9,5.2,7.9,7.9,7.9,7.9,5.2,7.9,7.9,5.2,7.9,7.8,5.1,5.2,5.2,7.5,5.0,5.3] ERROR-EVENT: Unknown packet type [8/16] ERROR-EVENT: Unknown packet type [9/16] - new: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] + new: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] detected: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [10/16] - new: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] + new: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] detected: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] - new: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] + new: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] detected: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] + new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] detected: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] ERROR-EVENT: Unknown packet type [11/16] ERROR-EVENT: Unknown packet type [12/16] @@ -84,45 +84,45 @@ RISK: Unidirectional Traffic detection-update: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] RISK: Error Code - new: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][] - new: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [MIDSTREAM] + new: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [MIDSTREAM] detected: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [TLS][Unknown][Web][Safe] ERROR-EVENT: Unknown packet type [13/16] - new: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] + new: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] detected: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com.edgekey.net] detection-update: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com.edgekey.net] ERROR-EVENT: Unknown packet type [14/16] ERROR-EVENT: Unknown packet type [15/16] - new: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] + new: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] detected: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][eu-api.asm.skype.com] - new: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] + new: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] detected: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][eu-prod.asyncgw.teams.microsoft.com] - new: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] + new: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] detection-update: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][eu-api.asm.skype.com] - new: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] + new: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] detected: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detected: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] detection-update: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] - new: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] - new: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] + new: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] + new: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] detected: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detected: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] - new: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] + new: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] detected: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][config.teams.microsoft.com] detection-update: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] detection-update: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][config.teams.microsoft.com] - new: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] + new: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] detected: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] detection-update: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] - new: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] + new: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] detected: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][northeuropecns.trafficmanager.net] - new: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] + new: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] detection-update: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][northeuropecns.trafficmanager.net] - new: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] + new: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] detected: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] [TLS.Teams][Azure][Collaborative][Safe][northeurope.notifications.teams.microsoft.com] @@ -130,11 +130,11 @@ detection-update: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [16/16] - new: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] + new: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] detected: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][presence.services.sfb.trafficmanager.net] detection-update: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][presence.services.sfb.trafficmanager.net] - new: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] - new: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [MIDSTREAM] + new: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] + new: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [MIDSTREAM] detected: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [TLS][Dropbox][Web][Safe] detected: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com] detection-update: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com] @@ -150,7 +150,7 @@ [ENTROPIES...: 4.4,5.3,5.0,5.9,5.1,7.3,7.3,5.0,7.7,5.0,5.9,5.2,5.6,5.0,7.9,7.8,7.9,5.2,7.9,7.9,7.9,7.9,5.2,7.9,7.9,5.2,7.9,7.9,7.8,7.9,5.2,7.9] detection-update: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] + new: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] detected: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port detection-update: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] @@ -165,12 +165,12 @@ [IATS(ms)....: 45.7,45.8,0.2,47.9,0.0,47.7,0.0,0.1,0.2,0.1,0.2,9.9,9.9,3.5,10.4,0.4,51.4,37.1,0.2,0.2,0.2,7.1,7.0,1.3,1.2,79.2,201.4,0.0,0.0,167.5,0.2] [PKTLENS.....: 64,52,40,259,1492,1492,52,40,40,1492,1492,40,453,40,198,133,503,91,40,109,40,78,78,40,479,40,46,1480,150,206,46,82] [ENTROPIES...: 4.4,5.0,4.6,5.4,7.1,7.4,4.7,4.7,4.5,7.6,7.6,4.7,7.5,4.7,6.6,6.1,7.6,5.4,4.6,6.0,4.5,5.2,5.4,4.7,7.5,4.7,4.5,7.9,6.6,6.7,4.5,5.4] - new: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] + new: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] detected: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][chatsvcagg.svcs.teams.office.com] detection-update: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][chatsvcagg.svcs.teams.office.com] - new: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] + new: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] detected: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] [TLS.Teams][Azure][Collaborative][Safe][chatsvcagg.teams.microsoft.com] - new: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] + new: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] detected: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -185,10 +185,10 @@ [IATS(ms)....: 34.2,34.3,0.3,36.9,0.0,36.6,0.0,0.2,0.2,0.1,0.0,0.1,1.0,12.0,0.3,36.0,22.7,0.2,0.2,0.1,10.4,10.3,0.6,0.6,77.1,91.7,0.0,49.1,80.4,115.1,0.2] [PKTLENS.....: 64,60,52,273,1492,1492,64,52,1492,52,1492,302,52,178,145,533,103,52,121,52,90,90,52,414,52,52,1480,247,52,227,52,1139] [ENTROPIES...: 4.3,5.1,4.7,5.5,7.4,7.3,4.8,4.8,7.5,4.7,7.6,7.4,4.8,6.3,6.2,7.5,5.6,4.9,6.0,4.9,5.4,5.5,4.8,7.4,4.9,5.1,7.8,7.0,5.0,6.8,4.7,7.8] - new: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] + new: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] detected: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][substrate.office.com] detection-update: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][substrate.office.com] - new: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] + new: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] detected: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] detection-update: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] analyse: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe] @@ -213,29 +213,29 @@ [PKTLENS.....: 64,52,40,251,46,1492,1492,40,1492,80,40,198,133,578,172,46,366,109,40,40,78,46,78,40,46,689,40,359,40,1480,694,248] [ENTROPIES...: 4.4,4.9,4.5,5.4,4.5,6.7,7.5,4.6,7.6,5.7,4.7,6.5,6.2,7.6,6.5,4.5,7.2,5.8,4.6,4.6,5.3,4.5,5.4,4.6,4.5,7.7,4.7,7.3,4.7,7.8,7.7,7.0] detection-update: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] - new: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] + new: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] detected: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][euaz.tr.teams.microsoft.com] - new: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] + new: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] detected: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] + new: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] detected: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] + new: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] detected: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][api.flightproxy.teams.microsoft.com] detection-update: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] detection-update: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....40] [ip4][..tcp] [....192.168.1.6][60551] -> [...52.114.15.45][..443] + new: [....40] [ip4][..tcp] [....192.168.1.6][60551] -> [...52.114.15.45][..443] detection-update: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][api.flightproxy.teams.microsoft.com] detection-update: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][euaz.tr.teams.microsoft.com] RISK: Minor Issues - new: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] + new: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] detected: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][outlook.office.com] detection-update: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][outlook.office.com] - new: [....42] [ip4][..tcp] [....192.168.1.6][60552] -> [...52.114.77.33][..443] - new: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] - new: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] + new: [....42] [ip4][..tcp] [....192.168.1.6][60552] -> [...52.114.77.33][..443] + new: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] + new: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] detected: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] - new: [....45] [ip4][..tcp] [....192.168.1.6][60555] -> [...52.114.77.33][..443] - new: [....46] [ip4][..tcp] [....192.168.1.6][60556] -> [.....40.126.9.7][..443] + new: [....45] [ip4][..tcp] [....192.168.1.6][60555] -> [...52.114.77.33][..443] + new: [....46] [ip4][..tcp] [....192.168.1.6][60556] -> [.....40.126.9.7][..443] detected: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] @@ -267,12 +267,12 @@ [ENTROPIES...: 4.4,4.9,4.5,5.5,4.4,7.3,7.5,4.6,7.5,4.5,7.7,6.7,4.6,6.5,4.5,5.7,4.5,5.6,4.6,7.8,4.6,7.9,7.9,4.6,7.9,4.6,7.9,7.9,4.6,4.5,7.9,7.9] detection-update: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] + new: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] detected: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] + new: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] detected: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -287,18 +287,18 @@ [IATS(ms)....: 48.6,48.7,0.3,51.0,0.1,50.7,0.0,0.3,0.3,1.7,49.8,48.1,1.4,0.0,0.0,50.5,49.1,0.0,0.0,0.0,37.2,37.2,0.0,11.5,11.5,1.0,36.0,16.0,53.0,0.7,0.1] [PKTLENS.....: 64,60,52,258,1492,1492,64,52,1375,52,145,103,52,1480,1480,1480,52,1480,1480,1480,1480,52,1480,1480,52,985,52,52,497,52,83,52] [ENTROPIES...: 4.4,5.3,4.9,6.0,7.3,7.3,5.1,4.9,7.6,5.0,5.9,5.7,5.0,7.9,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.2,7.8,7.9,5.1,7.8,5.1,5.2,7.6,5.1,5.3,5.0] - new: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] + new: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] detected: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] + new: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] detected: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] detection-update: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] - new: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] + new: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] detected: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] + new: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] detected: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][api.microsoftstream.com] detection-update: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][api.microsoftstream.com] - new: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] + new: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] detected: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][api.microsoftstream.com] detection-update: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS @@ -312,10 +312,10 @@ [IATS(ms)....: 29.5,29.6,0.2,45.7,0.2,45.7,0.1,0.1,0.1,0.1,0.0,0.1,0.6,23.2,0.2,30.2,0.0,6.1,0.0,0.2,22.9,22.6,1.5,1.4,2.9,0.0,32.7,0.2,30.1,125.5,125.6] [PKTLENS.....: 64,60,52,266,1492,1492,64,1492,52,52,1492,281,52,145,145,424,103,121,52,52,90,90,52,548,52,1365,135,52,94,52,510,52] [ENTROPIES...: 4.4,5.2,4.9,5.6,7.4,7.5,4.9,7.4,4.9,4.8,7.6,7.1,5.0,5.9,6.3,7.4,5.6,6.1,4.9,4.9,5.4,5.6,4.9,7.5,5.0,7.9,6.1,5.1,5.7,5.0,7.5,4.9] - new: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] + new: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] detected: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][euno-1.api.microsoftstream.com] detection-update: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][euno-1.api.microsoftstream.com] - new: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] + new: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] analyse: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.162| 0.032| 0.044| 1964.919| 3.600] @@ -329,16 +329,16 @@ detection-update: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][euno-1.api.microsoftstream.com] - new: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] + new: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] detected: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][dc.applicationinsights.microsoft.com] detection-update: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][dc.applicationinsights.microsoft.com] - new: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] + new: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] detected: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] detection-update: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] - new: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] + new: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] detected: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][emea.ng.msg.teams-msgapi.trafficmanager.net] detection-update: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][emea.ng.msg.teams-msgapi.trafficmanager.net] - new: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] + new: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] detected: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com] detection-update: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com] analyse: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe] @@ -361,40 +361,40 @@ [IATS(ms)....: 47.1,47.2,0.5,44.4,0.0,43.9,0.0,0.0,0.2,0.1,0.0,0.2,0.0,4.4,9.7,0.3,46.5,32.1,0.5,0.4,0.1,18.9,1.4,20.2,62.9,403.2,425.0,8978.2,0.0,0.0,0.0] [PKTLENS.....: 64,52,40,276,1492,1492,52,40,40,1492,1492,309,40,40,198,133,568,91,40,109,40,78,46,409,40,46,1100,46,411,415,86,78] [ENTROPIES...: 4.3,4.9,4.6,5.6,7.4,7.3,4.7,4.6,4.6,7.5,7.6,7.1,4.7,4.6,6.5,6.1,7.6,5.4,4.6,5.9,4.6,5.2,4.5,7.4,4.7,4.5,7.8,4.6,7.4,7.5,5.6,5.5] - new: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [MIDSTREAM] - new: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] + new: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [MIDSTREAM] + new: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] detected: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port detection-update: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port - new: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] - new: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] + new: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] + new: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] detected: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] - new: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] + new: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] + new: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] detected: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] [DNS.Azure][Unknown][Network][Acceptable][b-tr-teams-euno-05.northeurope.cloudapp.azure.com] detection-update: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] [DNS.Azure][Unknown][Network][Acceptable][b-tr-teams-euno-05.northeurope.cloudapp.azure.com] detected: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] + new: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] detected: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] - new: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] + new: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] + new: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] detected: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detection-update: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] + new: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] detected: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detected: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] + new: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] detected: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] + new: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] detected: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detection-update: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] - new: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] + new: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] + new: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] detected: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][52.114.250.152] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detected: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][52.114.250.153] @@ -403,30 +403,30 @@ RISK: TLS Cert Mismatch, TLS (probably) Not Carrying HTTPS detection-update: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] [TLS.Teams][Azure][Collaborative][Safe][52.114.250.153] RISK: TLS Cert Mismatch, TLS (probably) Not Carrying HTTPS - new: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] - new: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] + new: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] + new: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] detected: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][c-flightproxy-euno-01-teams.cloudapp.net] detection-update: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][c-flightproxy-euno-01-teams.cloudapp.net] detected: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] [TLS.Teams][Azure][Collaborative][Safe][api.flightproxy.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] [TLS.Teams][Azure][Collaborative][Safe][api.flightproxy.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] + new: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] detected: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] + new: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] detected: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] + new: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] detected: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] + new: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] detected: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] + new: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] detected: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] + new: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] detected: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe] @@ -439,10 +439,10 @@ [IATS(ms)....: 45.0,45.1,0.2,47.4,47.2,0.2,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.0,8.0,0.0,0.0,52.4,1.2,45.6,48.6,92.2,43.7,69.1,0.3,113.5,1566.9] [PKTLENS.....: 64,52,40,227,1492,52,1492,588,52,52,1492,588,52,40,588,166,40,40,40,147,46,85,46,91,40,141,224,40,71,40,46,46] [ENTROPIES...: 4.4,4.9,4.5,5.4,7.5,4.6,7.4,6.2,4.7,4.7,7.7,7.0,4.7,4.5,7.6,6.6,4.4,4.5,4.5,6.4,4.5,5.8,4.6,5.4,4.6,6.4,6.9,4.5,5.4,4.4,4.6,4.6] - new: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] + new: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] detected: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] detection-update: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] - new: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] + new: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] detected: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] [ICMP][Unknown][Network][Acceptable] analyse: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -516,7 +516,7 @@ idle: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] guessed: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [TLS][Telegram][Web][Safe] RISK: Unidirectional Traffic - end: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] + end: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] idle: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable] idle: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable] idle: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -527,10 +527,10 @@ RISK: Known Proto on Non Std Port idle: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe] guessed: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] [Skype_Teams][Azure][VoIP][Acceptable] - idle: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] + idle: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] idle: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] not-detected: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [Unknown][Unknown][Unrated] - idle: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] + idle: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] idle: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe] idle: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port diff --git a/test/results/flow-info/default/1kxun.pcap.out b/test/results/flow-info/default/1kxun.pcap.out index b6fce33a4..576df79d4 100644 --- a/test/results/flow-info/default/1kxun.pcap.out +++ b/test/results/flow-info/default/1kxun.pcap.out @@ -1,78 +1,78 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] + new: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] detected: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] + new: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] detected: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] + new: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] detected: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] + new: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] detected: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] [DHCP][Unknown][Network][Acceptable][] - new: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [MIDSTREAM] - new: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] + new: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] detected: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] + new: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] detected: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][shen] - new: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] + new: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] detected: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] + new: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] detected: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] + new: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] detected: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] + new: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] detected: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] + new: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] detected: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] + new: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] detected: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] detection-update: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] RISK: Unidirectional Traffic detection-update: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] - new: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] + new: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] detected: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] - new: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] + new: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] detected: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] detection-update: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] RISK: Unidirectional Traffic - new: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [MIDSTREAM] - new: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] + new: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [MIDSTREAM] + new: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] detected: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][wpad] - new: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] + new: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] detected: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] + new: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] detected: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] + new: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] detected: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] - new: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] - new: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] + new: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + new: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + new: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] detected: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] detection-update: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] RISK: Unidirectional Traffic detection-update: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] - new: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] + new: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] detection-update: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] detected: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] [HTTP.1kxun][Unknown][Streaming][Fun][kankan.1kxun.com] - new: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] + new: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] detected: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] detection-update: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] RISK: Unidirectional Traffic detection-update: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] - new: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] - new: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] - new: [....29] [ip4][..tcp] [..192.168.115.8][49601] -> [.106.187.35.246][...80] - new: [....30] [ip4][..tcp] [..192.168.115.8][49602] -> [.106.187.35.246][...80] - new: [....31] [ip4][..tcp] [..192.168.115.8][49603] -> [.106.187.35.246][...80] - new: [....32] [ip4][..tcp] [..192.168.115.8][49604] -> [.106.187.35.246][...80] - new: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] + new: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] + new: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] + new: [....29] [ip4][..tcp] [..192.168.115.8][49601] -> [.106.187.35.246][...80] + new: [....30] [ip4][..tcp] [..192.168.115.8][49602] -> [.106.187.35.246][...80] + new: [....31] [ip4][..tcp] [..192.168.115.8][49603] -> [.106.187.35.246][...80] + new: [....32] [ip4][..tcp] [..192.168.115.8][49604] -> [.106.187.35.246][...80] + new: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] detected: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] + new: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] detected: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected detected: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] @@ -131,11 +131,11 @@ [IATS(ms)....: 0.1,51.9,52.1,0.0,5.2,0.1,60.5,0.9,0.0,0.0,0.1,0.0,0.4,0.1,0.0,0.1,0.2,85.1,142.0,0.0,40.8,2.5,0.1,0.1,0.1,43.6,0.1,0.4,0.1,0.1,0.0] [PKTLENS.....: 52,52,52,40,40,402,402,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300] [ENTROPIES...: 4.5,4.5,5.0,4.8,4.8,5.8,5.8,4.3,5.6,6.7,7.7,7.8,7.7,7.7,7.7,7.7,7.6,4.1,6.3,4.8,4.8,7.7,7.8,7.7,7.7,7.7,4.8,4.8,7.7,7.7,5.6,3.0] - new: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] + new: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] detected: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][sanji-lifebook-] RISK: Unsafe Protocol - new: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] - new: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] + new: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] + new: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] detected: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] RISK: HTTP Susp User-Agent detected: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] @@ -150,37 +150,37 @@ [IATS(ms)....: 0.1,37.8,38.0,0.1,1.8,0.1,39.0,109.8,0.2,146.8,0.0,0.3,0.1,0.1,0.1,0.5,0.0,0.2,0.1,0.1,0.4,0.0,0.2,36.3,36.5,0.0,0.4,0.1,0.5,0.1,0.1] [PKTLENS.....: 52,52,52,40,40,397,397,46,1300,1300,40,40,1300,1300,1300,1300,40,40,1300,1300,1300,40,40,1300,1300,40,40,1300,1300,1300,1300,1300] [ENTROPIES...: 4.5,4.5,5.0,4.8,4.8,5.8,5.8,4.3,5.6,5.0,4.8,4.8,4.8,5.3,5.2,5.1,4.7,4.7,6.0,5.1,5.2,4.8,4.8,5.8,5.1,4.7,4.7,4.5,4.7,4.7,5.6,5.2] - new: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] + new: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] detected: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] [HTTP][Alibaba][Web][Acceptable][218.244.135.170] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] + new: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] detected: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] detection-update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] RISK: Unidirectional Traffic detection-update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] - new: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] + new: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] detected: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] [HTTP.QQ][Unknown][Chat][Fun][vv.video.qq.com] - new: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] - new: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + new: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] + new: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] detected: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] [HTTP][Alibaba][Web][Acceptable][42.120.51.152] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] + new: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] detected: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] + new: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] detected: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] + new: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] detected: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] - new: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] + new: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] + new: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] detected: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] + new: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] detected: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] detected: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] [HTTP][Unknown][Web][Acceptable][183.131.48.145] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] + new: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] analyse: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] [HTTP][Alibaba][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.399| 0.070| 0.104| 10878.943| 3.600] @@ -195,114 +195,114 @@ RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] [HTTP][Unknown][Media][Acceptable][183.131.48.144] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] + new: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] detected: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] + new: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] detected: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] + new: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] detected: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] + new: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] detected: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] + new: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] detected: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] + new: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] detected: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] [DHCP][Unknown][Network][Acceptable][macbook-air] - new: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] - new: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [MIDSTREAM] - new: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [MIDSTREAM] - new: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] + new: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + new: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [MIDSTREAM] + new: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] detected: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] - new: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] + new: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] detection-update: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] RISK: Error Code - new: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [MIDSTREAM] - new: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] + new: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [MIDSTREAM] + new: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] detected: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] + new: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] detected: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] + new: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] detected: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][isatap] - new: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] - new: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] - new: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] + new: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] + new: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] + new: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] detected: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][sanji-lifebook-] - new: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] + new: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] detected: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][gfile] - new: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] + new: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] detected: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][nasfile] - new: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] + new: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] detected: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][macbookair-e1d0] RISK: Unsafe Protocol - new: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] - new: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] + new: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] + new: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] detected: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] + new: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] detected: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] + new: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] detected: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][joanna-pc] - new: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] + new: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] detected: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] + new: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] detected: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] - new: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] + new: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] + new: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] detected: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] - new: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] + new: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] + new: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] detected: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] + new: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] detected: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] + new: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] detected: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] + new: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] detected: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] + new: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] detected: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable][[ff02::c]:1900] - new: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] + new: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] detected: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] - new: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] + new: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] + new: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] detected: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] - new: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] - new: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] + new: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] + new: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] + new: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] detected: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] + new: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] detected: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] + new: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] detected: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] + new: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] detected: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] - new: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] + new: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] + new: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] detected: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] + new: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] detected: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] + new: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] detected: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] + new: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] detected: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] + new: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] detected: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] + new: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] detected: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [MIDSTREAM] - new: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] + new: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [MIDSTREAM] + new: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] detected: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] + new: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] detected: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] + new: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] detected: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] + new: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] detected: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][kevin-pc] - new: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [MIDSTREAM] + new: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [MIDSTREAM] detected: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] - new: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] + new: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] detection-update: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] RISK: Unidirectional Traffic detection-update: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] @@ -310,26 +310,26 @@ RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] + new: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] detected: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] [DNS.Line][Unknown][Network][Acceptable][dl-obs.official.line.naver.jp] detection-update: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] [DNS.Line][Unknown][Network][Acceptable][dl-obs.official.line.naver.jp] - new: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] - new: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] + new: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] + new: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] detected: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable][dl-obs.official.line.naver.jp] detected: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable][dl-obs.official.line.naver.jp] - new: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] + new: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] detected: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] + new: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] detected: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [MIDSTREAM] + new: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [MIDSTREAM] detected: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [TLS][Facebook][Web][Safe] - new: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] + new: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] detected: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] + new: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] detected: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] + new: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] detected: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] + new: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] detected: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] @@ -339,7 +339,7 @@ update: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + update: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] update: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] [DHCP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -347,7 +347,7 @@ update: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + update: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] update: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] update: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected @@ -367,29 +367,29 @@ [IATS(ms)....: 0.0,54.5,54.6,0.0,4.9,0.0,65.5,0.1,0.1,0.4,0.1,0.1,0.2,0.0,0.0,0.0,0.0,61.5,0.0,69.0,0.1,0.1,0.0,0.7,0.1,0.1,0.1,0.5,70.7,0.0,45001.1] [PKTLENS.....: 52,52,52,40,40,401,401,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,1300,1300,1300,1267,40,40,41] [ENTROPIES...: 4.6,4.6,5.0,4.9,4.9,5.8,5.8,4.4,5.7,7.5,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,4.8,4.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,4.9,4.9,4.8] - new: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] + new: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] detected: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][sc.arrancar.org] - new: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] + new: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] detected: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] [NTP][Apple][System][Acceptable] - new: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] + new: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] detected: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] + new: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] detected: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] + new: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] detected: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] + new: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] detected: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] + new: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] detected: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] + new: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] detected: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] + new: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] detected: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] + new: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] detected: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] + new: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] detected: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] + new: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] detected: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -401,8 +401,8 @@ update: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - update: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] - update: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + update: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + update: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] update: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun] @@ -413,24 +413,24 @@ RISK: Non-Printable/Invalid Chars Detected DAEMON-EVENT: [Processed: 1032 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 129 / 129|skipped: 0|!detected: 0|guessed: 0|detection-updates: 19|updates: 38] - new: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.mobi] - new: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [MIDSTREAM] + new: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [MIDSTREAM] detected: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [HTTP.QQ][Tencent][Chat][Fun][cgi.connect.qq.com] detection-update: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Download][Fun][kankan.1kxun.mobi] RISK: Binary App Transfer - new: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.com] - new: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.com] idle: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -441,7 +441,7 @@ idle: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable] idle: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun] not-detected: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] + idle: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] idle: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -453,9 +453,9 @@ idle: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [TLS][Facebook][Web][Safe] idle: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] not-detected: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] [Unknown][Unknown][Unrated] - idle: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] + idle: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] not-detected: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] [Unknown][Unknown][Unrated] - idle: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + idle: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] idle: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -467,7 +467,7 @@ idle: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected not-detected: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] + idle: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] idle: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] [DHCP][Unknown][Network][Acceptable] idle: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -495,7 +495,7 @@ idle: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + idle: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] idle: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] idle: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -503,13 +503,13 @@ idle: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable] guessed: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] + end: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] idle: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] guessed: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] + end: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] not-detected: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + idle: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] end: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable] RISK: Error Code idle: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -517,7 +517,7 @@ idle: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] guessed: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [HTTP][Google][Web][Acceptable][] - idle: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] + idle: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] idle: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected idle: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun] @@ -527,7 +527,7 @@ RISK: HTTP Susp User-Agent idle: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] [HTTP.1kxun][Unknown][Streaming][Fun] guessed: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] - end: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] + end: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] end: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS end: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] @@ -538,17 +538,17 @@ RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS idle: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] + idle: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] not-detected: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] + idle: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] not-detected: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + idle: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] idle: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected idle: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] + idle: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] idle: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] idle: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -556,7 +556,7 @@ idle: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun] idle: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] + idle: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] idle: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun] idle: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun] @@ -571,20 +571,20 @@ idle: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected guessed: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [TLS][Line][Web][Safe] - idle: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] + idle: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] end: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] [HTTP][Unknown][Media][Acceptable] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun] not-detected: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] [Unknown][Unknown][Unrated] - idle: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] + idle: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] not-detected: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] [Unknown][Unknown][Unrated] - idle: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] + idle: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] idle: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] [NTP][Apple][System][Acceptable] idle: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun] guessed: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [TLS][Unknown][Web][Safe] - idle: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] + idle: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] idle: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] idle: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -599,31 +599,31 @@ idle: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] + idle: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] idle: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable] - new: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][messages.1kxun.mobi] - new: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [MIDSTREAM] + new: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [MIDSTREAM] detected: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent detection-update: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent, Unidirectional Traffic detection-update: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent, Error Code - new: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [MIDSTREAM] + new: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [MIDSTREAM] detected: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [HTTP.1kxun][Unknown][Streaming][Fun][android.yingshi.tcclick.1kxun.com] detection-update: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [HTTP.1kxun][Unknown][Streaming][Fun][android.yingshi.tcclick.1kxun.com] RISK: Error Code - new: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] analyse: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -635,23 +635,23 @@ [IATS(ms)....: 356.2,0.1,308.1,0.1,2.4,3.2,0.1,200.2,0.0,0.1,0.0,0.0,0.0,0.0,0.0,1.6,0.1,0.1,0.0,0.0,0.0,0.0,0.0,0.0,895.3,372.0,0.0,1.3,0.1,1.9,0.0] [PKTLENS.....: 264,373,13012,14452,2932,2932,1492,7252,2932,1492,2932,2932,1492,1492,1492,1492,1492,4372,6324,2932,2932,1492,1492,1492,788,260,373,17332,21652,1492,4372,17332] [ENTROPIES...: 5.9,5.7,8.0,8.0,7.9,7.9,7.9,8.0,7.9,7.8,7.9,7.9,7.9,7.8,7.8,7.9,7.8,7.9,7.9,7.9,7.9,7.9,7.8,7.8,7.7,5.8,5.8,8.0,8.0,7.9,7.9,8.0] - new: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [MIDSTREAM] + new: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [MIDSTREAM] detected: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [HTTP.1kxun][Unknown][Streaming][Fun][release.bigdata.1kxun.com] - new: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [HTTP][Alibaba][Streaming][Acceptable][tcad.wedolook.com] - new: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [MIDSTREAM] + new: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [MIDSTREAM] detected: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [HTTP.Google][AmazonAWS][Web][Acceptable][google.open-js.com] analyse: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -663,23 +663,23 @@ [IATS(ms)....: 380.4,4.6,408.6,215.7,0.5,1.0,1.0,178.5,0.3,0.5,379.6,185.4,1.4,0.7,331.7,5.7,174.2,6.1,0.3,0.9,170.5,0.4,6.0,1.1,0.3,0.7,169.5,0.5,0.6,5.3,0.4] [PKTLENS.....: 817,1492,1253,488,1492,1492,7252,4372,1492,1492,2504,476,2932,8692,1492,2932,8692,2932,1492,1492,7252,1492,1492,2932,1492,1492,2932,1492,1492,2932,1492,1492] [ENTROPIES...: 5.9,7.7,7.8,5.9,7.6,7.9,8.0,8.0,7.9,7.9,7.9,5.9,7.8,8.0,7.9,7.9,8.0,7.9,7.9,7.9,8.0,7.9,7.8,7.9,7.8,7.8,7.9,7.9,7.9,7.9,7.9,7.9] - new: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [MIDSTREAM] + new: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [MIDSTREAM] detected: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [HTTP][Tencent][Web][Acceptable][qzonestyle.gtimg.cn] - new: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [MIDSTREAM] + new: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [MIDSTREAM] detected: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [HTTP.Google][Google][Advertisement][Acceptable][pagead2.googlesyndication.com] - new: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [MIDSTREAM] + new: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [MIDSTREAM] detected: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [HTTP.Google][Google][Advertisement][Acceptable][www.google-analytics.com] - new: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] analyse: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -701,17 +701,17 @@ [IATS(ms)....: 205.6,2.1,0.0,0.0,0.0,224.8,0.4,0.3,1.4,0.0,193.7,0.4,0.4,1.7,1.3,1.9,226.0,899.7,238.0,0.0,2.4,199.2,0.5,1.0,1.3,0.0,0.0,407.3,371.5,0.0,1.5] [PKTLENS.....: 566,337,1492,4372,2932,4372,1492,1492,1492,1492,5812,1492,1492,1492,2932,4372,5812,3718,578,337,7252,15892,1492,1492,7252,1492,5812,640,566,337,7787,18772] [ENTROPIES...: 5.9,5.9,7.3,7.9,7.9,7.9,7.8,7.8,7.8,7.9,8.0,7.8,7.8,7.8,7.9,7.9,7.9,7.9,5.9,5.8,8.0,8.0,7.9,7.9,8.0,7.9,8.0,7.7,5.9,5.9,7.9,8.0] - new: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [MIDSTREAM] + new: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [MIDSTREAM] detected: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [HTTP.GoogleServices][Google][Web][Acceptable][www.googletagservices.com] - new: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] analyse: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -723,80 +723,80 @@ [IATS(ms)....: 188.5,0.0,1.4,179.4,1.4,0.7,0.4,2.4,0.7,270.1,0.1,0.0,0.6,0.0,3892.8,3428.9,186.1,186.3,192.6,209.0,367.2,352.3,5253.8,5339.0,3.6,6045.0,5959.1,0.4,0.5,194.9,189.4] [PKTLENS.....: 486,2932,2932,8692,2932,7252,1492,1492,14452,1492,2932,2932,7252,7252,4078,803,695,805,1511,807,1401,803,1516,1065,2932,1130,1155,1492,1492,1575,1166,1083] [ENTROPIES...: 5.9,7.8,7.9,8.0,7.9,8.0,7.9,7.9,8.0,7.9,7.9,7.9,8.0,8.0,8.0,5.9,6.4,5.9,7.5,5.9,6.2,5.9,6.5,5.8,6.5,6.8,5.8,6.4,7.8,7.9,5.8,6.9] - new: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [MIDSTREAM] + new: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [MIDSTREAM] detected: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [HTTP][Unknown][Web][Acceptable][m.vpon.com] - new: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [MIDSTREAM] + new: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [MIDSTREAM] detected: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] - new: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [MIDSTREAM] + new: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [MIDSTREAM] detected: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] detection-update: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] RISK: Unidirectional Traffic detection-update: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] - new: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [MIDSTREAM] + new: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [MIDSTREAM] detected: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] - new: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [MIDSTREAM] + new: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [MIDSTREAM] detected: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [HTTP][Unknown][Web][Acceptable][tw.api.vpon.com] - new: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [MIDSTREAM] + new: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [MIDSTREAM] detected: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [HTTP][Unknown][Web][Acceptable][tw.api.vpon.com] - new: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [MIDSTREAM] + new: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [MIDSTREAM] detected: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [HTTP][AmazonAWS][Web][Acceptable][cdn.liftoff.io] - new: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [MIDSTREAM] + new: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [MIDSTREAM] detected: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [HTTP.MpegDash][AmazonAWS][Media][Fun][cdn.liftoff.io] - new: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [MIDSTREAM] + new: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [MIDSTREAM] detected: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: HTTP Susp User-Agent detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: HTTP Susp User-Agent, Unidirectional Traffic - new: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [MIDSTREAM] + new: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [MIDSTREAM] detected: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][adx-tk.rayjump.com] RISK: Unidirectional Traffic - new: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [MIDSTREAM] + new: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [MIDSTREAM] detected: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: Unidirectional Traffic - new: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [MIDSTREAM] + new: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [MIDSTREAM] detected: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [HTTP][AmazonAWS][Web][Acceptable][tknet-cdn.rayjump.com] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] RISK: Unidirectional Traffic detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][adx-tk.rayjump.com] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] - new: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [MIDSTREAM] + new: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [MIDSTREAM] detected: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [HTTP][AmazonAWS][Web][Acceptable][impression-east.liftoff.io] - new: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [MIDSTREAM] + new: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [MIDSTREAM] detected: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [HTTP][AmazonAWS][Web][Acceptable][adexp.liftoff.io] - new: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [MIDSTREAM] + new: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [MIDSTREAM] detected: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [HTTP.Google][Google][Web][Acceptable][play.google.com] - new: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [MIDSTREAM] + new: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [MIDSTREAM] detected: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [HTTP][AmazonAWS][Web][Acceptable][click.liftoff.io] - new: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [MIDSTREAM] + new: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [MIDSTREAM] detected: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] detection-update: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] RISK: Unidirectional Traffic detection-update: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] - new: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [MIDSTREAM] + new: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [MIDSTREAM] detected: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] idle: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] idle: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] diff --git a/test/results/flow-info/default/443-chrome.pcap.out b/test/results/flow-info/default/443-chrome.pcap.out index b7bd2f569..6d5d1ad07 100644 --- a/test/results/flow-info/default/443-chrome.pcap.out +++ b/test/results/flow-info/default/443-chrome.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.178.62.197.130][..443] -> [...192.168.1.13][53059] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.178.62.197.130][..443] -> [...192.168.1.13][53059] [MIDSTREAM] guessed: [.....1] [ip4][..tcp] [.178.62.197.130][..443] -> [...192.168.1.13][53059] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [.178.62.197.130][..443] -> [...192.168.1.13][53059] + idle: [.....1] [ip4][..tcp] [.178.62.197.130][..443] -> [...192.168.1.13][53059] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/443-curl.pcap.out b/test/results/flow-info/default/443-curl.pcap.out index 6d4128d5d..348de7848 100644 --- a/test/results/flow-info/default/443-curl.pcap.out +++ b/test/results/flow-info/default/443-curl.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.13][55523] -> [.178.62.197.130][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.13][55523] -> [.178.62.197.130][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.13][55523] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][55523] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][55523] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] diff --git a/test/results/flow-info/default/443-firefox.pcap.out b/test/results/flow-info/default/443-firefox.pcap.out index ae545d3f8..08863a62f 100644 --- a/test/results/flow-info/default/443-firefox.pcap.out +++ b/test/results/flow-info/default/443-firefox.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.13][53096] -> [.178.62.197.130][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.13][53096] -> [.178.62.197.130][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.13][53096] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][53096] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][53096] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] diff --git a/test/results/flow-info/default/443-git.pcap.out b/test/results/flow-info/default/443-git.pcap.out index 79111fb10..fb1765297 100644 --- a/test/results/flow-info/default/443-git.pcap.out +++ b/test/results/flow-info/default/443-git.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.13][55744] -> [...140.82.114.4][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.13][55744] -> [...140.82.114.4][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.13][55744] -> [...140.82.114.4][..443] [TLS.Github][Github][Collaborative][Acceptable][github.com] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][55744] -> [...140.82.114.4][..443] [TLS.Github][Github][Collaborative][Acceptable][github.com] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][55744] -> [...140.82.114.4][..443] [TLS.Github][Github][Collaborative][Acceptable][github.com] diff --git a/test/results/flow-info/default/443-opvn.pcap.out b/test/results/flow-info/default/443-opvn.pcap.out index 8cbc8cec5..31e930897 100644 --- a/test/results/flow-info/default/443-opvn.pcap.out +++ b/test/results/flow-info/default/443-opvn.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.84][52973] -> [.192.12.192.103][.1194] + new: [.....1] [ip4][..tcp] [...192.168.1.84][52973] -> [.192.12.192.103][.1194] detected: [.....1] [ip4][..tcp] [...192.168.1.84][52973] -> [.192.12.192.103][.1194] [OpenVPN][Unknown][VPN][Acceptable] analyse: [.....1] [ip4][..tcp] [...192.168.1.84][52973] -> [.192.12.192.103][.1194] [OpenVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/443-safari.pcap.out b/test/results/flow-info/default/443-safari.pcap.out index e7957f1d6..7e46fe334 100644 --- a/test/results/flow-info/default/443-safari.pcap.out +++ b/test/results/flow-info/default/443-safari.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.13][53031] -> [.178.62.197.130][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.13][53031] -> [.178.62.197.130][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.13][53031] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][53031] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....1] [ip4][..tcp] [...192.168.1.13][53031] -> [.178.62.197.130][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] diff --git a/test/results/flow-info/default/4in6tunnel.pcap.out b/test/results/flow-info/default/4in6tunnel.pcap.out index 87771d624..82e61e8e3 100644 --- a/test/results/flow-info/default/4in6tunnel.pcap.out +++ b/test/results/flow-info/default/4in6tunnel.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][....4] [22e0:1685:eda7:38cc:58bd:f3f1:aa3f:22d8] -> [................344a:ba94:152a:ac34::2a] + new: [.....1] [ip6][....4] [22e0:1685:eda7:38cc:58bd:f3f1:aa3f:22d8] -> [................344a:ba94:152a:ac34::2a] detected: [.....1] [ip6][....4] [22e0:1685:eda7:38cc:58bd:f3f1:aa3f:22d8] -> [................344a:ba94:152a:ac34::2a] [IP_in_IP][Unknown][Network][Acceptable] idle: [.....1] [ip6][....4] [22e0:1685:eda7:38cc:58bd:f3f1:aa3f:22d8] -> [................344a:ba94:152a:ac34::2a] [IP_in_IP][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/6in4tunnel.pcap.out b/test/results/flow-info/default/6in4tunnel.pcap.out index 7882ce469..cb8930008 100644 --- a/test/results/flow-info/default/6in4tunnel.pcap.out +++ b/test/results/flow-info/default/6in4tunnel.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][...41] [....174.3.73.24] -> [.184.105.255.26] - analyse: [.....1] [ip4][...41] [....174.3.73.24] -> [.184.105.255.26] + new: [.....1] [ip4][...41] [....174.3.73.24] -> [.184.105.255.26] + analyse: [.....1] [ip4][...41] [....174.3.73.24] -> [.184.105.255.26] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 1.005| 0.495| 0.455| 206990.442| 4.200] [PKTLEN......: 92.000| 1897.000| 236.400| 383.000| 146712.700| 4.100] diff --git a/test/results/flow-info/default/6in6tunnel.pcap.out b/test/results/flow-info/default/6in6tunnel.pcap.out index 3a7b7928a..cd8b3a097 100644 --- a/test/results/flow-info/default/6in6tunnel.pcap.out +++ b/test/results/flow-info/default/6in6tunnel.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][...41] [........2001:4f8:4:7:2e0:81ff:fe52:ffff] -> [........2001:4f8:4:7:2e0:81ff:fe52:9a6b] - new: [.....2] [ip6][...41] [.............................feed::beef] -> [.............................feed::cafe] + new: [.....1] [ip6][...41] [........2001:4f8:4:7:2e0:81ff:fe52:ffff] -> [........2001:4f8:4:7:2e0:81ff:fe52:9a6b] + new: [.....2] [ip6][...41] [.............................feed::beef] -> [.............................feed::cafe] not-detected: [.....1] [ip6][...41] [........2001:4f8:4:7:2e0:81ff:fe52:ffff] -> [........2001:4f8:4:7:2e0:81ff:fe52:9a6b] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....1] [ip6][...41] [........2001:4f8:4:7:2e0:81ff:fe52:ffff] -> [........2001:4f8:4:7:2e0:81ff:fe52:9a6b] + idle: [.....1] [ip6][...41] [........2001:4f8:4:7:2e0:81ff:fe52:ffff] -> [........2001:4f8:4:7:2e0:81ff:fe52:9a6b] not-detected: [.....2] [ip6][...41] [.............................feed::beef] -> [.............................feed::cafe] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....2] [ip6][...41] [.............................feed::beef] -> [.............................feed::cafe] + idle: [.....2] [ip6][...41] [.............................feed::beef] -> [.............................feed::cafe] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/BGP_Cisco_hdlc_slarp.pcap.out b/test/results/flow-info/default/BGP_Cisco_hdlc_slarp.pcap.out index fb752e711..eb615713d 100644 --- a/test/results/flow-info/default/BGP_Cisco_hdlc_slarp.pcap.out +++ b/test/results/flow-info/default/BGP_Cisco_hdlc_slarp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....100.16.1.2][18324] -> [.....100.16.1.1][..179] + new: [.....1] [ip4][..tcp] [.....100.16.1.2][18324] -> [.....100.16.1.1][..179] detected: [.....1] [ip4][..tcp] [.....100.16.1.2][18324] -> [.....100.16.1.1][..179] [BGP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [.....100.16.1.2][18324] -> [.....100.16.1.1][..179] [BGP][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/BGP_redist.pcap.out b/test/results/flow-info/default/BGP_redist.pcap.out index 36d92703c..65804e47d 100644 --- a/test/results/flow-info/default/BGP_redist.pcap.out +++ b/test/results/flow-info/default/BGP_redist.pcap.out @@ -2,7 +2,7 @@ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] ERROR-EVENT: Unknown L3 protocol [1/16] - new: [.....1] [ip4][..tcp] [........2.2.2.2][..179] -> [........5.5.5.5][49433] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [........2.2.2.2][..179] -> [........5.5.5.5][49433] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [........2.2.2.2][..179] -> [........5.5.5.5][49433] [BGP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [........2.2.2.2][..179] -> [........5.5.5.5][49433] [BGP][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/EAQ.pcap.out b/test/results/flow-info/default/EAQ.pcap.out index a0e85af3c..3c6b2cf50 100644 --- a/test/results/flow-info/default/EAQ.pcap.out +++ b/test/results/flow-info/default/EAQ.pcap.out @@ -1,41 +1,41 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] + new: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] detected: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] [HTTP.Google][Google][Web][Acceptable][www.google.com] RISK: HTTP Susp User-Agent - new: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] + new: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] detected: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] [HTTP.Google][Google][Web][Acceptable][www.google.com.br] RISK: HTTP Susp User-Agent - new: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] - new: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] - new: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] - new: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] - new: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] - new: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] - new: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] - new: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] - new: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] - new: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] - new: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] - new: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] - new: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] - new: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] - new: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] - new: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] - new: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] - new: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] - new: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] - new: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] - new: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] - new: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] - new: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] - new: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] - new: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] - new: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] - new: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] - new: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] - new: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] + new: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] + new: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] + new: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] + new: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] + new: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] + new: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] + new: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] + new: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] + new: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] + new: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] + new: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] + new: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] + new: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] + new: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] + new: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] + new: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] + new: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] + new: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] + new: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] + new: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] + new: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] + new: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] + new: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] + new: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] + new: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] + new: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] + new: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] + new: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] + new: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] detected: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] [EAQ][Unknown][Network][Acceptable] detected: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] [EAQ][Unknown][Network][Acceptable] detected: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] [EAQ][Unknown][Network][Acceptable] @@ -46,27 +46,27 @@ detected: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] [EAQ][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] [EAQ][Unknown][Network][Acceptable] update: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] [EAQ][Unknown][Network][Acceptable] - update: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] - update: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] - update: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] + update: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] + update: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] + update: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] update: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] [EAQ][Unknown][Network][Acceptable] - update: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] - update: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] + update: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] + update: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] update: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] [EAQ][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] [EAQ][Unknown][Network][Acceptable] - update: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] + update: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] update: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] [EAQ][Unknown][Network][Acceptable] - update: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] - update: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] - update: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] - update: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] - update: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] + update: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] + update: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] + update: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] + update: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] + update: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] update: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] [EAQ][Unknown][Network][Acceptable] - update: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] - update: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] - update: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] + update: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] + update: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] + update: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] update: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] [EAQ][Unknown][Network][Acceptable] - update: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] + update: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] detected: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] [EAQ][Unknown][Network][Acceptable] RISK: Unidirectional Traffic detected: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] [EAQ][Unknown][Network][Acceptable] @@ -79,12 +79,12 @@ RISK: Unidirectional Traffic detected: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] [EAQ][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] - update: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] - update: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] - update: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] - update: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] - update: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] + update: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] + update: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] + update: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] + update: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] + update: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] + update: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] detected: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] [EAQ][Unknown][Network][Acceptable] RISK: Unidirectional Traffic detected: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] [EAQ][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out b/test/results/flow-info/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out index 04eb5a6a3..2b281f6ea 100644 --- a/test/results/flow-info/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out +++ b/test/results/flow-info/default/FAX-Call-t38-CA-TDM-SIP-FB-1.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....10.35.40.22][.2944] -> [.....10.23.1.42][.2944] + new: [.....1] [ip4][..udp] [....10.35.40.22][.2944] -> [.....10.23.1.42][.2944] detected: [.....1] [ip4][..udp] [....10.35.40.22][.2944] -> [.....10.23.1.42][.2944] [Megaco][Unknown][VoIP][Acceptable] - new: [.....2] [ip4][..udp] [....10.35.60.72][.5060] -> [...10.35.60.100][.5060] + new: [.....2] [ip4][..udp] [....10.35.60.72][.5060] -> [...10.35.60.100][.5060] detected: [.....2] [ip4][..udp] [....10.35.60.72][.5060] -> [...10.35.60.100][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [.....3] [ip4][..udp] [....10.35.40.25][.5060] -> [...10.35.40.200][.5060] + new: [.....3] [ip4][..udp] [....10.35.40.25][.5060] -> [...10.35.40.200][.5060] detected: [.....3] [ip4][..udp] [....10.35.40.25][.5060] -> [...10.35.40.200][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [.....4] [ip4][..udp] [138.132.169.101][.5060] -> [192.168.100.219][.5060] + new: [.....4] [ip4][..udp] [138.132.169.101][.5060] -> [192.168.100.219][.5060] detected: [.....4] [ip4][..udp] [138.132.169.101][.5060] -> [192.168.100.219][.5060] [SIP][Unknown][VoIP][Acceptable] analyse: [.....1] [ip4][..udp] [....10.35.40.22][.2944] -> [.....10.23.1.42][.2944] [Megaco][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -19,7 +19,7 @@ [IATS(ms)....: 0.1,2.6,0.1,4369.7,0.2,4369.4,0.1,4370.2,0.1,4370.2,0.1,4369.9,0.1,4370.1,0.3,4370.0,0.1,4369.4,0.1,3508.4,3524.3,204.4,193.0,657.5,0.0,652.5,0.2,4369.7,0.1,4370.2,0.6] [PKTLENS.....: 73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,73,73,278,150,362,400,80,87,74,74,279,151,74,74,279,151] [ENTROPIES...: 5.2,5.1,5.4,5.4,5.2,5.2,5.4,5.4,5.2,5.2,5.4,5.4,5.2,5.2,5.4,5.4,5.2,5.1,5.4,5.4,5.8,5.2,5.3,5.1,5.2,5.2,5.4,5.5,5.2,5.2,5.4,5.4] - new: [.....5] [ip4][..udp] [...10.35.60.100][15580] -> [.....10.23.1.52][16756] + new: [.....5] [ip4][..udp] [...10.35.60.100][15580] -> [.....10.23.1.52][16756] detected: [.....5] [ip4][..udp] [...10.35.60.100][15580] -> [.....10.23.1.52][16756] [RTP][Unknown][Media][Acceptable] analyse: [.....5] [ip4][..udp] [...10.35.60.100][15580] -> [.....10.23.1.52][16756] [RTP][Unknown][Media][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/IEC104.pcap.out b/test/results/flow-info/default/IEC104.pcap.out index 774242ae8..c4c51dd99 100644 --- a/test/results/flow-info/default/IEC104.pcap.out +++ b/test/results/flow-info/default/IEC104.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.175.211.1][.2404] -> [..10.119.105.26][54768] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [...10.175.211.3][.2404] -> [..10.119.105.26][54769] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...10.175.211.1][.2404] -> [..10.119.105.26][54768] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...10.175.211.3][.2404] -> [..10.119.105.26][54769] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...10.175.211.1][.2404] -> [..10.119.105.26][54768] [IEC60870][Unknown][IoT-Scada][Acceptable] RISK: Unidirectional Traffic detected: [.....2] [ip4][..tcp] [...10.175.211.3][.2404] -> [..10.119.105.26][54769] [IEC60870][Unknown][IoT-Scada][Acceptable] diff --git a/test/results/flow-info/default/KakaoTalk_chat.pcap.out b/test/results/flow-info/default/KakaoTalk_chat.pcap.out index 85d4f54d2..0f17962bb 100644 --- a/test/results/flow-info/default/KakaoTalk_chat.pcap.out +++ b/test/results/flow-info/default/KakaoTalk_chat.pcap.out @@ -1,97 +1,97 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...10.24.82.188][38448] -> [.....10.188.1.1][...53] + new: [.....1] [ip4][..udp] [...10.24.82.188][38448] -> [.....10.188.1.1][...53] detected: [.....1] [ip4][..udp] [...10.24.82.188][38448] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][auth.kakao.com] - new: [.....2] [ip4][..udp] [...10.24.82.188][35603] -> [.....10.188.1.1][...53] + new: [.....2] [ip4][..udp] [...10.24.82.188][35603] -> [.....10.188.1.1][...53] detected: [.....2] [ip4][..udp] [...10.24.82.188][35603] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][ac-talk.kakao.com] - new: [.....3] [ip4][..udp] [...10.24.82.188][57816] -> [.....10.188.1.1][...53] + new: [.....3] [ip4][..udp] [...10.24.82.188][57816] -> [.....10.188.1.1][...53] detected: [.....3] [ip4][..udp] [...10.24.82.188][57816] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][katalk.kakao.com] detection-update: [.....2] [ip4][..udp] [...10.24.82.188][35603] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][ac-talk.kakao.com] detection-update: [.....1] [ip4][..udp] [...10.24.82.188][38448] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][auth.kakao.com] detection-update: [.....3] [ip4][..udp] [...10.24.82.188][57816] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][katalk.kakao.com] - new: [.....4] [ip4][..udp] [...10.24.82.188][41909] -> [.....10.188.1.1][...53] + new: [.....4] [ip4][..udp] [...10.24.82.188][41909] -> [.....10.188.1.1][...53] detected: [.....4] [ip4][..udp] [...10.24.82.188][41909] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][booking.loco.kakao.com] - new: [.....5] [ip4][..udp] [...10.24.82.188][12908] -> [.....10.188.1.1][...53] + new: [.....5] [ip4][..udp] [...10.24.82.188][12908] -> [.....10.188.1.1][...53] detected: [.....5] [ip4][..udp] [...10.24.82.188][12908] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-m.talk.kakao.com] - new: [.....6] [ip4][..udp] [...10.24.82.188][58810] -> [.....10.188.1.1][...53] + new: [.....6] [ip4][..udp] [...10.24.82.188][58810] -> [.....10.188.1.1][...53] detected: [.....6] [ip4][..udp] [...10.24.82.188][58810] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][item.kakao.com] detection-update: [.....6] [ip4][..udp] [...10.24.82.188][58810] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][item.kakao.com] detection-update: [.....5] [ip4][..udp] [...10.24.82.188][12908] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-m.talk.kakao.com] detection-update: [.....4] [ip4][..udp] [...10.24.82.188][41909] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][booking.loco.kakao.com] - new: [.....7] [ip4][..udp] [...10.24.82.188][.5929] -> [.....10.188.1.1][...53] + new: [.....7] [ip4][..udp] [...10.24.82.188][.5929] -> [.....10.188.1.1][...53] detected: [.....7] [ip4][..udp] [...10.24.82.188][.5929] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-p.talk.kakao.com] - new: [.....8] [ip4][..udp] [...10.24.82.188][.9094] -> [.....10.188.1.1][...53] + new: [.....8] [ip4][..udp] [...10.24.82.188][.9094] -> [.....10.188.1.1][...53] detected: [.....8] [ip4][..udp] [...10.24.82.188][.9094] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-v.talk.kakao.com] - new: [.....9] [ip4][..udp] [...10.24.82.188][56820] -> [.....10.188.1.1][...53] + new: [.....9] [ip4][..udp] [...10.24.82.188][56820] -> [.....10.188.1.1][...53] detected: [.....9] [ip4][..udp] [...10.24.82.188][56820] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-c.talk.kakao.com] detection-update: [.....7] [ip4][..udp] [...10.24.82.188][.5929] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-p.talk.kakao.com] detection-update: [.....8] [ip4][..udp] [...10.24.82.188][.9094] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-v.talk.kakao.com] detection-update: [.....9] [ip4][..udp] [...10.24.82.188][56820] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-c.talk.kakao.com] - new: [....10] [ip4][..udp] [...10.24.82.188][29029] -> [.....10.188.1.1][...53] + new: [....10] [ip4][..udp] [...10.24.82.188][29029] -> [.....10.188.1.1][...53] detected: [....10] [ip4][..udp] [...10.24.82.188][29029] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-a.talk.kakao.com] - new: [....11] [ip4][..udp] [...10.24.82.188][25117] -> [.....10.188.1.1][...53] + new: [....11] [ip4][..udp] [...10.24.82.188][25117] -> [.....10.188.1.1][...53] detected: [....11] [ip4][..udp] [...10.24.82.188][25117] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-gp.talk.kakao.com] - new: [....12] [ip4][..udp] [...10.24.82.188][43077] -> [.....10.188.1.1][...53] + new: [....12] [ip4][..udp] [...10.24.82.188][43077] -> [.....10.188.1.1][...53] detected: [....12] [ip4][..udp] [...10.24.82.188][43077] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][dn-l.talk.kakao.com] detection-update: [....10] [ip4][..udp] [...10.24.82.188][29029] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-a.talk.kakao.com] detection-update: [....12] [ip4][..udp] [...10.24.82.188][43077] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][dn-l.talk.kakao.com] detection-update: [....11] [ip4][..udp] [...10.24.82.188][25117] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][up-gp.talk.kakao.com] - new: [....13] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] - new: [....14] [ip4][..tcp] [..216.58.221.10][...80] -> [...10.24.82.188][35922] [MIDSTREAM] - new: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] + new: [....13] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] + new: [....14] [ip4][..tcp] [..216.58.221.10][...80] -> [...10.24.82.188][35922] [MIDSTREAM] + new: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] detected: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] [TLS][Facebook][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....16] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34503] [MIDSTREAM] - new: [....17] [ip4][..udp] [...10.24.82.188][61011] -> [.....10.188.1.1][...53] + new: [....16] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34503] [MIDSTREAM] + new: [....17] [ip4][..udp] [...10.24.82.188][61011] -> [.....10.188.1.1][...53] detected: [....17] [ip4][..udp] [...10.24.82.188][61011] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][plus-talk.kakao.com] - new: [....18] [ip4][..udp] [...10.24.82.188][61011] -> [...10.188.191.1][...53] + new: [....18] [ip4][..udp] [...10.24.82.188][61011] -> [...10.188.191.1][...53] detected: [....18] [ip4][..udp] [...10.24.82.188][61011] -> [...10.188.191.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][plus-talk.kakao.com] detection-update: [....17] [ip4][..udp] [...10.24.82.188][61011] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][plus-talk.kakao.com] detection-update: [....18] [ip4][..udp] [...10.24.82.188][61011] -> [...10.188.191.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable][plus-talk.kakao.com] - new: [....19] [ip4][.icmp] [...10.24.82.188] -> [...10.188.191.1] + new: [....19] [ip4][.icmp] [...10.24.82.188] -> [...10.188.191.1] detected: [....19] [ip4][.icmp] [...10.24.82.188] -> [...10.188.191.1] [ICMP][Unknown][Network][Acceptable] - new: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] + new: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] detected: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher detection-update: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] [TLS.KakaoTalk][Unknown][Chat][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....21] [ip4][..tcp] [...10.24.82.188][37553] -> [....31.13.68.84][...80] - new: [....22] [ip4][..tcp] [....31.13.68.73][..443] -> [...10.24.82.188][47007] [MIDSTREAM] + new: [....21] [ip4][..tcp] [...10.24.82.188][37553] -> [....31.13.68.84][...80] + new: [....22] [ip4][..tcp] [....31.13.68.73][..443] -> [...10.24.82.188][47007] [MIDSTREAM] detected: [....22] [ip4][..tcp] [....31.13.68.73][..443] -> [...10.24.82.188][47007] [TLS][Facebook][Web][Safe] detected: [....21] [ip4][..tcp] [...10.24.82.188][37553] -> [....31.13.68.84][...80] [HTTP.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [....23] [ip4][..udp] [...10.24.82.188][24596] -> [.....10.188.1.1][...53] + new: [....23] [ip4][..udp] [...10.24.82.188][24596] -> [.....10.188.1.1][...53] detected: [....23] [ip4][..udp] [...10.24.82.188][24596] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][api.facebook.com] detection-update: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] [TLS][Facebook][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....23] [ip4][..udp] [...10.24.82.188][24596] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][api.facebook.com] - new: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] + new: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] detected: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][api.facebook.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....25] [ip4][..udp] [...10.24.82.188][19582] -> [.....10.188.1.1][...53] + new: [....25] [ip4][..udp] [...10.24.82.188][19582] -> [.....10.188.1.1][...53] detected: [....25] [ip4][..udp] [...10.24.82.188][19582] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][graph.facebook.com] detection-update: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][api.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][api.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....25] [ip4][..udp] [...10.24.82.188][19582] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][graph.facebook.com] - new: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] + new: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] detected: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....27] [ip4][..udp] [...10.24.82.188][.4017] -> [.....10.188.1.1][...53] + new: [....27] [ip4][..udp] [...10.24.82.188][.4017] -> [.....10.188.1.1][...53] detected: [....27] [ip4][..udp] [...10.24.82.188][.4017] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][developers.facebook.com] detection-update: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....27] [ip4][..udp] [...10.24.82.188][.4017] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][developers.facebook.com] - new: [....28] [ip4][..udp] [...10.24.82.188][14650] -> [.....10.188.1.1][...53] + new: [....28] [ip4][..udp] [...10.24.82.188][14650] -> [.....10.188.1.1][...53] detected: [....28] [ip4][..udp] [...10.24.82.188][14650] -> [.....10.188.1.1][...53] [DNS][Unknown][Network][Acceptable][2.97.252.173.in-addr.arpa] - new: [....29] [ip4][..tcp] [...10.24.82.188][45211] -> [....31.13.68.84][..443] + new: [....29] [ip4][..tcp] [...10.24.82.188][45211] -> [....31.13.68.84][..443] detection-update: [....28] [ip4][..udp] [...10.24.82.188][14650] -> [.....10.188.1.1][...53] [DNS][Unknown][Network][Acceptable][2.97.252.173.in-addr.arpa] detected: [....29] [ip4][..tcp] [...10.24.82.188][45211] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][developers.facebook.com] RISK: TLS (probably) Not Carrying HTTPS @@ -99,7 +99,7 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....29] [ip4][..tcp] [...10.24.82.188][45211] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][developers.facebook.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....30] [ip4][..tcp] [...10.24.82.188][58927] -> [.54.255.253.199][.5223] [MIDSTREAM] + new: [....30] [ip4][..tcp] [...10.24.82.188][58927] -> [.54.255.253.199][.5223] [MIDSTREAM] detected: [....30] [ip4][..tcp] [...10.24.82.188][58927] -> [.54.255.253.199][.5223] [TLS][AmazonAWS][Web][Safe] RISK: Known Proto on Non Std Port analyse: [....26] [ip4][..tcp] [...10.24.82.188][43581] -> [....31.13.68.70][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] @@ -112,10 +112,10 @@ [IATS(ms)....: 37.0,40.3,0.3,47.7,4.0,72.1,0.7,124.0,0.2,15.9,0.7,16.6,0.2,12.2,67.2,36.0,15.8,0.7,105.9,38.1,60.4,4.5,0.1,3.9,174.3,67.7,16.8,17.0,108.5,0.7,81.1] [PKTLENS.....: 60,44,40,605,44,40,1320,158,40,40,1320,933,40,40,1037,40,298,97,85,40,40,93,830,87,77,85,40,461,40,40,40,40] [ENTROPIES...: 4.7,5.2,4.9,6.7,4.6,5.0,6.4,5.9,4.8,4.7,7.0,7.0,4.7,4.7,7.8,4.9,7.0,6.1,6.0,4.8,4.8,6.0,7.7,5.9,5.8,6.0,4.8,7.5,4.8,5.0,4.9,5.0] - new: [....31] [ip4][..tcp] [...10.24.82.188][42332] -> [.210.103.240.15][..443] [MIDSTREAM] - new: [....32] [ip4][..tcp] [...10.24.82.188][37557] -> [....31.13.68.84][...80] + new: [....31] [ip4][..tcp] [...10.24.82.188][42332] -> [.210.103.240.15][..443] [MIDSTREAM] + new: [....32] [ip4][..tcp] [...10.24.82.188][37557] -> [....31.13.68.84][...80] detected: [....32] [ip4][..tcp] [...10.24.82.188][37557] -> [....31.13.68.84][...80] [HTTP.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [....33] [ip4][..tcp] [...10.24.82.188][45213] -> [....31.13.68.84][..443] + new: [....33] [ip4][..tcp] [...10.24.82.188][45213] -> [....31.13.68.84][..443] detected: [....33] [ip4][..tcp] [...10.24.82.188][45213] -> [....31.13.68.84][..443] [TLS][Facebook][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) analyse: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] @@ -130,7 +130,7 @@ [ENTROPIES...: 4.7,4.7,5.0,4.9,5.2,5.1,5.0,4.7,5.2,4.9,6.5,4.7,7.1,4.8,6.7,4.9,6.6,4.9,5.7,4.8,7.7,4.9,5.5,4.9,7.4,5.0,5.9,4.8,6.8,5.0,5.6,6.4] detection-update: [....15] [ip4][..tcp] [...10.24.82.188][35503] -> [...173.252.97.2][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][] RISK: Obsolete TLS (v1.1 or older) - new: [....34] [ip4][..tcp] [...10.24.82.188][35511] -> [...173.252.97.2][..443] + new: [....34] [ip4][..tcp] [...10.24.82.188][35511] -> [...173.252.97.2][..443] detected: [....34] [ip4][..tcp] [...10.24.82.188][35511] -> [...173.252.97.2][..443] [TLS][Facebook][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....33] [ip4][..tcp] [...10.24.82.188][45213] -> [....31.13.68.84][..443] [TLS][Facebook][Web][Safe][] @@ -141,11 +141,11 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....34] [ip4][..tcp] [...10.24.82.188][35511] -> [...173.252.97.2][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][] RISK: Obsolete TLS (v1.1 or older) - new: [....35] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [MIDSTREAM] - new: [....36] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [MIDSTREAM] + new: [....35] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [MIDSTREAM] + new: [....36] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [MIDSTREAM] detected: [....36] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [TLS][Google][Web][Safe] RISK: Known Proto on Non Std Port - new: [....37] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [MIDSTREAM] + new: [....37] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [MIDSTREAM] detected: [....37] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [TLS][Google][Web][Safe] analyse: [....34] [ip4][..tcp] [...10.24.82.188][35511] -> [...173.252.97.2][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy @@ -160,7 +160,7 @@ update: [....19] [ip4][.icmp] [...10.24.82.188] -> [...10.188.191.1] [ICMP][Unknown][Network][Acceptable] detection-update: [....30] [ip4][..tcp] [...10.24.82.188][58927] -> [.54.255.253.199][.5223] [TLS][AmazonAWS][Web][Safe] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....38] [ip4][..tcp] [...10.24.82.188][58964] -> [.54.255.253.199][.5223] + new: [....38] [ip4][..tcp] [...10.24.82.188][58964] -> [.54.255.253.199][.5223] detected: [....38] [ip4][..tcp] [...10.24.82.188][58964] -> [.54.255.253.199][.5223] [TLS][AmazonAWS][Web][Safe][] RISK: Known Proto on Non Std Port, Obsolete TLS (v1.1 or older) idle: [.....4] [ip4][..udp] [...10.24.82.188][41909] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable] @@ -185,7 +185,7 @@ idle: [.....7] [ip4][..udp] [...10.24.82.188][.5929] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable] guessed: [....16] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34503] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....16] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34503] + end: [....16] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34503] idle: [....27] [ip4][..udp] [...10.24.82.188][.4017] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun] idle: [....19] [ip4][.icmp] [...10.24.82.188] -> [...10.188.191.1] [ICMP][Unknown][Network][Acceptable] idle: [....23] [ip4][..udp] [...10.24.82.188][24596] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun] @@ -193,7 +193,7 @@ idle: [....37] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [TLS][Google][Web][Safe] guessed: [....13] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Fully encrypted flow - idle: [....13] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] + idle: [....13] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] end: [....20] [ip4][..tcp] [...10.24.82.188][37821] -> [.210.103.240.15][..443] [TLS.KakaoTalk][Unknown][Chat][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher idle: [....28] [ip4][..udp] [...10.24.82.188][14650] -> [.....10.188.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -205,7 +205,7 @@ RISK: Known Proto on Non Std Port idle: [.....5] [ip4][..udp] [...10.24.82.188][12908] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable] guessed: [....31] [ip4][..tcp] [...10.24.82.188][42332] -> [.210.103.240.15][..443] [TLS][Unknown][Web][Safe] - end: [....31] [ip4][..tcp] [...10.24.82.188][42332] -> [.210.103.240.15][..443] + end: [....31] [ip4][..tcp] [...10.24.82.188][42332] -> [.210.103.240.15][..443] idle: [.....2] [ip4][..udp] [...10.24.82.188][35603] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable] idle: [....24] [ip4][..tcp] [...10.24.82.188][45209] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] RISK: TLS (probably) Not Carrying HTTPS @@ -214,8 +214,8 @@ idle: [....33] [ip4][..tcp] [...10.24.82.188][45213] -> [....31.13.68.84][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] RISK: Obsolete TLS (v1.1 or older) guessed: [....14] [ip4][..tcp] [..216.58.221.10][...80] -> [...10.24.82.188][35922] [HTTP][Google][Web][Acceptable][] - end: [....14] [ip4][..tcp] [..216.58.221.10][...80] -> [...10.24.82.188][35922] + end: [....14] [ip4][..tcp] [..216.58.221.10][...80] -> [...10.24.82.188][35922] guessed: [....35] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [TLS][Unknown][Web][Safe] - idle: [....35] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] + idle: [....35] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] idle: [.....8] [ip4][..udp] [...10.24.82.188][.9094] -> [.....10.188.1.1][...53] [DNS.KakaoTalk][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/KakaoTalk_talk.pcap.out b/test/results/flow-info/default/KakaoTalk_talk.pcap.out index 92cb796bf..f55e3f63a 100644 --- a/test/results/flow-info/default/KakaoTalk_talk.pcap.out +++ b/test/results/flow-info/default/KakaoTalk_talk.pcap.out @@ -1,34 +1,34 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34533] [MIDSTREAM] - new: [.....3] [ip4][..tcp] [...10.24.82.188][58916] -> [.54.255.185.236][.5222] [MIDSTREAM] - new: [.....4] [ip4][..tcp] [...10.24.82.188][48489] -> [203.205.147.215][...80] - new: [.....5] [ip4][..tcp] [.216.58.220.161][..443] -> [...10.24.82.188][56697] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34533] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...10.24.82.188][58916] -> [.54.255.185.236][.5222] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [...10.24.82.188][48489] -> [203.205.147.215][...80] + new: [.....5] [ip4][..tcp] [.216.58.220.161][..443] -> [...10.24.82.188][56697] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [...10.24.82.188][48489] -> [203.205.147.215][...80] [HTTP_Proxy.QQ][Tencent][Chat][Fun][hkminorshort.weixin.qq.com] RISK: Known Proto on Non Std Port - new: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] + new: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] detected: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Obsolete TLS (v1.1 or older) detection-update: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] [TLS.KakaoTalk][Unknown][Chat][Acceptable][] RISK: Known Proto on Non Std Port, Self-signed Cert, Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [.....7] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [MIDSTREAM] - new: [.....8] [ip4][..tcp] [...10.24.82.188][58857] -> [..110.76.143.50][.9001] + new: [.....7] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [...10.24.82.188][58857] -> [..110.76.143.50][.9001] detected: [.....8] [ip4][..tcp] [...10.24.82.188][58857] -> [..110.76.143.50][.9001] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Obsolete TLS (v1.1 or older) detection-update: [.....8] [ip4][..tcp] [...10.24.82.188][58857] -> [..110.76.143.50][.9001] [TLS.KakaoTalk][Unknown][Chat][Acceptable][] RISK: Known Proto on Non Std Port, Self-signed Cert, Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [.....9] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [TLS][Google][Web][Safe] RISK: Known Proto on Non Std Port - new: [....10] [ip4][..udp] [...10.24.82.188][11321] -> [....1.201.1.174][23045] + new: [....10] [ip4][..udp] [...10.24.82.188][11321] -> [....1.201.1.174][23045] detected: [....10] [ip4][..udp] [...10.24.82.188][11321] -> [....1.201.1.174][23045] [KakaoTalk_Voice][Unknown][VoIP][Acceptable] - new: [....11] [ip4][..udp] [...10.24.82.188][10269] -> [....1.201.1.174][23047] + new: [....11] [ip4][..udp] [...10.24.82.188][10269] -> [....1.201.1.174][23047] detected: [....11] [ip4][..udp] [...10.24.82.188][10269] -> [....1.201.1.174][23047] [KakaoTalk_Voice][Unknown][VoIP][Acceptable] - new: [....12] [ip4][..udp] [...10.24.82.188][11320] -> [....1.201.1.174][23044] + new: [....12] [ip4][..udp] [...10.24.82.188][11320] -> [....1.201.1.174][23044] detected: [....12] [ip4][..udp] [...10.24.82.188][11320] -> [....1.201.1.174][23044] [RTP][Unknown][Media][Acceptable] - new: [....13] [ip4][..udp] [...10.24.82.188][10268] -> [....1.201.1.174][23046] + new: [....13] [ip4][..udp] [...10.24.82.188][10268] -> [....1.201.1.174][23046] detected: [....13] [ip4][..udp] [...10.24.82.188][10268] -> [....1.201.1.174][23046] [RTP][Unknown][Media][Acceptable] analyse: [....12] [ip4][..udp] [...10.24.82.188][11320] -> [....1.201.1.174][23044] [RTP][Unknown][Media][Acceptable] min| max| avg| stddev| variance| entropy @@ -50,10 +50,10 @@ [IATS(ms)....: 36.1,39.2,140.3,102.0,35.2,98.1,7.9,55.8,42.0,93.4,6.8,89.9,91.8,48.2,40.2,100.1,12.0,81.5,89.4,7.0,84.1,40.7,87.7,54.9,38.8,107.9,4.2,87.6,68.5,32.3,143.9] [PKTLENS.....: 107,176,99,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,83,150,125,83] [ENTROPIES...: 6.2,6.7,6.2,5.8,5.8,5.9,6.0,5.9,5.9,5.9,5.9,6.0,5.9,5.8,5.9,5.9,6.0,6.0,6.0,6.0,5.8,5.9,5.9,5.9,6.0,6.0,5.9,6.0,5.8,6.7,6.3,6.0] - new: [....14] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [MIDSTREAM] + new: [....14] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [MIDSTREAM] detected: [....14] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [TLS][Google][Web][Safe] - new: [....15] [ip4][..tcp] [..173.252.122.1][..443] -> [...10.24.82.188][52123] [MIDSTREAM] - new: [....16] [ip4][..tcp] [...10.24.82.188][53974] -> [203.205.151.233][.8080] [MIDSTREAM] + new: [....15] [ip4][..tcp] [..173.252.122.1][..443] -> [...10.24.82.188][52123] [MIDSTREAM] + new: [....16] [ip4][..tcp] [...10.24.82.188][53974] -> [203.205.151.233][.8080] [MIDSTREAM] analyse: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] [TLS.KakaoTalk][Unknown][Chat][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.002| 20.337| 1.801| 4.155| 17264411.673| 2.900] @@ -74,10 +74,10 @@ [IATS(ms)....: 148.0,148.3,14.4,196.3,3.7,185.6,22.2,228.4,215.7,291.7,316.8,4536.4,4872.6,301.5,147.9,147.9,122.3,336.2,8596.6,8810.7,73.7,557.6,700.9,602.5,20472.0,917.8,21237.1,519.3,0.3,0.2,1054.3] [PKTLENS.....: 60,60,52,194,52,904,52,378,286,750,718,52,846,830,52,350,52,222,52,350,52,222,222,52,64,238,238,414,52,52,52,64] [ENTROPIES...: 4.7,5.2,5.2,5.3,5.2,7.4,5.2,7.4,7.0,7.7,7.7,5.2,7.8,7.8,5.2,7.3,5.1,7.0,5.2,7.2,5.2,6.8,6.8,5.1,5.1,7.1,7.0,7.4,5.2,5.2,5.2,5.2] - new: [....17] [ip4][..tcp] [173.194.117.229][..443] -> [...10.24.82.188][38380] [MIDSTREAM] - new: [....18] [ip4][..tcp] [.173.252.88.128][..443] -> [...10.24.82.188][59912] [MIDSTREAM] - new: [....19] [ip4][..tcp] [...10.24.82.188][59954] -> [.173.252.88.128][..443] - new: [....20] [ip4][..udp] [...10.24.82.188][25223] -> [.....10.188.1.1][...53] + new: [....17] [ip4][..tcp] [173.194.117.229][..443] -> [...10.24.82.188][38380] [MIDSTREAM] + new: [....18] [ip4][..tcp] [.173.252.88.128][..443] -> [...10.24.82.188][59912] [MIDSTREAM] + new: [....19] [ip4][..tcp] [...10.24.82.188][59954] -> [.173.252.88.128][..443] + new: [....20] [ip4][..udp] [...10.24.82.188][25223] -> [.....10.188.1.1][...53] detected: [....20] [ip4][..udp] [...10.24.82.188][25223] -> [.....10.188.1.1][...53] [DNS.Facebook][Unknown][Network][Fun][mqtt.facebook.com] detected: [....19] [ip4][..tcp] [...10.24.82.188][59954] -> [.173.252.88.128][..443] [TLS][Facebook][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) @@ -86,34 +86,34 @@ RISK: Obsolete TLS (v1.1 or older) guessed: [....16] [ip4][..tcp] [...10.24.82.188][53974] -> [203.205.151.233][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....16] [ip4][..tcp] [...10.24.82.188][53974] -> [203.205.151.233][.8080] + idle: [....16] [ip4][..tcp] [...10.24.82.188][53974] -> [203.205.151.233][.8080] guessed: [....18] [ip4][..tcp] [.173.252.88.128][..443] -> [...10.24.82.188][59912] [TLS][Facebook][Web][Safe] RISK: Unidirectional Traffic - end: [....18] [ip4][..tcp] [.173.252.88.128][..443] -> [...10.24.82.188][59912] + end: [....18] [ip4][..tcp] [.173.252.88.128][..443] -> [...10.24.82.188][59912] idle: [....19] [ip4][..tcp] [...10.24.82.188][59954] -> [.173.252.88.128][..443] [TLS][Facebook][Web][Safe] RISK: Obsolete TLS (v1.1 or older) guessed: [.....3] [ip4][..tcp] [...10.24.82.188][58916] -> [.54.255.185.236][.5222] [AmazonAWS][AmazonAWS][Cloud][Acceptable] - idle: [.....3] [ip4][..tcp] [...10.24.82.188][58916] -> [.54.255.185.236][.5222] + idle: [.....3] [ip4][..tcp] [...10.24.82.188][58916] -> [.54.255.185.236][.5222] guessed: [....15] [ip4][..tcp] [..173.252.122.1][..443] -> [...10.24.82.188][52123] [TLS][Facebook][Web][Safe] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....15] [ip4][..tcp] [..173.252.122.1][..443] -> [...10.24.82.188][52123] + end: [....15] [ip4][..tcp] [..173.252.122.1][..443] -> [...10.24.82.188][52123] guessed: [.....5] [ip4][..tcp] [.216.58.220.161][..443] -> [...10.24.82.188][56697] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic, TCP Connection Issues - end: [.....5] [ip4][..tcp] [.216.58.220.161][..443] -> [...10.24.82.188][56697] + end: [.....5] [ip4][..tcp] [.216.58.220.161][..443] -> [...10.24.82.188][56697] guessed: [....17] [ip4][..tcp] [173.194.117.229][..443] -> [...10.24.82.188][38380] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....17] [ip4][..tcp] [173.194.117.229][..443] -> [...10.24.82.188][38380] + end: [....17] [ip4][..tcp] [173.194.117.229][..443] -> [...10.24.82.188][38380] idle: [....13] [ip4][..udp] [...10.24.82.188][10268] -> [....1.201.1.174][23046] [RTP][Unknown][Media][Acceptable] idle: [....11] [ip4][..udp] [...10.24.82.188][10269] -> [....1.201.1.174][23047] [KakaoTalk_Voice][Unknown][VoIP][Acceptable] end: [.....4] [ip4][..tcp] [...10.24.82.188][48489] -> [203.205.147.215][...80] [HTTP_Proxy.QQ][Tencent][Chat][Fun] RISK: Known Proto on Non Std Port guessed: [.....2] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34533] [HTTP][Unknown][Web][Acceptable][] - end: [.....2] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34533] + end: [.....2] [ip4][..tcp] [..120.28.26.242][...80] -> [...10.24.82.188][34533] idle: [.....6] [ip4][..tcp] [...10.24.82.188][32968] -> [..110.76.143.50][.8080] [TLS.KakaoTalk][Unknown][Chat][Acceptable] RISK: Known Proto on Non Std Port, Self-signed Cert, Obsolete TLS (v1.1 or older), Weak TLS Cipher idle: [....14] [ip4][..tcp] [...10.24.82.188][49217] -> [.216.58.220.174][..443] [TLS][Google][Web][Safe] guessed: [.....1] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] - idle: [.....1] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] + idle: [.....1] [ip4][..tcp] [...10.24.82.188][51021] -> [.103.246.57.251][.8080] idle: [.....8] [ip4][..tcp] [...10.24.82.188][58857] -> [..110.76.143.50][.9001] [TLS.KakaoTalk][Unknown][Chat][Acceptable] RISK: Known Proto on Non Std Port, Self-signed Cert, Obsolete TLS (v1.1 or older), Weak TLS Cipher idle: [.....9] [ip4][..tcp] [...10.24.82.188][34686] -> [.173.194.72.188][.5228] [TLS][Google][Web][Safe] @@ -122,5 +122,5 @@ idle: [....12] [ip4][..udp] [...10.24.82.188][11320] -> [....1.201.1.174][23044] [RTP][Unknown][Media][Acceptable] idle: [....10] [ip4][..udp] [...10.24.82.188][11321] -> [....1.201.1.174][23045] [KakaoTalk_Voice][Unknown][VoIP][Acceptable] guessed: [.....7] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] [TLS][Unknown][Web][Safe] - idle: [.....7] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] + idle: [.....7] [ip4][..tcp] [..139.150.0.125][..443] -> [...10.24.82.188][46947] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/NTPv2.pcap.out b/test/results/flow-info/default/NTPv2.pcap.out index 022c4bcfd..f44b8c1fd 100644 --- a/test/results/flow-info/default/NTPv2.pcap.out +++ b/test/results/flow-info/default/NTPv2.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..208.104.95.10][..123] -> [.....78.46.76.2][...80] + new: [.....1] [ip4][..udp] [..208.104.95.10][..123] -> [.....78.46.76.2][...80] detected: [.....1] [ip4][..udp] [..208.104.95.10][..123] -> [.....78.46.76.2][...80] [NTP][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [..208.104.95.10][..123] -> [.....78.46.76.2][...80] [NTP][Unknown][System][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/NTPv3.pcap.out b/test/results/flow-info/default/NTPv3.pcap.out index e197577a5..2007d7139 100644 --- a/test/results/flow-info/default/NTPv3.pcap.out +++ b/test/results/flow-info/default/NTPv3.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.175.144.140.29][..123] -> [.....78.46.76.2][...80] + new: [.....1] [ip4][..udp] [.175.144.140.29][..123] -> [.....78.46.76.2][...80] detected: [.....1] [ip4][..udp] [.175.144.140.29][..123] -> [.....78.46.76.2][...80] [NTP][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [.175.144.140.29][..123] -> [.....78.46.76.2][...80] [NTP][Unknown][System][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/NTPv4.pcap.out b/test/results/flow-info/default/NTPv4.pcap.out index ddf27f2b0..8f250125d 100644 --- a/test/results/flow-info/default/NTPv4.pcap.out +++ b/test/results/flow-info/default/NTPv4.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...85.22.62.120][..123] -> [....78.46.76.11][..123] + new: [.....1] [ip4][..udp] [...85.22.62.120][..123] -> [....78.46.76.11][..123] detected: [.....1] [ip4][..udp] [...85.22.62.120][..123] -> [....78.46.76.11][..123] [NTP][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [...85.22.62.120][..123] -> [....78.46.76.11][..123] [NTP][Unknown][System][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/Oscar.pcap.out b/test/results/flow-info/default/Oscar.pcap.out index f9553705b..94605389c 100644 --- a/test/results/flow-info/default/Oscar.pcap.out +++ b/test/results/flow-info/default/Oscar.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] - analyse: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] + new: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] + analyse: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 58.215| 3.883| 14.268| 203566836.875| 1.300] [PKTLEN......: 40.000| 1400.000| 172.500| 263.300| 69345.600| 4.000] @@ -14,5 +14,5 @@ [ENTROPIES...: 4.4,4.9,4.7,7.1,4.7,4.7,5.2,4.7,4.0,4.3,4.6,4.3,3.8,3.9,4.6,4.3,4.5,3.5,4.2,4.6,3.7,4.6,5.5,4.5,3.4,4.8,4.5,5.0,4.6,4.5,4.5,4.8] guessed: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] [TLS][Unknown][Web][Safe] RISK: Fully encrypted flow - idle: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] + idle: [.....1] [ip4][..tcp] [.....10.30.29.3][63357] -> [.178.237.24.249][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/TivoDVR.pcap.out b/test/results/flow-info/default/TivoDVR.pcap.out index af6875ba9..48a6823f9 100644 --- a/test/results/flow-info/default/TivoDVR.pcap.out +++ b/test/results/flow-info/default/TivoDVR.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..98.245.242.69][.2190] -> [255.255.255.255][.2190] + new: [.....1] [ip4][..udp] [..98.245.242.69][.2190] -> [255.255.255.255][.2190] detected: [.....1] [ip4][..udp] [..98.245.242.69][.2190] -> [255.255.255.255][.2190] [TiVoConnect][Unknown][Network][Fun] idle: [.....1] [ip4][..udp] [..98.245.242.69][.2190] -> [255.255.255.255][.2190] [TiVoConnect][Unknown][Network][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/WebattackRCE.pcap.out b/test/results/flow-info/default/WebattackRCE.pcap.out index aa6d0b426..633f9311f 100644 --- a/test/results/flow-info/default/WebattackRCE.pcap.out +++ b/test/results/flow-info/default/WebattackRCE.pcap.out @@ -1,2395 +1,2395 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][49544] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [......127.0.0.1][49544] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [......127.0.0.1][49544] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....2] [ip4][..tcp] [......127.0.0.1][49546] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [......127.0.0.1][49546] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [......127.0.0.1][49546] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....3] [ip4][..tcp] [......127.0.0.1][49548] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [......127.0.0.1][49548] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [......127.0.0.1][49548] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....4] [ip4][..tcp] [......127.0.0.1][49550] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [......127.0.0.1][49550] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [......127.0.0.1][49550] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....5] [ip4][..tcp] [......127.0.0.1][49552] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [......127.0.0.1][49552] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [......127.0.0.1][49552] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Possible Exploit - new: [.....6] [ip4][..tcp] [......127.0.0.1][49554] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [......127.0.0.1][49554] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [......127.0.0.1][49554] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....7] [ip4][..tcp] [......127.0.0.1][49556] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [......127.0.0.1][49556] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [......127.0.0.1][49556] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....8] [ip4][..tcp] [......127.0.0.1][49558] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [......127.0.0.1][49558] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [......127.0.0.1][49558] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....9] [ip4][..tcp] [......127.0.0.1][49560] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [......127.0.0.1][49560] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [......127.0.0.1][49560] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....10] [ip4][..tcp] [......127.0.0.1][49562] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....10] [ip4][..tcp] [......127.0.0.1][49562] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....10] [ip4][..tcp] [......127.0.0.1][49562] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....11] [ip4][..tcp] [......127.0.0.1][49564] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....11] [ip4][..tcp] [......127.0.0.1][49564] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....11] [ip4][..tcp] [......127.0.0.1][49564] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....12] [ip4][..tcp] [......127.0.0.1][49566] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....12] [ip4][..tcp] [......127.0.0.1][49566] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....12] [ip4][..tcp] [......127.0.0.1][49566] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....13] [ip4][..tcp] [......127.0.0.1][49568] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....13] [ip4][..tcp] [......127.0.0.1][49568] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....13] [ip4][..tcp] [......127.0.0.1][49568] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....14] [ip4][..tcp] [......127.0.0.1][49570] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....14] [ip4][..tcp] [......127.0.0.1][49570] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....14] [ip4][..tcp] [......127.0.0.1][49570] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....15] [ip4][..tcp] [......127.0.0.1][49572] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....15] [ip4][..tcp] [......127.0.0.1][49572] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....15] [ip4][..tcp] [......127.0.0.1][49572] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....16] [ip4][..tcp] [......127.0.0.1][49574] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....16] [ip4][..tcp] [......127.0.0.1][49574] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....16] [ip4][..tcp] [......127.0.0.1][49574] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....17] [ip4][..tcp] [......127.0.0.1][49576] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....17] [ip4][..tcp] [......127.0.0.1][49576] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....17] [ip4][..tcp] [......127.0.0.1][49576] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....18] [ip4][..tcp] [......127.0.0.1][49578] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....18] [ip4][..tcp] [......127.0.0.1][49578] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....18] [ip4][..tcp] [......127.0.0.1][49578] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....19] [ip4][..tcp] [......127.0.0.1][49580] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....19] [ip4][..tcp] [......127.0.0.1][49580] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....19] [ip4][..tcp] [......127.0.0.1][49580] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....20] [ip4][..tcp] [......127.0.0.1][49582] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....20] [ip4][..tcp] [......127.0.0.1][49582] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....20] [ip4][..tcp] [......127.0.0.1][49582] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....21] [ip4][..tcp] [......127.0.0.1][49584] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....21] [ip4][..tcp] [......127.0.0.1][49584] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....21] [ip4][..tcp] [......127.0.0.1][49584] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....22] [ip4][..tcp] [......127.0.0.1][49586] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....22] [ip4][..tcp] [......127.0.0.1][49586] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....22] [ip4][..tcp] [......127.0.0.1][49586] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....23] [ip4][..tcp] [......127.0.0.1][49588] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....23] [ip4][..tcp] [......127.0.0.1][49588] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....23] [ip4][..tcp] [......127.0.0.1][49588] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....24] [ip4][..tcp] [......127.0.0.1][49590] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....24] [ip4][..tcp] [......127.0.0.1][49590] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....24] [ip4][..tcp] [......127.0.0.1][49590] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....25] [ip4][..tcp] [......127.0.0.1][49592] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....25] [ip4][..tcp] [......127.0.0.1][49592] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....25] [ip4][..tcp] [......127.0.0.1][49592] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....26] [ip4][..tcp] [......127.0.0.1][49594] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....26] [ip4][..tcp] [......127.0.0.1][49594] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....26] [ip4][..tcp] [......127.0.0.1][49594] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....27] [ip4][..tcp] [......127.0.0.1][49596] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....27] [ip4][..tcp] [......127.0.0.1][49596] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....27] [ip4][..tcp] [......127.0.0.1][49596] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....28] [ip4][..tcp] [......127.0.0.1][49598] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....28] [ip4][..tcp] [......127.0.0.1][49598] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....28] [ip4][..tcp] [......127.0.0.1][49598] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....29] [ip4][..tcp] [......127.0.0.1][49600] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....29] [ip4][..tcp] [......127.0.0.1][49600] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....29] [ip4][..tcp] [......127.0.0.1][49600] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....30] [ip4][..tcp] [......127.0.0.1][49602] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....30] [ip4][..tcp] [......127.0.0.1][49602] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....30] [ip4][..tcp] [......127.0.0.1][49602] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....31] [ip4][..tcp] [......127.0.0.1][49604] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....31] [ip4][..tcp] [......127.0.0.1][49604] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....31] [ip4][..tcp] [......127.0.0.1][49604] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....32] [ip4][..tcp] [......127.0.0.1][49606] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....32] [ip4][..tcp] [......127.0.0.1][49606] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....32] [ip4][..tcp] [......127.0.0.1][49606] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....33] [ip4][..tcp] [......127.0.0.1][49608] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....33] [ip4][..tcp] [......127.0.0.1][49608] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....33] [ip4][..tcp] [......127.0.0.1][49608] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....34] [ip4][..tcp] [......127.0.0.1][49610] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....34] [ip4][..tcp] [......127.0.0.1][49610] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....34] [ip4][..tcp] [......127.0.0.1][49610] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....35] [ip4][..tcp] [......127.0.0.1][49612] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....35] [ip4][..tcp] [......127.0.0.1][49612] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....35] [ip4][..tcp] [......127.0.0.1][49612] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....36] [ip4][..tcp] [......127.0.0.1][49614] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....36] [ip4][..tcp] [......127.0.0.1][49614] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....36] [ip4][..tcp] [......127.0.0.1][49614] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....37] [ip4][..tcp] [......127.0.0.1][49616] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....37] [ip4][..tcp] [......127.0.0.1][49616] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....37] [ip4][..tcp] [......127.0.0.1][49616] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....38] [ip4][..tcp] [......127.0.0.1][49618] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....38] [ip4][..tcp] [......127.0.0.1][49618] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....38] [ip4][..tcp] [......127.0.0.1][49618] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....39] [ip4][..tcp] [......127.0.0.1][49620] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....39] [ip4][..tcp] [......127.0.0.1][49620] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....39] [ip4][..tcp] [......127.0.0.1][49620] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....40] [ip4][..tcp] [......127.0.0.1][49622] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....40] [ip4][..tcp] [......127.0.0.1][49622] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....40] [ip4][..tcp] [......127.0.0.1][49622] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....41] [ip4][..tcp] [......127.0.0.1][49624] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....41] [ip4][..tcp] [......127.0.0.1][49624] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....41] [ip4][..tcp] [......127.0.0.1][49624] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....42] [ip4][..tcp] [......127.0.0.1][49626] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....42] [ip4][..tcp] [......127.0.0.1][49626] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....42] [ip4][..tcp] [......127.0.0.1][49626] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....43] [ip4][..tcp] [......127.0.0.1][49628] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....43] [ip4][..tcp] [......127.0.0.1][49628] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....43] [ip4][..tcp] [......127.0.0.1][49628] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....44] [ip4][..tcp] [......127.0.0.1][49630] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....44] [ip4][..tcp] [......127.0.0.1][49630] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....44] [ip4][..tcp] [......127.0.0.1][49630] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....45] [ip4][..tcp] [......127.0.0.1][49632] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....45] [ip4][..tcp] [......127.0.0.1][49632] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....45] [ip4][..tcp] [......127.0.0.1][49632] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....46] [ip4][..tcp] [......127.0.0.1][49634] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....46] [ip4][..tcp] [......127.0.0.1][49634] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....46] [ip4][..tcp] [......127.0.0.1][49634] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....47] [ip4][..tcp] [......127.0.0.1][49636] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....47] [ip4][..tcp] [......127.0.0.1][49636] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....47] [ip4][..tcp] [......127.0.0.1][49636] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....48] [ip4][..tcp] [......127.0.0.1][49638] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....48] [ip4][..tcp] [......127.0.0.1][49638] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....48] [ip4][..tcp] [......127.0.0.1][49638] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....49] [ip4][..tcp] [......127.0.0.1][49640] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....49] [ip4][..tcp] [......127.0.0.1][49640] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....49] [ip4][..tcp] [......127.0.0.1][49640] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....50] [ip4][..tcp] [......127.0.0.1][49642] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....50] [ip4][..tcp] [......127.0.0.1][49642] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....50] [ip4][..tcp] [......127.0.0.1][49642] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....51] [ip4][..tcp] [......127.0.0.1][49644] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....51] [ip4][..tcp] [......127.0.0.1][49644] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....51] [ip4][..tcp] [......127.0.0.1][49644] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....52] [ip4][..tcp] [......127.0.0.1][49646] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....52] [ip4][..tcp] [......127.0.0.1][49646] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....52] [ip4][..tcp] [......127.0.0.1][49646] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....53] [ip4][..tcp] [......127.0.0.1][49648] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....53] [ip4][..tcp] [......127.0.0.1][49648] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....53] [ip4][..tcp] [......127.0.0.1][49648] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Crawler/Bot - new: [....54] [ip4][..tcp] [......127.0.0.1][49650] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....54] [ip4][..tcp] [......127.0.0.1][49650] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....54] [ip4][..tcp] [......127.0.0.1][49650] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....55] [ip4][..tcp] [......127.0.0.1][49652] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....55] [ip4][..tcp] [......127.0.0.1][49652] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....55] [ip4][..tcp] [......127.0.0.1][49652] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....56] [ip4][..tcp] [......127.0.0.1][49654] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....56] [ip4][..tcp] [......127.0.0.1][49654] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....56] [ip4][..tcp] [......127.0.0.1][49654] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....57] [ip4][..tcp] [......127.0.0.1][49656] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....57] [ip4][..tcp] [......127.0.0.1][49656] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....57] [ip4][..tcp] [......127.0.0.1][49656] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....58] [ip4][..tcp] [......127.0.0.1][49658] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....58] [ip4][..tcp] [......127.0.0.1][49658] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....58] [ip4][..tcp] [......127.0.0.1][49658] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....59] [ip4][..tcp] [......127.0.0.1][49660] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....59] [ip4][..tcp] [......127.0.0.1][49660] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....59] [ip4][..tcp] [......127.0.0.1][49660] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....60] [ip4][..tcp] [......127.0.0.1][49662] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....60] [ip4][..tcp] [......127.0.0.1][49662] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....60] [ip4][..tcp] [......127.0.0.1][49662] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....61] [ip4][..tcp] [......127.0.0.1][49664] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....61] [ip4][..tcp] [......127.0.0.1][49664] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....61] [ip4][..tcp] [......127.0.0.1][49664] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....62] [ip4][..tcp] [......127.0.0.1][49666] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....62] [ip4][..tcp] [......127.0.0.1][49666] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....62] [ip4][..tcp] [......127.0.0.1][49666] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....63] [ip4][..tcp] [......127.0.0.1][49668] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....63] [ip4][..tcp] [......127.0.0.1][49668] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....63] [ip4][..tcp] [......127.0.0.1][49668] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....64] [ip4][..tcp] [......127.0.0.1][49670] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....64] [ip4][..tcp] [......127.0.0.1][49670] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....64] [ip4][..tcp] [......127.0.0.1][49670] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....65] [ip4][..tcp] [......127.0.0.1][49672] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....65] [ip4][..tcp] [......127.0.0.1][49672] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....65] [ip4][..tcp] [......127.0.0.1][49672] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....66] [ip4][..tcp] [......127.0.0.1][49674] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....66] [ip4][..tcp] [......127.0.0.1][49674] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....66] [ip4][..tcp] [......127.0.0.1][49674] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....67] [ip4][..tcp] [......127.0.0.1][49676] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....67] [ip4][..tcp] [......127.0.0.1][49676] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....67] [ip4][..tcp] [......127.0.0.1][49676] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....68] [ip4][..tcp] [......127.0.0.1][49678] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....68] [ip4][..tcp] [......127.0.0.1][49678] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....68] [ip4][..tcp] [......127.0.0.1][49678] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....69] [ip4][..tcp] [......127.0.0.1][49680] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....69] [ip4][..tcp] [......127.0.0.1][49680] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....69] [ip4][..tcp] [......127.0.0.1][49680] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....70] [ip4][..tcp] [......127.0.0.1][49682] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....70] [ip4][..tcp] [......127.0.0.1][49682] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....70] [ip4][..tcp] [......127.0.0.1][49682] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....71] [ip4][..tcp] [......127.0.0.1][49684] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....71] [ip4][..tcp] [......127.0.0.1][49684] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....71] [ip4][..tcp] [......127.0.0.1][49684] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....72] [ip4][..tcp] [......127.0.0.1][49686] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....72] [ip4][..tcp] [......127.0.0.1][49686] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....72] [ip4][..tcp] [......127.0.0.1][49686] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....73] [ip4][..tcp] [......127.0.0.1][49688] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....73] [ip4][..tcp] [......127.0.0.1][49688] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....73] [ip4][..tcp] [......127.0.0.1][49688] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....74] [ip4][..tcp] [......127.0.0.1][49690] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....74] [ip4][..tcp] [......127.0.0.1][49690] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....74] [ip4][..tcp] [......127.0.0.1][49690] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....75] [ip4][..tcp] [......127.0.0.1][49692] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....75] [ip4][..tcp] [......127.0.0.1][49692] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....75] [ip4][..tcp] [......127.0.0.1][49692] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....76] [ip4][..tcp] [......127.0.0.1][49694] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....76] [ip4][..tcp] [......127.0.0.1][49694] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....76] [ip4][..tcp] [......127.0.0.1][49694] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....77] [ip4][..tcp] [......127.0.0.1][49696] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....77] [ip4][..tcp] [......127.0.0.1][49696] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....77] [ip4][..tcp] [......127.0.0.1][49696] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....78] [ip4][..tcp] [......127.0.0.1][49698] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....78] [ip4][..tcp] [......127.0.0.1][49698] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....78] [ip4][..tcp] [......127.0.0.1][49698] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....79] [ip4][..tcp] [......127.0.0.1][49700] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....79] [ip4][..tcp] [......127.0.0.1][49700] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....79] [ip4][..tcp] [......127.0.0.1][49700] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....80] [ip4][..tcp] [......127.0.0.1][49702] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....80] [ip4][..tcp] [......127.0.0.1][49702] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....80] [ip4][..tcp] [......127.0.0.1][49702] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....81] [ip4][..tcp] [......127.0.0.1][49704] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....81] [ip4][..tcp] [......127.0.0.1][49704] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....81] [ip4][..tcp] [......127.0.0.1][49704] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....82] [ip4][..tcp] [......127.0.0.1][49706] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....82] [ip4][..tcp] [......127.0.0.1][49706] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....82] [ip4][..tcp] [......127.0.0.1][49706] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....83] [ip4][..tcp] [......127.0.0.1][49708] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....83] [ip4][..tcp] [......127.0.0.1][49708] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....83] [ip4][..tcp] [......127.0.0.1][49708] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....84] [ip4][..tcp] [......127.0.0.1][49710] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....84] [ip4][..tcp] [......127.0.0.1][49710] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....84] [ip4][..tcp] [......127.0.0.1][49710] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....85] [ip4][..tcp] [......127.0.0.1][49712] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....85] [ip4][..tcp] [......127.0.0.1][49712] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....85] [ip4][..tcp] [......127.0.0.1][49712] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....86] [ip4][..tcp] [......127.0.0.1][49714] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....86] [ip4][..tcp] [......127.0.0.1][49714] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....86] [ip4][..tcp] [......127.0.0.1][49714] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....87] [ip4][..tcp] [......127.0.0.1][49716] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....87] [ip4][..tcp] [......127.0.0.1][49716] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....87] [ip4][..tcp] [......127.0.0.1][49716] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....88] [ip4][..tcp] [......127.0.0.1][49718] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....88] [ip4][..tcp] [......127.0.0.1][49718] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....88] [ip4][..tcp] [......127.0.0.1][49718] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....89] [ip4][..tcp] [......127.0.0.1][49720] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....89] [ip4][..tcp] [......127.0.0.1][49720] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....89] [ip4][..tcp] [......127.0.0.1][49720] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port - new: [....90] [ip4][..tcp] [......127.0.0.1][49722] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....90] [ip4][..tcp] [......127.0.0.1][49722] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....90] [ip4][..tcp] [......127.0.0.1][49722] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....91] [ip4][..tcp] [......127.0.0.1][49724] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....91] [ip4][..tcp] [......127.0.0.1][49724] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....91] [ip4][..tcp] [......127.0.0.1][49724] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....92] [ip4][..tcp] [......127.0.0.1][49726] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....92] [ip4][..tcp] [......127.0.0.1][49726] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....92] [ip4][..tcp] [......127.0.0.1][49726] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....93] [ip4][..tcp] [......127.0.0.1][49728] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....93] [ip4][..tcp] [......127.0.0.1][49728] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....93] [ip4][..tcp] [......127.0.0.1][49728] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....94] [ip4][..tcp] [......127.0.0.1][49730] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....94] [ip4][..tcp] [......127.0.0.1][49730] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....94] [ip4][..tcp] [......127.0.0.1][49730] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....95] [ip4][..tcp] [......127.0.0.1][49732] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....95] [ip4][..tcp] [......127.0.0.1][49732] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....95] [ip4][..tcp] [......127.0.0.1][49732] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....96] [ip4][..tcp] [......127.0.0.1][49734] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....96] [ip4][..tcp] [......127.0.0.1][49734] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....96] [ip4][..tcp] [......127.0.0.1][49734] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....97] [ip4][..tcp] [......127.0.0.1][49736] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....97] [ip4][..tcp] [......127.0.0.1][49736] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....97] [ip4][..tcp] [......127.0.0.1][49736] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....98] [ip4][..tcp] [......127.0.0.1][49738] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....98] [ip4][..tcp] [......127.0.0.1][49738] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....98] [ip4][..tcp] [......127.0.0.1][49738] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....99] [ip4][..tcp] [......127.0.0.1][49740] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [....99] [ip4][..tcp] [......127.0.0.1][49740] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [....99] [ip4][..tcp] [......127.0.0.1][49740] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...100] [ip4][..tcp] [......127.0.0.1][49742] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...100] [ip4][..tcp] [......127.0.0.1][49742] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...100] [ip4][..tcp] [......127.0.0.1][49742] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...101] [ip4][..tcp] [......127.0.0.1][49744] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...101] [ip4][..tcp] [......127.0.0.1][49744] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...101] [ip4][..tcp] [......127.0.0.1][49744] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...102] [ip4][..tcp] [......127.0.0.1][49746] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...102] [ip4][..tcp] [......127.0.0.1][49746] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...102] [ip4][..tcp] [......127.0.0.1][49746] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...103] [ip4][..tcp] [......127.0.0.1][49748] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...103] [ip4][..tcp] [......127.0.0.1][49748] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...103] [ip4][..tcp] [......127.0.0.1][49748] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...104] [ip4][..tcp] [......127.0.0.1][49750] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...104] [ip4][..tcp] [......127.0.0.1][49750] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...104] [ip4][..tcp] [......127.0.0.1][49750] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...105] [ip4][..tcp] [......127.0.0.1][49752] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...105] [ip4][..tcp] [......127.0.0.1][49752] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...105] [ip4][..tcp] [......127.0.0.1][49752] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...106] [ip4][..tcp] [......127.0.0.1][49754] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...106] [ip4][..tcp] [......127.0.0.1][49754] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...106] [ip4][..tcp] [......127.0.0.1][49754] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...107] [ip4][..tcp] [......127.0.0.1][49756] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...107] [ip4][..tcp] [......127.0.0.1][49756] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...107] [ip4][..tcp] [......127.0.0.1][49756] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...108] [ip4][..tcp] [......127.0.0.1][49758] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...108] [ip4][..tcp] [......127.0.0.1][49758] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...108] [ip4][..tcp] [......127.0.0.1][49758] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...109] [ip4][..tcp] [......127.0.0.1][49760] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...109] [ip4][..tcp] [......127.0.0.1][49760] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...109] [ip4][..tcp] [......127.0.0.1][49760] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...110] [ip4][..tcp] [......127.0.0.1][49764] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...110] [ip4][..tcp] [......127.0.0.1][49764] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...110] [ip4][..tcp] [......127.0.0.1][49764] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...111] [ip4][..tcp] [......127.0.0.1][49766] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...111] [ip4][..tcp] [......127.0.0.1][49766] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...111] [ip4][..tcp] [......127.0.0.1][49766] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...112] [ip4][..tcp] [......127.0.0.1][49768] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...112] [ip4][..tcp] [......127.0.0.1][49768] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...112] [ip4][..tcp] [......127.0.0.1][49768] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...113] [ip4][..tcp] [......127.0.0.1][49770] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...113] [ip4][..tcp] [......127.0.0.1][49770] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...113] [ip4][..tcp] [......127.0.0.1][49770] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...114] [ip4][..tcp] [......127.0.0.1][49772] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...114] [ip4][..tcp] [......127.0.0.1][49772] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...114] [ip4][..tcp] [......127.0.0.1][49772] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...115] [ip4][..tcp] [......127.0.0.1][49774] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...115] [ip4][..tcp] [......127.0.0.1][49774] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...115] [ip4][..tcp] [......127.0.0.1][49774] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...116] [ip4][..tcp] [......127.0.0.1][49776] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...116] [ip4][..tcp] [......127.0.0.1][49776] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...116] [ip4][..tcp] [......127.0.0.1][49776] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...117] [ip4][..tcp] [......127.0.0.1][49778] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...117] [ip4][..tcp] [......127.0.0.1][49778] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...117] [ip4][..tcp] [......127.0.0.1][49778] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...118] [ip4][..tcp] [......127.0.0.1][49780] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...118] [ip4][..tcp] [......127.0.0.1][49780] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...118] [ip4][..tcp] [......127.0.0.1][49780] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...119] [ip4][..tcp] [......127.0.0.1][49782] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...119] [ip4][..tcp] [......127.0.0.1][49782] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...119] [ip4][..tcp] [......127.0.0.1][49782] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...120] [ip4][..tcp] [......127.0.0.1][49784] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...120] [ip4][..tcp] [......127.0.0.1][49784] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...120] [ip4][..tcp] [......127.0.0.1][49784] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...121] [ip4][..tcp] [......127.0.0.1][49786] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...121] [ip4][..tcp] [......127.0.0.1][49786] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...121] [ip4][..tcp] [......127.0.0.1][49786] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...122] [ip4][..tcp] [......127.0.0.1][49788] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...122] [ip4][..tcp] [......127.0.0.1][49788] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...122] [ip4][..tcp] [......127.0.0.1][49788] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...123] [ip4][..tcp] [......127.0.0.1][49790] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...123] [ip4][..tcp] [......127.0.0.1][49790] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...123] [ip4][..tcp] [......127.0.0.1][49790] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...124] [ip4][..tcp] [......127.0.0.1][49792] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...124] [ip4][..tcp] [......127.0.0.1][49792] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...124] [ip4][..tcp] [......127.0.0.1][49792] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...125] [ip4][..tcp] [......127.0.0.1][49794] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...125] [ip4][..tcp] [......127.0.0.1][49794] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...125] [ip4][..tcp] [......127.0.0.1][49794] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...126] [ip4][..tcp] [......127.0.0.1][49796] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...126] [ip4][..tcp] [......127.0.0.1][49796] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...126] [ip4][..tcp] [......127.0.0.1][49796] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...127] [ip4][..tcp] [......127.0.0.1][49798] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...127] [ip4][..tcp] [......127.0.0.1][49798] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...127] [ip4][..tcp] [......127.0.0.1][49798] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...128] [ip4][..tcp] [......127.0.0.1][49800] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...128] [ip4][..tcp] [......127.0.0.1][49800] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...128] [ip4][..tcp] [......127.0.0.1][49800] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...129] [ip4][..tcp] [......127.0.0.1][49802] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...129] [ip4][..tcp] [......127.0.0.1][49802] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...129] [ip4][..tcp] [......127.0.0.1][49802] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...130] [ip4][..tcp] [......127.0.0.1][49804] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...130] [ip4][..tcp] [......127.0.0.1][49804] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...130] [ip4][..tcp] [......127.0.0.1][49804] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...131] [ip4][..tcp] [......127.0.0.1][49806] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...131] [ip4][..tcp] [......127.0.0.1][49806] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...131] [ip4][..tcp] [......127.0.0.1][49806] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...132] [ip4][..tcp] [......127.0.0.1][49808] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...132] [ip4][..tcp] [......127.0.0.1][49808] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...132] [ip4][..tcp] [......127.0.0.1][49808] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...133] [ip4][..tcp] [......127.0.0.1][49810] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...133] [ip4][..tcp] [......127.0.0.1][49810] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...133] [ip4][..tcp] [......127.0.0.1][49810] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...134] [ip4][..tcp] [......127.0.0.1][49812] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...134] [ip4][..tcp] [......127.0.0.1][49812] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...134] [ip4][..tcp] [......127.0.0.1][49812] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...135] [ip4][..tcp] [......127.0.0.1][49814] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...135] [ip4][..tcp] [......127.0.0.1][49814] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...135] [ip4][..tcp] [......127.0.0.1][49814] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...136] [ip4][..tcp] [......127.0.0.1][49816] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...136] [ip4][..tcp] [......127.0.0.1][49816] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...136] [ip4][..tcp] [......127.0.0.1][49816] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...137] [ip4][..tcp] [......127.0.0.1][49818] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...137] [ip4][..tcp] [......127.0.0.1][49818] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...137] [ip4][..tcp] [......127.0.0.1][49818] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...138] [ip4][..tcp] [......127.0.0.1][49820] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...138] [ip4][..tcp] [......127.0.0.1][49820] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...138] [ip4][..tcp] [......127.0.0.1][49820] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...139] [ip4][..tcp] [......127.0.0.1][49822] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...139] [ip4][..tcp] [......127.0.0.1][49822] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...139] [ip4][..tcp] [......127.0.0.1][49822] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...140] [ip4][..tcp] [......127.0.0.1][49824] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...140] [ip4][..tcp] [......127.0.0.1][49824] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...140] [ip4][..tcp] [......127.0.0.1][49824] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...141] [ip4][..tcp] [......127.0.0.1][49826] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...141] [ip4][..tcp] [......127.0.0.1][49826] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...141] [ip4][..tcp] [......127.0.0.1][49826] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...142] [ip4][..tcp] [......127.0.0.1][49828] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...142] [ip4][..tcp] [......127.0.0.1][49828] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...142] [ip4][..tcp] [......127.0.0.1][49828] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...143] [ip4][..tcp] [......127.0.0.1][49830] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...143] [ip4][..tcp] [......127.0.0.1][49830] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...143] [ip4][..tcp] [......127.0.0.1][49830] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...144] [ip4][..tcp] [......127.0.0.1][49832] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...144] [ip4][..tcp] [......127.0.0.1][49832] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...144] [ip4][..tcp] [......127.0.0.1][49832] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...145] [ip4][..tcp] [......127.0.0.1][49834] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...145] [ip4][..tcp] [......127.0.0.1][49834] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...145] [ip4][..tcp] [......127.0.0.1][49834] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...146] [ip4][..tcp] [......127.0.0.1][49836] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...146] [ip4][..tcp] [......127.0.0.1][49836] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...146] [ip4][..tcp] [......127.0.0.1][49836] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...147] [ip4][..tcp] [......127.0.0.1][49838] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...147] [ip4][..tcp] [......127.0.0.1][49838] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...147] [ip4][..tcp] [......127.0.0.1][49838] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...148] [ip4][..tcp] [......127.0.0.1][49840] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...148] [ip4][..tcp] [......127.0.0.1][49840] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...148] [ip4][..tcp] [......127.0.0.1][49840] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...149] [ip4][..tcp] [......127.0.0.1][49842] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...149] [ip4][..tcp] [......127.0.0.1][49842] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...149] [ip4][..tcp] [......127.0.0.1][49842] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...150] [ip4][..tcp] [......127.0.0.1][49844] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...150] [ip4][..tcp] [......127.0.0.1][49844] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...150] [ip4][..tcp] [......127.0.0.1][49844] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...151] [ip4][..tcp] [......127.0.0.1][49846] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...151] [ip4][..tcp] [......127.0.0.1][49846] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...151] [ip4][..tcp] [......127.0.0.1][49846] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...152] [ip4][..tcp] [......127.0.0.1][49848] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...152] [ip4][..tcp] [......127.0.0.1][49848] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...152] [ip4][..tcp] [......127.0.0.1][49848] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...153] [ip4][..tcp] [......127.0.0.1][49850] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...153] [ip4][..tcp] [......127.0.0.1][49850] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...153] [ip4][..tcp] [......127.0.0.1][49850] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...154] [ip4][..tcp] [......127.0.0.1][49852] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...154] [ip4][..tcp] [......127.0.0.1][49852] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...154] [ip4][..tcp] [......127.0.0.1][49852] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...155] [ip4][..tcp] [......127.0.0.1][49854] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...155] [ip4][..tcp] [......127.0.0.1][49854] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...155] [ip4][..tcp] [......127.0.0.1][49854] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...156] [ip4][..tcp] [......127.0.0.1][49856] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...156] [ip4][..tcp] [......127.0.0.1][49856] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...156] [ip4][..tcp] [......127.0.0.1][49856] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...157] [ip4][..tcp] [......127.0.0.1][49858] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...157] [ip4][..tcp] [......127.0.0.1][49858] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...157] [ip4][..tcp] [......127.0.0.1][49858] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...158] [ip4][..tcp] [......127.0.0.1][49860] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...158] [ip4][..tcp] [......127.0.0.1][49860] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...158] [ip4][..tcp] [......127.0.0.1][49860] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...159] [ip4][..tcp] [......127.0.0.1][49862] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...159] [ip4][..tcp] [......127.0.0.1][49862] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...159] [ip4][..tcp] [......127.0.0.1][49862] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...160] [ip4][..tcp] [......127.0.0.1][49864] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...160] [ip4][..tcp] [......127.0.0.1][49864] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...160] [ip4][..tcp] [......127.0.0.1][49864] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...161] [ip4][..tcp] [......127.0.0.1][49866] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...161] [ip4][..tcp] [......127.0.0.1][49866] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...161] [ip4][..tcp] [......127.0.0.1][49866] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...162] [ip4][..tcp] [......127.0.0.1][49868] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...162] [ip4][..tcp] [......127.0.0.1][49868] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...162] [ip4][..tcp] [......127.0.0.1][49868] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...163] [ip4][..tcp] [......127.0.0.1][49870] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...163] [ip4][..tcp] [......127.0.0.1][49870] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...163] [ip4][..tcp] [......127.0.0.1][49870] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...164] [ip4][..tcp] [......127.0.0.1][49872] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...164] [ip4][..tcp] [......127.0.0.1][49872] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...164] [ip4][..tcp] [......127.0.0.1][49872] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...165] [ip4][..tcp] [......127.0.0.1][49874] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...165] [ip4][..tcp] [......127.0.0.1][49874] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...165] [ip4][..tcp] [......127.0.0.1][49874] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...166] [ip4][..tcp] [......127.0.0.1][49876] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...166] [ip4][..tcp] [......127.0.0.1][49876] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...166] [ip4][..tcp] [......127.0.0.1][49876] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...167] [ip4][..tcp] [......127.0.0.1][49878] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...167] [ip4][..tcp] [......127.0.0.1][49878] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...167] [ip4][..tcp] [......127.0.0.1][49878] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...168] [ip4][..tcp] [......127.0.0.1][49880] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...168] [ip4][..tcp] [......127.0.0.1][49880] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...168] [ip4][..tcp] [......127.0.0.1][49880] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...169] [ip4][..tcp] [......127.0.0.1][49882] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...169] [ip4][..tcp] [......127.0.0.1][49882] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...169] [ip4][..tcp] [......127.0.0.1][49882] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...170] [ip4][..tcp] [......127.0.0.1][49884] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...170] [ip4][..tcp] [......127.0.0.1][49884] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...170] [ip4][..tcp] [......127.0.0.1][49884] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...171] [ip4][..tcp] [......127.0.0.1][49886] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...171] [ip4][..tcp] [......127.0.0.1][49886] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...171] [ip4][..tcp] [......127.0.0.1][49886] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...172] [ip4][..tcp] [......127.0.0.1][49888] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...172] [ip4][..tcp] [......127.0.0.1][49888] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...172] [ip4][..tcp] [......127.0.0.1][49888] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...173] [ip4][..tcp] [......127.0.0.1][49890] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...173] [ip4][..tcp] [......127.0.0.1][49890] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...173] [ip4][..tcp] [......127.0.0.1][49890] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...174] [ip4][..tcp] [......127.0.0.1][49892] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...174] [ip4][..tcp] [......127.0.0.1][49892] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...174] [ip4][..tcp] [......127.0.0.1][49892] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...175] [ip4][..tcp] [......127.0.0.1][49894] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...175] [ip4][..tcp] [......127.0.0.1][49894] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...175] [ip4][..tcp] [......127.0.0.1][49894] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...176] [ip4][..tcp] [......127.0.0.1][49896] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...176] [ip4][..tcp] [......127.0.0.1][49896] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...176] [ip4][..tcp] [......127.0.0.1][49896] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...177] [ip4][..tcp] [......127.0.0.1][49898] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...177] [ip4][..tcp] [......127.0.0.1][49898] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...177] [ip4][..tcp] [......127.0.0.1][49898] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...178] [ip4][..tcp] [......127.0.0.1][49900] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...178] [ip4][..tcp] [......127.0.0.1][49900] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...178] [ip4][..tcp] [......127.0.0.1][49900] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...179] [ip4][..tcp] [......127.0.0.1][49902] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...179] [ip4][..tcp] [......127.0.0.1][49902] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...179] [ip4][..tcp] [......127.0.0.1][49902] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...180] [ip4][..tcp] [......127.0.0.1][49904] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...180] [ip4][..tcp] [......127.0.0.1][49904] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...180] [ip4][..tcp] [......127.0.0.1][49904] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...181] [ip4][..tcp] [......127.0.0.1][49906] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...181] [ip4][..tcp] [......127.0.0.1][49906] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...181] [ip4][..tcp] [......127.0.0.1][49906] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...182] [ip4][..tcp] [......127.0.0.1][49908] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...182] [ip4][..tcp] [......127.0.0.1][49908] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...182] [ip4][..tcp] [......127.0.0.1][49908] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...183] [ip4][..tcp] [......127.0.0.1][49910] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...183] [ip4][..tcp] [......127.0.0.1][49910] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...183] [ip4][..tcp] [......127.0.0.1][49910] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...184] [ip4][..tcp] [......127.0.0.1][49912] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...184] [ip4][..tcp] [......127.0.0.1][49912] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...184] [ip4][..tcp] [......127.0.0.1][49912] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...185] [ip4][..tcp] [......127.0.0.1][49914] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...185] [ip4][..tcp] [......127.0.0.1][49914] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...185] [ip4][..tcp] [......127.0.0.1][49914] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...186] [ip4][..tcp] [......127.0.0.1][49916] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...186] [ip4][..tcp] [......127.0.0.1][49916] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...186] [ip4][..tcp] [......127.0.0.1][49916] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...187] [ip4][..tcp] [......127.0.0.1][49918] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...187] [ip4][..tcp] [......127.0.0.1][49918] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...187] [ip4][..tcp] [......127.0.0.1][49918] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...188] [ip4][..tcp] [......127.0.0.1][49920] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...188] [ip4][..tcp] [......127.0.0.1][49920] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...188] [ip4][..tcp] [......127.0.0.1][49920] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...189] [ip4][..tcp] [......127.0.0.1][49922] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...189] [ip4][..tcp] [......127.0.0.1][49922] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...189] [ip4][..tcp] [......127.0.0.1][49922] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...190] [ip4][..tcp] [......127.0.0.1][49924] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...190] [ip4][..tcp] [......127.0.0.1][49924] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...190] [ip4][..tcp] [......127.0.0.1][49924] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...191] [ip4][..tcp] [......127.0.0.1][49926] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...191] [ip4][..tcp] [......127.0.0.1][49926] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...191] [ip4][..tcp] [......127.0.0.1][49926] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...192] [ip4][..tcp] [......127.0.0.1][49928] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...192] [ip4][..tcp] [......127.0.0.1][49928] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...192] [ip4][..tcp] [......127.0.0.1][49928] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...193] [ip4][..tcp] [......127.0.0.1][49930] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...193] [ip4][..tcp] [......127.0.0.1][49930] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...193] [ip4][..tcp] [......127.0.0.1][49930] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...194] [ip4][..tcp] [......127.0.0.1][49932] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...194] [ip4][..tcp] [......127.0.0.1][49932] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...194] [ip4][..tcp] [......127.0.0.1][49932] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...195] [ip4][..tcp] [......127.0.0.1][49934] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...195] [ip4][..tcp] [......127.0.0.1][49934] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...195] [ip4][..tcp] [......127.0.0.1][49934] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...196] [ip4][..tcp] [......127.0.0.1][49936] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...196] [ip4][..tcp] [......127.0.0.1][49936] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...196] [ip4][..tcp] [......127.0.0.1][49936] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...197] [ip4][..tcp] [......127.0.0.1][49938] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...197] [ip4][..tcp] [......127.0.0.1][49938] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...197] [ip4][..tcp] [......127.0.0.1][49938] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...198] [ip4][..tcp] [......127.0.0.1][49940] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...198] [ip4][..tcp] [......127.0.0.1][49940] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...198] [ip4][..tcp] [......127.0.0.1][49940] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...199] [ip4][..tcp] [......127.0.0.1][49942] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...199] [ip4][..tcp] [......127.0.0.1][49942] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...199] [ip4][..tcp] [......127.0.0.1][49942] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...200] [ip4][..tcp] [......127.0.0.1][49944] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...200] [ip4][..tcp] [......127.0.0.1][49944] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...200] [ip4][..tcp] [......127.0.0.1][49944] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...201] [ip4][..tcp] [......127.0.0.1][49946] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...201] [ip4][..tcp] [......127.0.0.1][49946] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...201] [ip4][..tcp] [......127.0.0.1][49946] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...202] [ip4][..tcp] [......127.0.0.1][49948] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...202] [ip4][..tcp] [......127.0.0.1][49948] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...202] [ip4][..tcp] [......127.0.0.1][49948] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...203] [ip4][..tcp] [......127.0.0.1][49950] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...203] [ip4][..tcp] [......127.0.0.1][49950] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...203] [ip4][..tcp] [......127.0.0.1][49950] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...204] [ip4][..tcp] [......127.0.0.1][49952] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...204] [ip4][..tcp] [......127.0.0.1][49952] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...204] [ip4][..tcp] [......127.0.0.1][49952] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...205] [ip4][..tcp] [......127.0.0.1][49954] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...205] [ip4][..tcp] [......127.0.0.1][49954] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...205] [ip4][..tcp] [......127.0.0.1][49954] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...206] [ip4][..tcp] [......127.0.0.1][49956] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...206] [ip4][..tcp] [......127.0.0.1][49956] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...206] [ip4][..tcp] [......127.0.0.1][49956] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...207] [ip4][..tcp] [......127.0.0.1][49958] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...207] [ip4][..tcp] [......127.0.0.1][49958] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...207] [ip4][..tcp] [......127.0.0.1][49958] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...208] [ip4][..tcp] [......127.0.0.1][49960] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...208] [ip4][..tcp] [......127.0.0.1][49960] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...208] [ip4][..tcp] [......127.0.0.1][49960] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...209] [ip4][..tcp] [......127.0.0.1][49962] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...209] [ip4][..tcp] [......127.0.0.1][49962] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...209] [ip4][..tcp] [......127.0.0.1][49962] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...210] [ip4][..tcp] [......127.0.0.1][49964] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...210] [ip4][..tcp] [......127.0.0.1][49964] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...210] [ip4][..tcp] [......127.0.0.1][49964] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...211] [ip4][..tcp] [......127.0.0.1][49966] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...211] [ip4][..tcp] [......127.0.0.1][49966] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...211] [ip4][..tcp] [......127.0.0.1][49966] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...212] [ip4][..tcp] [......127.0.0.1][49968] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...212] [ip4][..tcp] [......127.0.0.1][49968] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...212] [ip4][..tcp] [......127.0.0.1][49968] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...213] [ip4][..tcp] [......127.0.0.1][49970] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...213] [ip4][..tcp] [......127.0.0.1][49970] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...213] [ip4][..tcp] [......127.0.0.1][49970] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...214] [ip4][..tcp] [......127.0.0.1][49972] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...214] [ip4][..tcp] [......127.0.0.1][49972] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...214] [ip4][..tcp] [......127.0.0.1][49972] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...215] [ip4][..tcp] [......127.0.0.1][49974] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...215] [ip4][..tcp] [......127.0.0.1][49974] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...215] [ip4][..tcp] [......127.0.0.1][49974] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...216] [ip4][..tcp] [......127.0.0.1][49976] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...216] [ip4][..tcp] [......127.0.0.1][49976] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...216] [ip4][..tcp] [......127.0.0.1][49976] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...217] [ip4][..tcp] [......127.0.0.1][49978] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...217] [ip4][..tcp] [......127.0.0.1][49978] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...217] [ip4][..tcp] [......127.0.0.1][49978] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...218] [ip4][..tcp] [......127.0.0.1][49980] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...218] [ip4][..tcp] [......127.0.0.1][49980] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...218] [ip4][..tcp] [......127.0.0.1][49980] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...219] [ip4][..tcp] [......127.0.0.1][49982] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...219] [ip4][..tcp] [......127.0.0.1][49982] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...219] [ip4][..tcp] [......127.0.0.1][49982] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...220] [ip4][..tcp] [......127.0.0.1][49984] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...220] [ip4][..tcp] [......127.0.0.1][49984] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...220] [ip4][..tcp] [......127.0.0.1][49984] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...221] [ip4][..tcp] [......127.0.0.1][49986] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...221] [ip4][..tcp] [......127.0.0.1][49986] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...221] [ip4][..tcp] [......127.0.0.1][49986] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...222] [ip4][..tcp] [......127.0.0.1][49988] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...222] [ip4][..tcp] [......127.0.0.1][49988] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...222] [ip4][..tcp] [......127.0.0.1][49988] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...223] [ip4][..tcp] [......127.0.0.1][49990] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...223] [ip4][..tcp] [......127.0.0.1][49990] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...223] [ip4][..tcp] [......127.0.0.1][49990] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...224] [ip4][..tcp] [......127.0.0.1][49992] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...224] [ip4][..tcp] [......127.0.0.1][49992] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...224] [ip4][..tcp] [......127.0.0.1][49992] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...225] [ip4][..tcp] [......127.0.0.1][49994] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...225] [ip4][..tcp] [......127.0.0.1][49994] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...225] [ip4][..tcp] [......127.0.0.1][49994] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...226] [ip4][..tcp] [......127.0.0.1][49996] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...226] [ip4][..tcp] [......127.0.0.1][49996] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...226] [ip4][..tcp] [......127.0.0.1][49996] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...227] [ip4][..tcp] [......127.0.0.1][49998] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...227] [ip4][..tcp] [......127.0.0.1][49998] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...227] [ip4][..tcp] [......127.0.0.1][49998] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...228] [ip4][..tcp] [......127.0.0.1][50000] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...228] [ip4][..tcp] [......127.0.0.1][50000] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...228] [ip4][..tcp] [......127.0.0.1][50000] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...229] [ip4][..tcp] [......127.0.0.1][50002] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...229] [ip4][..tcp] [......127.0.0.1][50002] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...229] [ip4][..tcp] [......127.0.0.1][50002] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...230] [ip4][..tcp] [......127.0.0.1][50004] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...230] [ip4][..tcp] [......127.0.0.1][50004] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...230] [ip4][..tcp] [......127.0.0.1][50004] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...231] [ip4][..tcp] [......127.0.0.1][50006] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...231] [ip4][..tcp] [......127.0.0.1][50006] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...231] [ip4][..tcp] [......127.0.0.1][50006] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...232] [ip4][..tcp] [......127.0.0.1][50008] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...232] [ip4][..tcp] [......127.0.0.1][50008] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...232] [ip4][..tcp] [......127.0.0.1][50008] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...233] [ip4][..tcp] [......127.0.0.1][50010] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...233] [ip4][..tcp] [......127.0.0.1][50010] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...233] [ip4][..tcp] [......127.0.0.1][50010] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...234] [ip4][..tcp] [......127.0.0.1][50012] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...234] [ip4][..tcp] [......127.0.0.1][50012] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...234] [ip4][..tcp] [......127.0.0.1][50012] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...235] [ip4][..tcp] [......127.0.0.1][50014] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...235] [ip4][..tcp] [......127.0.0.1][50014] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...235] [ip4][..tcp] [......127.0.0.1][50014] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...236] [ip4][..tcp] [......127.0.0.1][50016] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...236] [ip4][..tcp] [......127.0.0.1][50016] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...236] [ip4][..tcp] [......127.0.0.1][50016] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...237] [ip4][..tcp] [......127.0.0.1][50018] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...237] [ip4][..tcp] [......127.0.0.1][50018] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...237] [ip4][..tcp] [......127.0.0.1][50018] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...238] [ip4][..tcp] [......127.0.0.1][50020] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...238] [ip4][..tcp] [......127.0.0.1][50020] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...238] [ip4][..tcp] [......127.0.0.1][50020] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...239] [ip4][..tcp] [......127.0.0.1][50022] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...239] [ip4][..tcp] [......127.0.0.1][50022] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...239] [ip4][..tcp] [......127.0.0.1][50022] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...240] [ip4][..tcp] [......127.0.0.1][50024] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...240] [ip4][..tcp] [......127.0.0.1][50024] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...240] [ip4][..tcp] [......127.0.0.1][50024] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...241] [ip4][..tcp] [......127.0.0.1][50026] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...241] [ip4][..tcp] [......127.0.0.1][50026] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...241] [ip4][..tcp] [......127.0.0.1][50026] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...242] [ip4][..tcp] [......127.0.0.1][50028] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...242] [ip4][..tcp] [......127.0.0.1][50028] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...242] [ip4][..tcp] [......127.0.0.1][50028] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...243] [ip4][..tcp] [......127.0.0.1][50030] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...243] [ip4][..tcp] [......127.0.0.1][50030] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...243] [ip4][..tcp] [......127.0.0.1][50030] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...244] [ip4][..tcp] [......127.0.0.1][50032] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...244] [ip4][..tcp] [......127.0.0.1][50032] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...244] [ip4][..tcp] [......127.0.0.1][50032] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...245] [ip4][..tcp] [......127.0.0.1][50034] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...245] [ip4][..tcp] [......127.0.0.1][50034] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...245] [ip4][..tcp] [......127.0.0.1][50034] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...246] [ip4][..tcp] [......127.0.0.1][50036] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...246] [ip4][..tcp] [......127.0.0.1][50036] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...246] [ip4][..tcp] [......127.0.0.1][50036] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...247] [ip4][..tcp] [......127.0.0.1][50038] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...247] [ip4][..tcp] [......127.0.0.1][50038] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...247] [ip4][..tcp] [......127.0.0.1][50038] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...248] [ip4][..tcp] [......127.0.0.1][50040] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...248] [ip4][..tcp] [......127.0.0.1][50040] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...248] [ip4][..tcp] [......127.0.0.1][50040] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...249] [ip4][..tcp] [......127.0.0.1][50042] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...249] [ip4][..tcp] [......127.0.0.1][50042] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...249] [ip4][..tcp] [......127.0.0.1][50042] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...250] [ip4][..tcp] [......127.0.0.1][50044] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...250] [ip4][..tcp] [......127.0.0.1][50044] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...250] [ip4][..tcp] [......127.0.0.1][50044] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...251] [ip4][..tcp] [......127.0.0.1][50046] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...251] [ip4][..tcp] [......127.0.0.1][50046] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...251] [ip4][..tcp] [......127.0.0.1][50046] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...252] [ip4][..tcp] [......127.0.0.1][50048] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...252] [ip4][..tcp] [......127.0.0.1][50048] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...252] [ip4][..tcp] [......127.0.0.1][50048] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...253] [ip4][..tcp] [......127.0.0.1][50050] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...253] [ip4][..tcp] [......127.0.0.1][50050] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...253] [ip4][..tcp] [......127.0.0.1][50050] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...254] [ip4][..tcp] [......127.0.0.1][50052] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...254] [ip4][..tcp] [......127.0.0.1][50052] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...254] [ip4][..tcp] [......127.0.0.1][50052] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...255] [ip4][..tcp] [......127.0.0.1][50054] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...255] [ip4][..tcp] [......127.0.0.1][50054] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...255] [ip4][..tcp] [......127.0.0.1][50054] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...256] [ip4][..tcp] [......127.0.0.1][50056] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...256] [ip4][..tcp] [......127.0.0.1][50056] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...256] [ip4][..tcp] [......127.0.0.1][50056] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...257] [ip4][..tcp] [......127.0.0.1][50058] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...257] [ip4][..tcp] [......127.0.0.1][50058] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...257] [ip4][..tcp] [......127.0.0.1][50058] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...258] [ip4][..tcp] [......127.0.0.1][50060] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...258] [ip4][..tcp] [......127.0.0.1][50060] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...258] [ip4][..tcp] [......127.0.0.1][50060] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...259] [ip4][..tcp] [......127.0.0.1][50062] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...259] [ip4][..tcp] [......127.0.0.1][50062] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...259] [ip4][..tcp] [......127.0.0.1][50062] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...260] [ip4][..tcp] [......127.0.0.1][50064] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...260] [ip4][..tcp] [......127.0.0.1][50064] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...260] [ip4][..tcp] [......127.0.0.1][50064] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...261] [ip4][..tcp] [......127.0.0.1][50066] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...261] [ip4][..tcp] [......127.0.0.1][50066] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...261] [ip4][..tcp] [......127.0.0.1][50066] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...262] [ip4][..tcp] [......127.0.0.1][50068] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...262] [ip4][..tcp] [......127.0.0.1][50068] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...262] [ip4][..tcp] [......127.0.0.1][50068] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...263] [ip4][..tcp] [......127.0.0.1][50070] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...263] [ip4][..tcp] [......127.0.0.1][50070] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...263] [ip4][..tcp] [......127.0.0.1][50070] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...264] [ip4][..tcp] [......127.0.0.1][50072] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...264] [ip4][..tcp] [......127.0.0.1][50072] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...264] [ip4][..tcp] [......127.0.0.1][50072] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...265] [ip4][..tcp] [......127.0.0.1][50074] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...265] [ip4][..tcp] [......127.0.0.1][50074] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...265] [ip4][..tcp] [......127.0.0.1][50074] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...266] [ip4][..tcp] [......127.0.0.1][50076] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...266] [ip4][..tcp] [......127.0.0.1][50076] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...266] [ip4][..tcp] [......127.0.0.1][50076] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...267] [ip4][..tcp] [......127.0.0.1][50078] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...267] [ip4][..tcp] [......127.0.0.1][50078] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...267] [ip4][..tcp] [......127.0.0.1][50078] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...268] [ip4][..tcp] [......127.0.0.1][50080] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...268] [ip4][..tcp] [......127.0.0.1][50080] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...268] [ip4][..tcp] [......127.0.0.1][50080] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...269] [ip4][..tcp] [......127.0.0.1][50082] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...269] [ip4][..tcp] [......127.0.0.1][50082] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...269] [ip4][..tcp] [......127.0.0.1][50082] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...270] [ip4][..tcp] [......127.0.0.1][50084] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...270] [ip4][..tcp] [......127.0.0.1][50084] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...270] [ip4][..tcp] [......127.0.0.1][50084] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...271] [ip4][..tcp] [......127.0.0.1][50086] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...271] [ip4][..tcp] [......127.0.0.1][50086] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...271] [ip4][..tcp] [......127.0.0.1][50086] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...272] [ip4][..tcp] [......127.0.0.1][50088] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...272] [ip4][..tcp] [......127.0.0.1][50088] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...272] [ip4][..tcp] [......127.0.0.1][50088] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...273] [ip4][..tcp] [......127.0.0.1][50090] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...273] [ip4][..tcp] [......127.0.0.1][50090] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...273] [ip4][..tcp] [......127.0.0.1][50090] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...274] [ip4][..tcp] [......127.0.0.1][50092] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...274] [ip4][..tcp] [......127.0.0.1][50092] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...274] [ip4][..tcp] [......127.0.0.1][50092] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...275] [ip4][..tcp] [......127.0.0.1][50094] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...275] [ip4][..tcp] [......127.0.0.1][50094] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...275] [ip4][..tcp] [......127.0.0.1][50094] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...276] [ip4][..tcp] [......127.0.0.1][50096] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...276] [ip4][..tcp] [......127.0.0.1][50096] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...276] [ip4][..tcp] [......127.0.0.1][50096] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...277] [ip4][..tcp] [......127.0.0.1][50098] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...277] [ip4][..tcp] [......127.0.0.1][50098] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...277] [ip4][..tcp] [......127.0.0.1][50098] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...278] [ip4][..tcp] [......127.0.0.1][50100] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...278] [ip4][..tcp] [......127.0.0.1][50100] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...278] [ip4][..tcp] [......127.0.0.1][50100] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...279] [ip4][..tcp] [......127.0.0.1][50102] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...279] [ip4][..tcp] [......127.0.0.1][50102] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...279] [ip4][..tcp] [......127.0.0.1][50102] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...280] [ip4][..tcp] [......127.0.0.1][50104] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...280] [ip4][..tcp] [......127.0.0.1][50104] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...280] [ip4][..tcp] [......127.0.0.1][50104] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...281] [ip4][..tcp] [......127.0.0.1][50106] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...281] [ip4][..tcp] [......127.0.0.1][50106] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...281] [ip4][..tcp] [......127.0.0.1][50106] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...282] [ip4][..tcp] [......127.0.0.1][50108] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...282] [ip4][..tcp] [......127.0.0.1][50108] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...282] [ip4][..tcp] [......127.0.0.1][50108] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...283] [ip4][..tcp] [......127.0.0.1][50110] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...283] [ip4][..tcp] [......127.0.0.1][50110] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...283] [ip4][..tcp] [......127.0.0.1][50110] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...284] [ip4][..tcp] [......127.0.0.1][50112] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...284] [ip4][..tcp] [......127.0.0.1][50112] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...284] [ip4][..tcp] [......127.0.0.1][50112] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...285] [ip4][..tcp] [......127.0.0.1][50114] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...285] [ip4][..tcp] [......127.0.0.1][50114] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...285] [ip4][..tcp] [......127.0.0.1][50114] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...286] [ip4][..tcp] [......127.0.0.1][50116] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...286] [ip4][..tcp] [......127.0.0.1][50116] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...286] [ip4][..tcp] [......127.0.0.1][50116] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...287] [ip4][..tcp] [......127.0.0.1][50118] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...287] [ip4][..tcp] [......127.0.0.1][50118] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...287] [ip4][..tcp] [......127.0.0.1][50118] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...288] [ip4][..tcp] [......127.0.0.1][50120] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...288] [ip4][..tcp] [......127.0.0.1][50120] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...288] [ip4][..tcp] [......127.0.0.1][50120] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...289] [ip4][..tcp] [......127.0.0.1][50122] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...289] [ip4][..tcp] [......127.0.0.1][50122] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...289] [ip4][..tcp] [......127.0.0.1][50122] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...290] [ip4][..tcp] [......127.0.0.1][50124] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...290] [ip4][..tcp] [......127.0.0.1][50124] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...290] [ip4][..tcp] [......127.0.0.1][50124] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...291] [ip4][..tcp] [......127.0.0.1][50126] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...291] [ip4][..tcp] [......127.0.0.1][50126] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...291] [ip4][..tcp] [......127.0.0.1][50126] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...292] [ip4][..tcp] [......127.0.0.1][50128] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...292] [ip4][..tcp] [......127.0.0.1][50128] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...292] [ip4][..tcp] [......127.0.0.1][50128] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...293] [ip4][..tcp] [......127.0.0.1][50130] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...293] [ip4][..tcp] [......127.0.0.1][50130] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...293] [ip4][..tcp] [......127.0.0.1][50130] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...294] [ip4][..tcp] [......127.0.0.1][50132] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...294] [ip4][..tcp] [......127.0.0.1][50132] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...294] [ip4][..tcp] [......127.0.0.1][50132] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...295] [ip4][..tcp] [......127.0.0.1][50134] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...295] [ip4][..tcp] [......127.0.0.1][50134] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...295] [ip4][..tcp] [......127.0.0.1][50134] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...296] [ip4][..tcp] [......127.0.0.1][50136] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...296] [ip4][..tcp] [......127.0.0.1][50136] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...296] [ip4][..tcp] [......127.0.0.1][50136] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...297] [ip4][..tcp] [......127.0.0.1][50138] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...297] [ip4][..tcp] [......127.0.0.1][50138] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...297] [ip4][..tcp] [......127.0.0.1][50138] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...298] [ip4][..tcp] [......127.0.0.1][50140] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...298] [ip4][..tcp] [......127.0.0.1][50140] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...298] [ip4][..tcp] [......127.0.0.1][50140] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...299] [ip4][..tcp] [......127.0.0.1][50142] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...299] [ip4][..tcp] [......127.0.0.1][50142] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...299] [ip4][..tcp] [......127.0.0.1][50142] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...300] [ip4][..tcp] [......127.0.0.1][50144] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...300] [ip4][..tcp] [......127.0.0.1][50144] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...300] [ip4][..tcp] [......127.0.0.1][50144] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...301] [ip4][..tcp] [......127.0.0.1][50146] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...301] [ip4][..tcp] [......127.0.0.1][50146] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...301] [ip4][..tcp] [......127.0.0.1][50146] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...302] [ip4][..tcp] [......127.0.0.1][50148] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...302] [ip4][..tcp] [......127.0.0.1][50148] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...302] [ip4][..tcp] [......127.0.0.1][50148] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...303] [ip4][..tcp] [......127.0.0.1][50150] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...303] [ip4][..tcp] [......127.0.0.1][50150] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...303] [ip4][..tcp] [......127.0.0.1][50150] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...304] [ip4][..tcp] [......127.0.0.1][50152] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...304] [ip4][..tcp] [......127.0.0.1][50152] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...304] [ip4][..tcp] [......127.0.0.1][50152] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...305] [ip4][..tcp] [......127.0.0.1][50154] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...305] [ip4][..tcp] [......127.0.0.1][50154] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...305] [ip4][..tcp] [......127.0.0.1][50154] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...306] [ip4][..tcp] [......127.0.0.1][50156] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...306] [ip4][..tcp] [......127.0.0.1][50156] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...306] [ip4][..tcp] [......127.0.0.1][50156] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...307] [ip4][..tcp] [......127.0.0.1][50158] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...307] [ip4][..tcp] [......127.0.0.1][50158] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...307] [ip4][..tcp] [......127.0.0.1][50158] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...308] [ip4][..tcp] [......127.0.0.1][50160] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...308] [ip4][..tcp] [......127.0.0.1][50160] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...308] [ip4][..tcp] [......127.0.0.1][50160] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...309] [ip4][..tcp] [......127.0.0.1][50162] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...309] [ip4][..tcp] [......127.0.0.1][50162] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...309] [ip4][..tcp] [......127.0.0.1][50162] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...310] [ip4][..tcp] [......127.0.0.1][50164] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...310] [ip4][..tcp] [......127.0.0.1][50164] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...310] [ip4][..tcp] [......127.0.0.1][50164] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...311] [ip4][..tcp] [......127.0.0.1][50166] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...311] [ip4][..tcp] [......127.0.0.1][50166] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...311] [ip4][..tcp] [......127.0.0.1][50166] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...312] [ip4][..tcp] [......127.0.0.1][50168] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...312] [ip4][..tcp] [......127.0.0.1][50168] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...312] [ip4][..tcp] [......127.0.0.1][50168] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...313] [ip4][..tcp] [......127.0.0.1][50170] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...313] [ip4][..tcp] [......127.0.0.1][50170] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...313] [ip4][..tcp] [......127.0.0.1][50170] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...314] [ip4][..tcp] [......127.0.0.1][50172] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...314] [ip4][..tcp] [......127.0.0.1][50172] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...314] [ip4][..tcp] [......127.0.0.1][50172] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...315] [ip4][..tcp] [......127.0.0.1][50174] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...315] [ip4][..tcp] [......127.0.0.1][50174] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...315] [ip4][..tcp] [......127.0.0.1][50174] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...316] [ip4][..tcp] [......127.0.0.1][50176] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...316] [ip4][..tcp] [......127.0.0.1][50176] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...316] [ip4][..tcp] [......127.0.0.1][50176] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...317] [ip4][..tcp] [......127.0.0.1][50178] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...317] [ip4][..tcp] [......127.0.0.1][50178] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...317] [ip4][..tcp] [......127.0.0.1][50178] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...318] [ip4][..tcp] [......127.0.0.1][50180] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...318] [ip4][..tcp] [......127.0.0.1][50180] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...318] [ip4][..tcp] [......127.0.0.1][50180] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...319] [ip4][..tcp] [......127.0.0.1][50182] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...319] [ip4][..tcp] [......127.0.0.1][50182] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...319] [ip4][..tcp] [......127.0.0.1][50182] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...320] [ip4][..tcp] [......127.0.0.1][50184] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...320] [ip4][..tcp] [......127.0.0.1][50184] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...320] [ip4][..tcp] [......127.0.0.1][50184] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...321] [ip4][..tcp] [......127.0.0.1][50186] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...321] [ip4][..tcp] [......127.0.0.1][50186] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...321] [ip4][..tcp] [......127.0.0.1][50186] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...322] [ip4][..tcp] [......127.0.0.1][50188] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...322] [ip4][..tcp] [......127.0.0.1][50188] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...322] [ip4][..tcp] [......127.0.0.1][50188] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...323] [ip4][..tcp] [......127.0.0.1][50190] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...323] [ip4][..tcp] [......127.0.0.1][50190] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...323] [ip4][..tcp] [......127.0.0.1][50190] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...324] [ip4][..tcp] [......127.0.0.1][50192] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...324] [ip4][..tcp] [......127.0.0.1][50192] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...324] [ip4][..tcp] [......127.0.0.1][50192] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...325] [ip4][..tcp] [......127.0.0.1][50194] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...325] [ip4][..tcp] [......127.0.0.1][50194] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...325] [ip4][..tcp] [......127.0.0.1][50194] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...326] [ip4][..tcp] [......127.0.0.1][50196] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...326] [ip4][..tcp] [......127.0.0.1][50196] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...326] [ip4][..tcp] [......127.0.0.1][50196] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...327] [ip4][..tcp] [......127.0.0.1][50198] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...327] [ip4][..tcp] [......127.0.0.1][50198] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...327] [ip4][..tcp] [......127.0.0.1][50198] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...328] [ip4][..tcp] [......127.0.0.1][50200] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...328] [ip4][..tcp] [......127.0.0.1][50200] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...328] [ip4][..tcp] [......127.0.0.1][50200] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...329] [ip4][..tcp] [......127.0.0.1][50202] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...329] [ip4][..tcp] [......127.0.0.1][50202] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...329] [ip4][..tcp] [......127.0.0.1][50202] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...330] [ip4][..tcp] [......127.0.0.1][50204] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...330] [ip4][..tcp] [......127.0.0.1][50204] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...330] [ip4][..tcp] [......127.0.0.1][50204] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...331] [ip4][..tcp] [......127.0.0.1][50206] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...331] [ip4][..tcp] [......127.0.0.1][50206] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...331] [ip4][..tcp] [......127.0.0.1][50206] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...332] [ip4][..tcp] [......127.0.0.1][50208] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...332] [ip4][..tcp] [......127.0.0.1][50208] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...332] [ip4][..tcp] [......127.0.0.1][50208] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...333] [ip4][..tcp] [......127.0.0.1][50210] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...333] [ip4][..tcp] [......127.0.0.1][50210] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...333] [ip4][..tcp] [......127.0.0.1][50210] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...334] [ip4][..tcp] [......127.0.0.1][50212] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...334] [ip4][..tcp] [......127.0.0.1][50212] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...334] [ip4][..tcp] [......127.0.0.1][50212] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...335] [ip4][..tcp] [......127.0.0.1][50214] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...335] [ip4][..tcp] [......127.0.0.1][50214] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...335] [ip4][..tcp] [......127.0.0.1][50214] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...336] [ip4][..tcp] [......127.0.0.1][50216] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...336] [ip4][..tcp] [......127.0.0.1][50216] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...336] [ip4][..tcp] [......127.0.0.1][50216] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...337] [ip4][..tcp] [......127.0.0.1][50218] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...337] [ip4][..tcp] [......127.0.0.1][50218] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...337] [ip4][..tcp] [......127.0.0.1][50218] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...338] [ip4][..tcp] [......127.0.0.1][50220] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...338] [ip4][..tcp] [......127.0.0.1][50220] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...338] [ip4][..tcp] [......127.0.0.1][50220] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...339] [ip4][..tcp] [......127.0.0.1][50222] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...339] [ip4][..tcp] [......127.0.0.1][50222] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...339] [ip4][..tcp] [......127.0.0.1][50222] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...340] [ip4][..tcp] [......127.0.0.1][50224] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...340] [ip4][..tcp] [......127.0.0.1][50224] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...340] [ip4][..tcp] [......127.0.0.1][50224] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...341] [ip4][..tcp] [......127.0.0.1][50226] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...341] [ip4][..tcp] [......127.0.0.1][50226] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...341] [ip4][..tcp] [......127.0.0.1][50226] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...342] [ip4][..tcp] [......127.0.0.1][50228] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...342] [ip4][..tcp] [......127.0.0.1][50228] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...342] [ip4][..tcp] [......127.0.0.1][50228] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...343] [ip4][..tcp] [......127.0.0.1][50230] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...343] [ip4][..tcp] [......127.0.0.1][50230] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...343] [ip4][..tcp] [......127.0.0.1][50230] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...344] [ip4][..tcp] [......127.0.0.1][50232] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...344] [ip4][..tcp] [......127.0.0.1][50232] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...344] [ip4][..tcp] [......127.0.0.1][50232] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...345] [ip4][..tcp] [......127.0.0.1][50234] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...345] [ip4][..tcp] [......127.0.0.1][50234] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...345] [ip4][..tcp] [......127.0.0.1][50234] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...346] [ip4][..tcp] [......127.0.0.1][50236] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...346] [ip4][..tcp] [......127.0.0.1][50236] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...346] [ip4][..tcp] [......127.0.0.1][50236] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...347] [ip4][..tcp] [......127.0.0.1][50238] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...347] [ip4][..tcp] [......127.0.0.1][50238] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...347] [ip4][..tcp] [......127.0.0.1][50238] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...348] [ip4][..tcp] [......127.0.0.1][50240] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...348] [ip4][..tcp] [......127.0.0.1][50240] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...348] [ip4][..tcp] [......127.0.0.1][50240] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...349] [ip4][..tcp] [......127.0.0.1][50242] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...349] [ip4][..tcp] [......127.0.0.1][50242] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...349] [ip4][..tcp] [......127.0.0.1][50242] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...350] [ip4][..tcp] [......127.0.0.1][50244] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...350] [ip4][..tcp] [......127.0.0.1][50244] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...350] [ip4][..tcp] [......127.0.0.1][50244] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...351] [ip4][..tcp] [......127.0.0.1][50246] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...351] [ip4][..tcp] [......127.0.0.1][50246] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...351] [ip4][..tcp] [......127.0.0.1][50246] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...352] [ip4][..tcp] [......127.0.0.1][50248] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...352] [ip4][..tcp] [......127.0.0.1][50248] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...352] [ip4][..tcp] [......127.0.0.1][50248] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...353] [ip4][..tcp] [......127.0.0.1][50250] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...353] [ip4][..tcp] [......127.0.0.1][50250] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...353] [ip4][..tcp] [......127.0.0.1][50250] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...354] [ip4][..tcp] [......127.0.0.1][50252] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...354] [ip4][..tcp] [......127.0.0.1][50252] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...354] [ip4][..tcp] [......127.0.0.1][50252] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...355] [ip4][..tcp] [......127.0.0.1][50254] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...355] [ip4][..tcp] [......127.0.0.1][50254] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...355] [ip4][..tcp] [......127.0.0.1][50254] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...356] [ip4][..tcp] [......127.0.0.1][50256] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...356] [ip4][..tcp] [......127.0.0.1][50256] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...356] [ip4][..tcp] [......127.0.0.1][50256] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...357] [ip4][..tcp] [......127.0.0.1][50258] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...357] [ip4][..tcp] [......127.0.0.1][50258] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...357] [ip4][..tcp] [......127.0.0.1][50258] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...358] [ip4][..tcp] [......127.0.0.1][50260] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...358] [ip4][..tcp] [......127.0.0.1][50260] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...358] [ip4][..tcp] [......127.0.0.1][50260] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...359] [ip4][..tcp] [......127.0.0.1][50262] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...359] [ip4][..tcp] [......127.0.0.1][50262] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...359] [ip4][..tcp] [......127.0.0.1][50262] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...360] [ip4][..tcp] [......127.0.0.1][50264] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...360] [ip4][..tcp] [......127.0.0.1][50264] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...360] [ip4][..tcp] [......127.0.0.1][50264] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...361] [ip4][..tcp] [......127.0.0.1][50266] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...361] [ip4][..tcp] [......127.0.0.1][50266] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...361] [ip4][..tcp] [......127.0.0.1][50266] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...362] [ip4][..tcp] [......127.0.0.1][50268] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...362] [ip4][..tcp] [......127.0.0.1][50268] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...362] [ip4][..tcp] [......127.0.0.1][50268] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...363] [ip4][..tcp] [......127.0.0.1][50270] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...363] [ip4][..tcp] [......127.0.0.1][50270] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...363] [ip4][..tcp] [......127.0.0.1][50270] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...364] [ip4][..tcp] [......127.0.0.1][50272] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...364] [ip4][..tcp] [......127.0.0.1][50272] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...364] [ip4][..tcp] [......127.0.0.1][50272] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...365] [ip4][..tcp] [......127.0.0.1][50274] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...365] [ip4][..tcp] [......127.0.0.1][50274] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...365] [ip4][..tcp] [......127.0.0.1][50274] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...366] [ip4][..tcp] [......127.0.0.1][50276] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...366] [ip4][..tcp] [......127.0.0.1][50276] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...366] [ip4][..tcp] [......127.0.0.1][50276] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...367] [ip4][..tcp] [......127.0.0.1][50278] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...367] [ip4][..tcp] [......127.0.0.1][50278] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...367] [ip4][..tcp] [......127.0.0.1][50278] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...368] [ip4][..tcp] [......127.0.0.1][50280] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...368] [ip4][..tcp] [......127.0.0.1][50280] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...368] [ip4][..tcp] [......127.0.0.1][50280] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...369] [ip4][..tcp] [......127.0.0.1][50282] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...369] [ip4][..tcp] [......127.0.0.1][50282] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...369] [ip4][..tcp] [......127.0.0.1][50282] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...370] [ip4][..tcp] [......127.0.0.1][50284] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...370] [ip4][..tcp] [......127.0.0.1][50284] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...370] [ip4][..tcp] [......127.0.0.1][50284] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...371] [ip4][..tcp] [......127.0.0.1][50286] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...371] [ip4][..tcp] [......127.0.0.1][50286] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...371] [ip4][..tcp] [......127.0.0.1][50286] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...372] [ip4][..tcp] [......127.0.0.1][50288] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...372] [ip4][..tcp] [......127.0.0.1][50288] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...372] [ip4][..tcp] [......127.0.0.1][50288] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...373] [ip4][..tcp] [......127.0.0.1][50290] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...373] [ip4][..tcp] [......127.0.0.1][50290] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...373] [ip4][..tcp] [......127.0.0.1][50290] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...374] [ip4][..tcp] [......127.0.0.1][50292] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...374] [ip4][..tcp] [......127.0.0.1][50292] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...374] [ip4][..tcp] [......127.0.0.1][50292] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...375] [ip4][..tcp] [......127.0.0.1][50294] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...375] [ip4][..tcp] [......127.0.0.1][50294] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...375] [ip4][..tcp] [......127.0.0.1][50294] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...376] [ip4][..tcp] [......127.0.0.1][50296] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...376] [ip4][..tcp] [......127.0.0.1][50296] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...376] [ip4][..tcp] [......127.0.0.1][50296] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...377] [ip4][..tcp] [......127.0.0.1][50298] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...377] [ip4][..tcp] [......127.0.0.1][50298] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...377] [ip4][..tcp] [......127.0.0.1][50298] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...378] [ip4][..tcp] [......127.0.0.1][50300] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...378] [ip4][..tcp] [......127.0.0.1][50300] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...378] [ip4][..tcp] [......127.0.0.1][50300] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...379] [ip4][..tcp] [......127.0.0.1][50302] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...379] [ip4][..tcp] [......127.0.0.1][50302] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...379] [ip4][..tcp] [......127.0.0.1][50302] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...380] [ip4][..tcp] [......127.0.0.1][50304] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...380] [ip4][..tcp] [......127.0.0.1][50304] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...380] [ip4][..tcp] [......127.0.0.1][50304] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...381] [ip4][..tcp] [......127.0.0.1][50306] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...381] [ip4][..tcp] [......127.0.0.1][50306] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...381] [ip4][..tcp] [......127.0.0.1][50306] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...382] [ip4][..tcp] [......127.0.0.1][50308] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...382] [ip4][..tcp] [......127.0.0.1][50308] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...382] [ip4][..tcp] [......127.0.0.1][50308] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...383] [ip4][..tcp] [......127.0.0.1][50310] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...383] [ip4][..tcp] [......127.0.0.1][50310] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...383] [ip4][..tcp] [......127.0.0.1][50310] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...384] [ip4][..tcp] [......127.0.0.1][50312] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...384] [ip4][..tcp] [......127.0.0.1][50312] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...384] [ip4][..tcp] [......127.0.0.1][50312] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...385] [ip4][..tcp] [......127.0.0.1][50314] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...385] [ip4][..tcp] [......127.0.0.1][50314] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...385] [ip4][..tcp] [......127.0.0.1][50314] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...386] [ip4][..tcp] [......127.0.0.1][50316] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...386] [ip4][..tcp] [......127.0.0.1][50316] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...386] [ip4][..tcp] [......127.0.0.1][50316] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...387] [ip4][..tcp] [......127.0.0.1][50318] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...387] [ip4][..tcp] [......127.0.0.1][50318] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...387] [ip4][..tcp] [......127.0.0.1][50318] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...388] [ip4][..tcp] [......127.0.0.1][50320] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...388] [ip4][..tcp] [......127.0.0.1][50320] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...388] [ip4][..tcp] [......127.0.0.1][50320] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...389] [ip4][..tcp] [......127.0.0.1][50322] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...389] [ip4][..tcp] [......127.0.0.1][50322] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...389] [ip4][..tcp] [......127.0.0.1][50322] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...390] [ip4][..tcp] [......127.0.0.1][50324] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...390] [ip4][..tcp] [......127.0.0.1][50324] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...390] [ip4][..tcp] [......127.0.0.1][50324] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...391] [ip4][..tcp] [......127.0.0.1][50326] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...391] [ip4][..tcp] [......127.0.0.1][50326] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...391] [ip4][..tcp] [......127.0.0.1][50326] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...392] [ip4][..tcp] [......127.0.0.1][50328] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...392] [ip4][..tcp] [......127.0.0.1][50328] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...392] [ip4][..tcp] [......127.0.0.1][50328] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...393] [ip4][..tcp] [......127.0.0.1][50330] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...393] [ip4][..tcp] [......127.0.0.1][50330] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...393] [ip4][..tcp] [......127.0.0.1][50330] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...394] [ip4][..tcp] [......127.0.0.1][50332] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...394] [ip4][..tcp] [......127.0.0.1][50332] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...394] [ip4][..tcp] [......127.0.0.1][50332] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...395] [ip4][..tcp] [......127.0.0.1][50334] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...395] [ip4][..tcp] [......127.0.0.1][50334] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...395] [ip4][..tcp] [......127.0.0.1][50334] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...396] [ip4][..tcp] [......127.0.0.1][50336] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...396] [ip4][..tcp] [......127.0.0.1][50336] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...396] [ip4][..tcp] [......127.0.0.1][50336] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...397] [ip4][..tcp] [......127.0.0.1][50338] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...397] [ip4][..tcp] [......127.0.0.1][50338] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...397] [ip4][..tcp] [......127.0.0.1][50338] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...398] [ip4][..tcp] [......127.0.0.1][50340] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...398] [ip4][..tcp] [......127.0.0.1][50340] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...398] [ip4][..tcp] [......127.0.0.1][50340] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...399] [ip4][..tcp] [......127.0.0.1][50342] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...399] [ip4][..tcp] [......127.0.0.1][50342] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...399] [ip4][..tcp] [......127.0.0.1][50342] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...400] [ip4][..tcp] [......127.0.0.1][50344] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...400] [ip4][..tcp] [......127.0.0.1][50344] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...400] [ip4][..tcp] [......127.0.0.1][50344] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...401] [ip4][..tcp] [......127.0.0.1][50346] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...401] [ip4][..tcp] [......127.0.0.1][50346] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...401] [ip4][..tcp] [......127.0.0.1][50346] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...402] [ip4][..tcp] [......127.0.0.1][50348] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...402] [ip4][..tcp] [......127.0.0.1][50348] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...402] [ip4][..tcp] [......127.0.0.1][50348] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...403] [ip4][..tcp] [......127.0.0.1][50350] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...403] [ip4][..tcp] [......127.0.0.1][50350] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...403] [ip4][..tcp] [......127.0.0.1][50350] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...404] [ip4][..tcp] [......127.0.0.1][50352] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...404] [ip4][..tcp] [......127.0.0.1][50352] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...404] [ip4][..tcp] [......127.0.0.1][50352] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...405] [ip4][..tcp] [......127.0.0.1][50354] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...405] [ip4][..tcp] [......127.0.0.1][50354] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...405] [ip4][..tcp] [......127.0.0.1][50354] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...406] [ip4][..tcp] [......127.0.0.1][50356] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...406] [ip4][..tcp] [......127.0.0.1][50356] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...406] [ip4][..tcp] [......127.0.0.1][50356] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...407] [ip4][..tcp] [......127.0.0.1][50358] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...407] [ip4][..tcp] [......127.0.0.1][50358] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...407] [ip4][..tcp] [......127.0.0.1][50358] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...408] [ip4][..tcp] [......127.0.0.1][50360] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...408] [ip4][..tcp] [......127.0.0.1][50360] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...408] [ip4][..tcp] [......127.0.0.1][50360] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...409] [ip4][..tcp] [......127.0.0.1][50362] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...409] [ip4][..tcp] [......127.0.0.1][50362] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...409] [ip4][..tcp] [......127.0.0.1][50362] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...410] [ip4][..tcp] [......127.0.0.1][50364] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...410] [ip4][..tcp] [......127.0.0.1][50364] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...410] [ip4][..tcp] [......127.0.0.1][50364] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...411] [ip4][..tcp] [......127.0.0.1][50366] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...411] [ip4][..tcp] [......127.0.0.1][50366] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...411] [ip4][..tcp] [......127.0.0.1][50366] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...412] [ip4][..tcp] [......127.0.0.1][50368] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...412] [ip4][..tcp] [......127.0.0.1][50368] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...412] [ip4][..tcp] [......127.0.0.1][50368] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...413] [ip4][..tcp] [......127.0.0.1][50370] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...413] [ip4][..tcp] [......127.0.0.1][50370] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...413] [ip4][..tcp] [......127.0.0.1][50370] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...414] [ip4][..tcp] [......127.0.0.1][50372] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...414] [ip4][..tcp] [......127.0.0.1][50372] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...414] [ip4][..tcp] [......127.0.0.1][50372] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...415] [ip4][..tcp] [......127.0.0.1][50374] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...415] [ip4][..tcp] [......127.0.0.1][50374] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...415] [ip4][..tcp] [......127.0.0.1][50374] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...416] [ip4][..tcp] [......127.0.0.1][50376] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...416] [ip4][..tcp] [......127.0.0.1][50376] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...416] [ip4][..tcp] [......127.0.0.1][50376] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...417] [ip4][..tcp] [......127.0.0.1][50378] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...417] [ip4][..tcp] [......127.0.0.1][50378] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...417] [ip4][..tcp] [......127.0.0.1][50378] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...418] [ip4][..tcp] [......127.0.0.1][50380] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...418] [ip4][..tcp] [......127.0.0.1][50380] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...418] [ip4][..tcp] [......127.0.0.1][50380] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...419] [ip4][..tcp] [......127.0.0.1][50382] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...419] [ip4][..tcp] [......127.0.0.1][50382] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...419] [ip4][..tcp] [......127.0.0.1][50382] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...420] [ip4][..tcp] [......127.0.0.1][50384] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...420] [ip4][..tcp] [......127.0.0.1][50384] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...420] [ip4][..tcp] [......127.0.0.1][50384] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...421] [ip4][..tcp] [......127.0.0.1][50386] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...421] [ip4][..tcp] [......127.0.0.1][50386] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...421] [ip4][..tcp] [......127.0.0.1][50386] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...422] [ip4][..tcp] [......127.0.0.1][50388] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...422] [ip4][..tcp] [......127.0.0.1][50388] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...422] [ip4][..tcp] [......127.0.0.1][50388] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...423] [ip4][..tcp] [......127.0.0.1][50390] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...423] [ip4][..tcp] [......127.0.0.1][50390] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...423] [ip4][..tcp] [......127.0.0.1][50390] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...424] [ip4][..tcp] [......127.0.0.1][50392] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...424] [ip4][..tcp] [......127.0.0.1][50392] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...424] [ip4][..tcp] [......127.0.0.1][50392] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...425] [ip4][..tcp] [......127.0.0.1][50394] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...425] [ip4][..tcp] [......127.0.0.1][50394] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...425] [ip4][..tcp] [......127.0.0.1][50394] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...426] [ip4][..tcp] [......127.0.0.1][50396] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...426] [ip4][..tcp] [......127.0.0.1][50396] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...426] [ip4][..tcp] [......127.0.0.1][50396] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...427] [ip4][..tcp] [......127.0.0.1][50398] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...427] [ip4][..tcp] [......127.0.0.1][50398] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...427] [ip4][..tcp] [......127.0.0.1][50398] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...428] [ip4][..tcp] [......127.0.0.1][50400] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...428] [ip4][..tcp] [......127.0.0.1][50400] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...428] [ip4][..tcp] [......127.0.0.1][50400] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...429] [ip4][..tcp] [......127.0.0.1][50402] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...429] [ip4][..tcp] [......127.0.0.1][50402] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...429] [ip4][..tcp] [......127.0.0.1][50402] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...430] [ip4][..tcp] [......127.0.0.1][50404] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...430] [ip4][..tcp] [......127.0.0.1][50404] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...430] [ip4][..tcp] [......127.0.0.1][50404] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...431] [ip4][..tcp] [......127.0.0.1][50406] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...431] [ip4][..tcp] [......127.0.0.1][50406] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...431] [ip4][..tcp] [......127.0.0.1][50406] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...432] [ip4][..tcp] [......127.0.0.1][50408] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...432] [ip4][..tcp] [......127.0.0.1][50408] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...432] [ip4][..tcp] [......127.0.0.1][50408] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...433] [ip4][..tcp] [......127.0.0.1][50410] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...433] [ip4][..tcp] [......127.0.0.1][50410] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...433] [ip4][..tcp] [......127.0.0.1][50410] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...434] [ip4][..tcp] [......127.0.0.1][50412] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...434] [ip4][..tcp] [......127.0.0.1][50412] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...434] [ip4][..tcp] [......127.0.0.1][50412] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...435] [ip4][..tcp] [......127.0.0.1][50414] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...435] [ip4][..tcp] [......127.0.0.1][50414] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...435] [ip4][..tcp] [......127.0.0.1][50414] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...436] [ip4][..tcp] [......127.0.0.1][50416] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...436] [ip4][..tcp] [......127.0.0.1][50416] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...436] [ip4][..tcp] [......127.0.0.1][50416] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...437] [ip4][..tcp] [......127.0.0.1][50418] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...437] [ip4][..tcp] [......127.0.0.1][50418] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...437] [ip4][..tcp] [......127.0.0.1][50418] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...438] [ip4][..tcp] [......127.0.0.1][50438] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...438] [ip4][..tcp] [......127.0.0.1][50438] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...438] [ip4][..tcp] [......127.0.0.1][50438] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...439] [ip4][..tcp] [......127.0.0.1][50440] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...439] [ip4][..tcp] [......127.0.0.1][50440] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...439] [ip4][..tcp] [......127.0.0.1][50440] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...440] [ip4][..tcp] [......127.0.0.1][50442] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...440] [ip4][..tcp] [......127.0.0.1][50442] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...440] [ip4][..tcp] [......127.0.0.1][50442] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...441] [ip4][..tcp] [......127.0.0.1][50444] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...441] [ip4][..tcp] [......127.0.0.1][50444] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...441] [ip4][..tcp] [......127.0.0.1][50444] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...442] [ip4][..tcp] [......127.0.0.1][50446] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...442] [ip4][..tcp] [......127.0.0.1][50446] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...442] [ip4][..tcp] [......127.0.0.1][50446] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...443] [ip4][..tcp] [......127.0.0.1][50448] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...443] [ip4][..tcp] [......127.0.0.1][50448] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...443] [ip4][..tcp] [......127.0.0.1][50448] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...444] [ip4][..tcp] [......127.0.0.1][50450] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...444] [ip4][..tcp] [......127.0.0.1][50450] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...444] [ip4][..tcp] [......127.0.0.1][50450] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...445] [ip4][..tcp] [......127.0.0.1][50452] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...445] [ip4][..tcp] [......127.0.0.1][50452] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...445] [ip4][..tcp] [......127.0.0.1][50452] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...446] [ip4][..tcp] [......127.0.0.1][50454] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...446] [ip4][..tcp] [......127.0.0.1][50454] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...446] [ip4][..tcp] [......127.0.0.1][50454] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...447] [ip4][..tcp] [......127.0.0.1][50456] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...447] [ip4][..tcp] [......127.0.0.1][50456] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...447] [ip4][..tcp] [......127.0.0.1][50456] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...448] [ip4][..tcp] [......127.0.0.1][50458] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...448] [ip4][..tcp] [......127.0.0.1][50458] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...448] [ip4][..tcp] [......127.0.0.1][50458] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...449] [ip4][..tcp] [......127.0.0.1][50460] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...449] [ip4][..tcp] [......127.0.0.1][50460] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...449] [ip4][..tcp] [......127.0.0.1][50460] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...450] [ip4][..tcp] [......127.0.0.1][50462] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...450] [ip4][..tcp] [......127.0.0.1][50462] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...450] [ip4][..tcp] [......127.0.0.1][50462] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...451] [ip4][..tcp] [......127.0.0.1][50464] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...451] [ip4][..tcp] [......127.0.0.1][50464] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...451] [ip4][..tcp] [......127.0.0.1][50464] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...452] [ip4][..tcp] [......127.0.0.1][50466] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...452] [ip4][..tcp] [......127.0.0.1][50466] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...452] [ip4][..tcp] [......127.0.0.1][50466] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...453] [ip4][..tcp] [......127.0.0.1][50468] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...453] [ip4][..tcp] [......127.0.0.1][50468] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...453] [ip4][..tcp] [......127.0.0.1][50468] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...454] [ip4][..tcp] [......127.0.0.1][50470] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...454] [ip4][..tcp] [......127.0.0.1][50470] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...454] [ip4][..tcp] [......127.0.0.1][50470] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...455] [ip4][..tcp] [......127.0.0.1][50472] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...455] [ip4][..tcp] [......127.0.0.1][50472] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...455] [ip4][..tcp] [......127.0.0.1][50472] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...456] [ip4][..tcp] [......127.0.0.1][50474] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...456] [ip4][..tcp] [......127.0.0.1][50474] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...456] [ip4][..tcp] [......127.0.0.1][50474] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...457] [ip4][..tcp] [......127.0.0.1][50476] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...457] [ip4][..tcp] [......127.0.0.1][50476] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...457] [ip4][..tcp] [......127.0.0.1][50476] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...458] [ip4][..tcp] [......127.0.0.1][50478] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...458] [ip4][..tcp] [......127.0.0.1][50478] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...458] [ip4][..tcp] [......127.0.0.1][50478] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...459] [ip4][..tcp] [......127.0.0.1][50480] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...459] [ip4][..tcp] [......127.0.0.1][50480] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...459] [ip4][..tcp] [......127.0.0.1][50480] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...460] [ip4][..tcp] [......127.0.0.1][50482] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...460] [ip4][..tcp] [......127.0.0.1][50482] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...460] [ip4][..tcp] [......127.0.0.1][50482] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...461] [ip4][..tcp] [......127.0.0.1][50484] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...461] [ip4][..tcp] [......127.0.0.1][50484] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...461] [ip4][..tcp] [......127.0.0.1][50484] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...462] [ip4][..tcp] [......127.0.0.1][50486] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...462] [ip4][..tcp] [......127.0.0.1][50486] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...462] [ip4][..tcp] [......127.0.0.1][50486] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...463] [ip4][..tcp] [......127.0.0.1][50488] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...463] [ip4][..tcp] [......127.0.0.1][50488] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...463] [ip4][..tcp] [......127.0.0.1][50488] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...464] [ip4][..tcp] [......127.0.0.1][50490] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...464] [ip4][..tcp] [......127.0.0.1][50490] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...464] [ip4][..tcp] [......127.0.0.1][50490] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...465] [ip4][..tcp] [......127.0.0.1][50492] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...465] [ip4][..tcp] [......127.0.0.1][50492] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...465] [ip4][..tcp] [......127.0.0.1][50492] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...466] [ip4][..tcp] [......127.0.0.1][50494] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...466] [ip4][..tcp] [......127.0.0.1][50494] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...466] [ip4][..tcp] [......127.0.0.1][50494] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...467] [ip4][..tcp] [......127.0.0.1][50496] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...467] [ip4][..tcp] [......127.0.0.1][50496] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...467] [ip4][..tcp] [......127.0.0.1][50496] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...468] [ip4][..tcp] [......127.0.0.1][50498] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...468] [ip4][..tcp] [......127.0.0.1][50498] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...468] [ip4][..tcp] [......127.0.0.1][50498] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...469] [ip4][..tcp] [......127.0.0.1][50500] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...469] [ip4][..tcp] [......127.0.0.1][50500] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...469] [ip4][..tcp] [......127.0.0.1][50500] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...470] [ip4][..tcp] [......127.0.0.1][50502] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...470] [ip4][..tcp] [......127.0.0.1][50502] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...470] [ip4][..tcp] [......127.0.0.1][50502] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...471] [ip4][..tcp] [......127.0.0.1][50504] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...471] [ip4][..tcp] [......127.0.0.1][50504] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...471] [ip4][..tcp] [......127.0.0.1][50504] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...472] [ip4][..tcp] [......127.0.0.1][50506] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...472] [ip4][..tcp] [......127.0.0.1][50506] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...472] [ip4][..tcp] [......127.0.0.1][50506] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...473] [ip4][..tcp] [......127.0.0.1][50508] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...473] [ip4][..tcp] [......127.0.0.1][50508] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...473] [ip4][..tcp] [......127.0.0.1][50508] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...474] [ip4][..tcp] [......127.0.0.1][50510] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...474] [ip4][..tcp] [......127.0.0.1][50510] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...474] [ip4][..tcp] [......127.0.0.1][50510] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...475] [ip4][..tcp] [......127.0.0.1][50512] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...475] [ip4][..tcp] [......127.0.0.1][50512] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...475] [ip4][..tcp] [......127.0.0.1][50512] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...476] [ip4][..tcp] [......127.0.0.1][50514] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...476] [ip4][..tcp] [......127.0.0.1][50514] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...476] [ip4][..tcp] [......127.0.0.1][50514] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...477] [ip4][..tcp] [......127.0.0.1][50516] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...477] [ip4][..tcp] [......127.0.0.1][50516] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...477] [ip4][..tcp] [......127.0.0.1][50516] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...478] [ip4][..tcp] [......127.0.0.1][50518] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...478] [ip4][..tcp] [......127.0.0.1][50518] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...478] [ip4][..tcp] [......127.0.0.1][50518] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...479] [ip4][..tcp] [......127.0.0.1][50520] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...479] [ip4][..tcp] [......127.0.0.1][50520] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...479] [ip4][..tcp] [......127.0.0.1][50520] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...480] [ip4][..tcp] [......127.0.0.1][50522] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...480] [ip4][..tcp] [......127.0.0.1][50522] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...480] [ip4][..tcp] [......127.0.0.1][50522] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...481] [ip4][..tcp] [......127.0.0.1][50524] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...481] [ip4][..tcp] [......127.0.0.1][50524] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...481] [ip4][..tcp] [......127.0.0.1][50524] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...482] [ip4][..tcp] [......127.0.0.1][50526] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...482] [ip4][..tcp] [......127.0.0.1][50526] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...482] [ip4][..tcp] [......127.0.0.1][50526] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...483] [ip4][..tcp] [......127.0.0.1][50528] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...483] [ip4][..tcp] [......127.0.0.1][50528] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...483] [ip4][..tcp] [......127.0.0.1][50528] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...484] [ip4][..tcp] [......127.0.0.1][50530] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...484] [ip4][..tcp] [......127.0.0.1][50530] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...484] [ip4][..tcp] [......127.0.0.1][50530] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...485] [ip4][..tcp] [......127.0.0.1][50532] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...485] [ip4][..tcp] [......127.0.0.1][50532] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...485] [ip4][..tcp] [......127.0.0.1][50532] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...486] [ip4][..tcp] [......127.0.0.1][50534] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...486] [ip4][..tcp] [......127.0.0.1][50534] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...486] [ip4][..tcp] [......127.0.0.1][50534] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...487] [ip4][..tcp] [......127.0.0.1][50536] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...487] [ip4][..tcp] [......127.0.0.1][50536] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...487] [ip4][..tcp] [......127.0.0.1][50536] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...488] [ip4][..tcp] [......127.0.0.1][50538] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...488] [ip4][..tcp] [......127.0.0.1][50538] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...488] [ip4][..tcp] [......127.0.0.1][50538] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...489] [ip4][..tcp] [......127.0.0.1][50540] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...489] [ip4][..tcp] [......127.0.0.1][50540] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...489] [ip4][..tcp] [......127.0.0.1][50540] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...490] [ip4][..tcp] [......127.0.0.1][50542] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...490] [ip4][..tcp] [......127.0.0.1][50542] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...490] [ip4][..tcp] [......127.0.0.1][50542] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...491] [ip4][..tcp] [......127.0.0.1][50544] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...491] [ip4][..tcp] [......127.0.0.1][50544] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...491] [ip4][..tcp] [......127.0.0.1][50544] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...492] [ip4][..tcp] [......127.0.0.1][50546] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...492] [ip4][..tcp] [......127.0.0.1][50546] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...492] [ip4][..tcp] [......127.0.0.1][50546] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...493] [ip4][..tcp] [......127.0.0.1][50548] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...493] [ip4][..tcp] [......127.0.0.1][50548] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...493] [ip4][..tcp] [......127.0.0.1][50548] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...494] [ip4][..tcp] [......127.0.0.1][50550] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...494] [ip4][..tcp] [......127.0.0.1][50550] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...494] [ip4][..tcp] [......127.0.0.1][50550] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...495] [ip4][..tcp] [......127.0.0.1][50552] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...495] [ip4][..tcp] [......127.0.0.1][50552] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...495] [ip4][..tcp] [......127.0.0.1][50552] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...496] [ip4][..tcp] [......127.0.0.1][50554] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...496] [ip4][..tcp] [......127.0.0.1][50554] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...496] [ip4][..tcp] [......127.0.0.1][50554] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...497] [ip4][..tcp] [......127.0.0.1][50556] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...497] [ip4][..tcp] [......127.0.0.1][50556] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...497] [ip4][..tcp] [......127.0.0.1][50556] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...498] [ip4][..tcp] [......127.0.0.1][50558] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...498] [ip4][..tcp] [......127.0.0.1][50558] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...498] [ip4][..tcp] [......127.0.0.1][50558] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...499] [ip4][..tcp] [......127.0.0.1][50560] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...499] [ip4][..tcp] [......127.0.0.1][50560] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...499] [ip4][..tcp] [......127.0.0.1][50560] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...500] [ip4][..tcp] [......127.0.0.1][50562] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...500] [ip4][..tcp] [......127.0.0.1][50562] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...500] [ip4][..tcp] [......127.0.0.1][50562] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Possible Exploit - new: [...501] [ip4][..tcp] [......127.0.0.1][50564] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...501] [ip4][..tcp] [......127.0.0.1][50564] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...501] [ip4][..tcp] [......127.0.0.1][50564] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...502] [ip4][..tcp] [......127.0.0.1][50566] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...502] [ip4][..tcp] [......127.0.0.1][50566] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...502] [ip4][..tcp] [......127.0.0.1][50566] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...503] [ip4][..tcp] [......127.0.0.1][50568] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...503] [ip4][..tcp] [......127.0.0.1][50568] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...503] [ip4][..tcp] [......127.0.0.1][50568] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...504] [ip4][..tcp] [......127.0.0.1][50570] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...504] [ip4][..tcp] [......127.0.0.1][50570] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...504] [ip4][..tcp] [......127.0.0.1][50570] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...505] [ip4][..tcp] [......127.0.0.1][50572] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...505] [ip4][..tcp] [......127.0.0.1][50572] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...505] [ip4][..tcp] [......127.0.0.1][50572] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...506] [ip4][..tcp] [......127.0.0.1][50574] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...506] [ip4][..tcp] [......127.0.0.1][50574] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...506] [ip4][..tcp] [......127.0.0.1][50574] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...507] [ip4][..tcp] [......127.0.0.1][50576] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...507] [ip4][..tcp] [......127.0.0.1][50576] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...507] [ip4][..tcp] [......127.0.0.1][50576] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...508] [ip4][..tcp] [......127.0.0.1][50578] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...508] [ip4][..tcp] [......127.0.0.1][50578] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...508] [ip4][..tcp] [......127.0.0.1][50578] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...509] [ip4][..tcp] [......127.0.0.1][50580] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...509] [ip4][..tcp] [......127.0.0.1][50580] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...509] [ip4][..tcp] [......127.0.0.1][50580] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...510] [ip4][..tcp] [......127.0.0.1][50582] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...510] [ip4][..tcp] [......127.0.0.1][50582] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...510] [ip4][..tcp] [......127.0.0.1][50582] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...511] [ip4][..tcp] [......127.0.0.1][50584] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...511] [ip4][..tcp] [......127.0.0.1][50584] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...511] [ip4][..tcp] [......127.0.0.1][50584] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...512] [ip4][..tcp] [......127.0.0.1][50586] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...512] [ip4][..tcp] [......127.0.0.1][50586] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...512] [ip4][..tcp] [......127.0.0.1][50586] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...513] [ip4][..tcp] [......127.0.0.1][50588] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...513] [ip4][..tcp] [......127.0.0.1][50588] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...513] [ip4][..tcp] [......127.0.0.1][50588] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...514] [ip4][..tcp] [......127.0.0.1][50590] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...514] [ip4][..tcp] [......127.0.0.1][50590] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...514] [ip4][..tcp] [......127.0.0.1][50590] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...515] [ip4][..tcp] [......127.0.0.1][50592] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...515] [ip4][..tcp] [......127.0.0.1][50592] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...515] [ip4][..tcp] [......127.0.0.1][50592] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...516] [ip4][..tcp] [......127.0.0.1][50594] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...516] [ip4][..tcp] [......127.0.0.1][50594] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...516] [ip4][..tcp] [......127.0.0.1][50594] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...517] [ip4][..tcp] [......127.0.0.1][50596] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...517] [ip4][..tcp] [......127.0.0.1][50596] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...517] [ip4][..tcp] [......127.0.0.1][50596] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...518] [ip4][..tcp] [......127.0.0.1][50598] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...518] [ip4][..tcp] [......127.0.0.1][50598] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...518] [ip4][..tcp] [......127.0.0.1][50598] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...519] [ip4][..tcp] [......127.0.0.1][50600] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...519] [ip4][..tcp] [......127.0.0.1][50600] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...519] [ip4][..tcp] [......127.0.0.1][50600] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...520] [ip4][..tcp] [......127.0.0.1][50602] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...520] [ip4][..tcp] [......127.0.0.1][50602] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...520] [ip4][..tcp] [......127.0.0.1][50602] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...521] [ip4][..tcp] [......127.0.0.1][50604] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...521] [ip4][..tcp] [......127.0.0.1][50604] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...521] [ip4][..tcp] [......127.0.0.1][50604] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...522] [ip4][..tcp] [......127.0.0.1][50606] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...522] [ip4][..tcp] [......127.0.0.1][50606] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...522] [ip4][..tcp] [......127.0.0.1][50606] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...523] [ip4][..tcp] [......127.0.0.1][50608] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...523] [ip4][..tcp] [......127.0.0.1][50608] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...523] [ip4][..tcp] [......127.0.0.1][50608] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...524] [ip4][..tcp] [......127.0.0.1][50610] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...524] [ip4][..tcp] [......127.0.0.1][50610] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...524] [ip4][..tcp] [......127.0.0.1][50610] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...525] [ip4][..tcp] [......127.0.0.1][50612] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...525] [ip4][..tcp] [......127.0.0.1][50612] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...525] [ip4][..tcp] [......127.0.0.1][50612] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...526] [ip4][..tcp] [......127.0.0.1][50614] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...526] [ip4][..tcp] [......127.0.0.1][50614] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...526] [ip4][..tcp] [......127.0.0.1][50614] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...527] [ip4][..tcp] [......127.0.0.1][50616] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...527] [ip4][..tcp] [......127.0.0.1][50616] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...527] [ip4][..tcp] [......127.0.0.1][50616] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...528] [ip4][..tcp] [......127.0.0.1][50618] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...528] [ip4][..tcp] [......127.0.0.1][50618] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...528] [ip4][..tcp] [......127.0.0.1][50618] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...529] [ip4][..tcp] [......127.0.0.1][50620] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...529] [ip4][..tcp] [......127.0.0.1][50620] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...529] [ip4][..tcp] [......127.0.0.1][50620] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...530] [ip4][..tcp] [......127.0.0.1][50622] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...530] [ip4][..tcp] [......127.0.0.1][50622] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...530] [ip4][..tcp] [......127.0.0.1][50622] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...531] [ip4][..tcp] [......127.0.0.1][50624] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...531] [ip4][..tcp] [......127.0.0.1][50624] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...531] [ip4][..tcp] [......127.0.0.1][50624] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...532] [ip4][..tcp] [......127.0.0.1][50626] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...532] [ip4][..tcp] [......127.0.0.1][50626] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...532] [ip4][..tcp] [......127.0.0.1][50626] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...533] [ip4][..tcp] [......127.0.0.1][50628] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...533] [ip4][..tcp] [......127.0.0.1][50628] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...533] [ip4][..tcp] [......127.0.0.1][50628] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...534] [ip4][..tcp] [......127.0.0.1][50630] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...534] [ip4][..tcp] [......127.0.0.1][50630] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...534] [ip4][..tcp] [......127.0.0.1][50630] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...535] [ip4][..tcp] [......127.0.0.1][50632] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...535] [ip4][..tcp] [......127.0.0.1][50632] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...535] [ip4][..tcp] [......127.0.0.1][50632] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...536] [ip4][..tcp] [......127.0.0.1][50634] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...536] [ip4][..tcp] [......127.0.0.1][50634] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...536] [ip4][..tcp] [......127.0.0.1][50634] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...537] [ip4][..tcp] [......127.0.0.1][50636] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...537] [ip4][..tcp] [......127.0.0.1][50636] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...537] [ip4][..tcp] [......127.0.0.1][50636] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...538] [ip4][..tcp] [......127.0.0.1][50638] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...538] [ip4][..tcp] [......127.0.0.1][50638] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...538] [ip4][..tcp] [......127.0.0.1][50638] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...539] [ip4][..tcp] [......127.0.0.1][50640] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...539] [ip4][..tcp] [......127.0.0.1][50640] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...539] [ip4][..tcp] [......127.0.0.1][50640] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...540] [ip4][..tcp] [......127.0.0.1][50642] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...540] [ip4][..tcp] [......127.0.0.1][50642] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...540] [ip4][..tcp] [......127.0.0.1][50642] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...541] [ip4][..tcp] [......127.0.0.1][50644] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...541] [ip4][..tcp] [......127.0.0.1][50644] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...541] [ip4][..tcp] [......127.0.0.1][50644] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...542] [ip4][..tcp] [......127.0.0.1][50646] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...542] [ip4][..tcp] [......127.0.0.1][50646] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...542] [ip4][..tcp] [......127.0.0.1][50646] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...543] [ip4][..tcp] [......127.0.0.1][50648] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...543] [ip4][..tcp] [......127.0.0.1][50648] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...543] [ip4][..tcp] [......127.0.0.1][50648] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...544] [ip4][..tcp] [......127.0.0.1][50650] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...544] [ip4][..tcp] [......127.0.0.1][50650] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...544] [ip4][..tcp] [......127.0.0.1][50650] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...545] [ip4][..tcp] [......127.0.0.1][50652] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...545] [ip4][..tcp] [......127.0.0.1][50652] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...545] [ip4][..tcp] [......127.0.0.1][50652] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...546] [ip4][..tcp] [......127.0.0.1][50654] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...546] [ip4][..tcp] [......127.0.0.1][50654] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...546] [ip4][..tcp] [......127.0.0.1][50654] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...547] [ip4][..tcp] [......127.0.0.1][50656] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...547] [ip4][..tcp] [......127.0.0.1][50656] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...547] [ip4][..tcp] [......127.0.0.1][50656] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...548] [ip4][..tcp] [......127.0.0.1][50658] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...548] [ip4][..tcp] [......127.0.0.1][50658] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...548] [ip4][..tcp] [......127.0.0.1][50658] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...549] [ip4][..tcp] [......127.0.0.1][50660] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...549] [ip4][..tcp] [......127.0.0.1][50660] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...549] [ip4][..tcp] [......127.0.0.1][50660] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...550] [ip4][..tcp] [......127.0.0.1][50662] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...550] [ip4][..tcp] [......127.0.0.1][50662] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...550] [ip4][..tcp] [......127.0.0.1][50662] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...551] [ip4][..tcp] [......127.0.0.1][50664] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...551] [ip4][..tcp] [......127.0.0.1][50664] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...551] [ip4][..tcp] [......127.0.0.1][50664] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...552] [ip4][..tcp] [......127.0.0.1][50666] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...552] [ip4][..tcp] [......127.0.0.1][50666] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...552] [ip4][..tcp] [......127.0.0.1][50666] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...553] [ip4][..tcp] [......127.0.0.1][50668] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...553] [ip4][..tcp] [......127.0.0.1][50668] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...553] [ip4][..tcp] [......127.0.0.1][50668] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...554] [ip4][..tcp] [......127.0.0.1][50670] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...554] [ip4][..tcp] [......127.0.0.1][50670] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...554] [ip4][..tcp] [......127.0.0.1][50670] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...555] [ip4][..tcp] [......127.0.0.1][50672] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...555] [ip4][..tcp] [......127.0.0.1][50672] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...555] [ip4][..tcp] [......127.0.0.1][50672] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...556] [ip4][..tcp] [......127.0.0.1][50674] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...556] [ip4][..tcp] [......127.0.0.1][50674] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...556] [ip4][..tcp] [......127.0.0.1][50674] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...557] [ip4][..tcp] [......127.0.0.1][50676] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...557] [ip4][..tcp] [......127.0.0.1][50676] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...557] [ip4][..tcp] [......127.0.0.1][50676] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...558] [ip4][..tcp] [......127.0.0.1][50678] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...558] [ip4][..tcp] [......127.0.0.1][50678] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...558] [ip4][..tcp] [......127.0.0.1][50678] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...559] [ip4][..tcp] [......127.0.0.1][50680] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...559] [ip4][..tcp] [......127.0.0.1][50680] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...559] [ip4][..tcp] [......127.0.0.1][50680] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...560] [ip4][..tcp] [......127.0.0.1][50682] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...560] [ip4][..tcp] [......127.0.0.1][50682] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...560] [ip4][..tcp] [......127.0.0.1][50682] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...561] [ip4][..tcp] [......127.0.0.1][50684] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...561] [ip4][..tcp] [......127.0.0.1][50684] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...561] [ip4][..tcp] [......127.0.0.1][50684] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...562] [ip4][..tcp] [......127.0.0.1][50686] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...562] [ip4][..tcp] [......127.0.0.1][50686] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...562] [ip4][..tcp] [......127.0.0.1][50686] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...563] [ip4][..tcp] [......127.0.0.1][50688] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...563] [ip4][..tcp] [......127.0.0.1][50688] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...563] [ip4][..tcp] [......127.0.0.1][50688] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...564] [ip4][..tcp] [......127.0.0.1][50690] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...564] [ip4][..tcp] [......127.0.0.1][50690] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...564] [ip4][..tcp] [......127.0.0.1][50690] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...565] [ip4][..tcp] [......127.0.0.1][50692] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...565] [ip4][..tcp] [......127.0.0.1][50692] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...565] [ip4][..tcp] [......127.0.0.1][50692] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...566] [ip4][..tcp] [......127.0.0.1][50694] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...566] [ip4][..tcp] [......127.0.0.1][50694] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...566] [ip4][..tcp] [......127.0.0.1][50694] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...567] [ip4][..tcp] [......127.0.0.1][50696] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...567] [ip4][..tcp] [......127.0.0.1][50696] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...567] [ip4][..tcp] [......127.0.0.1][50696] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...568] [ip4][..tcp] [......127.0.0.1][50698] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...568] [ip4][..tcp] [......127.0.0.1][50698] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...568] [ip4][..tcp] [......127.0.0.1][50698] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...569] [ip4][..tcp] [......127.0.0.1][50700] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...569] [ip4][..tcp] [......127.0.0.1][50700] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...569] [ip4][..tcp] [......127.0.0.1][50700] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...570] [ip4][..tcp] [......127.0.0.1][50702] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...570] [ip4][..tcp] [......127.0.0.1][50702] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...570] [ip4][..tcp] [......127.0.0.1][50702] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...571] [ip4][..tcp] [......127.0.0.1][50704] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...571] [ip4][..tcp] [......127.0.0.1][50704] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...571] [ip4][..tcp] [......127.0.0.1][50704] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...572] [ip4][..tcp] [......127.0.0.1][50706] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...572] [ip4][..tcp] [......127.0.0.1][50706] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...572] [ip4][..tcp] [......127.0.0.1][50706] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...573] [ip4][..tcp] [......127.0.0.1][50708] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...573] [ip4][..tcp] [......127.0.0.1][50708] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...573] [ip4][..tcp] [......127.0.0.1][50708] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...574] [ip4][..tcp] [......127.0.0.1][50710] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...574] [ip4][..tcp] [......127.0.0.1][50710] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...574] [ip4][..tcp] [......127.0.0.1][50710] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...575] [ip4][..tcp] [......127.0.0.1][50712] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...575] [ip4][..tcp] [......127.0.0.1][50712] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...575] [ip4][..tcp] [......127.0.0.1][50712] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...576] [ip4][..tcp] [......127.0.0.1][50714] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...576] [ip4][..tcp] [......127.0.0.1][50714] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...576] [ip4][..tcp] [......127.0.0.1][50714] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...577] [ip4][..tcp] [......127.0.0.1][50716] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...577] [ip4][..tcp] [......127.0.0.1][50716] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...577] [ip4][..tcp] [......127.0.0.1][50716] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...578] [ip4][..tcp] [......127.0.0.1][50718] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...578] [ip4][..tcp] [......127.0.0.1][50718] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...578] [ip4][..tcp] [......127.0.0.1][50718] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...579] [ip4][..tcp] [......127.0.0.1][50720] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...579] [ip4][..tcp] [......127.0.0.1][50720] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...579] [ip4][..tcp] [......127.0.0.1][50720] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...580] [ip4][..tcp] [......127.0.0.1][50722] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...580] [ip4][..tcp] [......127.0.0.1][50722] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...580] [ip4][..tcp] [......127.0.0.1][50722] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...581] [ip4][..tcp] [......127.0.0.1][50724] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...581] [ip4][..tcp] [......127.0.0.1][50724] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...581] [ip4][..tcp] [......127.0.0.1][50724] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...582] [ip4][..tcp] [......127.0.0.1][50726] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...582] [ip4][..tcp] [......127.0.0.1][50726] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...582] [ip4][..tcp] [......127.0.0.1][50726] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...583] [ip4][..tcp] [......127.0.0.1][50728] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...583] [ip4][..tcp] [......127.0.0.1][50728] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...583] [ip4][..tcp] [......127.0.0.1][50728] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...584] [ip4][..tcp] [......127.0.0.1][50730] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...584] [ip4][..tcp] [......127.0.0.1][50730] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...584] [ip4][..tcp] [......127.0.0.1][50730] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...585] [ip4][..tcp] [......127.0.0.1][50732] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...585] [ip4][..tcp] [......127.0.0.1][50732] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...585] [ip4][..tcp] [......127.0.0.1][50732] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...586] [ip4][..tcp] [......127.0.0.1][50734] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...586] [ip4][..tcp] [......127.0.0.1][50734] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...586] [ip4][..tcp] [......127.0.0.1][50734] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...587] [ip4][..tcp] [......127.0.0.1][50736] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...587] [ip4][..tcp] [......127.0.0.1][50736] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...587] [ip4][..tcp] [......127.0.0.1][50736] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...588] [ip4][..tcp] [......127.0.0.1][50738] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...588] [ip4][..tcp] [......127.0.0.1][50738] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...588] [ip4][..tcp] [......127.0.0.1][50738] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...589] [ip4][..tcp] [......127.0.0.1][50740] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...589] [ip4][..tcp] [......127.0.0.1][50740] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...589] [ip4][..tcp] [......127.0.0.1][50740] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...590] [ip4][..tcp] [......127.0.0.1][50742] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...590] [ip4][..tcp] [......127.0.0.1][50742] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...590] [ip4][..tcp] [......127.0.0.1][50742] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...591] [ip4][..tcp] [......127.0.0.1][50744] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...591] [ip4][..tcp] [......127.0.0.1][50744] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...591] [ip4][..tcp] [......127.0.0.1][50744] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...592] [ip4][..tcp] [......127.0.0.1][50746] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...592] [ip4][..tcp] [......127.0.0.1][50746] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...592] [ip4][..tcp] [......127.0.0.1][50746] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...593] [ip4][..tcp] [......127.0.0.1][50748] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...593] [ip4][..tcp] [......127.0.0.1][50748] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...593] [ip4][..tcp] [......127.0.0.1][50748] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...594] [ip4][..tcp] [......127.0.0.1][50750] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...594] [ip4][..tcp] [......127.0.0.1][50750] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...594] [ip4][..tcp] [......127.0.0.1][50750] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...595] [ip4][..tcp] [......127.0.0.1][50752] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...595] [ip4][..tcp] [......127.0.0.1][50752] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...595] [ip4][..tcp] [......127.0.0.1][50752] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...596] [ip4][..tcp] [......127.0.0.1][50754] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...596] [ip4][..tcp] [......127.0.0.1][50754] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...596] [ip4][..tcp] [......127.0.0.1][50754] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...597] [ip4][..tcp] [......127.0.0.1][50756] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...597] [ip4][..tcp] [......127.0.0.1][50756] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...597] [ip4][..tcp] [......127.0.0.1][50756] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...598] [ip4][..tcp] [......127.0.0.1][50758] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...598] [ip4][..tcp] [......127.0.0.1][50758] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...598] [ip4][..tcp] [......127.0.0.1][50758] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...599] [ip4][..tcp] [......127.0.0.1][50760] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...599] [ip4][..tcp] [......127.0.0.1][50760] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...599] [ip4][..tcp] [......127.0.0.1][50760] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...600] [ip4][..tcp] [......127.0.0.1][50762] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...600] [ip4][..tcp] [......127.0.0.1][50762] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...600] [ip4][..tcp] [......127.0.0.1][50762] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...601] [ip4][..tcp] [......127.0.0.1][50764] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...601] [ip4][..tcp] [......127.0.0.1][50764] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...601] [ip4][..tcp] [......127.0.0.1][50764] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...602] [ip4][..tcp] [......127.0.0.1][50766] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...602] [ip4][..tcp] [......127.0.0.1][50766] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...602] [ip4][..tcp] [......127.0.0.1][50766] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...603] [ip4][..tcp] [......127.0.0.1][50768] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...603] [ip4][..tcp] [......127.0.0.1][50768] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...603] [ip4][..tcp] [......127.0.0.1][50768] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...604] [ip4][..tcp] [......127.0.0.1][50770] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...604] [ip4][..tcp] [......127.0.0.1][50770] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...604] [ip4][..tcp] [......127.0.0.1][50770] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...605] [ip4][..tcp] [......127.0.0.1][50772] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...605] [ip4][..tcp] [......127.0.0.1][50772] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...605] [ip4][..tcp] [......127.0.0.1][50772] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...606] [ip4][..tcp] [......127.0.0.1][50774] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...606] [ip4][..tcp] [......127.0.0.1][50774] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...606] [ip4][..tcp] [......127.0.0.1][50774] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...607] [ip4][..tcp] [......127.0.0.1][50776] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...607] [ip4][..tcp] [......127.0.0.1][50776] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...607] [ip4][..tcp] [......127.0.0.1][50776] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...608] [ip4][..tcp] [......127.0.0.1][50778] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...608] [ip4][..tcp] [......127.0.0.1][50778] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...608] [ip4][..tcp] [......127.0.0.1][50778] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...609] [ip4][..tcp] [......127.0.0.1][50780] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...609] [ip4][..tcp] [......127.0.0.1][50780] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...609] [ip4][..tcp] [......127.0.0.1][50780] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...610] [ip4][..tcp] [......127.0.0.1][50782] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...610] [ip4][..tcp] [......127.0.0.1][50782] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...610] [ip4][..tcp] [......127.0.0.1][50782] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...611] [ip4][..tcp] [......127.0.0.1][50784] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...611] [ip4][..tcp] [......127.0.0.1][50784] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...611] [ip4][..tcp] [......127.0.0.1][50784] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...612] [ip4][..tcp] [......127.0.0.1][50786] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...612] [ip4][..tcp] [......127.0.0.1][50786] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...612] [ip4][..tcp] [......127.0.0.1][50786] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...613] [ip4][..tcp] [......127.0.0.1][50788] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...613] [ip4][..tcp] [......127.0.0.1][50788] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...613] [ip4][..tcp] [......127.0.0.1][50788] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...614] [ip4][..tcp] [......127.0.0.1][50790] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...614] [ip4][..tcp] [......127.0.0.1][50790] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...614] [ip4][..tcp] [......127.0.0.1][50790] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...615] [ip4][..tcp] [......127.0.0.1][50792] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...615] [ip4][..tcp] [......127.0.0.1][50792] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...615] [ip4][..tcp] [......127.0.0.1][50792] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...616] [ip4][..tcp] [......127.0.0.1][50794] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...616] [ip4][..tcp] [......127.0.0.1][50794] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...616] [ip4][..tcp] [......127.0.0.1][50794] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...617] [ip4][..tcp] [......127.0.0.1][50796] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...617] [ip4][..tcp] [......127.0.0.1][50796] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...617] [ip4][..tcp] [......127.0.0.1][50796] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...618] [ip4][..tcp] [......127.0.0.1][50798] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...618] [ip4][..tcp] [......127.0.0.1][50798] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...618] [ip4][..tcp] [......127.0.0.1][50798] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...619] [ip4][..tcp] [......127.0.0.1][50800] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...619] [ip4][..tcp] [......127.0.0.1][50800] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...619] [ip4][..tcp] [......127.0.0.1][50800] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...620] [ip4][..tcp] [......127.0.0.1][50802] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...620] [ip4][..tcp] [......127.0.0.1][50802] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...620] [ip4][..tcp] [......127.0.0.1][50802] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...621] [ip4][..tcp] [......127.0.0.1][50804] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...621] [ip4][..tcp] [......127.0.0.1][50804] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...621] [ip4][..tcp] [......127.0.0.1][50804] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...622] [ip4][..tcp] [......127.0.0.1][50806] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...622] [ip4][..tcp] [......127.0.0.1][50806] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...622] [ip4][..tcp] [......127.0.0.1][50806] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...623] [ip4][..tcp] [......127.0.0.1][50808] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...623] [ip4][..tcp] [......127.0.0.1][50808] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...623] [ip4][..tcp] [......127.0.0.1][50808] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...624] [ip4][..tcp] [......127.0.0.1][50810] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...624] [ip4][..tcp] [......127.0.0.1][50810] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...624] [ip4][..tcp] [......127.0.0.1][50810] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...625] [ip4][..tcp] [......127.0.0.1][50812] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...625] [ip4][..tcp] [......127.0.0.1][50812] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...625] [ip4][..tcp] [......127.0.0.1][50812] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...626] [ip4][..tcp] [......127.0.0.1][50814] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...626] [ip4][..tcp] [......127.0.0.1][50814] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...626] [ip4][..tcp] [......127.0.0.1][50814] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...627] [ip4][..tcp] [......127.0.0.1][50816] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...627] [ip4][..tcp] [......127.0.0.1][50816] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...627] [ip4][..tcp] [......127.0.0.1][50816] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...628] [ip4][..tcp] [......127.0.0.1][50818] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...628] [ip4][..tcp] [......127.0.0.1][50818] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...628] [ip4][..tcp] [......127.0.0.1][50818] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...629] [ip4][..tcp] [......127.0.0.1][50820] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...629] [ip4][..tcp] [......127.0.0.1][50820] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...629] [ip4][..tcp] [......127.0.0.1][50820] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...630] [ip4][..tcp] [......127.0.0.1][50822] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...630] [ip4][..tcp] [......127.0.0.1][50822] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...630] [ip4][..tcp] [......127.0.0.1][50822] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...631] [ip4][..tcp] [......127.0.0.1][50824] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...631] [ip4][..tcp] [......127.0.0.1][50824] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...631] [ip4][..tcp] [......127.0.0.1][50824] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...632] [ip4][..tcp] [......127.0.0.1][50826] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...632] [ip4][..tcp] [......127.0.0.1][50826] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...632] [ip4][..tcp] [......127.0.0.1][50826] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...633] [ip4][..tcp] [......127.0.0.1][50828] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...633] [ip4][..tcp] [......127.0.0.1][50828] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...633] [ip4][..tcp] [......127.0.0.1][50828] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...634] [ip4][..tcp] [......127.0.0.1][50830] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...634] [ip4][..tcp] [......127.0.0.1][50830] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...634] [ip4][..tcp] [......127.0.0.1][50830] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...635] [ip4][..tcp] [......127.0.0.1][50832] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...635] [ip4][..tcp] [......127.0.0.1][50832] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...635] [ip4][..tcp] [......127.0.0.1][50832] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...636] [ip4][..tcp] [......127.0.0.1][50834] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...636] [ip4][..tcp] [......127.0.0.1][50834] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...636] [ip4][..tcp] [......127.0.0.1][50834] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...637] [ip4][..tcp] [......127.0.0.1][50836] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...637] [ip4][..tcp] [......127.0.0.1][50836] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...637] [ip4][..tcp] [......127.0.0.1][50836] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...638] [ip4][..tcp] [......127.0.0.1][50838] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...638] [ip4][..tcp] [......127.0.0.1][50838] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...638] [ip4][..tcp] [......127.0.0.1][50838] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...639] [ip4][..tcp] [......127.0.0.1][50840] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...639] [ip4][..tcp] [......127.0.0.1][50840] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...639] [ip4][..tcp] [......127.0.0.1][50840] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...640] [ip4][..tcp] [......127.0.0.1][50842] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...640] [ip4][..tcp] [......127.0.0.1][50842] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...640] [ip4][..tcp] [......127.0.0.1][50842] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...641] [ip4][..tcp] [......127.0.0.1][50844] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...641] [ip4][..tcp] [......127.0.0.1][50844] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...641] [ip4][..tcp] [......127.0.0.1][50844] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...642] [ip4][..tcp] [......127.0.0.1][50846] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...642] [ip4][..tcp] [......127.0.0.1][50846] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...642] [ip4][..tcp] [......127.0.0.1][50846] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...643] [ip4][..tcp] [......127.0.0.1][50848] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...643] [ip4][..tcp] [......127.0.0.1][50848] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...643] [ip4][..tcp] [......127.0.0.1][50848] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...644] [ip4][..tcp] [......127.0.0.1][50850] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...644] [ip4][..tcp] [......127.0.0.1][50850] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...644] [ip4][..tcp] [......127.0.0.1][50850] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...645] [ip4][..tcp] [......127.0.0.1][50852] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...645] [ip4][..tcp] [......127.0.0.1][50852] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...645] [ip4][..tcp] [......127.0.0.1][50852] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...646] [ip4][..tcp] [......127.0.0.1][50854] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...646] [ip4][..tcp] [......127.0.0.1][50854] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...646] [ip4][..tcp] [......127.0.0.1][50854] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...647] [ip4][..tcp] [......127.0.0.1][50856] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...647] [ip4][..tcp] [......127.0.0.1][50856] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...647] [ip4][..tcp] [......127.0.0.1][50856] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...648] [ip4][..tcp] [......127.0.0.1][50858] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...648] [ip4][..tcp] [......127.0.0.1][50858] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...648] [ip4][..tcp] [......127.0.0.1][50858] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...649] [ip4][..tcp] [......127.0.0.1][50860] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...649] [ip4][..tcp] [......127.0.0.1][50860] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...649] [ip4][..tcp] [......127.0.0.1][50860] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...650] [ip4][..tcp] [......127.0.0.1][50862] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...650] [ip4][..tcp] [......127.0.0.1][50862] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...650] [ip4][..tcp] [......127.0.0.1][50862] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...651] [ip4][..tcp] [......127.0.0.1][50864] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...651] [ip4][..tcp] [......127.0.0.1][50864] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...651] [ip4][..tcp] [......127.0.0.1][50864] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...652] [ip4][..tcp] [......127.0.0.1][50866] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...652] [ip4][..tcp] [......127.0.0.1][50866] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...652] [ip4][..tcp] [......127.0.0.1][50866] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...653] [ip4][..tcp] [......127.0.0.1][50868] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...653] [ip4][..tcp] [......127.0.0.1][50868] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...653] [ip4][..tcp] [......127.0.0.1][50868] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...654] [ip4][..tcp] [......127.0.0.1][50870] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...654] [ip4][..tcp] [......127.0.0.1][50870] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...654] [ip4][..tcp] [......127.0.0.1][50870] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...655] [ip4][..tcp] [......127.0.0.1][50872] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...655] [ip4][..tcp] [......127.0.0.1][50872] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...655] [ip4][..tcp] [......127.0.0.1][50872] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...656] [ip4][..tcp] [......127.0.0.1][50874] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...656] [ip4][..tcp] [......127.0.0.1][50874] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...656] [ip4][..tcp] [......127.0.0.1][50874] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...657] [ip4][..tcp] [......127.0.0.1][50876] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...657] [ip4][..tcp] [......127.0.0.1][50876] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...657] [ip4][..tcp] [......127.0.0.1][50876] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...658] [ip4][..tcp] [......127.0.0.1][50878] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...658] [ip4][..tcp] [......127.0.0.1][50878] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...658] [ip4][..tcp] [......127.0.0.1][50878] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...659] [ip4][..tcp] [......127.0.0.1][50880] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...659] [ip4][..tcp] [......127.0.0.1][50880] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...659] [ip4][..tcp] [......127.0.0.1][50880] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...660] [ip4][..tcp] [......127.0.0.1][50882] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...660] [ip4][..tcp] [......127.0.0.1][50882] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...660] [ip4][..tcp] [......127.0.0.1][50882] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...661] [ip4][..tcp] [......127.0.0.1][50884] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...661] [ip4][..tcp] [......127.0.0.1][50884] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...661] [ip4][..tcp] [......127.0.0.1][50884] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...662] [ip4][..tcp] [......127.0.0.1][50886] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...662] [ip4][..tcp] [......127.0.0.1][50886] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...662] [ip4][..tcp] [......127.0.0.1][50886] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...663] [ip4][..tcp] [......127.0.0.1][50888] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...663] [ip4][..tcp] [......127.0.0.1][50888] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...663] [ip4][..tcp] [......127.0.0.1][50888] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...664] [ip4][..tcp] [......127.0.0.1][50890] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...664] [ip4][..tcp] [......127.0.0.1][50890] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...664] [ip4][..tcp] [......127.0.0.1][50890] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...665] [ip4][..tcp] [......127.0.0.1][50892] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...665] [ip4][..tcp] [......127.0.0.1][50892] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...665] [ip4][..tcp] [......127.0.0.1][50892] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...666] [ip4][..tcp] [......127.0.0.1][50894] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...666] [ip4][..tcp] [......127.0.0.1][50894] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...666] [ip4][..tcp] [......127.0.0.1][50894] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...667] [ip4][..tcp] [......127.0.0.1][50896] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...667] [ip4][..tcp] [......127.0.0.1][50896] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...667] [ip4][..tcp] [......127.0.0.1][50896] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...668] [ip4][..tcp] [......127.0.0.1][50898] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...668] [ip4][..tcp] [......127.0.0.1][50898] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...668] [ip4][..tcp] [......127.0.0.1][50898] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...669] [ip4][..tcp] [......127.0.0.1][50900] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...669] [ip4][..tcp] [......127.0.0.1][50900] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...669] [ip4][..tcp] [......127.0.0.1][50900] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...670] [ip4][..tcp] [......127.0.0.1][50902] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...670] [ip4][..tcp] [......127.0.0.1][50902] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...670] [ip4][..tcp] [......127.0.0.1][50902] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...671] [ip4][..tcp] [......127.0.0.1][50904] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...671] [ip4][..tcp] [......127.0.0.1][50904] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...671] [ip4][..tcp] [......127.0.0.1][50904] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...672] [ip4][..tcp] [......127.0.0.1][50906] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...672] [ip4][..tcp] [......127.0.0.1][50906] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...672] [ip4][..tcp] [......127.0.0.1][50906] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...673] [ip4][..tcp] [......127.0.0.1][50908] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...673] [ip4][..tcp] [......127.0.0.1][50908] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...673] [ip4][..tcp] [......127.0.0.1][50908] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...674] [ip4][..tcp] [......127.0.0.1][50910] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...674] [ip4][..tcp] [......127.0.0.1][50910] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...674] [ip4][..tcp] [......127.0.0.1][50910] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...675] [ip4][..tcp] [......127.0.0.1][50912] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...675] [ip4][..tcp] [......127.0.0.1][50912] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...675] [ip4][..tcp] [......127.0.0.1][50912] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...676] [ip4][..tcp] [......127.0.0.1][50914] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...676] [ip4][..tcp] [......127.0.0.1][50914] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...676] [ip4][..tcp] [......127.0.0.1][50914] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...677] [ip4][..tcp] [......127.0.0.1][50916] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...677] [ip4][..tcp] [......127.0.0.1][50916] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...677] [ip4][..tcp] [......127.0.0.1][50916] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...678] [ip4][..tcp] [......127.0.0.1][50918] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...678] [ip4][..tcp] [......127.0.0.1][50918] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...678] [ip4][..tcp] [......127.0.0.1][50918] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...679] [ip4][..tcp] [......127.0.0.1][50920] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...679] [ip4][..tcp] [......127.0.0.1][50920] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...679] [ip4][..tcp] [......127.0.0.1][50920] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...680] [ip4][..tcp] [......127.0.0.1][50922] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...680] [ip4][..tcp] [......127.0.0.1][50922] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...680] [ip4][..tcp] [......127.0.0.1][50922] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...681] [ip4][..tcp] [......127.0.0.1][50924] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...681] [ip4][..tcp] [......127.0.0.1][50924] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...681] [ip4][..tcp] [......127.0.0.1][50924] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...682] [ip4][..tcp] [......127.0.0.1][50926] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...682] [ip4][..tcp] [......127.0.0.1][50926] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...682] [ip4][..tcp] [......127.0.0.1][50926] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...683] [ip4][..tcp] [......127.0.0.1][50928] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...683] [ip4][..tcp] [......127.0.0.1][50928] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...683] [ip4][..tcp] [......127.0.0.1][50928] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...684] [ip4][..tcp] [......127.0.0.1][50930] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...684] [ip4][..tcp] [......127.0.0.1][50930] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...684] [ip4][..tcp] [......127.0.0.1][50930] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...685] [ip4][..tcp] [......127.0.0.1][50932] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...685] [ip4][..tcp] [......127.0.0.1][50932] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...685] [ip4][..tcp] [......127.0.0.1][50932] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...686] [ip4][..tcp] [......127.0.0.1][50934] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...686] [ip4][..tcp] [......127.0.0.1][50934] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...686] [ip4][..tcp] [......127.0.0.1][50934] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...687] [ip4][..tcp] [......127.0.0.1][50936] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...687] [ip4][..tcp] [......127.0.0.1][50936] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...687] [ip4][..tcp] [......127.0.0.1][50936] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...688] [ip4][..tcp] [......127.0.0.1][50938] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...688] [ip4][..tcp] [......127.0.0.1][50938] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...688] [ip4][..tcp] [......127.0.0.1][50938] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...689] [ip4][..tcp] [......127.0.0.1][50940] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...689] [ip4][..tcp] [......127.0.0.1][50940] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...689] [ip4][..tcp] [......127.0.0.1][50940] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...690] [ip4][..tcp] [......127.0.0.1][50942] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...690] [ip4][..tcp] [......127.0.0.1][50942] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...690] [ip4][..tcp] [......127.0.0.1][50942] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...691] [ip4][..tcp] [......127.0.0.1][50944] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...691] [ip4][..tcp] [......127.0.0.1][50944] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...691] [ip4][..tcp] [......127.0.0.1][50944] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...692] [ip4][..tcp] [......127.0.0.1][50946] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...692] [ip4][..tcp] [......127.0.0.1][50946] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...692] [ip4][..tcp] [......127.0.0.1][50946] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...693] [ip4][..tcp] [......127.0.0.1][50948] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...693] [ip4][..tcp] [......127.0.0.1][50948] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...693] [ip4][..tcp] [......127.0.0.1][50948] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...694] [ip4][..tcp] [......127.0.0.1][50950] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...694] [ip4][..tcp] [......127.0.0.1][50950] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...694] [ip4][..tcp] [......127.0.0.1][50950] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...695] [ip4][..tcp] [......127.0.0.1][50952] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...695] [ip4][..tcp] [......127.0.0.1][50952] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...695] [ip4][..tcp] [......127.0.0.1][50952] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...696] [ip4][..tcp] [......127.0.0.1][50954] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...696] [ip4][..tcp] [......127.0.0.1][50954] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...696] [ip4][..tcp] [......127.0.0.1][50954] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...697] [ip4][..tcp] [......127.0.0.1][50956] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...697] [ip4][..tcp] [......127.0.0.1][50956] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...697] [ip4][..tcp] [......127.0.0.1][50956] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...698] [ip4][..tcp] [......127.0.0.1][50958] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...698] [ip4][..tcp] [......127.0.0.1][50958] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...698] [ip4][..tcp] [......127.0.0.1][50958] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...699] [ip4][..tcp] [......127.0.0.1][50960] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...699] [ip4][..tcp] [......127.0.0.1][50960] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...699] [ip4][..tcp] [......127.0.0.1][50960] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...700] [ip4][..tcp] [......127.0.0.1][50962] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...700] [ip4][..tcp] [......127.0.0.1][50962] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...700] [ip4][..tcp] [......127.0.0.1][50962] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...701] [ip4][..tcp] [......127.0.0.1][50964] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...701] [ip4][..tcp] [......127.0.0.1][50964] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...701] [ip4][..tcp] [......127.0.0.1][50964] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...702] [ip4][..tcp] [......127.0.0.1][50966] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...702] [ip4][..tcp] [......127.0.0.1][50966] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...702] [ip4][..tcp] [......127.0.0.1][50966] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...703] [ip4][..tcp] [......127.0.0.1][50968] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...703] [ip4][..tcp] [......127.0.0.1][50968] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...703] [ip4][..tcp] [......127.0.0.1][50968] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...704] [ip4][..tcp] [......127.0.0.1][50970] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...704] [ip4][..tcp] [......127.0.0.1][50970] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...704] [ip4][..tcp] [......127.0.0.1][50970] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...705] [ip4][..tcp] [......127.0.0.1][50972] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...705] [ip4][..tcp] [......127.0.0.1][50972] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...705] [ip4][..tcp] [......127.0.0.1][50972] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...706] [ip4][..tcp] [......127.0.0.1][50974] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...706] [ip4][..tcp] [......127.0.0.1][50974] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...706] [ip4][..tcp] [......127.0.0.1][50974] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...707] [ip4][..tcp] [......127.0.0.1][50976] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...707] [ip4][..tcp] [......127.0.0.1][50976] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...707] [ip4][..tcp] [......127.0.0.1][50976] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...708] [ip4][..tcp] [......127.0.0.1][50978] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...708] [ip4][..tcp] [......127.0.0.1][50978] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...708] [ip4][..tcp] [......127.0.0.1][50978] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...709] [ip4][..tcp] [......127.0.0.1][50980] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...709] [ip4][..tcp] [......127.0.0.1][50980] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...709] [ip4][..tcp] [......127.0.0.1][50980] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...710] [ip4][..tcp] [......127.0.0.1][50982] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...710] [ip4][..tcp] [......127.0.0.1][50982] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...710] [ip4][..tcp] [......127.0.0.1][50982] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...711] [ip4][..tcp] [......127.0.0.1][50984] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...711] [ip4][..tcp] [......127.0.0.1][50984] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...711] [ip4][..tcp] [......127.0.0.1][50984] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...712] [ip4][..tcp] [......127.0.0.1][50986] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...712] [ip4][..tcp] [......127.0.0.1][50986] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...712] [ip4][..tcp] [......127.0.0.1][50986] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...713] [ip4][..tcp] [......127.0.0.1][50988] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...713] [ip4][..tcp] [......127.0.0.1][50988] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...713] [ip4][..tcp] [......127.0.0.1][50988] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...714] [ip4][..tcp] [......127.0.0.1][50990] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...714] [ip4][..tcp] [......127.0.0.1][50990] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...714] [ip4][..tcp] [......127.0.0.1][50990] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...715] [ip4][..tcp] [......127.0.0.1][50992] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...715] [ip4][..tcp] [......127.0.0.1][50992] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...715] [ip4][..tcp] [......127.0.0.1][50992] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...716] [ip4][..tcp] [......127.0.0.1][50994] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...716] [ip4][..tcp] [......127.0.0.1][50994] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...716] [ip4][..tcp] [......127.0.0.1][50994] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...717] [ip4][..tcp] [......127.0.0.1][50996] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...717] [ip4][..tcp] [......127.0.0.1][50996] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...717] [ip4][..tcp] [......127.0.0.1][50996] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...718] [ip4][..tcp] [......127.0.0.1][50998] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...718] [ip4][..tcp] [......127.0.0.1][50998] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...718] [ip4][..tcp] [......127.0.0.1][50998] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...719] [ip4][..tcp] [......127.0.0.1][51000] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...719] [ip4][..tcp] [......127.0.0.1][51000] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...719] [ip4][..tcp] [......127.0.0.1][51000] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...720] [ip4][..tcp] [......127.0.0.1][51002] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...720] [ip4][..tcp] [......127.0.0.1][51002] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...720] [ip4][..tcp] [......127.0.0.1][51002] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...721] [ip4][..tcp] [......127.0.0.1][51004] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...721] [ip4][..tcp] [......127.0.0.1][51004] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...721] [ip4][..tcp] [......127.0.0.1][51004] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...722] [ip4][..tcp] [......127.0.0.1][51006] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...722] [ip4][..tcp] [......127.0.0.1][51006] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...722] [ip4][..tcp] [......127.0.0.1][51006] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...723] [ip4][..tcp] [......127.0.0.1][51008] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...723] [ip4][..tcp] [......127.0.0.1][51008] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...723] [ip4][..tcp] [......127.0.0.1][51008] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...724] [ip4][..tcp] [......127.0.0.1][51010] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...724] [ip4][..tcp] [......127.0.0.1][51010] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...724] [ip4][..tcp] [......127.0.0.1][51010] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...725] [ip4][..tcp] [......127.0.0.1][51012] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...725] [ip4][..tcp] [......127.0.0.1][51012] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...725] [ip4][..tcp] [......127.0.0.1][51012] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...726] [ip4][..tcp] [......127.0.0.1][51014] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...726] [ip4][..tcp] [......127.0.0.1][51014] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...726] [ip4][..tcp] [......127.0.0.1][51014] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...727] [ip4][..tcp] [......127.0.0.1][51016] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...727] [ip4][..tcp] [......127.0.0.1][51016] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...727] [ip4][..tcp] [......127.0.0.1][51016] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...728] [ip4][..tcp] [......127.0.0.1][51018] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...728] [ip4][..tcp] [......127.0.0.1][51018] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...728] [ip4][..tcp] [......127.0.0.1][51018] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...729] [ip4][..tcp] [......127.0.0.1][51020] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...729] [ip4][..tcp] [......127.0.0.1][51020] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...729] [ip4][..tcp] [......127.0.0.1][51020] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...730] [ip4][..tcp] [......127.0.0.1][51022] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...730] [ip4][..tcp] [......127.0.0.1][51022] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...730] [ip4][..tcp] [......127.0.0.1][51022] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...731] [ip4][..tcp] [......127.0.0.1][51024] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...731] [ip4][..tcp] [......127.0.0.1][51024] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...731] [ip4][..tcp] [......127.0.0.1][51024] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...732] [ip4][..tcp] [......127.0.0.1][51026] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...732] [ip4][..tcp] [......127.0.0.1][51026] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...732] [ip4][..tcp] [......127.0.0.1][51026] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...733] [ip4][..tcp] [......127.0.0.1][51028] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...733] [ip4][..tcp] [......127.0.0.1][51028] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...733] [ip4][..tcp] [......127.0.0.1][51028] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...734] [ip4][..tcp] [......127.0.0.1][51030] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...734] [ip4][..tcp] [......127.0.0.1][51030] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...734] [ip4][..tcp] [......127.0.0.1][51030] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...735] [ip4][..tcp] [......127.0.0.1][51032] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...735] [ip4][..tcp] [......127.0.0.1][51032] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...735] [ip4][..tcp] [......127.0.0.1][51032] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...736] [ip4][..tcp] [......127.0.0.1][51034] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...736] [ip4][..tcp] [......127.0.0.1][51034] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...736] [ip4][..tcp] [......127.0.0.1][51034] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...737] [ip4][..tcp] [......127.0.0.1][51036] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...737] [ip4][..tcp] [......127.0.0.1][51036] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...737] [ip4][..tcp] [......127.0.0.1][51036] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...738] [ip4][..tcp] [......127.0.0.1][51038] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...738] [ip4][..tcp] [......127.0.0.1][51038] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...738] [ip4][..tcp] [......127.0.0.1][51038] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...739] [ip4][..tcp] [......127.0.0.1][51040] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...739] [ip4][..tcp] [......127.0.0.1][51040] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...739] [ip4][..tcp] [......127.0.0.1][51040] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...740] [ip4][..tcp] [......127.0.0.1][51042] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...740] [ip4][..tcp] [......127.0.0.1][51042] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...740] [ip4][..tcp] [......127.0.0.1][51042] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...741] [ip4][..tcp] [......127.0.0.1][51044] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...741] [ip4][..tcp] [......127.0.0.1][51044] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...741] [ip4][..tcp] [......127.0.0.1][51044] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...742] [ip4][..tcp] [......127.0.0.1][51046] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...742] [ip4][..tcp] [......127.0.0.1][51046] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...742] [ip4][..tcp] [......127.0.0.1][51046] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...743] [ip4][..tcp] [......127.0.0.1][51048] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...743] [ip4][..tcp] [......127.0.0.1][51048] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...743] [ip4][..tcp] [......127.0.0.1][51048] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...744] [ip4][..tcp] [......127.0.0.1][51050] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...744] [ip4][..tcp] [......127.0.0.1][51050] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...744] [ip4][..tcp] [......127.0.0.1][51050] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...745] [ip4][..tcp] [......127.0.0.1][51052] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...745] [ip4][..tcp] [......127.0.0.1][51052] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...745] [ip4][..tcp] [......127.0.0.1][51052] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...746] [ip4][..tcp] [......127.0.0.1][51054] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...746] [ip4][..tcp] [......127.0.0.1][51054] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...746] [ip4][..tcp] [......127.0.0.1][51054] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...747] [ip4][..tcp] [......127.0.0.1][51056] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...747] [ip4][..tcp] [......127.0.0.1][51056] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...747] [ip4][..tcp] [......127.0.0.1][51056] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...748] [ip4][..tcp] [......127.0.0.1][51058] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...748] [ip4][..tcp] [......127.0.0.1][51058] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...748] [ip4][..tcp] [......127.0.0.1][51058] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...749] [ip4][..tcp] [......127.0.0.1][51060] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...749] [ip4][..tcp] [......127.0.0.1][51060] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...749] [ip4][..tcp] [......127.0.0.1][51060] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...750] [ip4][..tcp] [......127.0.0.1][51062] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...750] [ip4][..tcp] [......127.0.0.1][51062] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...750] [ip4][..tcp] [......127.0.0.1][51062] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...751] [ip4][..tcp] [......127.0.0.1][51064] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...751] [ip4][..tcp] [......127.0.0.1][51064] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...751] [ip4][..tcp] [......127.0.0.1][51064] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...752] [ip4][..tcp] [......127.0.0.1][51066] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...752] [ip4][..tcp] [......127.0.0.1][51066] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...752] [ip4][..tcp] [......127.0.0.1][51066] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...753] [ip4][..tcp] [......127.0.0.1][51068] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...753] [ip4][..tcp] [......127.0.0.1][51068] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...753] [ip4][..tcp] [......127.0.0.1][51068] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...754] [ip4][..tcp] [......127.0.0.1][51070] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...754] [ip4][..tcp] [......127.0.0.1][51070] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...754] [ip4][..tcp] [......127.0.0.1][51070] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...755] [ip4][..tcp] [......127.0.0.1][51072] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...755] [ip4][..tcp] [......127.0.0.1][51072] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...755] [ip4][..tcp] [......127.0.0.1][51072] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...756] [ip4][..tcp] [......127.0.0.1][51074] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...756] [ip4][..tcp] [......127.0.0.1][51074] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...756] [ip4][..tcp] [......127.0.0.1][51074] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...757] [ip4][..tcp] [......127.0.0.1][51076] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...757] [ip4][..tcp] [......127.0.0.1][51076] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...757] [ip4][..tcp] [......127.0.0.1][51076] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...758] [ip4][..tcp] [......127.0.0.1][51078] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...758] [ip4][..tcp] [......127.0.0.1][51078] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...758] [ip4][..tcp] [......127.0.0.1][51078] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...759] [ip4][..tcp] [......127.0.0.1][51080] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...759] [ip4][..tcp] [......127.0.0.1][51080] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...759] [ip4][..tcp] [......127.0.0.1][51080] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...760] [ip4][..tcp] [......127.0.0.1][51082] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...760] [ip4][..tcp] [......127.0.0.1][51082] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...760] [ip4][..tcp] [......127.0.0.1][51082] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...761] [ip4][..tcp] [......127.0.0.1][51084] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...761] [ip4][..tcp] [......127.0.0.1][51084] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...761] [ip4][..tcp] [......127.0.0.1][51084] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...762] [ip4][..tcp] [......127.0.0.1][51086] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...762] [ip4][..tcp] [......127.0.0.1][51086] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...762] [ip4][..tcp] [......127.0.0.1][51086] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...763] [ip4][..tcp] [......127.0.0.1][51088] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...763] [ip4][..tcp] [......127.0.0.1][51088] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...763] [ip4][..tcp] [......127.0.0.1][51088] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...764] [ip4][..tcp] [......127.0.0.1][51090] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...764] [ip4][..tcp] [......127.0.0.1][51090] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...764] [ip4][..tcp] [......127.0.0.1][51090] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...765] [ip4][..tcp] [......127.0.0.1][51092] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...765] [ip4][..tcp] [......127.0.0.1][51092] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...765] [ip4][..tcp] [......127.0.0.1][51092] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...766] [ip4][..tcp] [......127.0.0.1][51094] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...766] [ip4][..tcp] [......127.0.0.1][51094] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...766] [ip4][..tcp] [......127.0.0.1][51094] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...767] [ip4][..tcp] [......127.0.0.1][51096] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...767] [ip4][..tcp] [......127.0.0.1][51096] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...767] [ip4][..tcp] [......127.0.0.1][51096] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...768] [ip4][..tcp] [......127.0.0.1][51098] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...768] [ip4][..tcp] [......127.0.0.1][51098] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...768] [ip4][..tcp] [......127.0.0.1][51098] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...769] [ip4][..tcp] [......127.0.0.1][51100] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...769] [ip4][..tcp] [......127.0.0.1][51100] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...769] [ip4][..tcp] [......127.0.0.1][51100] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...770] [ip4][..tcp] [......127.0.0.1][51148] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...770] [ip4][..tcp] [......127.0.0.1][51148] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...770] [ip4][..tcp] [......127.0.0.1][51148] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...771] [ip4][..tcp] [......127.0.0.1][51150] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...771] [ip4][..tcp] [......127.0.0.1][51150] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...771] [ip4][..tcp] [......127.0.0.1][51150] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...772] [ip4][..tcp] [......127.0.0.1][51152] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...772] [ip4][..tcp] [......127.0.0.1][51152] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...772] [ip4][..tcp] [......127.0.0.1][51152] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...773] [ip4][..tcp] [......127.0.0.1][51154] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...773] [ip4][..tcp] [......127.0.0.1][51154] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...773] [ip4][..tcp] [......127.0.0.1][51154] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...774] [ip4][..tcp] [......127.0.0.1][51156] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...774] [ip4][..tcp] [......127.0.0.1][51156] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...774] [ip4][..tcp] [......127.0.0.1][51156] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...775] [ip4][..tcp] [......127.0.0.1][51158] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...775] [ip4][..tcp] [......127.0.0.1][51158] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...775] [ip4][..tcp] [......127.0.0.1][51158] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...776] [ip4][..tcp] [......127.0.0.1][51160] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...776] [ip4][..tcp] [......127.0.0.1][51160] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...776] [ip4][..tcp] [......127.0.0.1][51160] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...777] [ip4][..tcp] [......127.0.0.1][51162] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...777] [ip4][..tcp] [......127.0.0.1][51162] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...777] [ip4][..tcp] [......127.0.0.1][51162] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...778] [ip4][..tcp] [......127.0.0.1][51164] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...778] [ip4][..tcp] [......127.0.0.1][51164] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...778] [ip4][..tcp] [......127.0.0.1][51164] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...779] [ip4][..tcp] [......127.0.0.1][51166] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...779] [ip4][..tcp] [......127.0.0.1][51166] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...779] [ip4][..tcp] [......127.0.0.1][51166] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...780] [ip4][..tcp] [......127.0.0.1][51168] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...780] [ip4][..tcp] [......127.0.0.1][51168] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...780] [ip4][..tcp] [......127.0.0.1][51168] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...781] [ip4][..tcp] [......127.0.0.1][51170] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...781] [ip4][..tcp] [......127.0.0.1][51170] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...781] [ip4][..tcp] [......127.0.0.1][51170] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...782] [ip4][..tcp] [......127.0.0.1][51172] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...782] [ip4][..tcp] [......127.0.0.1][51172] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...782] [ip4][..tcp] [......127.0.0.1][51172] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...783] [ip4][..tcp] [......127.0.0.1][51174] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...783] [ip4][..tcp] [......127.0.0.1][51174] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...783] [ip4][..tcp] [......127.0.0.1][51174] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...784] [ip4][..tcp] [......127.0.0.1][51176] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...784] [ip4][..tcp] [......127.0.0.1][51176] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...784] [ip4][..tcp] [......127.0.0.1][51176] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...785] [ip4][..tcp] [......127.0.0.1][51178] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...785] [ip4][..tcp] [......127.0.0.1][51178] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...785] [ip4][..tcp] [......127.0.0.1][51178] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...786] [ip4][..tcp] [......127.0.0.1][51182] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...786] [ip4][..tcp] [......127.0.0.1][51182] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...786] [ip4][..tcp] [......127.0.0.1][51182] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...787] [ip4][..tcp] [......127.0.0.1][51184] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...787] [ip4][..tcp] [......127.0.0.1][51184] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...787] [ip4][..tcp] [......127.0.0.1][51184] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...788] [ip4][..tcp] [......127.0.0.1][51186] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...788] [ip4][..tcp] [......127.0.0.1][51186] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...788] [ip4][..tcp] [......127.0.0.1][51186] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: RCE Injection, Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...789] [ip4][..tcp] [......127.0.0.1][51188] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...789] [ip4][..tcp] [......127.0.0.1][51188] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...789] [ip4][..tcp] [......127.0.0.1][51188] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...790] [ip4][..tcp] [......127.0.0.1][51190] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...790] [ip4][..tcp] [......127.0.0.1][51190] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...790] [ip4][..tcp] [......127.0.0.1][51190] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...791] [ip4][..tcp] [......127.0.0.1][51192] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...791] [ip4][..tcp] [......127.0.0.1][51192] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...791] [ip4][..tcp] [......127.0.0.1][51192] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...792] [ip4][..tcp] [......127.0.0.1][51194] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...792] [ip4][..tcp] [......127.0.0.1][51194] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...792] [ip4][..tcp] [......127.0.0.1][51194] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...793] [ip4][..tcp] [......127.0.0.1][51196] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...793] [ip4][..tcp] [......127.0.0.1][51196] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...793] [ip4][..tcp] [......127.0.0.1][51196] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...794] [ip4][..tcp] [......127.0.0.1][51198] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...794] [ip4][..tcp] [......127.0.0.1][51198] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...794] [ip4][..tcp] [......127.0.0.1][51198] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...795] [ip4][..tcp] [......127.0.0.1][51200] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...795] [ip4][..tcp] [......127.0.0.1][51200] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...795] [ip4][..tcp] [......127.0.0.1][51200] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...796] [ip4][..tcp] [......127.0.0.1][51202] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...796] [ip4][..tcp] [......127.0.0.1][51202] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...796] [ip4][..tcp] [......127.0.0.1][51202] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [...797] [ip4][..tcp] [......127.0.0.1][51204] -> [......127.0.0.1][.8080] [MIDSTREAM] + new: [...797] [ip4][..tcp] [......127.0.0.1][51204] -> [......127.0.0.1][.8080] [MIDSTREAM] detected: [...797] [ip4][..tcp] [......127.0.0.1][51204] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable][127.0.0.1] RISK: RCE Injection, Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [...745] [ip4][..tcp] [......127.0.0.1][51052] -> [......127.0.0.1][.8080] [HTTP][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/WebattackSQLinj.pcap.out b/test/results/flow-info/default/WebattackSQLinj.pcap.out index 92722f5fe..ec016b176 100644 --- a/test/results/flow-info/default/WebattackSQLinj.pcap.out +++ b/test/results/flow-info/default/WebattackSQLinj.pcap.out @@ -1,31 +1,31 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....172.16.0.1][36196] -> [..192.168.10.50][...80] + new: [.....1] [ip4][..tcp] [.....172.16.0.1][36196] -> [..192.168.10.50][...80] detected: [.....1] [ip4][..tcp] [.....172.16.0.1][36196] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....2] [ip4][..tcp] [.....172.16.0.1][36198] -> [..192.168.10.50][...80] + new: [.....2] [ip4][..tcp] [.....172.16.0.1][36198] -> [..192.168.10.50][...80] detected: [.....2] [ip4][..tcp] [.....172.16.0.1][36198] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....3] [ip4][..tcp] [.....172.16.0.1][36200] -> [..192.168.10.50][...80] + new: [.....3] [ip4][..tcp] [.....172.16.0.1][36200] -> [..192.168.10.50][...80] detected: [.....3] [ip4][..tcp] [.....172.16.0.1][36200] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....4] [ip4][..tcp] [.....172.16.0.1][36202] -> [..192.168.10.50][...80] + new: [.....4] [ip4][..tcp] [.....172.16.0.1][36202] -> [..192.168.10.50][...80] detected: [.....4] [ip4][..tcp] [.....172.16.0.1][36202] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....5] [ip4][..tcp] [.....172.16.0.1][36204] -> [..192.168.10.50][...80] + new: [.....5] [ip4][..tcp] [.....172.16.0.1][36204] -> [..192.168.10.50][...80] detected: [.....5] [ip4][..tcp] [.....172.16.0.1][36204] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....6] [ip4][..tcp] [.....172.16.0.1][36206] -> [..192.168.10.50][...80] + new: [.....6] [ip4][..tcp] [.....172.16.0.1][36206] -> [..192.168.10.50][...80] detected: [.....6] [ip4][..tcp] [.....172.16.0.1][36206] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....7] [ip4][..tcp] [.....172.16.0.1][36208] -> [..192.168.10.50][...80] + new: [.....7] [ip4][..tcp] [.....172.16.0.1][36208] -> [..192.168.10.50][...80] detected: [.....7] [ip4][..tcp] [.....172.16.0.1][36208] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....8] [ip4][..tcp] [.....172.16.0.1][36210] -> [..192.168.10.50][...80] + new: [.....8] [ip4][..tcp] [.....172.16.0.1][36210] -> [..192.168.10.50][...80] detected: [.....8] [ip4][..tcp] [.....172.16.0.1][36210] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....9] [ip4][..tcp] [.....172.16.0.1][36212] -> [..192.168.10.50][...80] + new: [.....9] [ip4][..tcp] [.....172.16.0.1][36212] -> [..192.168.10.50][...80] detected: [.....9] [ip4][..tcp] [.....172.16.0.1][36212] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header end: [.....1] [ip4][..tcp] [.....172.16.0.1][36196] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/WebattackXSS.pcap.out b/test/results/flow-info/default/WebattackXSS.pcap.out index f00bc3c91..69670ea80 100644 --- a/test/results/flow-info/default/WebattackXSS.pcap.out +++ b/test/results/flow-info/default/WebattackXSS.pcap.out @@ -1,18 +1,18 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....172.16.0.1][52098] -> [..192.168.10.50][...80] + new: [.....1] [ip4][..tcp] [.....172.16.0.1][52098] -> [..192.168.10.50][...80] detected: [.....1] [ip4][..tcp] [.....172.16.0.1][52098] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....2] [ip4][..tcp] [.....172.16.0.1][52100] -> [..192.168.10.50][...80] - new: [.....3] [ip4][..tcp] [.....172.16.0.1][52118] -> [..192.168.10.50][...80] - new: [.....4] [ip4][..tcp] [.....172.16.0.1][52120] -> [..192.168.10.50][...80] - new: [.....5] [ip4][..tcp] [.....172.16.0.1][52200] -> [..192.168.10.50][...80] + new: [.....2] [ip4][..tcp] [.....172.16.0.1][52100] -> [..192.168.10.50][...80] + new: [.....3] [ip4][..tcp] [.....172.16.0.1][52118] -> [..192.168.10.50][...80] + new: [.....4] [ip4][..tcp] [.....172.16.0.1][52120] -> [..192.168.10.50][...80] + new: [.....5] [ip4][..tcp] [.....172.16.0.1][52200] -> [..192.168.10.50][...80] detected: [.....5] [ip4][..tcp] [.....172.16.0.1][52200] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [.....6] [ip4][..tcp] [.....172.16.0.1][52202] -> [..192.168.10.50][...80] - new: [.....7] [ip4][..tcp] [.....172.16.0.1][52220] -> [..192.168.10.50][...80] - new: [.....8] [ip4][..tcp] [.....172.16.0.1][52222] -> [..192.168.10.50][...80] + new: [.....6] [ip4][..tcp] [.....172.16.0.1][52202] -> [..192.168.10.50][...80] + new: [.....7] [ip4][..tcp] [.....172.16.0.1][52220] -> [..192.168.10.50][...80] + new: [.....8] [ip4][..tcp] [.....172.16.0.1][52222] -> [..192.168.10.50][...80] analyse: [.....5] [ip4][..tcp] [.....172.16.0.1][52200] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.805| 0.259| 0.699| 488344.093| 2.400] @@ -23,12 +23,12 @@ [IATS(ms)....: 0.1,0.9,0.0,0.9,1.5,2.3,23.6,26.5,34.2,32.2,1.1,1.0,0.2,0.9,0.2,0.4,39.8,69.9,111.2,1.1,61.6,62.7,1.1,842.7,846.6,3.8,131.7,132.7,1.1,2804.2,2805.2] [PKTLENS.....: 60,60,52,361,52,564,52,394,1184,417,793,440,1500,7978,52,52,52,52,363,557,52,393,557,52,611,415,52,409,573,52,52,52] [ENTROPIES...: 4.6,5.1,4.9,5.9,4.9,5.8,4.9,6.0,7.5,6.0,7.3,5.9,7.6,8.0,4.9,4.9,4.9,4.9,6.0,5.8,5.0,6.0,5.8,4.9,5.9,5.7,4.9,6.0,5.8,5.0,5.1,4.9] - new: [.....9] [ip4][..tcp] [.....172.16.0.1][52298] -> [..192.168.10.50][...80] + new: [.....9] [ip4][..tcp] [.....172.16.0.1][52298] -> [..192.168.10.50][...80] detected: [.....9] [ip4][..tcp] [.....172.16.0.1][52298] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [....10] [ip4][..tcp] [.....172.16.0.1][52300] -> [..192.168.10.50][...80] - new: [....11] [ip4][..tcp] [.....172.16.0.1][52318] -> [..192.168.10.50][...80] - new: [....12] [ip4][..tcp] [.....172.16.0.1][52320] -> [..192.168.10.50][...80] + new: [....10] [ip4][..tcp] [.....172.16.0.1][52300] -> [..192.168.10.50][...80] + new: [....11] [ip4][..tcp] [.....172.16.0.1][52318] -> [..192.168.10.50][...80] + new: [....12] [ip4][..tcp] [.....172.16.0.1][52320] -> [..192.168.10.50][...80] analyse: [.....9] [ip4][..tcp] [.....172.16.0.1][52298] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.856| 0.080| 0.207| 42651.251| 2.700] @@ -43,42 +43,42 @@ RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header detected: [....11] [ip4][..tcp] [.....172.16.0.1][52318] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [....13] [ip4][..tcp] [.....172.16.0.1][52386] -> [..192.168.10.50][...80] - new: [....14] [ip4][..tcp] [.....172.16.0.1][52400] -> [..192.168.10.50][...80] - new: [....15] [ip4][..tcp] [.....172.16.0.1][52414] -> [..192.168.10.50][...80] - new: [....16] [ip4][..tcp] [.....172.16.0.1][52440] -> [..192.168.10.50][...80] - new: [....17] [ip4][..tcp] [.....172.16.0.1][52454] -> [..192.168.10.50][...80] - new: [....18] [ip4][..tcp] [.....172.16.0.1][52480] -> [..192.168.10.50][...80] - new: [....19] [ip4][..tcp] [.....172.16.0.1][52494] -> [..192.168.10.50][...80] - new: [....20] [ip4][..tcp] [.....172.16.0.1][52508] -> [..192.168.10.50][...80] - new: [....21] [ip4][..tcp] [.....172.16.0.1][52534] -> [..192.168.10.50][...80] - new: [....22] [ip4][..tcp] [.....172.16.0.1][52548] -> [..192.168.10.50][...80] - new: [....23] [ip4][..tcp] [.....172.16.0.1][52574] -> [..192.168.10.50][...80] - new: [....24] [ip4][..tcp] [.....172.16.0.1][52588] -> [..192.168.10.50][...80] - new: [....25] [ip4][..tcp] [.....172.16.0.1][52602] -> [..192.168.10.50][...80] - new: [....26] [ip4][..tcp] [.....172.16.0.1][52628] -> [..192.168.10.50][...80] - new: [....27] [ip4][..tcp] [.....172.16.0.1][52642] -> [..192.168.10.50][...80] - new: [....28] [ip4][..tcp] [.....172.16.0.1][52668] -> [..192.168.10.50][...80] - new: [....29] [ip4][..tcp] [.....172.16.0.1][52682] -> [..192.168.10.50][...80] - new: [....30] [ip4][..tcp] [.....172.16.0.1][52696] -> [..192.168.10.50][...80] - new: [....31] [ip4][..tcp] [.....172.16.0.1][52722] -> [..192.168.10.50][...80] - new: [....32] [ip4][..tcp] [.....172.16.0.1][52736] -> [..192.168.10.50][...80] - new: [....33] [ip4][..tcp] [.....172.16.0.1][52750] -> [..192.168.10.50][...80] - new: [....34] [ip4][..tcp] [.....172.16.0.1][52776] -> [..192.168.10.50][...80] - new: [....35] [ip4][..tcp] [.....172.16.0.1][52790] -> [..192.168.10.50][...80] - new: [....36] [ip4][..tcp] [.....172.16.0.1][52816] -> [..192.168.10.50][...80] - new: [....37] [ip4][..tcp] [.....172.16.0.1][52830] -> [..192.168.10.50][...80] - new: [....38] [ip4][..tcp] [.....172.16.0.1][52856] -> [..192.168.10.50][...80] - new: [....39] [ip4][..tcp] [.....172.16.0.1][52870] -> [..192.168.10.50][...80] - new: [....40] [ip4][..tcp] [.....172.16.0.1][52884] -> [..192.168.10.50][...80] - new: [....41] [ip4][..tcp] [.....172.16.0.1][52910] -> [..192.168.10.50][...80] - new: [....42] [ip4][..tcp] [.....172.16.0.1][52924] -> [..192.168.10.50][...80] - new: [....43] [ip4][..tcp] [.....172.16.0.1][52938] -> [..192.168.10.50][...80] + new: [....13] [ip4][..tcp] [.....172.16.0.1][52386] -> [..192.168.10.50][...80] + new: [....14] [ip4][..tcp] [.....172.16.0.1][52400] -> [..192.168.10.50][...80] + new: [....15] [ip4][..tcp] [.....172.16.0.1][52414] -> [..192.168.10.50][...80] + new: [....16] [ip4][..tcp] [.....172.16.0.1][52440] -> [..192.168.10.50][...80] + new: [....17] [ip4][..tcp] [.....172.16.0.1][52454] -> [..192.168.10.50][...80] + new: [....18] [ip4][..tcp] [.....172.16.0.1][52480] -> [..192.168.10.50][...80] + new: [....19] [ip4][..tcp] [.....172.16.0.1][52494] -> [..192.168.10.50][...80] + new: [....20] [ip4][..tcp] [.....172.16.0.1][52508] -> [..192.168.10.50][...80] + new: [....21] [ip4][..tcp] [.....172.16.0.1][52534] -> [..192.168.10.50][...80] + new: [....22] [ip4][..tcp] [.....172.16.0.1][52548] -> [..192.168.10.50][...80] + new: [....23] [ip4][..tcp] [.....172.16.0.1][52574] -> [..192.168.10.50][...80] + new: [....24] [ip4][..tcp] [.....172.16.0.1][52588] -> [..192.168.10.50][...80] + new: [....25] [ip4][..tcp] [.....172.16.0.1][52602] -> [..192.168.10.50][...80] + new: [....26] [ip4][..tcp] [.....172.16.0.1][52628] -> [..192.168.10.50][...80] + new: [....27] [ip4][..tcp] [.....172.16.0.1][52642] -> [..192.168.10.50][...80] + new: [....28] [ip4][..tcp] [.....172.16.0.1][52668] -> [..192.168.10.50][...80] + new: [....29] [ip4][..tcp] [.....172.16.0.1][52682] -> [..192.168.10.50][...80] + new: [....30] [ip4][..tcp] [.....172.16.0.1][52696] -> [..192.168.10.50][...80] + new: [....31] [ip4][..tcp] [.....172.16.0.1][52722] -> [..192.168.10.50][...80] + new: [....32] [ip4][..tcp] [.....172.16.0.1][52736] -> [..192.168.10.50][...80] + new: [....33] [ip4][..tcp] [.....172.16.0.1][52750] -> [..192.168.10.50][...80] + new: [....34] [ip4][..tcp] [.....172.16.0.1][52776] -> [..192.168.10.50][...80] + new: [....35] [ip4][..tcp] [.....172.16.0.1][52790] -> [..192.168.10.50][...80] + new: [....36] [ip4][..tcp] [.....172.16.0.1][52816] -> [..192.168.10.50][...80] + new: [....37] [ip4][..tcp] [.....172.16.0.1][52830] -> [..192.168.10.50][...80] + new: [....38] [ip4][..tcp] [.....172.16.0.1][52856] -> [..192.168.10.50][...80] + new: [....39] [ip4][..tcp] [.....172.16.0.1][52870] -> [..192.168.10.50][...80] + new: [....40] [ip4][..tcp] [.....172.16.0.1][52884] -> [..192.168.10.50][...80] + new: [....41] [ip4][..tcp] [.....172.16.0.1][52910] -> [..192.168.10.50][...80] + new: [....42] [ip4][..tcp] [.....172.16.0.1][52924] -> [..192.168.10.50][...80] + new: [....43] [ip4][..tcp] [.....172.16.0.1][52938] -> [..192.168.10.50][...80] detected: [....41] [ip4][..tcp] [.....172.16.0.1][52910] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [....44] [ip4][..tcp] [.....172.16.0.1][52964] -> [..192.168.10.50][...80] - new: [....45] [ip4][..tcp] [.....172.16.0.1][52978] -> [..192.168.10.50][...80] - new: [....46] [ip4][..tcp] [.....172.16.0.1][53004] -> [..192.168.10.50][...80] + new: [....44] [ip4][..tcp] [.....172.16.0.1][52964] -> [..192.168.10.50][...80] + new: [....45] [ip4][..tcp] [.....172.16.0.1][52978] -> [..192.168.10.50][...80] + new: [....46] [ip4][..tcp] [.....172.16.0.1][53004] -> [..192.168.10.50][...80] analyse: [....41] [ip4][..tcp] [.....172.16.0.1][52910] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.809| 0.610| 0.941| 885441.823| 3.700] @@ -89,62 +89,62 @@ [IATS(ms)....: 0.1,0.8,3808.1,3808.9,3.1,3.9,1010.4,1014.2,3.8,247.0,250.6,3.6,1037.9,1041.6,3.8,265.4,269.2,3.7,1020.1,1024.5,4.4,240.9,244.6,3.7,1033.1,1036.8,3.7,252.8,256.5,3.7,1006.2] [PKTLENS.....: 60,60,52,637,52,1919,52,435,1822,52,637,1920,52,435,1822,52,637,1921,52,435,1822,52,637,1920,52,435,1822,52,637,1918,52,435] [ENTROPIES...: 4.5,5.0,4.8,6.0,4.9,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.7,6.0,7.8,4.7,5.9,7.7,4.8,6.0,7.8,4.9,5.9] - new: [....47] [ip4][..tcp] [.....172.16.0.1][53018] -> [..192.168.10.50][...80] - new: [....48] [ip4][..tcp] [.....172.16.0.1][53032] -> [..192.168.10.50][...80] - new: [....49] [ip4][..tcp] [.....172.16.0.1][53058] -> [..192.168.10.50][...80] - new: [....50] [ip4][..tcp] [.....172.16.0.1][53072] -> [..192.168.10.50][...80] - new: [....51] [ip4][..tcp] [.....172.16.0.1][53098] -> [..192.168.10.50][...80] - new: [....52] [ip4][..tcp] [.....172.16.0.1][53112] -> [..192.168.10.50][...80] - new: [....53] [ip4][..tcp] [.....172.16.0.1][53126] -> [..192.168.10.50][...80] - new: [....54] [ip4][..tcp] [.....172.16.0.1][53152] -> [..192.168.10.50][...80] - new: [....55] [ip4][..tcp] [.....172.16.0.1][53166] -> [..192.168.10.50][...80] - new: [....56] [ip4][..tcp] [.....172.16.0.1][53192] -> [..192.168.10.50][...80] - new: [....57] [ip4][..tcp] [.....172.16.0.1][53206] -> [..192.168.10.50][...80] - new: [....58] [ip4][..tcp] [.....172.16.0.1][53220] -> [..192.168.10.50][...80] - new: [....59] [ip4][..tcp] [.....172.16.0.1][53246] -> [..192.168.10.50][...80] - new: [....60] [ip4][..tcp] [.....172.16.0.1][53260] -> [..192.168.10.50][...80] + new: [....47] [ip4][..tcp] [.....172.16.0.1][53018] -> [..192.168.10.50][...80] + new: [....48] [ip4][..tcp] [.....172.16.0.1][53032] -> [..192.168.10.50][...80] + new: [....49] [ip4][..tcp] [.....172.16.0.1][53058] -> [..192.168.10.50][...80] + new: [....50] [ip4][..tcp] [.....172.16.0.1][53072] -> [..192.168.10.50][...80] + new: [....51] [ip4][..tcp] [.....172.16.0.1][53098] -> [..192.168.10.50][...80] + new: [....52] [ip4][..tcp] [.....172.16.0.1][53112] -> [..192.168.10.50][...80] + new: [....53] [ip4][..tcp] [.....172.16.0.1][53126] -> [..192.168.10.50][...80] + new: [....54] [ip4][..tcp] [.....172.16.0.1][53152] -> [..192.168.10.50][...80] + new: [....55] [ip4][..tcp] [.....172.16.0.1][53166] -> [..192.168.10.50][...80] + new: [....56] [ip4][..tcp] [.....172.16.0.1][53192] -> [..192.168.10.50][...80] + new: [....57] [ip4][..tcp] [.....172.16.0.1][53206] -> [..192.168.10.50][...80] + new: [....58] [ip4][..tcp] [.....172.16.0.1][53220] -> [..192.168.10.50][...80] + new: [....59] [ip4][..tcp] [.....172.16.0.1][53246] -> [..192.168.10.50][...80] + new: [....60] [ip4][..tcp] [.....172.16.0.1][53260] -> [..192.168.10.50][...80] end: [.....1] [ip4][..tcp] [.....172.16.0.1][52098] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [.....2] [ip4][..tcp] [.....172.16.0.1][52100] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....2] [ip4][..tcp] [.....172.16.0.1][52100] -> [..192.168.10.50][...80] + end: [.....2] [ip4][..tcp] [.....172.16.0.1][52100] -> [..192.168.10.50][...80] guessed: [.....3] [ip4][..tcp] [.....172.16.0.1][52118] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....3] [ip4][..tcp] [.....172.16.0.1][52118] -> [..192.168.10.50][...80] + end: [.....3] [ip4][..tcp] [.....172.16.0.1][52118] -> [..192.168.10.50][...80] guessed: [.....4] [ip4][..tcp] [.....172.16.0.1][52120] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....4] [ip4][..tcp] [.....172.16.0.1][52120] -> [..192.168.10.50][...80] - new: [....61] [ip4][..tcp] [.....172.16.0.1][53286] -> [..192.168.10.50][...80] - new: [....62] [ip4][..tcp] [.....172.16.0.1][53300] -> [..192.168.10.50][...80] - new: [....63] [ip4][..tcp] [.....172.16.0.1][53314] -> [..192.168.10.50][...80] - new: [....64] [ip4][..tcp] [.....172.16.0.1][53340] -> [..192.168.10.50][...80] - new: [....65] [ip4][..tcp] [.....172.16.0.1][53354] -> [..192.168.10.50][...80] - new: [....66] [ip4][..tcp] [.....172.16.0.1][53380] -> [..192.168.10.50][...80] - new: [....67] [ip4][..tcp] [.....172.16.0.1][53394] -> [..192.168.10.50][...80] - new: [....68] [ip4][..tcp] [.....172.16.0.1][53408] -> [..192.168.10.50][...80] - new: [....69] [ip4][..tcp] [.....172.16.0.1][53422] -> [..192.168.10.50][...80] - new: [....70] [ip4][..tcp] [.....172.16.0.1][53436] -> [..192.168.10.50][...80] - new: [....71] [ip4][..tcp] [.....172.16.0.1][53450] -> [..192.168.10.50][...80] - new: [....72] [ip4][..tcp] [.....172.16.0.1][53476] -> [..192.168.10.50][...80] - new: [....73] [ip4][..tcp] [.....172.16.0.1][53490] -> [..192.168.10.50][...80] + end: [.....4] [ip4][..tcp] [.....172.16.0.1][52120] -> [..192.168.10.50][...80] + new: [....61] [ip4][..tcp] [.....172.16.0.1][53286] -> [..192.168.10.50][...80] + new: [....62] [ip4][..tcp] [.....172.16.0.1][53300] -> [..192.168.10.50][...80] + new: [....63] [ip4][..tcp] [.....172.16.0.1][53314] -> [..192.168.10.50][...80] + new: [....64] [ip4][..tcp] [.....172.16.0.1][53340] -> [..192.168.10.50][...80] + new: [....65] [ip4][..tcp] [.....172.16.0.1][53354] -> [..192.168.10.50][...80] + new: [....66] [ip4][..tcp] [.....172.16.0.1][53380] -> [..192.168.10.50][...80] + new: [....67] [ip4][..tcp] [.....172.16.0.1][53394] -> [..192.168.10.50][...80] + new: [....68] [ip4][..tcp] [.....172.16.0.1][53408] -> [..192.168.10.50][...80] + new: [....69] [ip4][..tcp] [.....172.16.0.1][53422] -> [..192.168.10.50][...80] + new: [....70] [ip4][..tcp] [.....172.16.0.1][53436] -> [..192.168.10.50][...80] + new: [....71] [ip4][..tcp] [.....172.16.0.1][53450] -> [..192.168.10.50][...80] + new: [....72] [ip4][..tcp] [.....172.16.0.1][53476] -> [..192.168.10.50][...80] + new: [....73] [ip4][..tcp] [.....172.16.0.1][53490] -> [..192.168.10.50][...80] end: [.....5] [ip4][..tcp] [.....172.16.0.1][52200] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [.....6] [ip4][..tcp] [.....172.16.0.1][52202] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....6] [ip4][..tcp] [.....172.16.0.1][52202] -> [..192.168.10.50][...80] + end: [.....6] [ip4][..tcp] [.....172.16.0.1][52202] -> [..192.168.10.50][...80] guessed: [.....7] [ip4][..tcp] [.....172.16.0.1][52220] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....7] [ip4][..tcp] [.....172.16.0.1][52220] -> [..192.168.10.50][...80] + end: [.....7] [ip4][..tcp] [.....172.16.0.1][52220] -> [..192.168.10.50][...80] guessed: [.....8] [ip4][..tcp] [.....172.16.0.1][52222] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....8] [ip4][..tcp] [.....172.16.0.1][52222] -> [..192.168.10.50][...80] - new: [....74] [ip4][..tcp] [.....172.16.0.1][53516] -> [..192.168.10.50][...80] - new: [....75] [ip4][..tcp] [.....172.16.0.1][53530] -> [..192.168.10.50][...80] - new: [....76] [ip4][..tcp] [.....172.16.0.1][53544] -> [..192.168.10.50][...80] - new: [....77] [ip4][..tcp] [.....172.16.0.1][53570] -> [..192.168.10.50][...80] - new: [....78] [ip4][..tcp] [.....172.16.0.1][53584] -> [..192.168.10.50][...80] - new: [....79] [ip4][..tcp] [.....172.16.0.1][53598] -> [..192.168.10.50][...80] - new: [....80] [ip4][..tcp] [.....172.16.0.1][53624] -> [..192.168.10.50][...80] + end: [.....8] [ip4][..tcp] [.....172.16.0.1][52222] -> [..192.168.10.50][...80] + new: [....74] [ip4][..tcp] [.....172.16.0.1][53516] -> [..192.168.10.50][...80] + new: [....75] [ip4][..tcp] [.....172.16.0.1][53530] -> [..192.168.10.50][...80] + new: [....76] [ip4][..tcp] [.....172.16.0.1][53544] -> [..192.168.10.50][...80] + new: [....77] [ip4][..tcp] [.....172.16.0.1][53570] -> [..192.168.10.50][...80] + new: [....78] [ip4][..tcp] [.....172.16.0.1][53584] -> [..192.168.10.50][...80] + new: [....79] [ip4][..tcp] [.....172.16.0.1][53598] -> [..192.168.10.50][...80] + new: [....80] [ip4][..tcp] [.....172.16.0.1][53624] -> [..192.168.10.50][...80] detected: [....78] [ip4][..tcp] [.....172.16.0.1][53584] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [....81] [ip4][..tcp] [.....172.16.0.1][53638] -> [..192.168.10.50][...80] - new: [....82] [ip4][..tcp] [.....172.16.0.1][53664] -> [..192.168.10.50][...80] - new: [....83] [ip4][..tcp] [.....172.16.0.1][53678] -> [..192.168.10.50][...80] - new: [....84] [ip4][..tcp] [.....172.16.0.1][53692] -> [..192.168.10.50][...80] + new: [....81] [ip4][..tcp] [.....172.16.0.1][53638] -> [..192.168.10.50][...80] + new: [....82] [ip4][..tcp] [.....172.16.0.1][53664] -> [..192.168.10.50][...80] + new: [....83] [ip4][..tcp] [.....172.16.0.1][53678] -> [..192.168.10.50][...80] + new: [....84] [ip4][..tcp] [.....172.16.0.1][53692] -> [..192.168.10.50][...80] analyse: [....78] [ip4][..tcp] [.....172.16.0.1][53584] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.899| 0.653| 1.186| 1406566.662| 3.500] @@ -160,116 +160,116 @@ end: [....11] [ip4][..tcp] [.....172.16.0.1][52318] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [....12] [ip4][..tcp] [.....172.16.0.1][52320] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....12] [ip4][..tcp] [.....172.16.0.1][52320] -> [..192.168.10.50][...80] + end: [....12] [ip4][..tcp] [.....172.16.0.1][52320] -> [..192.168.10.50][...80] guessed: [....13] [ip4][..tcp] [.....172.16.0.1][52386] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....13] [ip4][..tcp] [.....172.16.0.1][52386] -> [..192.168.10.50][...80] - new: [....85] [ip4][..tcp] [.....172.16.0.1][53718] -> [..192.168.10.50][...80] - new: [....86] [ip4][..tcp] [.....172.16.0.1][53732] -> [..192.168.10.50][...80] - new: [....87] [ip4][..tcp] [.....172.16.0.1][53758] -> [..192.168.10.50][...80] - new: [....88] [ip4][..tcp] [.....172.16.0.1][53772] -> [..192.168.10.50][...80] - new: [....89] [ip4][..tcp] [.....172.16.0.1][53786] -> [..192.168.10.50][...80] - new: [....90] [ip4][..tcp] [.....172.16.0.1][53812] -> [..192.168.10.50][...80] + end: [....13] [ip4][..tcp] [.....172.16.0.1][52386] -> [..192.168.10.50][...80] + new: [....85] [ip4][..tcp] [.....172.16.0.1][53718] -> [..192.168.10.50][...80] + new: [....86] [ip4][..tcp] [.....172.16.0.1][53732] -> [..192.168.10.50][...80] + new: [....87] [ip4][..tcp] [.....172.16.0.1][53758] -> [..192.168.10.50][...80] + new: [....88] [ip4][..tcp] [.....172.16.0.1][53772] -> [..192.168.10.50][...80] + new: [....89] [ip4][..tcp] [.....172.16.0.1][53786] -> [..192.168.10.50][...80] + new: [....90] [ip4][..tcp] [.....172.16.0.1][53812] -> [..192.168.10.50][...80] guessed: [....14] [ip4][..tcp] [.....172.16.0.1][52400] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....14] [ip4][..tcp] [.....172.16.0.1][52400] -> [..192.168.10.50][...80] + end: [....14] [ip4][..tcp] [.....172.16.0.1][52400] -> [..192.168.10.50][...80] guessed: [....15] [ip4][..tcp] [.....172.16.0.1][52414] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....15] [ip4][..tcp] [.....172.16.0.1][52414] -> [..192.168.10.50][...80] + end: [....15] [ip4][..tcp] [.....172.16.0.1][52414] -> [..192.168.10.50][...80] guessed: [....16] [ip4][..tcp] [.....172.16.0.1][52440] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....16] [ip4][..tcp] [.....172.16.0.1][52440] -> [..192.168.10.50][...80] + end: [....16] [ip4][..tcp] [.....172.16.0.1][52440] -> [..192.168.10.50][...80] guessed: [....17] [ip4][..tcp] [.....172.16.0.1][52454] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....17] [ip4][..tcp] [.....172.16.0.1][52454] -> [..192.168.10.50][...80] + end: [....17] [ip4][..tcp] [.....172.16.0.1][52454] -> [..192.168.10.50][...80] guessed: [....18] [ip4][..tcp] [.....172.16.0.1][52480] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....18] [ip4][..tcp] [.....172.16.0.1][52480] -> [..192.168.10.50][...80] + end: [....18] [ip4][..tcp] [.....172.16.0.1][52480] -> [..192.168.10.50][...80] guessed: [....19] [ip4][..tcp] [.....172.16.0.1][52494] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....19] [ip4][..tcp] [.....172.16.0.1][52494] -> [..192.168.10.50][...80] - new: [....91] [ip4][..tcp] [.....172.16.0.1][53826] -> [..192.168.10.50][...80] - new: [....92] [ip4][..tcp] [.....172.16.0.1][53852] -> [..192.168.10.50][...80] - new: [....93] [ip4][..tcp] [.....172.16.0.1][53866] -> [..192.168.10.50][...80] - new: [....94] [ip4][..tcp] [.....172.16.0.1][53880] -> [..192.168.10.50][...80] - new: [....95] [ip4][..tcp] [.....172.16.0.1][53906] -> [..192.168.10.50][...80] - new: [....96] [ip4][..tcp] [.....172.16.0.1][53920] -> [..192.168.10.50][...80] + end: [....19] [ip4][..tcp] [.....172.16.0.1][52494] -> [..192.168.10.50][...80] + new: [....91] [ip4][..tcp] [.....172.16.0.1][53826] -> [..192.168.10.50][...80] + new: [....92] [ip4][..tcp] [.....172.16.0.1][53852] -> [..192.168.10.50][...80] + new: [....93] [ip4][..tcp] [.....172.16.0.1][53866] -> [..192.168.10.50][...80] + new: [....94] [ip4][..tcp] [.....172.16.0.1][53880] -> [..192.168.10.50][...80] + new: [....95] [ip4][..tcp] [.....172.16.0.1][53906] -> [..192.168.10.50][...80] + new: [....96] [ip4][..tcp] [.....172.16.0.1][53920] -> [..192.168.10.50][...80] guessed: [....20] [ip4][..tcp] [.....172.16.0.1][52508] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....20] [ip4][..tcp] [.....172.16.0.1][52508] -> [..192.168.10.50][...80] + end: [....20] [ip4][..tcp] [.....172.16.0.1][52508] -> [..192.168.10.50][...80] guessed: [....21] [ip4][..tcp] [.....172.16.0.1][52534] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....21] [ip4][..tcp] [.....172.16.0.1][52534] -> [..192.168.10.50][...80] + end: [....21] [ip4][..tcp] [.....172.16.0.1][52534] -> [..192.168.10.50][...80] guessed: [....22] [ip4][..tcp] [.....172.16.0.1][52548] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....22] [ip4][..tcp] [.....172.16.0.1][52548] -> [..192.168.10.50][...80] + end: [....22] [ip4][..tcp] [.....172.16.0.1][52548] -> [..192.168.10.50][...80] guessed: [....23] [ip4][..tcp] [.....172.16.0.1][52574] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....23] [ip4][..tcp] [.....172.16.0.1][52574] -> [..192.168.10.50][...80] + end: [....23] [ip4][..tcp] [.....172.16.0.1][52574] -> [..192.168.10.50][...80] guessed: [....24] [ip4][..tcp] [.....172.16.0.1][52588] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....24] [ip4][..tcp] [.....172.16.0.1][52588] -> [..192.168.10.50][...80] + end: [....24] [ip4][..tcp] [.....172.16.0.1][52588] -> [..192.168.10.50][...80] guessed: [....25] [ip4][..tcp] [.....172.16.0.1][52602] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....25] [ip4][..tcp] [.....172.16.0.1][52602] -> [..192.168.10.50][...80] - new: [....97] [ip4][..tcp] [.....172.16.0.1][53946] -> [..192.168.10.50][...80] - new: [....98] [ip4][..tcp] [.....172.16.0.1][53960] -> [..192.168.10.50][...80] - new: [....99] [ip4][..tcp] [.....172.16.0.1][53974] -> [..192.168.10.50][...80] - new: [...100] [ip4][..tcp] [.....172.16.0.1][54000] -> [..192.168.10.50][...80] - new: [...101] [ip4][..tcp] [.....172.16.0.1][54014] -> [..192.168.10.50][...80] + end: [....25] [ip4][..tcp] [.....172.16.0.1][52602] -> [..192.168.10.50][...80] + new: [....97] [ip4][..tcp] [.....172.16.0.1][53946] -> [..192.168.10.50][...80] + new: [....98] [ip4][..tcp] [.....172.16.0.1][53960] -> [..192.168.10.50][...80] + new: [....99] [ip4][..tcp] [.....172.16.0.1][53974] -> [..192.168.10.50][...80] + new: [...100] [ip4][..tcp] [.....172.16.0.1][54000] -> [..192.168.10.50][...80] + new: [...101] [ip4][..tcp] [.....172.16.0.1][54014] -> [..192.168.10.50][...80] guessed: [....26] [ip4][..tcp] [.....172.16.0.1][52628] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....26] [ip4][..tcp] [.....172.16.0.1][52628] -> [..192.168.10.50][...80] + end: [....26] [ip4][..tcp] [.....172.16.0.1][52628] -> [..192.168.10.50][...80] guessed: [....27] [ip4][..tcp] [.....172.16.0.1][52642] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....27] [ip4][..tcp] [.....172.16.0.1][52642] -> [..192.168.10.50][...80] + end: [....27] [ip4][..tcp] [.....172.16.0.1][52642] -> [..192.168.10.50][...80] guessed: [....28] [ip4][..tcp] [.....172.16.0.1][52668] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....28] [ip4][..tcp] [.....172.16.0.1][52668] -> [..192.168.10.50][...80] + end: [....28] [ip4][..tcp] [.....172.16.0.1][52668] -> [..192.168.10.50][...80] guessed: [....29] [ip4][..tcp] [.....172.16.0.1][52682] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....29] [ip4][..tcp] [.....172.16.0.1][52682] -> [..192.168.10.50][...80] + end: [....29] [ip4][..tcp] [.....172.16.0.1][52682] -> [..192.168.10.50][...80] guessed: [....30] [ip4][..tcp] [.....172.16.0.1][52696] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....30] [ip4][..tcp] [.....172.16.0.1][52696] -> [..192.168.10.50][...80] - new: [...102] [ip4][..tcp] [.....172.16.0.1][54040] -> [..192.168.10.50][...80] - new: [...103] [ip4][..tcp] [.....172.16.0.1][54054] -> [..192.168.10.50][...80] - new: [...104] [ip4][..tcp] [.....172.16.0.1][54068] -> [..192.168.10.50][...80] - new: [...105] [ip4][..tcp] [.....172.16.0.1][54094] -> [..192.168.10.50][...80] - new: [...106] [ip4][..tcp] [.....172.16.0.1][54108] -> [..192.168.10.50][...80] - new: [...107] [ip4][..tcp] [.....172.16.0.1][54134] -> [..192.168.10.50][...80] + end: [....30] [ip4][..tcp] [.....172.16.0.1][52696] -> [..192.168.10.50][...80] + new: [...102] [ip4][..tcp] [.....172.16.0.1][54040] -> [..192.168.10.50][...80] + new: [...103] [ip4][..tcp] [.....172.16.0.1][54054] -> [..192.168.10.50][...80] + new: [...104] [ip4][..tcp] [.....172.16.0.1][54068] -> [..192.168.10.50][...80] + new: [...105] [ip4][..tcp] [.....172.16.0.1][54094] -> [..192.168.10.50][...80] + new: [...106] [ip4][..tcp] [.....172.16.0.1][54108] -> [..192.168.10.50][...80] + new: [...107] [ip4][..tcp] [.....172.16.0.1][54134] -> [..192.168.10.50][...80] guessed: [....36] [ip4][..tcp] [.....172.16.0.1][52816] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....36] [ip4][..tcp] [.....172.16.0.1][52816] -> [..192.168.10.50][...80] + end: [....36] [ip4][..tcp] [.....172.16.0.1][52816] -> [..192.168.10.50][...80] guessed: [....31] [ip4][..tcp] [.....172.16.0.1][52722] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....31] [ip4][..tcp] [.....172.16.0.1][52722] -> [..192.168.10.50][...80] + end: [....31] [ip4][..tcp] [.....172.16.0.1][52722] -> [..192.168.10.50][...80] guessed: [....32] [ip4][..tcp] [.....172.16.0.1][52736] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....32] [ip4][..tcp] [.....172.16.0.1][52736] -> [..192.168.10.50][...80] + end: [....32] [ip4][..tcp] [.....172.16.0.1][52736] -> [..192.168.10.50][...80] guessed: [....33] [ip4][..tcp] [.....172.16.0.1][52750] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....33] [ip4][..tcp] [.....172.16.0.1][52750] -> [..192.168.10.50][...80] + end: [....33] [ip4][..tcp] [.....172.16.0.1][52750] -> [..192.168.10.50][...80] guessed: [....34] [ip4][..tcp] [.....172.16.0.1][52776] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....34] [ip4][..tcp] [.....172.16.0.1][52776] -> [..192.168.10.50][...80] + end: [....34] [ip4][..tcp] [.....172.16.0.1][52776] -> [..192.168.10.50][...80] guessed: [....35] [ip4][..tcp] [.....172.16.0.1][52790] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....35] [ip4][..tcp] [.....172.16.0.1][52790] -> [..192.168.10.50][...80] - new: [...108] [ip4][..tcp] [.....172.16.0.1][54148] -> [..192.168.10.50][...80] - new: [...109] [ip4][..tcp] [.....172.16.0.1][54162] -> [..192.168.10.50][...80] - new: [...110] [ip4][..tcp] [.....172.16.0.1][54188] -> [..192.168.10.50][...80] - new: [...111] [ip4][..tcp] [.....172.16.0.1][54202] -> [..192.168.10.50][...80] - new: [...112] [ip4][..tcp] [.....172.16.0.1][54228] -> [..192.168.10.50][...80] - new: [...113] [ip4][..tcp] [.....172.16.0.1][54242] -> [..192.168.10.50][...80] + end: [....35] [ip4][..tcp] [.....172.16.0.1][52790] -> [..192.168.10.50][...80] + new: [...108] [ip4][..tcp] [.....172.16.0.1][54148] -> [..192.168.10.50][...80] + new: [...109] [ip4][..tcp] [.....172.16.0.1][54162] -> [..192.168.10.50][...80] + new: [...110] [ip4][..tcp] [.....172.16.0.1][54188] -> [..192.168.10.50][...80] + new: [...111] [ip4][..tcp] [.....172.16.0.1][54202] -> [..192.168.10.50][...80] + new: [...112] [ip4][..tcp] [.....172.16.0.1][54228] -> [..192.168.10.50][...80] + new: [...113] [ip4][..tcp] [.....172.16.0.1][54242] -> [..192.168.10.50][...80] guessed: [....37] [ip4][..tcp] [.....172.16.0.1][52830] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....37] [ip4][..tcp] [.....172.16.0.1][52830] -> [..192.168.10.50][...80] + end: [....37] [ip4][..tcp] [.....172.16.0.1][52830] -> [..192.168.10.50][...80] guessed: [....38] [ip4][..tcp] [.....172.16.0.1][52856] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....38] [ip4][..tcp] [.....172.16.0.1][52856] -> [..192.168.10.50][...80] + end: [....38] [ip4][..tcp] [.....172.16.0.1][52856] -> [..192.168.10.50][...80] guessed: [....39] [ip4][..tcp] [.....172.16.0.1][52870] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....39] [ip4][..tcp] [.....172.16.0.1][52870] -> [..192.168.10.50][...80] + end: [....39] [ip4][..tcp] [.....172.16.0.1][52870] -> [..192.168.10.50][...80] guessed: [....40] [ip4][..tcp] [.....172.16.0.1][52884] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....40] [ip4][..tcp] [.....172.16.0.1][52884] -> [..192.168.10.50][...80] + end: [....40] [ip4][..tcp] [.....172.16.0.1][52884] -> [..192.168.10.50][...80] guessed: [....42] [ip4][..tcp] [.....172.16.0.1][52924] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....42] [ip4][..tcp] [.....172.16.0.1][52924] -> [..192.168.10.50][...80] + end: [....42] [ip4][..tcp] [.....172.16.0.1][52924] -> [..192.168.10.50][...80] end: [.....9] [ip4][..tcp] [.....172.16.0.1][52298] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...114] [ip4][..tcp] [.....172.16.0.1][54268] -> [..192.168.10.50][...80] - new: [...115] [ip4][..tcp] [.....172.16.0.1][54282] -> [..192.168.10.50][...80] - new: [...116] [ip4][..tcp] [.....172.16.0.1][54296] -> [..192.168.10.50][...80] + new: [...114] [ip4][..tcp] [.....172.16.0.1][54268] -> [..192.168.10.50][...80] + new: [...115] [ip4][..tcp] [.....172.16.0.1][54282] -> [..192.168.10.50][...80] + new: [...116] [ip4][..tcp] [.....172.16.0.1][54296] -> [..192.168.10.50][...80] detected: [...114] [ip4][..tcp] [.....172.16.0.1][54268] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...117] [ip4][..tcp] [.....172.16.0.1][54322] -> [..192.168.10.50][...80] - new: [...118] [ip4][..tcp] [.....172.16.0.1][54336] -> [..192.168.10.50][...80] + new: [...117] [ip4][..tcp] [.....172.16.0.1][54322] -> [..192.168.10.50][...80] + new: [...118] [ip4][..tcp] [.....172.16.0.1][54336] -> [..192.168.10.50][...80] guessed: [....43] [ip4][..tcp] [.....172.16.0.1][52938] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....43] [ip4][..tcp] [.....172.16.0.1][52938] -> [..192.168.10.50][...80] + end: [....43] [ip4][..tcp] [.....172.16.0.1][52938] -> [..192.168.10.50][...80] guessed: [....44] [ip4][..tcp] [.....172.16.0.1][52964] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....44] [ip4][..tcp] [.....172.16.0.1][52964] -> [..192.168.10.50][...80] + end: [....44] [ip4][..tcp] [.....172.16.0.1][52964] -> [..192.168.10.50][...80] guessed: [....45] [ip4][..tcp] [.....172.16.0.1][52978] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....45] [ip4][..tcp] [.....172.16.0.1][52978] -> [..192.168.10.50][...80] + end: [....45] [ip4][..tcp] [.....172.16.0.1][52978] -> [..192.168.10.50][...80] guessed: [....46] [ip4][..tcp] [.....172.16.0.1][53004] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....46] [ip4][..tcp] [.....172.16.0.1][53004] -> [..192.168.10.50][...80] + end: [....46] [ip4][..tcp] [.....172.16.0.1][53004] -> [..192.168.10.50][...80] guessed: [....47] [ip4][..tcp] [.....172.16.0.1][53018] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....47] [ip4][..tcp] [.....172.16.0.1][53018] -> [..192.168.10.50][...80] + end: [....47] [ip4][..tcp] [.....172.16.0.1][53018] -> [..192.168.10.50][...80] guessed: [....48] [ip4][..tcp] [.....172.16.0.1][53032] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....48] [ip4][..tcp] [.....172.16.0.1][53032] -> [..192.168.10.50][...80] - new: [...119] [ip4][..tcp] [.....172.16.0.1][54362] -> [..192.168.10.50][...80] + end: [....48] [ip4][..tcp] [.....172.16.0.1][53032] -> [..192.168.10.50][...80] + new: [...119] [ip4][..tcp] [.....172.16.0.1][54362] -> [..192.168.10.50][...80] analyse: [...114] [ip4][..tcp] [.....172.16.0.1][54268] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.827| 0.609| 0.943| 889903.972| 3.700] @@ -280,116 +280,116 @@ [IATS(ms)....: 0.1,0.9,3826.3,3827.2,3.1,3.9,1023.0,1026.9,3.9,268.2,273.7,5.4,1005.2,1009.2,4.0,256.2,259.9,3.6,1006.9,1010.6,3.7,250.1,253.8,3.8,1011.3,1016.1,4.8,241.0,244.7,3.6,1020.5] [PKTLENS.....: 60,60,52,637,52,1921,52,435,1822,52,637,1920,52,435,1822,52,637,1920,52,435,1822,52,637,1919,52,435,1822,52,637,1917,52,435] [ENTROPIES...: 4.6,5.0,4.9,6.0,4.9,7.8,5.0,5.9,7.7,4.9,6.1,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.1,7.8,5.0,5.9,7.7,4.9,6.1,7.8,4.9,5.9] - new: [...120] [ip4][..tcp] [.....172.16.0.1][54376] -> [..192.168.10.50][...80] - new: [...121] [ip4][..tcp] [.....172.16.0.1][54390] -> [..192.168.10.50][...80] - new: [...122] [ip4][..tcp] [.....172.16.0.1][54416] -> [..192.168.10.50][...80] - new: [...123] [ip4][..tcp] [.....172.16.0.1][54430] -> [..192.168.10.50][...80] - new: [...124] [ip4][..tcp] [.....172.16.0.1][54456] -> [..192.168.10.50][...80] + new: [...120] [ip4][..tcp] [.....172.16.0.1][54376] -> [..192.168.10.50][...80] + new: [...121] [ip4][..tcp] [.....172.16.0.1][54390] -> [..192.168.10.50][...80] + new: [...122] [ip4][..tcp] [.....172.16.0.1][54416] -> [..192.168.10.50][...80] + new: [...123] [ip4][..tcp] [.....172.16.0.1][54430] -> [..192.168.10.50][...80] + new: [...124] [ip4][..tcp] [.....172.16.0.1][54456] -> [..192.168.10.50][...80] guessed: [....49] [ip4][..tcp] [.....172.16.0.1][53058] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....49] [ip4][..tcp] [.....172.16.0.1][53058] -> [..192.168.10.50][...80] + end: [....49] [ip4][..tcp] [.....172.16.0.1][53058] -> [..192.168.10.50][...80] guessed: [....50] [ip4][..tcp] [.....172.16.0.1][53072] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....50] [ip4][..tcp] [.....172.16.0.1][53072] -> [..192.168.10.50][...80] + end: [....50] [ip4][..tcp] [.....172.16.0.1][53072] -> [..192.168.10.50][...80] guessed: [....51] [ip4][..tcp] [.....172.16.0.1][53098] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....51] [ip4][..tcp] [.....172.16.0.1][53098] -> [..192.168.10.50][...80] + end: [....51] [ip4][..tcp] [.....172.16.0.1][53098] -> [..192.168.10.50][...80] guessed: [....52] [ip4][..tcp] [.....172.16.0.1][53112] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....52] [ip4][..tcp] [.....172.16.0.1][53112] -> [..192.168.10.50][...80] + end: [....52] [ip4][..tcp] [.....172.16.0.1][53112] -> [..192.168.10.50][...80] guessed: [....53] [ip4][..tcp] [.....172.16.0.1][53126] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....53] [ip4][..tcp] [.....172.16.0.1][53126] -> [..192.168.10.50][...80] - new: [...125] [ip4][..tcp] [.....172.16.0.1][54470] -> [..192.168.10.50][...80] - new: [...126] [ip4][..tcp] [.....172.16.0.1][54484] -> [..192.168.10.50][...80] - new: [...127] [ip4][..tcp] [.....172.16.0.1][54510] -> [..192.168.10.50][...80] - new: [...128] [ip4][..tcp] [.....172.16.0.1][54524] -> [..192.168.10.50][...80] - new: [...129] [ip4][..tcp] [.....172.16.0.1][54538] -> [..192.168.10.50][...80] - new: [...130] [ip4][..tcp] [.....172.16.0.1][54552] -> [..192.168.10.50][...80] - new: [...131] [ip4][..tcp] [.....172.16.0.1][54566] -> [..192.168.10.50][...80] + end: [....53] [ip4][..tcp] [.....172.16.0.1][53126] -> [..192.168.10.50][...80] + new: [...125] [ip4][..tcp] [.....172.16.0.1][54470] -> [..192.168.10.50][...80] + new: [...126] [ip4][..tcp] [.....172.16.0.1][54484] -> [..192.168.10.50][...80] + new: [...127] [ip4][..tcp] [.....172.16.0.1][54510] -> [..192.168.10.50][...80] + new: [...128] [ip4][..tcp] [.....172.16.0.1][54524] -> [..192.168.10.50][...80] + new: [...129] [ip4][..tcp] [.....172.16.0.1][54538] -> [..192.168.10.50][...80] + new: [...130] [ip4][..tcp] [.....172.16.0.1][54552] -> [..192.168.10.50][...80] + new: [...131] [ip4][..tcp] [.....172.16.0.1][54566] -> [..192.168.10.50][...80] guessed: [....54] [ip4][..tcp] [.....172.16.0.1][53152] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....54] [ip4][..tcp] [.....172.16.0.1][53152] -> [..192.168.10.50][...80] + end: [....54] [ip4][..tcp] [.....172.16.0.1][53152] -> [..192.168.10.50][...80] guessed: [....55] [ip4][..tcp] [.....172.16.0.1][53166] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....55] [ip4][..tcp] [.....172.16.0.1][53166] -> [..192.168.10.50][...80] + end: [....55] [ip4][..tcp] [.....172.16.0.1][53166] -> [..192.168.10.50][...80] guessed: [....56] [ip4][..tcp] [.....172.16.0.1][53192] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....56] [ip4][..tcp] [.....172.16.0.1][53192] -> [..192.168.10.50][...80] + end: [....56] [ip4][..tcp] [.....172.16.0.1][53192] -> [..192.168.10.50][...80] guessed: [....57] [ip4][..tcp] [.....172.16.0.1][53206] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....57] [ip4][..tcp] [.....172.16.0.1][53206] -> [..192.168.10.50][...80] + end: [....57] [ip4][..tcp] [.....172.16.0.1][53206] -> [..192.168.10.50][...80] guessed: [....58] [ip4][..tcp] [.....172.16.0.1][53220] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....58] [ip4][..tcp] [.....172.16.0.1][53220] -> [..192.168.10.50][...80] + end: [....58] [ip4][..tcp] [.....172.16.0.1][53220] -> [..192.168.10.50][...80] guessed: [....59] [ip4][..tcp] [.....172.16.0.1][53246] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....59] [ip4][..tcp] [.....172.16.0.1][53246] -> [..192.168.10.50][...80] + end: [....59] [ip4][..tcp] [.....172.16.0.1][53246] -> [..192.168.10.50][...80] guessed: [....60] [ip4][..tcp] [.....172.16.0.1][53260] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....60] [ip4][..tcp] [.....172.16.0.1][53260] -> [..192.168.10.50][...80] - new: [...132] [ip4][..tcp] [.....172.16.0.1][54580] -> [..192.168.10.50][...80] - new: [...133] [ip4][..tcp] [.....172.16.0.1][54606] -> [..192.168.10.50][...80] - new: [...134] [ip4][..tcp] [.....172.16.0.1][54620] -> [..192.168.10.50][...80] - new: [...135] [ip4][..tcp] [.....172.16.0.1][54634] -> [..192.168.10.50][...80] - new: [...136] [ip4][..tcp] [.....172.16.0.1][54660] -> [..192.168.10.50][...80] - new: [...137] [ip4][..tcp] [.....172.16.0.1][54674] -> [..192.168.10.50][...80] + end: [....60] [ip4][..tcp] [.....172.16.0.1][53260] -> [..192.168.10.50][...80] + new: [...132] [ip4][..tcp] [.....172.16.0.1][54580] -> [..192.168.10.50][...80] + new: [...133] [ip4][..tcp] [.....172.16.0.1][54606] -> [..192.168.10.50][...80] + new: [...134] [ip4][..tcp] [.....172.16.0.1][54620] -> [..192.168.10.50][...80] + new: [...135] [ip4][..tcp] [.....172.16.0.1][54634] -> [..192.168.10.50][...80] + new: [...136] [ip4][..tcp] [.....172.16.0.1][54660] -> [..192.168.10.50][...80] + new: [...137] [ip4][..tcp] [.....172.16.0.1][54674] -> [..192.168.10.50][...80] guessed: [....61] [ip4][..tcp] [.....172.16.0.1][53286] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....61] [ip4][..tcp] [.....172.16.0.1][53286] -> [..192.168.10.50][...80] + end: [....61] [ip4][..tcp] [.....172.16.0.1][53286] -> [..192.168.10.50][...80] guessed: [....62] [ip4][..tcp] [.....172.16.0.1][53300] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....62] [ip4][..tcp] [.....172.16.0.1][53300] -> [..192.168.10.50][...80] + end: [....62] [ip4][..tcp] [.....172.16.0.1][53300] -> [..192.168.10.50][...80] guessed: [....63] [ip4][..tcp] [.....172.16.0.1][53314] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....63] [ip4][..tcp] [.....172.16.0.1][53314] -> [..192.168.10.50][...80] + end: [....63] [ip4][..tcp] [.....172.16.0.1][53314] -> [..192.168.10.50][...80] guessed: [....64] [ip4][..tcp] [.....172.16.0.1][53340] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....64] [ip4][..tcp] [.....172.16.0.1][53340] -> [..192.168.10.50][...80] + end: [....64] [ip4][..tcp] [.....172.16.0.1][53340] -> [..192.168.10.50][...80] guessed: [....65] [ip4][..tcp] [.....172.16.0.1][53354] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....65] [ip4][..tcp] [.....172.16.0.1][53354] -> [..192.168.10.50][...80] - new: [...138] [ip4][..tcp] [.....172.16.0.1][54688] -> [..192.168.10.50][...80] - new: [...139] [ip4][..tcp] [.....172.16.0.1][54714] -> [..192.168.10.50][...80] - new: [...140] [ip4][..tcp] [.....172.16.0.1][54728] -> [..192.168.10.50][...80] - new: [...141] [ip4][..tcp] [.....172.16.0.1][54742] -> [..192.168.10.50][...80] - new: [...142] [ip4][..tcp] [.....172.16.0.1][54768] -> [..192.168.10.50][...80] - new: [...143] [ip4][..tcp] [.....172.16.0.1][54782] -> [..192.168.10.50][...80] + end: [....65] [ip4][..tcp] [.....172.16.0.1][53354] -> [..192.168.10.50][...80] + new: [...138] [ip4][..tcp] [.....172.16.0.1][54688] -> [..192.168.10.50][...80] + new: [...139] [ip4][..tcp] [.....172.16.0.1][54714] -> [..192.168.10.50][...80] + new: [...140] [ip4][..tcp] [.....172.16.0.1][54728] -> [..192.168.10.50][...80] + new: [...141] [ip4][..tcp] [.....172.16.0.1][54742] -> [..192.168.10.50][...80] + new: [...142] [ip4][..tcp] [.....172.16.0.1][54768] -> [..192.168.10.50][...80] + new: [...143] [ip4][..tcp] [.....172.16.0.1][54782] -> [..192.168.10.50][...80] guessed: [....66] [ip4][..tcp] [.....172.16.0.1][53380] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....66] [ip4][..tcp] [.....172.16.0.1][53380] -> [..192.168.10.50][...80] + end: [....66] [ip4][..tcp] [.....172.16.0.1][53380] -> [..192.168.10.50][...80] guessed: [....67] [ip4][..tcp] [.....172.16.0.1][53394] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....67] [ip4][..tcp] [.....172.16.0.1][53394] -> [..192.168.10.50][...80] + end: [....67] [ip4][..tcp] [.....172.16.0.1][53394] -> [..192.168.10.50][...80] guessed: [....68] [ip4][..tcp] [.....172.16.0.1][53408] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....68] [ip4][..tcp] [.....172.16.0.1][53408] -> [..192.168.10.50][...80] + end: [....68] [ip4][..tcp] [.....172.16.0.1][53408] -> [..192.168.10.50][...80] guessed: [....69] [ip4][..tcp] [.....172.16.0.1][53422] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....69] [ip4][..tcp] [.....172.16.0.1][53422] -> [..192.168.10.50][...80] + end: [....69] [ip4][..tcp] [.....172.16.0.1][53422] -> [..192.168.10.50][...80] guessed: [....70] [ip4][..tcp] [.....172.16.0.1][53436] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....70] [ip4][..tcp] [.....172.16.0.1][53436] -> [..192.168.10.50][...80] + end: [....70] [ip4][..tcp] [.....172.16.0.1][53436] -> [..192.168.10.50][...80] guessed: [....71] [ip4][..tcp] [.....172.16.0.1][53450] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....71] [ip4][..tcp] [.....172.16.0.1][53450] -> [..192.168.10.50][...80] - new: [...144] [ip4][..tcp] [.....172.16.0.1][54808] -> [..192.168.10.50][...80] - new: [...145] [ip4][..tcp] [.....172.16.0.1][54822] -> [..192.168.10.50][...80] - new: [...146] [ip4][..tcp] [.....172.16.0.1][54836] -> [..192.168.10.50][...80] - new: [...147] [ip4][..tcp] [.....172.16.0.1][54862] -> [..192.168.10.50][...80] - new: [...148] [ip4][..tcp] [.....172.16.0.1][54876] -> [..192.168.10.50][...80] - new: [...149] [ip4][..tcp] [.....172.16.0.1][54890] -> [..192.168.10.50][...80] + end: [....71] [ip4][..tcp] [.....172.16.0.1][53450] -> [..192.168.10.50][...80] + new: [...144] [ip4][..tcp] [.....172.16.0.1][54808] -> [..192.168.10.50][...80] + new: [...145] [ip4][..tcp] [.....172.16.0.1][54822] -> [..192.168.10.50][...80] + new: [...146] [ip4][..tcp] [.....172.16.0.1][54836] -> [..192.168.10.50][...80] + new: [...147] [ip4][..tcp] [.....172.16.0.1][54862] -> [..192.168.10.50][...80] + new: [...148] [ip4][..tcp] [.....172.16.0.1][54876] -> [..192.168.10.50][...80] + new: [...149] [ip4][..tcp] [.....172.16.0.1][54890] -> [..192.168.10.50][...80] end: [....41] [ip4][..tcp] [.....172.16.0.1][52910] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [....72] [ip4][..tcp] [.....172.16.0.1][53476] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....72] [ip4][..tcp] [.....172.16.0.1][53476] -> [..192.168.10.50][...80] + end: [....72] [ip4][..tcp] [.....172.16.0.1][53476] -> [..192.168.10.50][...80] guessed: [....73] [ip4][..tcp] [.....172.16.0.1][53490] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....73] [ip4][..tcp] [.....172.16.0.1][53490] -> [..192.168.10.50][...80] + end: [....73] [ip4][..tcp] [.....172.16.0.1][53490] -> [..192.168.10.50][...80] guessed: [....74] [ip4][..tcp] [.....172.16.0.1][53516] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....74] [ip4][..tcp] [.....172.16.0.1][53516] -> [..192.168.10.50][...80] + end: [....74] [ip4][..tcp] [.....172.16.0.1][53516] -> [..192.168.10.50][...80] guessed: [....75] [ip4][..tcp] [.....172.16.0.1][53530] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....75] [ip4][..tcp] [.....172.16.0.1][53530] -> [..192.168.10.50][...80] + end: [....75] [ip4][..tcp] [.....172.16.0.1][53530] -> [..192.168.10.50][...80] guessed: [....76] [ip4][..tcp] [.....172.16.0.1][53544] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....76] [ip4][..tcp] [.....172.16.0.1][53544] -> [..192.168.10.50][...80] + end: [....76] [ip4][..tcp] [.....172.16.0.1][53544] -> [..192.168.10.50][...80] guessed: [....77] [ip4][..tcp] [.....172.16.0.1][53570] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....77] [ip4][..tcp] [.....172.16.0.1][53570] -> [..192.168.10.50][...80] - new: [...150] [ip4][..tcp] [.....172.16.0.1][54916] -> [..192.168.10.50][...80] - new: [...151] [ip4][..tcp] [.....172.16.0.1][54930] -> [..192.168.10.50][...80] - new: [...152] [ip4][..tcp] [.....172.16.0.1][54956] -> [..192.168.10.50][...80] - new: [...153] [ip4][..tcp] [.....172.16.0.1][54970] -> [..192.168.10.50][...80] - new: [...154] [ip4][..tcp] [.....172.16.0.1][54984] -> [..192.168.10.50][...80] + end: [....77] [ip4][..tcp] [.....172.16.0.1][53570] -> [..192.168.10.50][...80] + new: [...150] [ip4][..tcp] [.....172.16.0.1][54916] -> [..192.168.10.50][...80] + new: [...151] [ip4][..tcp] [.....172.16.0.1][54930] -> [..192.168.10.50][...80] + new: [...152] [ip4][..tcp] [.....172.16.0.1][54956] -> [..192.168.10.50][...80] + new: [...153] [ip4][..tcp] [.....172.16.0.1][54970] -> [..192.168.10.50][...80] + new: [...154] [ip4][..tcp] [.....172.16.0.1][54984] -> [..192.168.10.50][...80] detected: [...152] [ip4][..tcp] [.....172.16.0.1][54956] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [....79] [ip4][..tcp] [.....172.16.0.1][53598] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....79] [ip4][..tcp] [.....172.16.0.1][53598] -> [..192.168.10.50][...80] + end: [....79] [ip4][..tcp] [.....172.16.0.1][53598] -> [..192.168.10.50][...80] guessed: [....80] [ip4][..tcp] [.....172.16.0.1][53624] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....80] [ip4][..tcp] [.....172.16.0.1][53624] -> [..192.168.10.50][...80] + end: [....80] [ip4][..tcp] [.....172.16.0.1][53624] -> [..192.168.10.50][...80] guessed: [....81] [ip4][..tcp] [.....172.16.0.1][53638] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....81] [ip4][..tcp] [.....172.16.0.1][53638] -> [..192.168.10.50][...80] + end: [....81] [ip4][..tcp] [.....172.16.0.1][53638] -> [..192.168.10.50][...80] guessed: [....82] [ip4][..tcp] [.....172.16.0.1][53664] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....82] [ip4][..tcp] [.....172.16.0.1][53664] -> [..192.168.10.50][...80] + end: [....82] [ip4][..tcp] [.....172.16.0.1][53664] -> [..192.168.10.50][...80] guessed: [....83] [ip4][..tcp] [.....172.16.0.1][53678] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....83] [ip4][..tcp] [.....172.16.0.1][53678] -> [..192.168.10.50][...80] - new: [...155] [ip4][..tcp] [.....172.16.0.1][55010] -> [..192.168.10.50][...80] - new: [...156] [ip4][..tcp] [.....172.16.0.1][55024] -> [..192.168.10.50][...80] - new: [...157] [ip4][..tcp] [.....172.16.0.1][55038] -> [..192.168.10.50][...80] + end: [....83] [ip4][..tcp] [.....172.16.0.1][53678] -> [..192.168.10.50][...80] + new: [...155] [ip4][..tcp] [.....172.16.0.1][55010] -> [..192.168.10.50][...80] + new: [...156] [ip4][..tcp] [.....172.16.0.1][55024] -> [..192.168.10.50][...80] + new: [...157] [ip4][..tcp] [.....172.16.0.1][55038] -> [..192.168.10.50][...80] analyse: [...152] [ip4][..tcp] [.....172.16.0.1][54956] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.643| 0.568| 0.904| 816455.025| 3.600] @@ -400,112 +400,112 @@ [IATS(ms)....: 0.1,0.7,3641.9,3642.6,3.1,4.1,234.1,238.5,4.2,1006.1,1011.0,4.9,233.1,236.8,3.8,1005.6,1010.7,5.0,236.2,239.8,3.6,1006.8,1010.5,3.7,232.6,236.3,3.6,1034.9,1038.9,4.1,256.3] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1919,52,435,1822,52,637,1915,52,435,1822,52,637,1921,52,435,1822,52,637,1919,52,435,1822,52,637] [ENTROPIES...: 4.6,5.1,4.9,5.9,4.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.0,7.8,4.9,5.9,7.7,4.9,6.1] - new: [...158] [ip4][..tcp] [.....172.16.0.1][55064] -> [..192.168.10.50][...80] - new: [...159] [ip4][..tcp] [.....172.16.0.1][55078] -> [..192.168.10.50][...80] - new: [...160] [ip4][..tcp] [.....172.16.0.1][55092] -> [..192.168.10.50][...80] + new: [...158] [ip4][..tcp] [.....172.16.0.1][55064] -> [..192.168.10.50][...80] + new: [...159] [ip4][..tcp] [.....172.16.0.1][55078] -> [..192.168.10.50][...80] + new: [...160] [ip4][..tcp] [.....172.16.0.1][55092] -> [..192.168.10.50][...80] guessed: [....84] [ip4][..tcp] [.....172.16.0.1][53692] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....84] [ip4][..tcp] [.....172.16.0.1][53692] -> [..192.168.10.50][...80] + end: [....84] [ip4][..tcp] [.....172.16.0.1][53692] -> [..192.168.10.50][...80] guessed: [....85] [ip4][..tcp] [.....172.16.0.1][53718] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....85] [ip4][..tcp] [.....172.16.0.1][53718] -> [..192.168.10.50][...80] + end: [....85] [ip4][..tcp] [.....172.16.0.1][53718] -> [..192.168.10.50][...80] guessed: [....86] [ip4][..tcp] [.....172.16.0.1][53732] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....86] [ip4][..tcp] [.....172.16.0.1][53732] -> [..192.168.10.50][...80] + end: [....86] [ip4][..tcp] [.....172.16.0.1][53732] -> [..192.168.10.50][...80] guessed: [....87] [ip4][..tcp] [.....172.16.0.1][53758] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....87] [ip4][..tcp] [.....172.16.0.1][53758] -> [..192.168.10.50][...80] + end: [....87] [ip4][..tcp] [.....172.16.0.1][53758] -> [..192.168.10.50][...80] guessed: [....88] [ip4][..tcp] [.....172.16.0.1][53772] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....88] [ip4][..tcp] [.....172.16.0.1][53772] -> [..192.168.10.50][...80] - new: [...161] [ip4][..tcp] [.....172.16.0.1][55118] -> [..192.168.10.50][...80] - new: [...162] [ip4][..tcp] [.....172.16.0.1][55132] -> [..192.168.10.50][...80] - new: [...163] [ip4][..tcp] [.....172.16.0.1][55158] -> [..192.168.10.50][...80] - new: [...164] [ip4][..tcp] [.....172.16.0.1][55172] -> [..192.168.10.50][...80] - new: [...165] [ip4][..tcp] [.....172.16.0.1][55186] -> [..192.168.10.50][...80] - new: [...166] [ip4][..tcp] [.....172.16.0.1][55212] -> [..192.168.10.50][...80] + end: [....88] [ip4][..tcp] [.....172.16.0.1][53772] -> [..192.168.10.50][...80] + new: [...161] [ip4][..tcp] [.....172.16.0.1][55118] -> [..192.168.10.50][...80] + new: [...162] [ip4][..tcp] [.....172.16.0.1][55132] -> [..192.168.10.50][...80] + new: [...163] [ip4][..tcp] [.....172.16.0.1][55158] -> [..192.168.10.50][...80] + new: [...164] [ip4][..tcp] [.....172.16.0.1][55172] -> [..192.168.10.50][...80] + new: [...165] [ip4][..tcp] [.....172.16.0.1][55186] -> [..192.168.10.50][...80] + new: [...166] [ip4][..tcp] [.....172.16.0.1][55212] -> [..192.168.10.50][...80] guessed: [....89] [ip4][..tcp] [.....172.16.0.1][53786] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....89] [ip4][..tcp] [.....172.16.0.1][53786] -> [..192.168.10.50][...80] + end: [....89] [ip4][..tcp] [.....172.16.0.1][53786] -> [..192.168.10.50][...80] guessed: [....90] [ip4][..tcp] [.....172.16.0.1][53812] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....90] [ip4][..tcp] [.....172.16.0.1][53812] -> [..192.168.10.50][...80] + end: [....90] [ip4][..tcp] [.....172.16.0.1][53812] -> [..192.168.10.50][...80] guessed: [....91] [ip4][..tcp] [.....172.16.0.1][53826] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....91] [ip4][..tcp] [.....172.16.0.1][53826] -> [..192.168.10.50][...80] + end: [....91] [ip4][..tcp] [.....172.16.0.1][53826] -> [..192.168.10.50][...80] guessed: [....92] [ip4][..tcp] [.....172.16.0.1][53852] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....92] [ip4][..tcp] [.....172.16.0.1][53852] -> [..192.168.10.50][...80] + end: [....92] [ip4][..tcp] [.....172.16.0.1][53852] -> [..192.168.10.50][...80] guessed: [....93] [ip4][..tcp] [.....172.16.0.1][53866] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....93] [ip4][..tcp] [.....172.16.0.1][53866] -> [..192.168.10.50][...80] + end: [....93] [ip4][..tcp] [.....172.16.0.1][53866] -> [..192.168.10.50][...80] guessed: [....94] [ip4][..tcp] [.....172.16.0.1][53880] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....94] [ip4][..tcp] [.....172.16.0.1][53880] -> [..192.168.10.50][...80] - new: [...167] [ip4][..tcp] [.....172.16.0.1][55226] -> [..192.168.10.50][...80] - new: [...168] [ip4][..tcp] [.....172.16.0.1][55240] -> [..192.168.10.50][...80] - new: [...169] [ip4][..tcp] [.....172.16.0.1][55266] -> [..192.168.10.50][...80] - new: [...170] [ip4][..tcp] [.....172.16.0.1][55280] -> [..192.168.10.50][...80] - new: [...171] [ip4][..tcp] [.....172.16.0.1][55294] -> [..192.168.10.50][...80] - new: [...172] [ip4][..tcp] [.....172.16.0.1][55320] -> [..192.168.10.50][...80] + end: [....94] [ip4][..tcp] [.....172.16.0.1][53880] -> [..192.168.10.50][...80] + new: [...167] [ip4][..tcp] [.....172.16.0.1][55226] -> [..192.168.10.50][...80] + new: [...168] [ip4][..tcp] [.....172.16.0.1][55240] -> [..192.168.10.50][...80] + new: [...169] [ip4][..tcp] [.....172.16.0.1][55266] -> [..192.168.10.50][...80] + new: [...170] [ip4][..tcp] [.....172.16.0.1][55280] -> [..192.168.10.50][...80] + new: [...171] [ip4][..tcp] [.....172.16.0.1][55294] -> [..192.168.10.50][...80] + new: [...172] [ip4][..tcp] [.....172.16.0.1][55320] -> [..192.168.10.50][...80] guessed: [....95] [ip4][..tcp] [.....172.16.0.1][53906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....95] [ip4][..tcp] [.....172.16.0.1][53906] -> [..192.168.10.50][...80] + end: [....95] [ip4][..tcp] [.....172.16.0.1][53906] -> [..192.168.10.50][...80] guessed: [....96] [ip4][..tcp] [.....172.16.0.1][53920] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....96] [ip4][..tcp] [.....172.16.0.1][53920] -> [..192.168.10.50][...80] + end: [....96] [ip4][..tcp] [.....172.16.0.1][53920] -> [..192.168.10.50][...80] guessed: [....97] [ip4][..tcp] [.....172.16.0.1][53946] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....97] [ip4][..tcp] [.....172.16.0.1][53946] -> [..192.168.10.50][...80] + end: [....97] [ip4][..tcp] [.....172.16.0.1][53946] -> [..192.168.10.50][...80] guessed: [....98] [ip4][..tcp] [.....172.16.0.1][53960] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....98] [ip4][..tcp] [.....172.16.0.1][53960] -> [..192.168.10.50][...80] + end: [....98] [ip4][..tcp] [.....172.16.0.1][53960] -> [..192.168.10.50][...80] guessed: [....99] [ip4][..tcp] [.....172.16.0.1][53974] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....99] [ip4][..tcp] [.....172.16.0.1][53974] -> [..192.168.10.50][...80] + end: [....99] [ip4][..tcp] [.....172.16.0.1][53974] -> [..192.168.10.50][...80] guessed: [...100] [ip4][..tcp] [.....172.16.0.1][54000] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...100] [ip4][..tcp] [.....172.16.0.1][54000] -> [..192.168.10.50][...80] - new: [...173] [ip4][..tcp] [.....172.16.0.1][55334] -> [..192.168.10.50][...80] - new: [...174] [ip4][..tcp] [.....172.16.0.1][55348] -> [..192.168.10.50][...80] - new: [...175] [ip4][..tcp] [.....172.16.0.1][55362] -> [..192.168.10.50][...80] - new: [...176] [ip4][..tcp] [.....172.16.0.1][55376] -> [..192.168.10.50][...80] - new: [...177] [ip4][..tcp] [.....172.16.0.1][55390] -> [..192.168.10.50][...80] - new: [...178] [ip4][..tcp] [.....172.16.0.1][55416] -> [..192.168.10.50][...80] - new: [...179] [ip4][..tcp] [.....172.16.0.1][55430] -> [..192.168.10.50][...80] + end: [...100] [ip4][..tcp] [.....172.16.0.1][54000] -> [..192.168.10.50][...80] + new: [...173] [ip4][..tcp] [.....172.16.0.1][55334] -> [..192.168.10.50][...80] + new: [...174] [ip4][..tcp] [.....172.16.0.1][55348] -> [..192.168.10.50][...80] + new: [...175] [ip4][..tcp] [.....172.16.0.1][55362] -> [..192.168.10.50][...80] + new: [...176] [ip4][..tcp] [.....172.16.0.1][55376] -> [..192.168.10.50][...80] + new: [...177] [ip4][..tcp] [.....172.16.0.1][55390] -> [..192.168.10.50][...80] + new: [...178] [ip4][..tcp] [.....172.16.0.1][55416] -> [..192.168.10.50][...80] + new: [...179] [ip4][..tcp] [.....172.16.0.1][55430] -> [..192.168.10.50][...80] guessed: [...101] [ip4][..tcp] [.....172.16.0.1][54014] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...101] [ip4][..tcp] [.....172.16.0.1][54014] -> [..192.168.10.50][...80] + end: [...101] [ip4][..tcp] [.....172.16.0.1][54014] -> [..192.168.10.50][...80] guessed: [...102] [ip4][..tcp] [.....172.16.0.1][54040] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...102] [ip4][..tcp] [.....172.16.0.1][54040] -> [..192.168.10.50][...80] + end: [...102] [ip4][..tcp] [.....172.16.0.1][54040] -> [..192.168.10.50][...80] guessed: [...103] [ip4][..tcp] [.....172.16.0.1][54054] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...103] [ip4][..tcp] [.....172.16.0.1][54054] -> [..192.168.10.50][...80] + end: [...103] [ip4][..tcp] [.....172.16.0.1][54054] -> [..192.168.10.50][...80] guessed: [...104] [ip4][..tcp] [.....172.16.0.1][54068] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...104] [ip4][..tcp] [.....172.16.0.1][54068] -> [..192.168.10.50][...80] + end: [...104] [ip4][..tcp] [.....172.16.0.1][54068] -> [..192.168.10.50][...80] guessed: [...105] [ip4][..tcp] [.....172.16.0.1][54094] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...105] [ip4][..tcp] [.....172.16.0.1][54094] -> [..192.168.10.50][...80] + end: [...105] [ip4][..tcp] [.....172.16.0.1][54094] -> [..192.168.10.50][...80] guessed: [...106] [ip4][..tcp] [.....172.16.0.1][54108] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...106] [ip4][..tcp] [.....172.16.0.1][54108] -> [..192.168.10.50][...80] - new: [...180] [ip4][..tcp] [.....172.16.0.1][55444] -> [..192.168.10.50][...80] - new: [...181] [ip4][..tcp] [.....172.16.0.1][55470] -> [..192.168.10.50][...80] - new: [...182] [ip4][..tcp] [.....172.16.0.1][55484] -> [..192.168.10.50][...80] - new: [...183] [ip4][..tcp] [.....172.16.0.1][55510] -> [..192.168.10.50][...80] - new: [...184] [ip4][..tcp] [.....172.16.0.1][55524] -> [..192.168.10.50][...80] - new: [...185] [ip4][..tcp] [.....172.16.0.1][55538] -> [..192.168.10.50][...80] + end: [...106] [ip4][..tcp] [.....172.16.0.1][54108] -> [..192.168.10.50][...80] + new: [...180] [ip4][..tcp] [.....172.16.0.1][55444] -> [..192.168.10.50][...80] + new: [...181] [ip4][..tcp] [.....172.16.0.1][55470] -> [..192.168.10.50][...80] + new: [...182] [ip4][..tcp] [.....172.16.0.1][55484] -> [..192.168.10.50][...80] + new: [...183] [ip4][..tcp] [.....172.16.0.1][55510] -> [..192.168.10.50][...80] + new: [...184] [ip4][..tcp] [.....172.16.0.1][55524] -> [..192.168.10.50][...80] + new: [...185] [ip4][..tcp] [.....172.16.0.1][55538] -> [..192.168.10.50][...80] guessed: [...107] [ip4][..tcp] [.....172.16.0.1][54134] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...107] [ip4][..tcp] [.....172.16.0.1][54134] -> [..192.168.10.50][...80] + end: [...107] [ip4][..tcp] [.....172.16.0.1][54134] -> [..192.168.10.50][...80] guessed: [...108] [ip4][..tcp] [.....172.16.0.1][54148] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...108] [ip4][..tcp] [.....172.16.0.1][54148] -> [..192.168.10.50][...80] + end: [...108] [ip4][..tcp] [.....172.16.0.1][54148] -> [..192.168.10.50][...80] guessed: [...109] [ip4][..tcp] [.....172.16.0.1][54162] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...109] [ip4][..tcp] [.....172.16.0.1][54162] -> [..192.168.10.50][...80] + end: [...109] [ip4][..tcp] [.....172.16.0.1][54162] -> [..192.168.10.50][...80] guessed: [...110] [ip4][..tcp] [.....172.16.0.1][54188] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...110] [ip4][..tcp] [.....172.16.0.1][54188] -> [..192.168.10.50][...80] + end: [...110] [ip4][..tcp] [.....172.16.0.1][54188] -> [..192.168.10.50][...80] guessed: [...111] [ip4][..tcp] [.....172.16.0.1][54202] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...111] [ip4][..tcp] [.....172.16.0.1][54202] -> [..192.168.10.50][...80] - new: [...186] [ip4][..tcp] [.....172.16.0.1][55564] -> [..192.168.10.50][...80] - new: [...187] [ip4][..tcp] [.....172.16.0.1][55578] -> [..192.168.10.50][...80] - new: [...188] [ip4][..tcp] [.....172.16.0.1][55592] -> [..192.168.10.50][...80] - new: [...189] [ip4][..tcp] [.....172.16.0.1][55618] -> [..192.168.10.50][...80] - new: [...190] [ip4][..tcp] [.....172.16.0.1][55632] -> [..192.168.10.50][...80] - new: [...191] [ip4][..tcp] [.....172.16.0.1][55646] -> [..192.168.10.50][...80] + end: [...111] [ip4][..tcp] [.....172.16.0.1][54202] -> [..192.168.10.50][...80] + new: [...186] [ip4][..tcp] [.....172.16.0.1][55564] -> [..192.168.10.50][...80] + new: [...187] [ip4][..tcp] [.....172.16.0.1][55578] -> [..192.168.10.50][...80] + new: [...188] [ip4][..tcp] [.....172.16.0.1][55592] -> [..192.168.10.50][...80] + new: [...189] [ip4][..tcp] [.....172.16.0.1][55618] -> [..192.168.10.50][...80] + new: [...190] [ip4][..tcp] [.....172.16.0.1][55632] -> [..192.168.10.50][...80] + new: [...191] [ip4][..tcp] [.....172.16.0.1][55646] -> [..192.168.10.50][...80] end: [....78] [ip4][..tcp] [.....172.16.0.1][53584] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...112] [ip4][..tcp] [.....172.16.0.1][54228] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...112] [ip4][..tcp] [.....172.16.0.1][54228] -> [..192.168.10.50][...80] + end: [...112] [ip4][..tcp] [.....172.16.0.1][54228] -> [..192.168.10.50][...80] guessed: [...113] [ip4][..tcp] [.....172.16.0.1][54242] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...113] [ip4][..tcp] [.....172.16.0.1][54242] -> [..192.168.10.50][...80] + end: [...113] [ip4][..tcp] [.....172.16.0.1][54242] -> [..192.168.10.50][...80] guessed: [...115] [ip4][..tcp] [.....172.16.0.1][54282] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...115] [ip4][..tcp] [.....172.16.0.1][54282] -> [..192.168.10.50][...80] + end: [...115] [ip4][..tcp] [.....172.16.0.1][54282] -> [..192.168.10.50][...80] guessed: [...116] [ip4][..tcp] [.....172.16.0.1][54296] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...116] [ip4][..tcp] [.....172.16.0.1][54296] -> [..192.168.10.50][...80] - new: [...192] [ip4][..tcp] [.....172.16.0.1][55672] -> [..192.168.10.50][...80] + end: [...116] [ip4][..tcp] [.....172.16.0.1][54296] -> [..192.168.10.50][...80] + new: [...192] [ip4][..tcp] [.....172.16.0.1][55672] -> [..192.168.10.50][...80] detected: [...190] [ip4][..tcp] [.....172.16.0.1][55632] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...193] [ip4][..tcp] [.....172.16.0.1][55686] -> [..192.168.10.50][...80] - new: [...194] [ip4][..tcp] [.....172.16.0.1][55700] -> [..192.168.10.50][...80] - new: [...195] [ip4][..tcp] [.....172.16.0.1][55726] -> [..192.168.10.50][...80] + new: [...193] [ip4][..tcp] [.....172.16.0.1][55686] -> [..192.168.10.50][...80] + new: [...194] [ip4][..tcp] [.....172.16.0.1][55700] -> [..192.168.10.50][...80] + new: [...195] [ip4][..tcp] [.....172.16.0.1][55726] -> [..192.168.10.50][...80] analyse: [...190] [ip4][..tcp] [.....172.16.0.1][55632] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.785| 0.602| 0.936| 875951.489| 3.700] @@ -516,129 +516,129 @@ [IATS(ms)....: 0.1,0.9,3784.1,3784.9,3.1,3.8,1004.0,1007.6,3.7,223.7,227.4,3.7,1007.8,1011.6,3.8,255.8,259.5,3.6,1007.9,1012.0,4.2,230.4,234.8,4.3,1037.5,1041.9,4.5,238.3,242.0,3.7,1009.9] [PKTLENS.....: 60,60,52,637,52,1921,52,435,1822,52,637,1920,52,435,1822,52,637,1921,52,435,1822,52,637,1920,52,435,1822,52,637,1920,52,435] [ENTROPIES...: 4.6,5.0,4.9,6.0,4.9,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.1,7.8,5.0,5.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9] - new: [...196] [ip4][..tcp] [.....172.16.0.1][55740] -> [..192.168.10.50][...80] + new: [...196] [ip4][..tcp] [.....172.16.0.1][55740] -> [..192.168.10.50][...80] guessed: [...117] [ip4][..tcp] [.....172.16.0.1][54322] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...117] [ip4][..tcp] [.....172.16.0.1][54322] -> [..192.168.10.50][...80] + end: [...117] [ip4][..tcp] [.....172.16.0.1][54322] -> [..192.168.10.50][...80] guessed: [...118] [ip4][..tcp] [.....172.16.0.1][54336] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...118] [ip4][..tcp] [.....172.16.0.1][54336] -> [..192.168.10.50][...80] + end: [...118] [ip4][..tcp] [.....172.16.0.1][54336] -> [..192.168.10.50][...80] guessed: [...119] [ip4][..tcp] [.....172.16.0.1][54362] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...119] [ip4][..tcp] [.....172.16.0.1][54362] -> [..192.168.10.50][...80] + end: [...119] [ip4][..tcp] [.....172.16.0.1][54362] -> [..192.168.10.50][...80] guessed: [...120] [ip4][..tcp] [.....172.16.0.1][54376] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...120] [ip4][..tcp] [.....172.16.0.1][54376] -> [..192.168.10.50][...80] + end: [...120] [ip4][..tcp] [.....172.16.0.1][54376] -> [..192.168.10.50][...80] guessed: [...121] [ip4][..tcp] [.....172.16.0.1][54390] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...121] [ip4][..tcp] [.....172.16.0.1][54390] -> [..192.168.10.50][...80] + end: [...121] [ip4][..tcp] [.....172.16.0.1][54390] -> [..192.168.10.50][...80] guessed: [...122] [ip4][..tcp] [.....172.16.0.1][54416] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...122] [ip4][..tcp] [.....172.16.0.1][54416] -> [..192.168.10.50][...80] + end: [...122] [ip4][..tcp] [.....172.16.0.1][54416] -> [..192.168.10.50][...80] guessed: [...123] [ip4][..tcp] [.....172.16.0.1][54430] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...123] [ip4][..tcp] [.....172.16.0.1][54430] -> [..192.168.10.50][...80] - new: [...197] [ip4][..tcp] [.....172.16.0.1][55766] -> [..192.168.10.50][...80] - new: [...198] [ip4][..tcp] [.....172.16.0.1][55780] -> [..192.168.10.50][...80] - new: [...199] [ip4][..tcp] [.....172.16.0.1][55794] -> [..192.168.10.50][...80] - new: [...200] [ip4][..tcp] [.....172.16.0.1][55820] -> [..192.168.10.50][...80] - new: [...201] [ip4][..tcp] [.....172.16.0.1][55834] -> [..192.168.10.50][...80] - new: [...202] [ip4][..tcp] [.....172.16.0.1][55860] -> [..192.168.10.50][...80] + end: [...123] [ip4][..tcp] [.....172.16.0.1][54430] -> [..192.168.10.50][...80] + new: [...197] [ip4][..tcp] [.....172.16.0.1][55766] -> [..192.168.10.50][...80] + new: [...198] [ip4][..tcp] [.....172.16.0.1][55780] -> [..192.168.10.50][...80] + new: [...199] [ip4][..tcp] [.....172.16.0.1][55794] -> [..192.168.10.50][...80] + new: [...200] [ip4][..tcp] [.....172.16.0.1][55820] -> [..192.168.10.50][...80] + new: [...201] [ip4][..tcp] [.....172.16.0.1][55834] -> [..192.168.10.50][...80] + new: [...202] [ip4][..tcp] [.....172.16.0.1][55860] -> [..192.168.10.50][...80] guessed: [...124] [ip4][..tcp] [.....172.16.0.1][54456] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...124] [ip4][..tcp] [.....172.16.0.1][54456] -> [..192.168.10.50][...80] + end: [...124] [ip4][..tcp] [.....172.16.0.1][54456] -> [..192.168.10.50][...80] guessed: [...125] [ip4][..tcp] [.....172.16.0.1][54470] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...125] [ip4][..tcp] [.....172.16.0.1][54470] -> [..192.168.10.50][...80] + end: [...125] [ip4][..tcp] [.....172.16.0.1][54470] -> [..192.168.10.50][...80] guessed: [...126] [ip4][..tcp] [.....172.16.0.1][54484] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...126] [ip4][..tcp] [.....172.16.0.1][54484] -> [..192.168.10.50][...80] + end: [...126] [ip4][..tcp] [.....172.16.0.1][54484] -> [..192.168.10.50][...80] guessed: [...127] [ip4][..tcp] [.....172.16.0.1][54510] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...127] [ip4][..tcp] [.....172.16.0.1][54510] -> [..192.168.10.50][...80] + end: [...127] [ip4][..tcp] [.....172.16.0.1][54510] -> [..192.168.10.50][...80] guessed: [...128] [ip4][..tcp] [.....172.16.0.1][54524] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...128] [ip4][..tcp] [.....172.16.0.1][54524] -> [..192.168.10.50][...80] - new: [...203] [ip4][..tcp] [.....172.16.0.1][55874] -> [..192.168.10.50][...80] - new: [...204] [ip4][..tcp] [.....172.16.0.1][55888] -> [..192.168.10.50][...80] - new: [...205] [ip4][..tcp] [.....172.16.0.1][55914] -> [..192.168.10.50][...80] - new: [...206] [ip4][..tcp] [.....172.16.0.1][55928] -> [..192.168.10.50][...80] - new: [...207] [ip4][..tcp] [.....172.16.0.1][55942] -> [..192.168.10.50][...80] - new: [...208] [ip4][..tcp] [.....172.16.0.1][55968] -> [..192.168.10.50][...80] + end: [...128] [ip4][..tcp] [.....172.16.0.1][54524] -> [..192.168.10.50][...80] + new: [...203] [ip4][..tcp] [.....172.16.0.1][55874] -> [..192.168.10.50][...80] + new: [...204] [ip4][..tcp] [.....172.16.0.1][55888] -> [..192.168.10.50][...80] + new: [...205] [ip4][..tcp] [.....172.16.0.1][55914] -> [..192.168.10.50][...80] + new: [...206] [ip4][..tcp] [.....172.16.0.1][55928] -> [..192.168.10.50][...80] + new: [...207] [ip4][..tcp] [.....172.16.0.1][55942] -> [..192.168.10.50][...80] + new: [...208] [ip4][..tcp] [.....172.16.0.1][55968] -> [..192.168.10.50][...80] guessed: [...129] [ip4][..tcp] [.....172.16.0.1][54538] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...129] [ip4][..tcp] [.....172.16.0.1][54538] -> [..192.168.10.50][...80] + end: [...129] [ip4][..tcp] [.....172.16.0.1][54538] -> [..192.168.10.50][...80] guessed: [...130] [ip4][..tcp] [.....172.16.0.1][54552] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...130] [ip4][..tcp] [.....172.16.0.1][54552] -> [..192.168.10.50][...80] + end: [...130] [ip4][..tcp] [.....172.16.0.1][54552] -> [..192.168.10.50][...80] guessed: [...131] [ip4][..tcp] [.....172.16.0.1][54566] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...131] [ip4][..tcp] [.....172.16.0.1][54566] -> [..192.168.10.50][...80] + end: [...131] [ip4][..tcp] [.....172.16.0.1][54566] -> [..192.168.10.50][...80] guessed: [...132] [ip4][..tcp] [.....172.16.0.1][54580] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...132] [ip4][..tcp] [.....172.16.0.1][54580] -> [..192.168.10.50][...80] + end: [...132] [ip4][..tcp] [.....172.16.0.1][54580] -> [..192.168.10.50][...80] guessed: [...133] [ip4][..tcp] [.....172.16.0.1][54606] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...133] [ip4][..tcp] [.....172.16.0.1][54606] -> [..192.168.10.50][...80] + end: [...133] [ip4][..tcp] [.....172.16.0.1][54606] -> [..192.168.10.50][...80] guessed: [...134] [ip4][..tcp] [.....172.16.0.1][54620] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...134] [ip4][..tcp] [.....172.16.0.1][54620] -> [..192.168.10.50][...80] + end: [...134] [ip4][..tcp] [.....172.16.0.1][54620] -> [..192.168.10.50][...80] guessed: [...135] [ip4][..tcp] [.....172.16.0.1][54634] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...135] [ip4][..tcp] [.....172.16.0.1][54634] -> [..192.168.10.50][...80] - new: [...209] [ip4][..tcp] [.....172.16.0.1][55982] -> [..192.168.10.50][...80] - new: [...210] [ip4][..tcp] [.....172.16.0.1][55996] -> [..192.168.10.50][...80] - new: [...211] [ip4][..tcp] [.....172.16.0.1][56022] -> [..192.168.10.50][...80] - new: [...212] [ip4][..tcp] [.....172.16.0.1][56036] -> [..192.168.10.50][...80] - new: [...213] [ip4][..tcp] [.....172.16.0.1][56062] -> [..192.168.10.50][...80] - new: [...214] [ip4][..tcp] [.....172.16.0.1][56076] -> [..192.168.10.50][...80] + end: [...135] [ip4][..tcp] [.....172.16.0.1][54634] -> [..192.168.10.50][...80] + new: [...209] [ip4][..tcp] [.....172.16.0.1][55982] -> [..192.168.10.50][...80] + new: [...210] [ip4][..tcp] [.....172.16.0.1][55996] -> [..192.168.10.50][...80] + new: [...211] [ip4][..tcp] [.....172.16.0.1][56022] -> [..192.168.10.50][...80] + new: [...212] [ip4][..tcp] [.....172.16.0.1][56036] -> [..192.168.10.50][...80] + new: [...213] [ip4][..tcp] [.....172.16.0.1][56062] -> [..192.168.10.50][...80] + new: [...214] [ip4][..tcp] [.....172.16.0.1][56076] -> [..192.168.10.50][...80] guessed: [...136] [ip4][..tcp] [.....172.16.0.1][54660] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...136] [ip4][..tcp] [.....172.16.0.1][54660] -> [..192.168.10.50][...80] + end: [...136] [ip4][..tcp] [.....172.16.0.1][54660] -> [..192.168.10.50][...80] guessed: [...137] [ip4][..tcp] [.....172.16.0.1][54674] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...137] [ip4][..tcp] [.....172.16.0.1][54674] -> [..192.168.10.50][...80] + end: [...137] [ip4][..tcp] [.....172.16.0.1][54674] -> [..192.168.10.50][...80] guessed: [...138] [ip4][..tcp] [.....172.16.0.1][54688] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...138] [ip4][..tcp] [.....172.16.0.1][54688] -> [..192.168.10.50][...80] + end: [...138] [ip4][..tcp] [.....172.16.0.1][54688] -> [..192.168.10.50][...80] guessed: [...139] [ip4][..tcp] [.....172.16.0.1][54714] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...139] [ip4][..tcp] [.....172.16.0.1][54714] -> [..192.168.10.50][...80] + end: [...139] [ip4][..tcp] [.....172.16.0.1][54714] -> [..192.168.10.50][...80] guessed: [...140] [ip4][..tcp] [.....172.16.0.1][54728] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...140] [ip4][..tcp] [.....172.16.0.1][54728] -> [..192.168.10.50][...80] + end: [...140] [ip4][..tcp] [.....172.16.0.1][54728] -> [..192.168.10.50][...80] guessed: [...141] [ip4][..tcp] [.....172.16.0.1][54742] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...141] [ip4][..tcp] [.....172.16.0.1][54742] -> [..192.168.10.50][...80] - new: [...215] [ip4][..tcp] [.....172.16.0.1][56090] -> [..192.168.10.50][...80] - new: [...216] [ip4][..tcp] [.....172.16.0.1][56116] -> [..192.168.10.50][...80] - new: [...217] [ip4][..tcp] [.....172.16.0.1][56130] -> [..192.168.10.50][...80] - new: [...218] [ip4][..tcp] [.....172.16.0.1][56144] -> [..192.168.10.50][...80] - new: [...219] [ip4][..tcp] [.....172.16.0.1][56158] -> [..192.168.10.50][...80] - new: [...220] [ip4][..tcp] [.....172.16.0.1][56172] -> [..192.168.10.50][...80] - new: [...221] [ip4][..tcp] [.....172.16.0.1][56186] -> [..192.168.10.50][...80] + end: [...141] [ip4][..tcp] [.....172.16.0.1][54742] -> [..192.168.10.50][...80] + new: [...215] [ip4][..tcp] [.....172.16.0.1][56090] -> [..192.168.10.50][...80] + new: [...216] [ip4][..tcp] [.....172.16.0.1][56116] -> [..192.168.10.50][...80] + new: [...217] [ip4][..tcp] [.....172.16.0.1][56130] -> [..192.168.10.50][...80] + new: [...218] [ip4][..tcp] [.....172.16.0.1][56144] -> [..192.168.10.50][...80] + new: [...219] [ip4][..tcp] [.....172.16.0.1][56158] -> [..192.168.10.50][...80] + new: [...220] [ip4][..tcp] [.....172.16.0.1][56172] -> [..192.168.10.50][...80] + new: [...221] [ip4][..tcp] [.....172.16.0.1][56186] -> [..192.168.10.50][...80] guessed: [...142] [ip4][..tcp] [.....172.16.0.1][54768] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...142] [ip4][..tcp] [.....172.16.0.1][54768] -> [..192.168.10.50][...80] + end: [...142] [ip4][..tcp] [.....172.16.0.1][54768] -> [..192.168.10.50][...80] guessed: [...143] [ip4][..tcp] [.....172.16.0.1][54782] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...143] [ip4][..tcp] [.....172.16.0.1][54782] -> [..192.168.10.50][...80] + end: [...143] [ip4][..tcp] [.....172.16.0.1][54782] -> [..192.168.10.50][...80] guessed: [...144] [ip4][..tcp] [.....172.16.0.1][54808] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...144] [ip4][..tcp] [.....172.16.0.1][54808] -> [..192.168.10.50][...80] + end: [...144] [ip4][..tcp] [.....172.16.0.1][54808] -> [..192.168.10.50][...80] guessed: [...145] [ip4][..tcp] [.....172.16.0.1][54822] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...145] [ip4][..tcp] [.....172.16.0.1][54822] -> [..192.168.10.50][...80] + end: [...145] [ip4][..tcp] [.....172.16.0.1][54822] -> [..192.168.10.50][...80] guessed: [...146] [ip4][..tcp] [.....172.16.0.1][54836] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...146] [ip4][..tcp] [.....172.16.0.1][54836] -> [..192.168.10.50][...80] - new: [...222] [ip4][..tcp] [.....172.16.0.1][56212] -> [..192.168.10.50][...80] - new: [...223] [ip4][..tcp] [.....172.16.0.1][56226] -> [..192.168.10.50][...80] - new: [...224] [ip4][..tcp] [.....172.16.0.1][56240] -> [..192.168.10.50][...80] - new: [...225] [ip4][..tcp] [.....172.16.0.1][56266] -> [..192.168.10.50][...80] - new: [...226] [ip4][..tcp] [.....172.16.0.1][56280] -> [..192.168.10.50][...80] + end: [...146] [ip4][..tcp] [.....172.16.0.1][54836] -> [..192.168.10.50][...80] + new: [...222] [ip4][..tcp] [.....172.16.0.1][56212] -> [..192.168.10.50][...80] + new: [...223] [ip4][..tcp] [.....172.16.0.1][56226] -> [..192.168.10.50][...80] + new: [...224] [ip4][..tcp] [.....172.16.0.1][56240] -> [..192.168.10.50][...80] + new: [...225] [ip4][..tcp] [.....172.16.0.1][56266] -> [..192.168.10.50][...80] + new: [...226] [ip4][..tcp] [.....172.16.0.1][56280] -> [..192.168.10.50][...80] guessed: [...147] [ip4][..tcp] [.....172.16.0.1][54862] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...147] [ip4][..tcp] [.....172.16.0.1][54862] -> [..192.168.10.50][...80] + end: [...147] [ip4][..tcp] [.....172.16.0.1][54862] -> [..192.168.10.50][...80] guessed: [...148] [ip4][..tcp] [.....172.16.0.1][54876] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...148] [ip4][..tcp] [.....172.16.0.1][54876] -> [..192.168.10.50][...80] + end: [...148] [ip4][..tcp] [.....172.16.0.1][54876] -> [..192.168.10.50][...80] guessed: [...149] [ip4][..tcp] [.....172.16.0.1][54890] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...149] [ip4][..tcp] [.....172.16.0.1][54890] -> [..192.168.10.50][...80] + end: [...149] [ip4][..tcp] [.....172.16.0.1][54890] -> [..192.168.10.50][...80] guessed: [...150] [ip4][..tcp] [.....172.16.0.1][54916] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...150] [ip4][..tcp] [.....172.16.0.1][54916] -> [..192.168.10.50][...80] + end: [...150] [ip4][..tcp] [.....172.16.0.1][54916] -> [..192.168.10.50][...80] guessed: [...151] [ip4][..tcp] [.....172.16.0.1][54930] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...151] [ip4][..tcp] [.....172.16.0.1][54930] -> [..192.168.10.50][...80] + end: [...151] [ip4][..tcp] [.....172.16.0.1][54930] -> [..192.168.10.50][...80] end: [...114] [ip4][..tcp] [.....172.16.0.1][54268] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...227] [ip4][..tcp] [.....172.16.0.1][56306] -> [..192.168.10.50][...80] - new: [...228] [ip4][..tcp] [.....172.16.0.1][56320] -> [..192.168.10.50][...80] - new: [...229] [ip4][..tcp] [.....172.16.0.1][56334] -> [..192.168.10.50][...80] + new: [...227] [ip4][..tcp] [.....172.16.0.1][56306] -> [..192.168.10.50][...80] + new: [...228] [ip4][..tcp] [.....172.16.0.1][56320] -> [..192.168.10.50][...80] + new: [...229] [ip4][..tcp] [.....172.16.0.1][56334] -> [..192.168.10.50][...80] detected: [...227] [ip4][..tcp] [.....172.16.0.1][56306] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...230] [ip4][..tcp] [.....172.16.0.1][56360] -> [..192.168.10.50][...80] - new: [...231] [ip4][..tcp] [.....172.16.0.1][56374] -> [..192.168.10.50][...80] - new: [...232] [ip4][..tcp] [.....172.16.0.1][56400] -> [..192.168.10.50][...80] + new: [...230] [ip4][..tcp] [.....172.16.0.1][56360] -> [..192.168.10.50][...80] + new: [...231] [ip4][..tcp] [.....172.16.0.1][56374] -> [..192.168.10.50][...80] + new: [...232] [ip4][..tcp] [.....172.16.0.1][56400] -> [..192.168.10.50][...80] guessed: [...153] [ip4][..tcp] [.....172.16.0.1][54970] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...153] [ip4][..tcp] [.....172.16.0.1][54970] -> [..192.168.10.50][...80] + end: [...153] [ip4][..tcp] [.....172.16.0.1][54970] -> [..192.168.10.50][...80] guessed: [...154] [ip4][..tcp] [.....172.16.0.1][54984] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...154] [ip4][..tcp] [.....172.16.0.1][54984] -> [..192.168.10.50][...80] + end: [...154] [ip4][..tcp] [.....172.16.0.1][54984] -> [..192.168.10.50][...80] guessed: [...155] [ip4][..tcp] [.....172.16.0.1][55010] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...155] [ip4][..tcp] [.....172.16.0.1][55010] -> [..192.168.10.50][...80] + end: [...155] [ip4][..tcp] [.....172.16.0.1][55010] -> [..192.168.10.50][...80] guessed: [...156] [ip4][..tcp] [.....172.16.0.1][55024] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...156] [ip4][..tcp] [.....172.16.0.1][55024] -> [..192.168.10.50][...80] + end: [...156] [ip4][..tcp] [.....172.16.0.1][55024] -> [..192.168.10.50][...80] guessed: [...157] [ip4][..tcp] [.....172.16.0.1][55038] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...157] [ip4][..tcp] [.....172.16.0.1][55038] -> [..192.168.10.50][...80] + end: [...157] [ip4][..tcp] [.....172.16.0.1][55038] -> [..192.168.10.50][...80] guessed: [...158] [ip4][..tcp] [.....172.16.0.1][55064] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...158] [ip4][..tcp] [.....172.16.0.1][55064] -> [..192.168.10.50][...80] + end: [...158] [ip4][..tcp] [.....172.16.0.1][55064] -> [..192.168.10.50][...80] analyse: [...227] [ip4][..tcp] [.....172.16.0.1][56306] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.805| 0.635| 1.170| 1368332.173| 3.400] @@ -649,119 +649,119 @@ [IATS(ms)....: 0.1,0.7,4804.7,4805.4,3.1,3.8,248.6,252.2,3.7,1022.4,1026.2,3.8,225.2,229.2,0.0,4.0,1026.8,1030.9,4.2,232.5,236.2,0.1,3.6,1006.0,1010.7,4.8,233.2,236.8,3.6,1008.0,1011.7] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1920,52,435,1822,52,637,1500,472,52,435,1822,52,637,1500,472,52,435,1822,52,637,1920,52,435,1822] [ENTROPIES...: 4.6,5.1,5.0,5.9,4.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.7,7.5,4.8,5.9,7.7,5.0,6.0,7.7,7.6,5.0,5.9,7.7,5.0,6.0,7.7,4.9,5.9,7.7] - new: [...233] [ip4][..tcp] [.....172.16.0.1][56414] -> [..192.168.10.50][...80] - new: [...234] [ip4][..tcp] [.....172.16.0.1][56428] -> [..192.168.10.50][...80] - new: [...235] [ip4][..tcp] [.....172.16.0.1][56454] -> [..192.168.10.50][...80] - new: [...236] [ip4][..tcp] [.....172.16.0.1][56468] -> [..192.168.10.50][...80] - new: [...237] [ip4][..tcp] [.....172.16.0.1][56482] -> [..192.168.10.50][...80] - new: [...238] [ip4][..tcp] [.....172.16.0.1][56508] -> [..192.168.10.50][...80] + new: [...233] [ip4][..tcp] [.....172.16.0.1][56414] -> [..192.168.10.50][...80] + new: [...234] [ip4][..tcp] [.....172.16.0.1][56428] -> [..192.168.10.50][...80] + new: [...235] [ip4][..tcp] [.....172.16.0.1][56454] -> [..192.168.10.50][...80] + new: [...236] [ip4][..tcp] [.....172.16.0.1][56468] -> [..192.168.10.50][...80] + new: [...237] [ip4][..tcp] [.....172.16.0.1][56482] -> [..192.168.10.50][...80] + new: [...238] [ip4][..tcp] [.....172.16.0.1][56508] -> [..192.168.10.50][...80] guessed: [...159] [ip4][..tcp] [.....172.16.0.1][55078] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...159] [ip4][..tcp] [.....172.16.0.1][55078] -> [..192.168.10.50][...80] + end: [...159] [ip4][..tcp] [.....172.16.0.1][55078] -> [..192.168.10.50][...80] guessed: [...160] [ip4][..tcp] [.....172.16.0.1][55092] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...160] [ip4][..tcp] [.....172.16.0.1][55092] -> [..192.168.10.50][...80] + end: [...160] [ip4][..tcp] [.....172.16.0.1][55092] -> [..192.168.10.50][...80] guessed: [...161] [ip4][..tcp] [.....172.16.0.1][55118] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...161] [ip4][..tcp] [.....172.16.0.1][55118] -> [..192.168.10.50][...80] + end: [...161] [ip4][..tcp] [.....172.16.0.1][55118] -> [..192.168.10.50][...80] guessed: [...162] [ip4][..tcp] [.....172.16.0.1][55132] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...162] [ip4][..tcp] [.....172.16.0.1][55132] -> [..192.168.10.50][...80] + end: [...162] [ip4][..tcp] [.....172.16.0.1][55132] -> [..192.168.10.50][...80] guessed: [...163] [ip4][..tcp] [.....172.16.0.1][55158] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...163] [ip4][..tcp] [.....172.16.0.1][55158] -> [..192.168.10.50][...80] + end: [...163] [ip4][..tcp] [.....172.16.0.1][55158] -> [..192.168.10.50][...80] guessed: [...164] [ip4][..tcp] [.....172.16.0.1][55172] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...164] [ip4][..tcp] [.....172.16.0.1][55172] -> [..192.168.10.50][...80] + end: [...164] [ip4][..tcp] [.....172.16.0.1][55172] -> [..192.168.10.50][...80] guessed: [...165] [ip4][..tcp] [.....172.16.0.1][55186] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...165] [ip4][..tcp] [.....172.16.0.1][55186] -> [..192.168.10.50][...80] - new: [...239] [ip4][..tcp] [.....172.16.0.1][56522] -> [..192.168.10.50][...80] - new: [...240] [ip4][..tcp] [.....172.16.0.1][56536] -> [..192.168.10.50][...80] - new: [...241] [ip4][..tcp] [.....172.16.0.1][56562] -> [..192.168.10.50][...80] - new: [...242] [ip4][..tcp] [.....172.16.0.1][56576] -> [..192.168.10.50][...80] - new: [...243] [ip4][..tcp] [.....172.16.0.1][56590] -> [..192.168.10.50][...80] - new: [...244] [ip4][..tcp] [.....172.16.0.1][56616] -> [..192.168.10.50][...80] + end: [...165] [ip4][..tcp] [.....172.16.0.1][55186] -> [..192.168.10.50][...80] + new: [...239] [ip4][..tcp] [.....172.16.0.1][56522] -> [..192.168.10.50][...80] + new: [...240] [ip4][..tcp] [.....172.16.0.1][56536] -> [..192.168.10.50][...80] + new: [...241] [ip4][..tcp] [.....172.16.0.1][56562] -> [..192.168.10.50][...80] + new: [...242] [ip4][..tcp] [.....172.16.0.1][56576] -> [..192.168.10.50][...80] + new: [...243] [ip4][..tcp] [.....172.16.0.1][56590] -> [..192.168.10.50][...80] + new: [...244] [ip4][..tcp] [.....172.16.0.1][56616] -> [..192.168.10.50][...80] guessed: [...166] [ip4][..tcp] [.....172.16.0.1][55212] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...166] [ip4][..tcp] [.....172.16.0.1][55212] -> [..192.168.10.50][...80] + end: [...166] [ip4][..tcp] [.....172.16.0.1][55212] -> [..192.168.10.50][...80] guessed: [...167] [ip4][..tcp] [.....172.16.0.1][55226] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...167] [ip4][..tcp] [.....172.16.0.1][55226] -> [..192.168.10.50][...80] + end: [...167] [ip4][..tcp] [.....172.16.0.1][55226] -> [..192.168.10.50][...80] guessed: [...168] [ip4][..tcp] [.....172.16.0.1][55240] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...168] [ip4][..tcp] [.....172.16.0.1][55240] -> [..192.168.10.50][...80] + end: [...168] [ip4][..tcp] [.....172.16.0.1][55240] -> [..192.168.10.50][...80] guessed: [...169] [ip4][..tcp] [.....172.16.0.1][55266] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...169] [ip4][..tcp] [.....172.16.0.1][55266] -> [..192.168.10.50][...80] + end: [...169] [ip4][..tcp] [.....172.16.0.1][55266] -> [..192.168.10.50][...80] guessed: [...170] [ip4][..tcp] [.....172.16.0.1][55280] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...170] [ip4][..tcp] [.....172.16.0.1][55280] -> [..192.168.10.50][...80] - new: [...245] [ip4][..tcp] [.....172.16.0.1][56630] -> [..192.168.10.50][...80] - new: [...246] [ip4][..tcp] [.....172.16.0.1][56644] -> [..192.168.10.50][...80] - new: [...247] [ip4][..tcp] [.....172.16.0.1][56670] -> [..192.168.10.50][...80] - new: [...248] [ip4][..tcp] [.....172.16.0.1][56684] -> [..192.168.10.50][...80] - new: [...249] [ip4][..tcp] [.....172.16.0.1][56710] -> [..192.168.10.50][...80] - new: [...250] [ip4][..tcp] [.....172.16.0.1][56724] -> [..192.168.10.50][...80] + end: [...170] [ip4][..tcp] [.....172.16.0.1][55280] -> [..192.168.10.50][...80] + new: [...245] [ip4][..tcp] [.....172.16.0.1][56630] -> [..192.168.10.50][...80] + new: [...246] [ip4][..tcp] [.....172.16.0.1][56644] -> [..192.168.10.50][...80] + new: [...247] [ip4][..tcp] [.....172.16.0.1][56670] -> [..192.168.10.50][...80] + new: [...248] [ip4][..tcp] [.....172.16.0.1][56684] -> [..192.168.10.50][...80] + new: [...249] [ip4][..tcp] [.....172.16.0.1][56710] -> [..192.168.10.50][...80] + new: [...250] [ip4][..tcp] [.....172.16.0.1][56724] -> [..192.168.10.50][...80] guessed: [...171] [ip4][..tcp] [.....172.16.0.1][55294] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...171] [ip4][..tcp] [.....172.16.0.1][55294] -> [..192.168.10.50][...80] + end: [...171] [ip4][..tcp] [.....172.16.0.1][55294] -> [..192.168.10.50][...80] guessed: [...172] [ip4][..tcp] [.....172.16.0.1][55320] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...172] [ip4][..tcp] [.....172.16.0.1][55320] -> [..192.168.10.50][...80] + end: [...172] [ip4][..tcp] [.....172.16.0.1][55320] -> [..192.168.10.50][...80] guessed: [...173] [ip4][..tcp] [.....172.16.0.1][55334] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...173] [ip4][..tcp] [.....172.16.0.1][55334] -> [..192.168.10.50][...80] + end: [...173] [ip4][..tcp] [.....172.16.0.1][55334] -> [..192.168.10.50][...80] guessed: [...174] [ip4][..tcp] [.....172.16.0.1][55348] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...174] [ip4][..tcp] [.....172.16.0.1][55348] -> [..192.168.10.50][...80] + end: [...174] [ip4][..tcp] [.....172.16.0.1][55348] -> [..192.168.10.50][...80] guessed: [...175] [ip4][..tcp] [.....172.16.0.1][55362] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...175] [ip4][..tcp] [.....172.16.0.1][55362] -> [..192.168.10.50][...80] + end: [...175] [ip4][..tcp] [.....172.16.0.1][55362] -> [..192.168.10.50][...80] guessed: [...176] [ip4][..tcp] [.....172.16.0.1][55376] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...176] [ip4][..tcp] [.....172.16.0.1][55376] -> [..192.168.10.50][...80] + end: [...176] [ip4][..tcp] [.....172.16.0.1][55376] -> [..192.168.10.50][...80] guessed: [...177] [ip4][..tcp] [.....172.16.0.1][55390] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...177] [ip4][..tcp] [.....172.16.0.1][55390] -> [..192.168.10.50][...80] - new: [...251] [ip4][..tcp] [.....172.16.0.1][56738] -> [..192.168.10.50][...80] - new: [...252] [ip4][..tcp] [.....172.16.0.1][56764] -> [..192.168.10.50][...80] - new: [...253] [ip4][..tcp] [.....172.16.0.1][56778] -> [..192.168.10.50][...80] - new: [...254] [ip4][..tcp] [.....172.16.0.1][56792] -> [..192.168.10.50][...80] - new: [...255] [ip4][..tcp] [.....172.16.0.1][56818] -> [..192.168.10.50][...80] - new: [...256] [ip4][..tcp] [.....172.16.0.1][56832] -> [..192.168.10.50][...80] + end: [...177] [ip4][..tcp] [.....172.16.0.1][55390] -> [..192.168.10.50][...80] + new: [...251] [ip4][..tcp] [.....172.16.0.1][56738] -> [..192.168.10.50][...80] + new: [...252] [ip4][..tcp] [.....172.16.0.1][56764] -> [..192.168.10.50][...80] + new: [...253] [ip4][..tcp] [.....172.16.0.1][56778] -> [..192.168.10.50][...80] + new: [...254] [ip4][..tcp] [.....172.16.0.1][56792] -> [..192.168.10.50][...80] + new: [...255] [ip4][..tcp] [.....172.16.0.1][56818] -> [..192.168.10.50][...80] + new: [...256] [ip4][..tcp] [.....172.16.0.1][56832] -> [..192.168.10.50][...80] guessed: [...178] [ip4][..tcp] [.....172.16.0.1][55416] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...178] [ip4][..tcp] [.....172.16.0.1][55416] -> [..192.168.10.50][...80] + end: [...178] [ip4][..tcp] [.....172.16.0.1][55416] -> [..192.168.10.50][...80] guessed: [...179] [ip4][..tcp] [.....172.16.0.1][55430] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...179] [ip4][..tcp] [.....172.16.0.1][55430] -> [..192.168.10.50][...80] + end: [...179] [ip4][..tcp] [.....172.16.0.1][55430] -> [..192.168.10.50][...80] guessed: [...180] [ip4][..tcp] [.....172.16.0.1][55444] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...180] [ip4][..tcp] [.....172.16.0.1][55444] -> [..192.168.10.50][...80] + end: [...180] [ip4][..tcp] [.....172.16.0.1][55444] -> [..192.168.10.50][...80] guessed: [...181] [ip4][..tcp] [.....172.16.0.1][55470] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...181] [ip4][..tcp] [.....172.16.0.1][55470] -> [..192.168.10.50][...80] + end: [...181] [ip4][..tcp] [.....172.16.0.1][55470] -> [..192.168.10.50][...80] guessed: [...182] [ip4][..tcp] [.....172.16.0.1][55484] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...182] [ip4][..tcp] [.....172.16.0.1][55484] -> [..192.168.10.50][...80] - new: [...257] [ip4][..tcp] [.....172.16.0.1][56858] -> [..192.168.10.50][...80] - new: [...258] [ip4][..tcp] [.....172.16.0.1][56872] -> [..192.168.10.50][...80] - new: [...259] [ip4][..tcp] [.....172.16.0.1][56886] -> [..192.168.10.50][...80] - new: [...260] [ip4][..tcp] [.....172.16.0.1][56912] -> [..192.168.10.50][...80] - new: [...261] [ip4][..tcp] [.....172.16.0.1][56926] -> [..192.168.10.50][...80] - new: [...262] [ip4][..tcp] [.....172.16.0.1][56940] -> [..192.168.10.50][...80] + end: [...182] [ip4][..tcp] [.....172.16.0.1][55484] -> [..192.168.10.50][...80] + new: [...257] [ip4][..tcp] [.....172.16.0.1][56858] -> [..192.168.10.50][...80] + new: [...258] [ip4][..tcp] [.....172.16.0.1][56872] -> [..192.168.10.50][...80] + new: [...259] [ip4][..tcp] [.....172.16.0.1][56886] -> [..192.168.10.50][...80] + new: [...260] [ip4][..tcp] [.....172.16.0.1][56912] -> [..192.168.10.50][...80] + new: [...261] [ip4][..tcp] [.....172.16.0.1][56926] -> [..192.168.10.50][...80] + new: [...262] [ip4][..tcp] [.....172.16.0.1][56940] -> [..192.168.10.50][...80] guessed: [...183] [ip4][..tcp] [.....172.16.0.1][55510] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...183] [ip4][..tcp] [.....172.16.0.1][55510] -> [..192.168.10.50][...80] + end: [...183] [ip4][..tcp] [.....172.16.0.1][55510] -> [..192.168.10.50][...80] guessed: [...184] [ip4][..tcp] [.....172.16.0.1][55524] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...184] [ip4][..tcp] [.....172.16.0.1][55524] -> [..192.168.10.50][...80] + end: [...184] [ip4][..tcp] [.....172.16.0.1][55524] -> [..192.168.10.50][...80] guessed: [...185] [ip4][..tcp] [.....172.16.0.1][55538] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...185] [ip4][..tcp] [.....172.16.0.1][55538] -> [..192.168.10.50][...80] + end: [...185] [ip4][..tcp] [.....172.16.0.1][55538] -> [..192.168.10.50][...80] guessed: [...186] [ip4][..tcp] [.....172.16.0.1][55564] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...186] [ip4][..tcp] [.....172.16.0.1][55564] -> [..192.168.10.50][...80] + end: [...186] [ip4][..tcp] [.....172.16.0.1][55564] -> [..192.168.10.50][...80] guessed: [...187] [ip4][..tcp] [.....172.16.0.1][55578] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...187] [ip4][..tcp] [.....172.16.0.1][55578] -> [..192.168.10.50][...80] + end: [...187] [ip4][..tcp] [.....172.16.0.1][55578] -> [..192.168.10.50][...80] guessed: [...188] [ip4][..tcp] [.....172.16.0.1][55592] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...188] [ip4][..tcp] [.....172.16.0.1][55592] -> [..192.168.10.50][...80] - new: [...263] [ip4][..tcp] [.....172.16.0.1][56966] -> [..192.168.10.50][...80] - new: [...264] [ip4][..tcp] [.....172.16.0.1][56980] -> [..192.168.10.50][...80] - new: [...265] [ip4][..tcp] [.....172.16.0.1][56994] -> [..192.168.10.50][...80] - new: [...266] [ip4][..tcp] [.....172.16.0.1][57008] -> [..192.168.10.50][...80] - new: [...267] [ip4][..tcp] [.....172.16.0.1][57022] -> [..192.168.10.50][...80] - new: [...268] [ip4][..tcp] [.....172.16.0.1][57036] -> [..192.168.10.50][...80] + end: [...188] [ip4][..tcp] [.....172.16.0.1][55592] -> [..192.168.10.50][...80] + new: [...263] [ip4][..tcp] [.....172.16.0.1][56966] -> [..192.168.10.50][...80] + new: [...264] [ip4][..tcp] [.....172.16.0.1][56980] -> [..192.168.10.50][...80] + new: [...265] [ip4][..tcp] [.....172.16.0.1][56994] -> [..192.168.10.50][...80] + new: [...266] [ip4][..tcp] [.....172.16.0.1][57008] -> [..192.168.10.50][...80] + new: [...267] [ip4][..tcp] [.....172.16.0.1][57022] -> [..192.168.10.50][...80] + new: [...268] [ip4][..tcp] [.....172.16.0.1][57036] -> [..192.168.10.50][...80] detected: [...265] [ip4][..tcp] [.....172.16.0.1][56994] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header end: [...152] [ip4][..tcp] [.....172.16.0.1][54956] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...189] [ip4][..tcp] [.....172.16.0.1][55618] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...189] [ip4][..tcp] [.....172.16.0.1][55618] -> [..192.168.10.50][...80] + end: [...189] [ip4][..tcp] [.....172.16.0.1][55618] -> [..192.168.10.50][...80] guessed: [...191] [ip4][..tcp] [.....172.16.0.1][55646] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...191] [ip4][..tcp] [.....172.16.0.1][55646] -> [..192.168.10.50][...80] + end: [...191] [ip4][..tcp] [.....172.16.0.1][55646] -> [..192.168.10.50][...80] guessed: [...192] [ip4][..tcp] [.....172.16.0.1][55672] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...192] [ip4][..tcp] [.....172.16.0.1][55672] -> [..192.168.10.50][...80] + end: [...192] [ip4][..tcp] [.....172.16.0.1][55672] -> [..192.168.10.50][...80] guessed: [...193] [ip4][..tcp] [.....172.16.0.1][55686] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...193] [ip4][..tcp] [.....172.16.0.1][55686] -> [..192.168.10.50][...80] + end: [...193] [ip4][..tcp] [.....172.16.0.1][55686] -> [..192.168.10.50][...80] guessed: [...194] [ip4][..tcp] [.....172.16.0.1][55700] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...194] [ip4][..tcp] [.....172.16.0.1][55700] -> [..192.168.10.50][...80] - new: [...269] [ip4][..tcp] [.....172.16.0.1][57062] -> [..192.168.10.50][...80] - new: [...270] [ip4][..tcp] [.....172.16.0.1][57076] -> [..192.168.10.50][...80] - new: [...271] [ip4][..tcp] [.....172.16.0.1][57090] -> [..192.168.10.50][...80] + end: [...194] [ip4][..tcp] [.....172.16.0.1][55700] -> [..192.168.10.50][...80] + new: [...269] [ip4][..tcp] [.....172.16.0.1][57062] -> [..192.168.10.50][...80] + new: [...270] [ip4][..tcp] [.....172.16.0.1][57076] -> [..192.168.10.50][...80] + new: [...271] [ip4][..tcp] [.....172.16.0.1][57090] -> [..192.168.10.50][...80] analyse: [...265] [ip4][..tcp] [.....172.16.0.1][56994] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.819| 0.606| 0.944| 891595.915| 3.700] @@ -772,118 +772,118 @@ [IATS(ms)....: 0.1,0.9,3818.1,3819.0,2.9,3.6,1026.8,1031.2,4.4,231.9,235.6,3.8,1007.0,1010.7,3.8,236.2,239.9,3.6,1008.9,1012.8,4.2,228.6,232.8,4.0,1040.9,1048.3,7.4,251.6,255.2,3.6,1017.7] [PKTLENS.....: 60,60,52,637,52,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1920,52,435,1822,52,637,1918,52,435] [ENTROPIES...: 4.6,5.0,4.9,6.0,4.9,7.8,5.0,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.0,7.8,4.9,5.9] - new: [...272] [ip4][..tcp] [.....172.16.0.1][57116] -> [..192.168.10.50][...80] - new: [...273] [ip4][..tcp] [.....172.16.0.1][57130] -> [..192.168.10.50][...80] - new: [...274] [ip4][..tcp] [.....172.16.0.1][57144] -> [..192.168.10.50][...80] + new: [...272] [ip4][..tcp] [.....172.16.0.1][57116] -> [..192.168.10.50][...80] + new: [...273] [ip4][..tcp] [.....172.16.0.1][57130] -> [..192.168.10.50][...80] + new: [...274] [ip4][..tcp] [.....172.16.0.1][57144] -> [..192.168.10.50][...80] guessed: [...195] [ip4][..tcp] [.....172.16.0.1][55726] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...195] [ip4][..tcp] [.....172.16.0.1][55726] -> [..192.168.10.50][...80] + end: [...195] [ip4][..tcp] [.....172.16.0.1][55726] -> [..192.168.10.50][...80] guessed: [...196] [ip4][..tcp] [.....172.16.0.1][55740] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...196] [ip4][..tcp] [.....172.16.0.1][55740] -> [..192.168.10.50][...80] + end: [...196] [ip4][..tcp] [.....172.16.0.1][55740] -> [..192.168.10.50][...80] guessed: [...197] [ip4][..tcp] [.....172.16.0.1][55766] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...197] [ip4][..tcp] [.....172.16.0.1][55766] -> [..192.168.10.50][...80] + end: [...197] [ip4][..tcp] [.....172.16.0.1][55766] -> [..192.168.10.50][...80] guessed: [...198] [ip4][..tcp] [.....172.16.0.1][55780] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...198] [ip4][..tcp] [.....172.16.0.1][55780] -> [..192.168.10.50][...80] + end: [...198] [ip4][..tcp] [.....172.16.0.1][55780] -> [..192.168.10.50][...80] guessed: [...199] [ip4][..tcp] [.....172.16.0.1][55794] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...199] [ip4][..tcp] [.....172.16.0.1][55794] -> [..192.168.10.50][...80] + end: [...199] [ip4][..tcp] [.....172.16.0.1][55794] -> [..192.168.10.50][...80] guessed: [...200] [ip4][..tcp] [.....172.16.0.1][55820] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...200] [ip4][..tcp] [.....172.16.0.1][55820] -> [..192.168.10.50][...80] - new: [...275] [ip4][..tcp] [.....172.16.0.1][57170] -> [..192.168.10.50][...80] - new: [...276] [ip4][..tcp] [.....172.16.0.1][57184] -> [..192.168.10.50][...80] - new: [...277] [ip4][..tcp] [.....172.16.0.1][57210] -> [..192.168.10.50][...80] - new: [...278] [ip4][..tcp] [.....172.16.0.1][57224] -> [..192.168.10.50][...80] - new: [...279] [ip4][..tcp] [.....172.16.0.1][57238] -> [..192.168.10.50][...80] - new: [...280] [ip4][..tcp] [.....172.16.0.1][57264] -> [..192.168.10.50][...80] + end: [...200] [ip4][..tcp] [.....172.16.0.1][55820] -> [..192.168.10.50][...80] + new: [...275] [ip4][..tcp] [.....172.16.0.1][57170] -> [..192.168.10.50][...80] + new: [...276] [ip4][..tcp] [.....172.16.0.1][57184] -> [..192.168.10.50][...80] + new: [...277] [ip4][..tcp] [.....172.16.0.1][57210] -> [..192.168.10.50][...80] + new: [...278] [ip4][..tcp] [.....172.16.0.1][57224] -> [..192.168.10.50][...80] + new: [...279] [ip4][..tcp] [.....172.16.0.1][57238] -> [..192.168.10.50][...80] + new: [...280] [ip4][..tcp] [.....172.16.0.1][57264] -> [..192.168.10.50][...80] guessed: [...201] [ip4][..tcp] [.....172.16.0.1][55834] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...201] [ip4][..tcp] [.....172.16.0.1][55834] -> [..192.168.10.50][...80] + end: [...201] [ip4][..tcp] [.....172.16.0.1][55834] -> [..192.168.10.50][...80] guessed: [...202] [ip4][..tcp] [.....172.16.0.1][55860] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...202] [ip4][..tcp] [.....172.16.0.1][55860] -> [..192.168.10.50][...80] + end: [...202] [ip4][..tcp] [.....172.16.0.1][55860] -> [..192.168.10.50][...80] guessed: [...203] [ip4][..tcp] [.....172.16.0.1][55874] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...203] [ip4][..tcp] [.....172.16.0.1][55874] -> [..192.168.10.50][...80] + end: [...203] [ip4][..tcp] [.....172.16.0.1][55874] -> [..192.168.10.50][...80] guessed: [...204] [ip4][..tcp] [.....172.16.0.1][55888] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...204] [ip4][..tcp] [.....172.16.0.1][55888] -> [..192.168.10.50][...80] + end: [...204] [ip4][..tcp] [.....172.16.0.1][55888] -> [..192.168.10.50][...80] guessed: [...205] [ip4][..tcp] [.....172.16.0.1][55914] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...205] [ip4][..tcp] [.....172.16.0.1][55914] -> [..192.168.10.50][...80] + end: [...205] [ip4][..tcp] [.....172.16.0.1][55914] -> [..192.168.10.50][...80] guessed: [...206] [ip4][..tcp] [.....172.16.0.1][55928] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...206] [ip4][..tcp] [.....172.16.0.1][55928] -> [..192.168.10.50][...80] - new: [...281] [ip4][..tcp] [.....172.16.0.1][57278] -> [..192.168.10.50][...80] - new: [...282] [ip4][..tcp] [.....172.16.0.1][57292] -> [..192.168.10.50][...80] - new: [...283] [ip4][..tcp] [.....172.16.0.1][57318] -> [..192.168.10.50][...80] - new: [...284] [ip4][..tcp] [.....172.16.0.1][57332] -> [..192.168.10.50][...80] - new: [...285] [ip4][..tcp] [.....172.16.0.1][57346] -> [..192.168.10.50][...80] - new: [...286] [ip4][..tcp] [.....172.16.0.1][57372] -> [..192.168.10.50][...80] + end: [...206] [ip4][..tcp] [.....172.16.0.1][55928] -> [..192.168.10.50][...80] + new: [...281] [ip4][..tcp] [.....172.16.0.1][57278] -> [..192.168.10.50][...80] + new: [...282] [ip4][..tcp] [.....172.16.0.1][57292] -> [..192.168.10.50][...80] + new: [...283] [ip4][..tcp] [.....172.16.0.1][57318] -> [..192.168.10.50][...80] + new: [...284] [ip4][..tcp] [.....172.16.0.1][57332] -> [..192.168.10.50][...80] + new: [...285] [ip4][..tcp] [.....172.16.0.1][57346] -> [..192.168.10.50][...80] + new: [...286] [ip4][..tcp] [.....172.16.0.1][57372] -> [..192.168.10.50][...80] guessed: [...207] [ip4][..tcp] [.....172.16.0.1][55942] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...207] [ip4][..tcp] [.....172.16.0.1][55942] -> [..192.168.10.50][...80] + end: [...207] [ip4][..tcp] [.....172.16.0.1][55942] -> [..192.168.10.50][...80] guessed: [...208] [ip4][..tcp] [.....172.16.0.1][55968] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...208] [ip4][..tcp] [.....172.16.0.1][55968] -> [..192.168.10.50][...80] + end: [...208] [ip4][..tcp] [.....172.16.0.1][55968] -> [..192.168.10.50][...80] guessed: [...209] [ip4][..tcp] [.....172.16.0.1][55982] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...209] [ip4][..tcp] [.....172.16.0.1][55982] -> [..192.168.10.50][...80] + end: [...209] [ip4][..tcp] [.....172.16.0.1][55982] -> [..192.168.10.50][...80] guessed: [...210] [ip4][..tcp] [.....172.16.0.1][55996] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...210] [ip4][..tcp] [.....172.16.0.1][55996] -> [..192.168.10.50][...80] + end: [...210] [ip4][..tcp] [.....172.16.0.1][55996] -> [..192.168.10.50][...80] guessed: [...211] [ip4][..tcp] [.....172.16.0.1][56022] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...211] [ip4][..tcp] [.....172.16.0.1][56022] -> [..192.168.10.50][...80] + end: [...211] [ip4][..tcp] [.....172.16.0.1][56022] -> [..192.168.10.50][...80] guessed: [...212] [ip4][..tcp] [.....172.16.0.1][56036] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...212] [ip4][..tcp] [.....172.16.0.1][56036] -> [..192.168.10.50][...80] - new: [...287] [ip4][..tcp] [.....172.16.0.1][57386] -> [..192.168.10.50][...80] - new: [...288] [ip4][..tcp] [.....172.16.0.1][57400] -> [..192.168.10.50][...80] - new: [...289] [ip4][..tcp] [.....172.16.0.1][57426] -> [..192.168.10.50][...80] - new: [...290] [ip4][..tcp] [.....172.16.0.1][57440] -> [..192.168.10.50][...80] - new: [...291] [ip4][..tcp] [.....172.16.0.1][57454] -> [..192.168.10.50][...80] - new: [...292] [ip4][..tcp] [.....172.16.0.1][57480] -> [..192.168.10.50][...80] + end: [...212] [ip4][..tcp] [.....172.16.0.1][56036] -> [..192.168.10.50][...80] + new: [...287] [ip4][..tcp] [.....172.16.0.1][57386] -> [..192.168.10.50][...80] + new: [...288] [ip4][..tcp] [.....172.16.0.1][57400] -> [..192.168.10.50][...80] + new: [...289] [ip4][..tcp] [.....172.16.0.1][57426] -> [..192.168.10.50][...80] + new: [...290] [ip4][..tcp] [.....172.16.0.1][57440] -> [..192.168.10.50][...80] + new: [...291] [ip4][..tcp] [.....172.16.0.1][57454] -> [..192.168.10.50][...80] + new: [...292] [ip4][..tcp] [.....172.16.0.1][57480] -> [..192.168.10.50][...80] guessed: [...213] [ip4][..tcp] [.....172.16.0.1][56062] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...213] [ip4][..tcp] [.....172.16.0.1][56062] -> [..192.168.10.50][...80] + end: [...213] [ip4][..tcp] [.....172.16.0.1][56062] -> [..192.168.10.50][...80] guessed: [...214] [ip4][..tcp] [.....172.16.0.1][56076] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...214] [ip4][..tcp] [.....172.16.0.1][56076] -> [..192.168.10.50][...80] + end: [...214] [ip4][..tcp] [.....172.16.0.1][56076] -> [..192.168.10.50][...80] guessed: [...215] [ip4][..tcp] [.....172.16.0.1][56090] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...215] [ip4][..tcp] [.....172.16.0.1][56090] -> [..192.168.10.50][...80] + end: [...215] [ip4][..tcp] [.....172.16.0.1][56090] -> [..192.168.10.50][...80] guessed: [...216] [ip4][..tcp] [.....172.16.0.1][56116] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...216] [ip4][..tcp] [.....172.16.0.1][56116] -> [..192.168.10.50][...80] + end: [...216] [ip4][..tcp] [.....172.16.0.1][56116] -> [..192.168.10.50][...80] guessed: [...217] [ip4][..tcp] [.....172.16.0.1][56130] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...217] [ip4][..tcp] [.....172.16.0.1][56130] -> [..192.168.10.50][...80] + end: [...217] [ip4][..tcp] [.....172.16.0.1][56130] -> [..192.168.10.50][...80] guessed: [...218] [ip4][..tcp] [.....172.16.0.1][56144] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...218] [ip4][..tcp] [.....172.16.0.1][56144] -> [..192.168.10.50][...80] - new: [...293] [ip4][..tcp] [.....172.16.0.1][57494] -> [..192.168.10.50][...80] - new: [...294] [ip4][..tcp] [.....172.16.0.1][57508] -> [..192.168.10.50][...80] - new: [...295] [ip4][..tcp] [.....172.16.0.1][57522] -> [..192.168.10.50][...80] - new: [...296] [ip4][..tcp] [.....172.16.0.1][57536] -> [..192.168.10.50][...80] - new: [...297] [ip4][..tcp] [.....172.16.0.1][57550] -> [..192.168.10.50][...80] - new: [...298] [ip4][..tcp] [.....172.16.0.1][57576] -> [..192.168.10.50][...80] - new: [...299] [ip4][..tcp] [.....172.16.0.1][57590] -> [..192.168.10.50][...80] + end: [...218] [ip4][..tcp] [.....172.16.0.1][56144] -> [..192.168.10.50][...80] + new: [...293] [ip4][..tcp] [.....172.16.0.1][57494] -> [..192.168.10.50][...80] + new: [...294] [ip4][..tcp] [.....172.16.0.1][57508] -> [..192.168.10.50][...80] + new: [...295] [ip4][..tcp] [.....172.16.0.1][57522] -> [..192.168.10.50][...80] + new: [...296] [ip4][..tcp] [.....172.16.0.1][57536] -> [..192.168.10.50][...80] + new: [...297] [ip4][..tcp] [.....172.16.0.1][57550] -> [..192.168.10.50][...80] + new: [...298] [ip4][..tcp] [.....172.16.0.1][57576] -> [..192.168.10.50][...80] + new: [...299] [ip4][..tcp] [.....172.16.0.1][57590] -> [..192.168.10.50][...80] guessed: [...219] [ip4][..tcp] [.....172.16.0.1][56158] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...219] [ip4][..tcp] [.....172.16.0.1][56158] -> [..192.168.10.50][...80] + end: [...219] [ip4][..tcp] [.....172.16.0.1][56158] -> [..192.168.10.50][...80] guessed: [...220] [ip4][..tcp] [.....172.16.0.1][56172] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...220] [ip4][..tcp] [.....172.16.0.1][56172] -> [..192.168.10.50][...80] + end: [...220] [ip4][..tcp] [.....172.16.0.1][56172] -> [..192.168.10.50][...80] guessed: [...221] [ip4][..tcp] [.....172.16.0.1][56186] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...221] [ip4][..tcp] [.....172.16.0.1][56186] -> [..192.168.10.50][...80] + end: [...221] [ip4][..tcp] [.....172.16.0.1][56186] -> [..192.168.10.50][...80] guessed: [...222] [ip4][..tcp] [.....172.16.0.1][56212] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...222] [ip4][..tcp] [.....172.16.0.1][56212] -> [..192.168.10.50][...80] + end: [...222] [ip4][..tcp] [.....172.16.0.1][56212] -> [..192.168.10.50][...80] guessed: [...223] [ip4][..tcp] [.....172.16.0.1][56226] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...223] [ip4][..tcp] [.....172.16.0.1][56226] -> [..192.168.10.50][...80] + end: [...223] [ip4][..tcp] [.....172.16.0.1][56226] -> [..192.168.10.50][...80] guessed: [...224] [ip4][..tcp] [.....172.16.0.1][56240] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...224] [ip4][..tcp] [.....172.16.0.1][56240] -> [..192.168.10.50][...80] - new: [...300] [ip4][..tcp] [.....172.16.0.1][57604] -> [..192.168.10.50][...80] - new: [...301] [ip4][..tcp] [.....172.16.0.1][57630] -> [..192.168.10.50][...80] - new: [...302] [ip4][..tcp] [.....172.16.0.1][57644] -> [..192.168.10.50][...80] - new: [...303] [ip4][..tcp] [.....172.16.0.1][57658] -> [..192.168.10.50][...80] - new: [...304] [ip4][..tcp] [.....172.16.0.1][57684] -> [..192.168.10.50][...80] - new: [...305] [ip4][..tcp] [.....172.16.0.1][57698] -> [..192.168.10.50][...80] + end: [...224] [ip4][..tcp] [.....172.16.0.1][56240] -> [..192.168.10.50][...80] + new: [...300] [ip4][..tcp] [.....172.16.0.1][57604] -> [..192.168.10.50][...80] + new: [...301] [ip4][..tcp] [.....172.16.0.1][57630] -> [..192.168.10.50][...80] + new: [...302] [ip4][..tcp] [.....172.16.0.1][57644] -> [..192.168.10.50][...80] + new: [...303] [ip4][..tcp] [.....172.16.0.1][57658] -> [..192.168.10.50][...80] + new: [...304] [ip4][..tcp] [.....172.16.0.1][57684] -> [..192.168.10.50][...80] + new: [...305] [ip4][..tcp] [.....172.16.0.1][57698] -> [..192.168.10.50][...80] end: [...190] [ip4][..tcp] [.....172.16.0.1][55632] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...225] [ip4][..tcp] [.....172.16.0.1][56266] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...225] [ip4][..tcp] [.....172.16.0.1][56266] -> [..192.168.10.50][...80] + end: [...225] [ip4][..tcp] [.....172.16.0.1][56266] -> [..192.168.10.50][...80] guessed: [...226] [ip4][..tcp] [.....172.16.0.1][56280] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...226] [ip4][..tcp] [.....172.16.0.1][56280] -> [..192.168.10.50][...80] + end: [...226] [ip4][..tcp] [.....172.16.0.1][56280] -> [..192.168.10.50][...80] guessed: [...228] [ip4][..tcp] [.....172.16.0.1][56320] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...228] [ip4][..tcp] [.....172.16.0.1][56320] -> [..192.168.10.50][...80] + end: [...228] [ip4][..tcp] [.....172.16.0.1][56320] -> [..192.168.10.50][...80] guessed: [...229] [ip4][..tcp] [.....172.16.0.1][56334] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...229] [ip4][..tcp] [.....172.16.0.1][56334] -> [..192.168.10.50][...80] + end: [...229] [ip4][..tcp] [.....172.16.0.1][56334] -> [..192.168.10.50][...80] guessed: [...230] [ip4][..tcp] [.....172.16.0.1][56360] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...230] [ip4][..tcp] [.....172.16.0.1][56360] -> [..192.168.10.50][...80] - new: [...306] [ip4][..tcp] [.....172.16.0.1][57712] -> [..192.168.10.50][...80] + end: [...230] [ip4][..tcp] [.....172.16.0.1][56360] -> [..192.168.10.50][...80] + new: [...306] [ip4][..tcp] [.....172.16.0.1][57712] -> [..192.168.10.50][...80] detected: [...304] [ip4][..tcp] [.....172.16.0.1][57684] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...307] [ip4][..tcp] [.....172.16.0.1][57738] -> [..192.168.10.50][...80] - new: [...308] [ip4][..tcp] [.....172.16.0.1][57752] -> [..192.168.10.50][...80] - new: [...309] [ip4][..tcp] [.....172.16.0.1][57778] -> [..192.168.10.50][...80] + new: [...307] [ip4][..tcp] [.....172.16.0.1][57738] -> [..192.168.10.50][...80] + new: [...308] [ip4][..tcp] [.....172.16.0.1][57752] -> [..192.168.10.50][...80] + new: [...309] [ip4][..tcp] [.....172.16.0.1][57778] -> [..192.168.10.50][...80] analyse: [...304] [ip4][..tcp] [.....172.16.0.1][57684] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.536| 0.567| 0.877| 769788.412| 3.700] @@ -894,132 +894,132 @@ [IATS(ms)....: 0.1,0.9,3535.3,3536.2,3.0,3.9,353.5,357.6,4.1,1009.5,1013.5,4.1,235.9,239.6,3.7,1007.5,1011.2,3.7,236.1,239.8,3.7,1007.6,1011.4,3.8,240.9,244.7,3.7,1011.7,1015.5,3.8,232.1] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1918,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1920,52,435,1822,52,637] [ENTROPIES...: 4.6,5.0,4.8,5.9,4.8,7.7,4.6,6.0,7.8,4.8,5.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.8,6.0,7.8,4.8,5.9,7.7,4.8,6.0,7.8,4.8,5.9,7.7,4.8,6.0] - new: [...310] [ip4][..tcp] [.....172.16.0.1][57792] -> [..192.168.10.50][...80] - new: [...311] [ip4][..tcp] [.....172.16.0.1][57806] -> [..192.168.10.50][...80] + new: [...310] [ip4][..tcp] [.....172.16.0.1][57792] -> [..192.168.10.50][...80] + new: [...311] [ip4][..tcp] [.....172.16.0.1][57806] -> [..192.168.10.50][...80] guessed: [...231] [ip4][..tcp] [.....172.16.0.1][56374] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...231] [ip4][..tcp] [.....172.16.0.1][56374] -> [..192.168.10.50][...80] + end: [...231] [ip4][..tcp] [.....172.16.0.1][56374] -> [..192.168.10.50][...80] guessed: [...232] [ip4][..tcp] [.....172.16.0.1][56400] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...232] [ip4][..tcp] [.....172.16.0.1][56400] -> [..192.168.10.50][...80] + end: [...232] [ip4][..tcp] [.....172.16.0.1][56400] -> [..192.168.10.50][...80] guessed: [...233] [ip4][..tcp] [.....172.16.0.1][56414] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...233] [ip4][..tcp] [.....172.16.0.1][56414] -> [..192.168.10.50][...80] + end: [...233] [ip4][..tcp] [.....172.16.0.1][56414] -> [..192.168.10.50][...80] guessed: [...234] [ip4][..tcp] [.....172.16.0.1][56428] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...234] [ip4][..tcp] [.....172.16.0.1][56428] -> [..192.168.10.50][...80] + end: [...234] [ip4][..tcp] [.....172.16.0.1][56428] -> [..192.168.10.50][...80] guessed: [...235] [ip4][..tcp] [.....172.16.0.1][56454] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...235] [ip4][..tcp] [.....172.16.0.1][56454] -> [..192.168.10.50][...80] + end: [...235] [ip4][..tcp] [.....172.16.0.1][56454] -> [..192.168.10.50][...80] guessed: [...236] [ip4][..tcp] [.....172.16.0.1][56468] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...236] [ip4][..tcp] [.....172.16.0.1][56468] -> [..192.168.10.50][...80] - new: [...312] [ip4][..tcp] [.....172.16.0.1][57832] -> [..192.168.10.50][...80] - new: [...313] [ip4][..tcp] [.....172.16.0.1][57846] -> [..192.168.10.50][...80] - new: [...314] [ip4][..tcp] [.....172.16.0.1][57860] -> [..192.168.10.50][...80] - new: [...315] [ip4][..tcp] [.....172.16.0.1][57886] -> [..192.168.10.50][...80] - new: [...316] [ip4][..tcp] [.....172.16.0.1][57900] -> [..192.168.10.50][...80] - new: [...317] [ip4][..tcp] [.....172.16.0.1][57914] -> [..192.168.10.50][...80] + end: [...236] [ip4][..tcp] [.....172.16.0.1][56468] -> [..192.168.10.50][...80] + new: [...312] [ip4][..tcp] [.....172.16.0.1][57832] -> [..192.168.10.50][...80] + new: [...313] [ip4][..tcp] [.....172.16.0.1][57846] -> [..192.168.10.50][...80] + new: [...314] [ip4][..tcp] [.....172.16.0.1][57860] -> [..192.168.10.50][...80] + new: [...315] [ip4][..tcp] [.....172.16.0.1][57886] -> [..192.168.10.50][...80] + new: [...316] [ip4][..tcp] [.....172.16.0.1][57900] -> [..192.168.10.50][...80] + new: [...317] [ip4][..tcp] [.....172.16.0.1][57914] -> [..192.168.10.50][...80] guessed: [...237] [ip4][..tcp] [.....172.16.0.1][56482] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...237] [ip4][..tcp] [.....172.16.0.1][56482] -> [..192.168.10.50][...80] + end: [...237] [ip4][..tcp] [.....172.16.0.1][56482] -> [..192.168.10.50][...80] guessed: [...238] [ip4][..tcp] [.....172.16.0.1][56508] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...238] [ip4][..tcp] [.....172.16.0.1][56508] -> [..192.168.10.50][...80] + end: [...238] [ip4][..tcp] [.....172.16.0.1][56508] -> [..192.168.10.50][...80] guessed: [...239] [ip4][..tcp] [.....172.16.0.1][56522] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...239] [ip4][..tcp] [.....172.16.0.1][56522] -> [..192.168.10.50][...80] + end: [...239] [ip4][..tcp] [.....172.16.0.1][56522] -> [..192.168.10.50][...80] guessed: [...240] [ip4][..tcp] [.....172.16.0.1][56536] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...240] [ip4][..tcp] [.....172.16.0.1][56536] -> [..192.168.10.50][...80] + end: [...240] [ip4][..tcp] [.....172.16.0.1][56536] -> [..192.168.10.50][...80] guessed: [...241] [ip4][..tcp] [.....172.16.0.1][56562] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...241] [ip4][..tcp] [.....172.16.0.1][56562] -> [..192.168.10.50][...80] + end: [...241] [ip4][..tcp] [.....172.16.0.1][56562] -> [..192.168.10.50][...80] guessed: [...242] [ip4][..tcp] [.....172.16.0.1][56576] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...242] [ip4][..tcp] [.....172.16.0.1][56576] -> [..192.168.10.50][...80] - new: [...318] [ip4][..tcp] [.....172.16.0.1][57940] -> [..192.168.10.50][...80] - new: [...319] [ip4][..tcp] [.....172.16.0.1][57954] -> [..192.168.10.50][...80] - new: [...320] [ip4][..tcp] [.....172.16.0.1][57980] -> [..192.168.10.50][...80] - new: [...321] [ip4][..tcp] [.....172.16.0.1][57994] -> [..192.168.10.50][...80] - new: [...322] [ip4][..tcp] [.....172.16.0.1][58008] -> [..192.168.10.50][...80] + end: [...242] [ip4][..tcp] [.....172.16.0.1][56576] -> [..192.168.10.50][...80] + new: [...318] [ip4][..tcp] [.....172.16.0.1][57940] -> [..192.168.10.50][...80] + new: [...319] [ip4][..tcp] [.....172.16.0.1][57954] -> [..192.168.10.50][...80] + new: [...320] [ip4][..tcp] [.....172.16.0.1][57980] -> [..192.168.10.50][...80] + new: [...321] [ip4][..tcp] [.....172.16.0.1][57994] -> [..192.168.10.50][...80] + new: [...322] [ip4][..tcp] [.....172.16.0.1][58008] -> [..192.168.10.50][...80] guessed: [...243] [ip4][..tcp] [.....172.16.0.1][56590] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...243] [ip4][..tcp] [.....172.16.0.1][56590] -> [..192.168.10.50][...80] + end: [...243] [ip4][..tcp] [.....172.16.0.1][56590] -> [..192.168.10.50][...80] guessed: [...244] [ip4][..tcp] [.....172.16.0.1][56616] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...244] [ip4][..tcp] [.....172.16.0.1][56616] -> [..192.168.10.50][...80] + end: [...244] [ip4][..tcp] [.....172.16.0.1][56616] -> [..192.168.10.50][...80] guessed: [...245] [ip4][..tcp] [.....172.16.0.1][56630] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...245] [ip4][..tcp] [.....172.16.0.1][56630] -> [..192.168.10.50][...80] + end: [...245] [ip4][..tcp] [.....172.16.0.1][56630] -> [..192.168.10.50][...80] guessed: [...246] [ip4][..tcp] [.....172.16.0.1][56644] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...246] [ip4][..tcp] [.....172.16.0.1][56644] -> [..192.168.10.50][...80] + end: [...246] [ip4][..tcp] [.....172.16.0.1][56644] -> [..192.168.10.50][...80] guessed: [...247] [ip4][..tcp] [.....172.16.0.1][56670] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...247] [ip4][..tcp] [.....172.16.0.1][56670] -> [..192.168.10.50][...80] + end: [...247] [ip4][..tcp] [.....172.16.0.1][56670] -> [..192.168.10.50][...80] guessed: [...248] [ip4][..tcp] [.....172.16.0.1][56684] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...248] [ip4][..tcp] [.....172.16.0.1][56684] -> [..192.168.10.50][...80] - new: [...323] [ip4][..tcp] [.....172.16.0.1][58034] -> [..192.168.10.50][...80] - new: [...324] [ip4][..tcp] [.....172.16.0.1][58048] -> [..192.168.10.50][...80] - new: [...325] [ip4][..tcp] [.....172.16.0.1][58062] -> [..192.168.10.50][...80] - new: [...326] [ip4][..tcp] [.....172.16.0.1][58088] -> [..192.168.10.50][...80] - new: [...327] [ip4][..tcp] [.....172.16.0.1][58102] -> [..192.168.10.50][...80] - new: [...328] [ip4][..tcp] [.....172.16.0.1][58116] -> [..192.168.10.50][...80] - new: [...329] [ip4][..tcp] [.....172.16.0.1][58130] -> [..192.168.10.50][...80] + end: [...248] [ip4][..tcp] [.....172.16.0.1][56684] -> [..192.168.10.50][...80] + new: [...323] [ip4][..tcp] [.....172.16.0.1][58034] -> [..192.168.10.50][...80] + new: [...324] [ip4][..tcp] [.....172.16.0.1][58048] -> [..192.168.10.50][...80] + new: [...325] [ip4][..tcp] [.....172.16.0.1][58062] -> [..192.168.10.50][...80] + new: [...326] [ip4][..tcp] [.....172.16.0.1][58088] -> [..192.168.10.50][...80] + new: [...327] [ip4][..tcp] [.....172.16.0.1][58102] -> [..192.168.10.50][...80] + new: [...328] [ip4][..tcp] [.....172.16.0.1][58116] -> [..192.168.10.50][...80] + new: [...329] [ip4][..tcp] [.....172.16.0.1][58130] -> [..192.168.10.50][...80] guessed: [...249] [ip4][..tcp] [.....172.16.0.1][56710] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...249] [ip4][..tcp] [.....172.16.0.1][56710] -> [..192.168.10.50][...80] + end: [...249] [ip4][..tcp] [.....172.16.0.1][56710] -> [..192.168.10.50][...80] guessed: [...250] [ip4][..tcp] [.....172.16.0.1][56724] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...250] [ip4][..tcp] [.....172.16.0.1][56724] -> [..192.168.10.50][...80] + end: [...250] [ip4][..tcp] [.....172.16.0.1][56724] -> [..192.168.10.50][...80] guessed: [...251] [ip4][..tcp] [.....172.16.0.1][56738] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...251] [ip4][..tcp] [.....172.16.0.1][56738] -> [..192.168.10.50][...80] + end: [...251] [ip4][..tcp] [.....172.16.0.1][56738] -> [..192.168.10.50][...80] guessed: [...252] [ip4][..tcp] [.....172.16.0.1][56764] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...252] [ip4][..tcp] [.....172.16.0.1][56764] -> [..192.168.10.50][...80] + end: [...252] [ip4][..tcp] [.....172.16.0.1][56764] -> [..192.168.10.50][...80] guessed: [...253] [ip4][..tcp] [.....172.16.0.1][56778] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...253] [ip4][..tcp] [.....172.16.0.1][56778] -> [..192.168.10.50][...80] - new: [...330] [ip4][..tcp] [.....172.16.0.1][58144] -> [..192.168.10.50][...80] - new: [...331] [ip4][..tcp] [.....172.16.0.1][58158] -> [..192.168.10.50][...80] - new: [...332] [ip4][..tcp] [.....172.16.0.1][58184] -> [..192.168.10.50][...80] - new: [...333] [ip4][..tcp] [.....172.16.0.1][58198] -> [..192.168.10.50][...80] - new: [...334] [ip4][..tcp] [.....172.16.0.1][58224] -> [..192.168.10.50][...80] + end: [...253] [ip4][..tcp] [.....172.16.0.1][56778] -> [..192.168.10.50][...80] + new: [...330] [ip4][..tcp] [.....172.16.0.1][58144] -> [..192.168.10.50][...80] + new: [...331] [ip4][..tcp] [.....172.16.0.1][58158] -> [..192.168.10.50][...80] + new: [...332] [ip4][..tcp] [.....172.16.0.1][58184] -> [..192.168.10.50][...80] + new: [...333] [ip4][..tcp] [.....172.16.0.1][58198] -> [..192.168.10.50][...80] + new: [...334] [ip4][..tcp] [.....172.16.0.1][58224] -> [..192.168.10.50][...80] DAEMON-EVENT: [Processed: 4739 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 82 / 334|skipped: 0|!detected: 0|guessed: 242|detection-updates: 0|updates: 0] - new: [...335] [ip4][..tcp] [.....172.16.0.1][58238] -> [..192.168.10.50][...80] + new: [...335] [ip4][..tcp] [.....172.16.0.1][58238] -> [..192.168.10.50][...80] guessed: [...254] [ip4][..tcp] [.....172.16.0.1][56792] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...254] [ip4][..tcp] [.....172.16.0.1][56792] -> [..192.168.10.50][...80] + end: [...254] [ip4][..tcp] [.....172.16.0.1][56792] -> [..192.168.10.50][...80] guessed: [...255] [ip4][..tcp] [.....172.16.0.1][56818] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...255] [ip4][..tcp] [.....172.16.0.1][56818] -> [..192.168.10.50][...80] + end: [...255] [ip4][..tcp] [.....172.16.0.1][56818] -> [..192.168.10.50][...80] guessed: [...256] [ip4][..tcp] [.....172.16.0.1][56832] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...256] [ip4][..tcp] [.....172.16.0.1][56832] -> [..192.168.10.50][...80] + end: [...256] [ip4][..tcp] [.....172.16.0.1][56832] -> [..192.168.10.50][...80] guessed: [...257] [ip4][..tcp] [.....172.16.0.1][56858] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...257] [ip4][..tcp] [.....172.16.0.1][56858] -> [..192.168.10.50][...80] + end: [...257] [ip4][..tcp] [.....172.16.0.1][56858] -> [..192.168.10.50][...80] guessed: [...258] [ip4][..tcp] [.....172.16.0.1][56872] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...258] [ip4][..tcp] [.....172.16.0.1][56872] -> [..192.168.10.50][...80] + end: [...258] [ip4][..tcp] [.....172.16.0.1][56872] -> [..192.168.10.50][...80] guessed: [...259] [ip4][..tcp] [.....172.16.0.1][56886] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...259] [ip4][..tcp] [.....172.16.0.1][56886] -> [..192.168.10.50][...80] - new: [...336] [ip4][..tcp] [.....172.16.0.1][58252] -> [..192.168.10.50][...80] - new: [...337] [ip4][..tcp] [.....172.16.0.1][58278] -> [..192.168.10.50][...80] - new: [...338] [ip4][..tcp] [.....172.16.0.1][58292] -> [..192.168.10.50][...80] - new: [...339] [ip4][..tcp] [.....172.16.0.1][58306] -> [..192.168.10.50][...80] - new: [...340] [ip4][..tcp] [.....172.16.0.1][58332] -> [..192.168.10.50][...80] - new: [...341] [ip4][..tcp] [.....172.16.0.1][58346] -> [..192.168.10.50][...80] + end: [...259] [ip4][..tcp] [.....172.16.0.1][56886] -> [..192.168.10.50][...80] + new: [...336] [ip4][..tcp] [.....172.16.0.1][58252] -> [..192.168.10.50][...80] + new: [...337] [ip4][..tcp] [.....172.16.0.1][58278] -> [..192.168.10.50][...80] + new: [...338] [ip4][..tcp] [.....172.16.0.1][58292] -> [..192.168.10.50][...80] + new: [...339] [ip4][..tcp] [.....172.16.0.1][58306] -> [..192.168.10.50][...80] + new: [...340] [ip4][..tcp] [.....172.16.0.1][58332] -> [..192.168.10.50][...80] + new: [...341] [ip4][..tcp] [.....172.16.0.1][58346] -> [..192.168.10.50][...80] guessed: [...260] [ip4][..tcp] [.....172.16.0.1][56912] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...260] [ip4][..tcp] [.....172.16.0.1][56912] -> [..192.168.10.50][...80] + end: [...260] [ip4][..tcp] [.....172.16.0.1][56912] -> [..192.168.10.50][...80] guessed: [...261] [ip4][..tcp] [.....172.16.0.1][56926] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...261] [ip4][..tcp] [.....172.16.0.1][56926] -> [..192.168.10.50][...80] + end: [...261] [ip4][..tcp] [.....172.16.0.1][56926] -> [..192.168.10.50][...80] guessed: [...262] [ip4][..tcp] [.....172.16.0.1][56940] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...262] [ip4][..tcp] [.....172.16.0.1][56940] -> [..192.168.10.50][...80] + end: [...262] [ip4][..tcp] [.....172.16.0.1][56940] -> [..192.168.10.50][...80] guessed: [...263] [ip4][..tcp] [.....172.16.0.1][56966] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...263] [ip4][..tcp] [.....172.16.0.1][56966] -> [..192.168.10.50][...80] + end: [...263] [ip4][..tcp] [.....172.16.0.1][56966] -> [..192.168.10.50][...80] guessed: [...264] [ip4][..tcp] [.....172.16.0.1][56980] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...264] [ip4][..tcp] [.....172.16.0.1][56980] -> [..192.168.10.50][...80] + end: [...264] [ip4][..tcp] [.....172.16.0.1][56980] -> [..192.168.10.50][...80] guessed: [...266] [ip4][..tcp] [.....172.16.0.1][57008] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...266] [ip4][..tcp] [.....172.16.0.1][57008] -> [..192.168.10.50][...80] + end: [...266] [ip4][..tcp] [.....172.16.0.1][57008] -> [..192.168.10.50][...80] end: [...227] [ip4][..tcp] [.....172.16.0.1][56306] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...342] [ip4][..tcp] [.....172.16.0.1][58360] -> [..192.168.10.50][...80] - new: [...343] [ip4][..tcp] [.....172.16.0.1][58386] -> [..192.168.10.50][...80] - new: [...344] [ip4][..tcp] [.....172.16.0.1][58400] -> [..192.168.10.50][...80] + new: [...342] [ip4][..tcp] [.....172.16.0.1][58360] -> [..192.168.10.50][...80] + new: [...343] [ip4][..tcp] [.....172.16.0.1][58386] -> [..192.168.10.50][...80] + new: [...344] [ip4][..tcp] [.....172.16.0.1][58400] -> [..192.168.10.50][...80] detected: [...342] [ip4][..tcp] [.....172.16.0.1][58360] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...345] [ip4][..tcp] [.....172.16.0.1][58414] -> [..192.168.10.50][...80] - new: [...346] [ip4][..tcp] [.....172.16.0.1][58440] -> [..192.168.10.50][...80] - new: [...347] [ip4][..tcp] [.....172.16.0.1][58454] -> [..192.168.10.50][...80] + new: [...345] [ip4][..tcp] [.....172.16.0.1][58414] -> [..192.168.10.50][...80] + new: [...346] [ip4][..tcp] [.....172.16.0.1][58440] -> [..192.168.10.50][...80] + new: [...347] [ip4][..tcp] [.....172.16.0.1][58454] -> [..192.168.10.50][...80] guessed: [...267] [ip4][..tcp] [.....172.16.0.1][57022] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...267] [ip4][..tcp] [.....172.16.0.1][57022] -> [..192.168.10.50][...80] + end: [...267] [ip4][..tcp] [.....172.16.0.1][57022] -> [..192.168.10.50][...80] guessed: [...268] [ip4][..tcp] [.....172.16.0.1][57036] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...268] [ip4][..tcp] [.....172.16.0.1][57036] -> [..192.168.10.50][...80] + end: [...268] [ip4][..tcp] [.....172.16.0.1][57036] -> [..192.168.10.50][...80] guessed: [...269] [ip4][..tcp] [.....172.16.0.1][57062] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...269] [ip4][..tcp] [.....172.16.0.1][57062] -> [..192.168.10.50][...80] + end: [...269] [ip4][..tcp] [.....172.16.0.1][57062] -> [..192.168.10.50][...80] guessed: [...270] [ip4][..tcp] [.....172.16.0.1][57076] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...270] [ip4][..tcp] [.....172.16.0.1][57076] -> [..192.168.10.50][...80] + end: [...270] [ip4][..tcp] [.....172.16.0.1][57076] -> [..192.168.10.50][...80] guessed: [...271] [ip4][..tcp] [.....172.16.0.1][57090] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...271] [ip4][..tcp] [.....172.16.0.1][57090] -> [..192.168.10.50][...80] + end: [...271] [ip4][..tcp] [.....172.16.0.1][57090] -> [..192.168.10.50][...80] guessed: [...272] [ip4][..tcp] [.....172.16.0.1][57116] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...272] [ip4][..tcp] [.....172.16.0.1][57116] -> [..192.168.10.50][...80] + end: [...272] [ip4][..tcp] [.....172.16.0.1][57116] -> [..192.168.10.50][...80] analyse: [...342] [ip4][..tcp] [.....172.16.0.1][58360] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.810| 0.603| 0.941| 884966.883| 3.700] @@ -1030,118 +1030,118 @@ [IATS(ms)....: 0.1,0.7,3808.9,3809.5,3.4,4.1,1007.1,1011.3,4.3,225.9,229.5,3.8,1021.8,1025.8,4.1,234.0,238.5,4.5,1006.3,1010.7,4.3,238.5,243.2,4.5,1006.7,1011.2,4.5,253.5,257.1,3.6,1008.0] [PKTLENS.....: 60,60,52,637,52,1920,52,435,1822,52,637,1920,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1921,52,435] [ENTROPIES...: 4.6,5.1,5.0,6.0,5.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.8,5.9] - new: [...348] [ip4][..tcp] [.....172.16.0.1][58468] -> [..192.168.10.50][...80] - new: [...349] [ip4][..tcp] [.....172.16.0.1][58482] -> [..192.168.10.50][...80] - new: [...350] [ip4][..tcp] [.....172.16.0.1][58496] -> [..192.168.10.50][...80] - new: [...351] [ip4][..tcp] [.....172.16.0.1][58510] -> [..192.168.10.50][...80] - new: [...352] [ip4][..tcp] [.....172.16.0.1][58536] -> [..192.168.10.50][...80] - new: [...353] [ip4][..tcp] [.....172.16.0.1][58550] -> [..192.168.10.50][...80] - new: [...354] [ip4][..tcp] [.....172.16.0.1][58564] -> [..192.168.10.50][...80] + new: [...348] [ip4][..tcp] [.....172.16.0.1][58468] -> [..192.168.10.50][...80] + new: [...349] [ip4][..tcp] [.....172.16.0.1][58482] -> [..192.168.10.50][...80] + new: [...350] [ip4][..tcp] [.....172.16.0.1][58496] -> [..192.168.10.50][...80] + new: [...351] [ip4][..tcp] [.....172.16.0.1][58510] -> [..192.168.10.50][...80] + new: [...352] [ip4][..tcp] [.....172.16.0.1][58536] -> [..192.168.10.50][...80] + new: [...353] [ip4][..tcp] [.....172.16.0.1][58550] -> [..192.168.10.50][...80] + new: [...354] [ip4][..tcp] [.....172.16.0.1][58564] -> [..192.168.10.50][...80] guessed: [...273] [ip4][..tcp] [.....172.16.0.1][57130] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...273] [ip4][..tcp] [.....172.16.0.1][57130] -> [..192.168.10.50][...80] + end: [...273] [ip4][..tcp] [.....172.16.0.1][57130] -> [..192.168.10.50][...80] guessed: [...274] [ip4][..tcp] [.....172.16.0.1][57144] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...274] [ip4][..tcp] [.....172.16.0.1][57144] -> [..192.168.10.50][...80] + end: [...274] [ip4][..tcp] [.....172.16.0.1][57144] -> [..192.168.10.50][...80] guessed: [...275] [ip4][..tcp] [.....172.16.0.1][57170] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...275] [ip4][..tcp] [.....172.16.0.1][57170] -> [..192.168.10.50][...80] + end: [...275] [ip4][..tcp] [.....172.16.0.1][57170] -> [..192.168.10.50][...80] guessed: [...276] [ip4][..tcp] [.....172.16.0.1][57184] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...276] [ip4][..tcp] [.....172.16.0.1][57184] -> [..192.168.10.50][...80] + end: [...276] [ip4][..tcp] [.....172.16.0.1][57184] -> [..192.168.10.50][...80] guessed: [...277] [ip4][..tcp] [.....172.16.0.1][57210] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...277] [ip4][..tcp] [.....172.16.0.1][57210] -> [..192.168.10.50][...80] + end: [...277] [ip4][..tcp] [.....172.16.0.1][57210] -> [..192.168.10.50][...80] guessed: [...278] [ip4][..tcp] [.....172.16.0.1][57224] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...278] [ip4][..tcp] [.....172.16.0.1][57224] -> [..192.168.10.50][...80] - new: [...355] [ip4][..tcp] [.....172.16.0.1][58590] -> [..192.168.10.50][...80] - new: [...356] [ip4][..tcp] [.....172.16.0.1][58604] -> [..192.168.10.50][...80] - new: [...357] [ip4][..tcp] [.....172.16.0.1][58630] -> [..192.168.10.50][...80] - new: [...358] [ip4][..tcp] [.....172.16.0.1][58650] -> [..192.168.10.50][...80] - new: [...359] [ip4][..tcp] [.....172.16.0.1][58664] -> [..192.168.10.50][...80] + end: [...278] [ip4][..tcp] [.....172.16.0.1][57224] -> [..192.168.10.50][...80] + new: [...355] [ip4][..tcp] [.....172.16.0.1][58590] -> [..192.168.10.50][...80] + new: [...356] [ip4][..tcp] [.....172.16.0.1][58604] -> [..192.168.10.50][...80] + new: [...357] [ip4][..tcp] [.....172.16.0.1][58630] -> [..192.168.10.50][...80] + new: [...358] [ip4][..tcp] [.....172.16.0.1][58650] -> [..192.168.10.50][...80] + new: [...359] [ip4][..tcp] [.....172.16.0.1][58664] -> [..192.168.10.50][...80] guessed: [...279] [ip4][..tcp] [.....172.16.0.1][57238] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...279] [ip4][..tcp] [.....172.16.0.1][57238] -> [..192.168.10.50][...80] + end: [...279] [ip4][..tcp] [.....172.16.0.1][57238] -> [..192.168.10.50][...80] guessed: [...280] [ip4][..tcp] [.....172.16.0.1][57264] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...280] [ip4][..tcp] [.....172.16.0.1][57264] -> [..192.168.10.50][...80] + end: [...280] [ip4][..tcp] [.....172.16.0.1][57264] -> [..192.168.10.50][...80] guessed: [...281] [ip4][..tcp] [.....172.16.0.1][57278] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...281] [ip4][..tcp] [.....172.16.0.1][57278] -> [..192.168.10.50][...80] + end: [...281] [ip4][..tcp] [.....172.16.0.1][57278] -> [..192.168.10.50][...80] guessed: [...282] [ip4][..tcp] [.....172.16.0.1][57292] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...282] [ip4][..tcp] [.....172.16.0.1][57292] -> [..192.168.10.50][...80] + end: [...282] [ip4][..tcp] [.....172.16.0.1][57292] -> [..192.168.10.50][...80] guessed: [...283] [ip4][..tcp] [.....172.16.0.1][57318] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...283] [ip4][..tcp] [.....172.16.0.1][57318] -> [..192.168.10.50][...80] + end: [...283] [ip4][..tcp] [.....172.16.0.1][57318] -> [..192.168.10.50][...80] guessed: [...284] [ip4][..tcp] [.....172.16.0.1][57332] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...284] [ip4][..tcp] [.....172.16.0.1][57332] -> [..192.168.10.50][...80] - new: [...360] [ip4][..tcp] [.....172.16.0.1][58690] -> [..192.168.10.50][...80] - new: [...361] [ip4][..tcp] [.....172.16.0.1][58704] -> [..192.168.10.50][...80] - new: [...362] [ip4][..tcp] [.....172.16.0.1][58718] -> [..192.168.10.50][...80] - new: [...363] [ip4][..tcp] [.....172.16.0.1][58744] -> [..192.168.10.50][...80] - new: [...364] [ip4][..tcp] [.....172.16.0.1][58758] -> [..192.168.10.50][...80] - new: [...365] [ip4][..tcp] [.....172.16.0.1][58772] -> [..192.168.10.50][...80] + end: [...284] [ip4][..tcp] [.....172.16.0.1][57332] -> [..192.168.10.50][...80] + new: [...360] [ip4][..tcp] [.....172.16.0.1][58690] -> [..192.168.10.50][...80] + new: [...361] [ip4][..tcp] [.....172.16.0.1][58704] -> [..192.168.10.50][...80] + new: [...362] [ip4][..tcp] [.....172.16.0.1][58718] -> [..192.168.10.50][...80] + new: [...363] [ip4][..tcp] [.....172.16.0.1][58744] -> [..192.168.10.50][...80] + new: [...364] [ip4][..tcp] [.....172.16.0.1][58758] -> [..192.168.10.50][...80] + new: [...365] [ip4][..tcp] [.....172.16.0.1][58772] -> [..192.168.10.50][...80] guessed: [...285] [ip4][..tcp] [.....172.16.0.1][57346] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...285] [ip4][..tcp] [.....172.16.0.1][57346] -> [..192.168.10.50][...80] + end: [...285] [ip4][..tcp] [.....172.16.0.1][57346] -> [..192.168.10.50][...80] guessed: [...286] [ip4][..tcp] [.....172.16.0.1][57372] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...286] [ip4][..tcp] [.....172.16.0.1][57372] -> [..192.168.10.50][...80] + end: [...286] [ip4][..tcp] [.....172.16.0.1][57372] -> [..192.168.10.50][...80] guessed: [...287] [ip4][..tcp] [.....172.16.0.1][57386] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...287] [ip4][..tcp] [.....172.16.0.1][57386] -> [..192.168.10.50][...80] + end: [...287] [ip4][..tcp] [.....172.16.0.1][57386] -> [..192.168.10.50][...80] guessed: [...288] [ip4][..tcp] [.....172.16.0.1][57400] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...288] [ip4][..tcp] [.....172.16.0.1][57400] -> [..192.168.10.50][...80] + end: [...288] [ip4][..tcp] [.....172.16.0.1][57400] -> [..192.168.10.50][...80] guessed: [...289] [ip4][..tcp] [.....172.16.0.1][57426] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...289] [ip4][..tcp] [.....172.16.0.1][57426] -> [..192.168.10.50][...80] + end: [...289] [ip4][..tcp] [.....172.16.0.1][57426] -> [..192.168.10.50][...80] guessed: [...290] [ip4][..tcp] [.....172.16.0.1][57440] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...290] [ip4][..tcp] [.....172.16.0.1][57440] -> [..192.168.10.50][...80] - new: [...366] [ip4][..tcp] [.....172.16.0.1][58798] -> [..192.168.10.50][...80] - new: [...367] [ip4][..tcp] [.....172.16.0.1][58812] -> [..192.168.10.50][...80] - new: [...368] [ip4][..tcp] [.....172.16.0.1][58838] -> [..192.168.10.50][...80] - new: [...369] [ip4][..tcp] [.....172.16.0.1][58852] -> [..192.168.10.50][...80] - new: [...370] [ip4][..tcp] [.....172.16.0.1][58866] -> [..192.168.10.50][...80] - new: [...371] [ip4][..tcp] [.....172.16.0.1][58892] -> [..192.168.10.50][...80] + end: [...290] [ip4][..tcp] [.....172.16.0.1][57440] -> [..192.168.10.50][...80] + new: [...366] [ip4][..tcp] [.....172.16.0.1][58798] -> [..192.168.10.50][...80] + new: [...367] [ip4][..tcp] [.....172.16.0.1][58812] -> [..192.168.10.50][...80] + new: [...368] [ip4][..tcp] [.....172.16.0.1][58838] -> [..192.168.10.50][...80] + new: [...369] [ip4][..tcp] [.....172.16.0.1][58852] -> [..192.168.10.50][...80] + new: [...370] [ip4][..tcp] [.....172.16.0.1][58866] -> [..192.168.10.50][...80] + new: [...371] [ip4][..tcp] [.....172.16.0.1][58892] -> [..192.168.10.50][...80] guessed: [...291] [ip4][..tcp] [.....172.16.0.1][57454] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...291] [ip4][..tcp] [.....172.16.0.1][57454] -> [..192.168.10.50][...80] + end: [...291] [ip4][..tcp] [.....172.16.0.1][57454] -> [..192.168.10.50][...80] guessed: [...292] [ip4][..tcp] [.....172.16.0.1][57480] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...292] [ip4][..tcp] [.....172.16.0.1][57480] -> [..192.168.10.50][...80] + end: [...292] [ip4][..tcp] [.....172.16.0.1][57480] -> [..192.168.10.50][...80] guessed: [...293] [ip4][..tcp] [.....172.16.0.1][57494] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...293] [ip4][..tcp] [.....172.16.0.1][57494] -> [..192.168.10.50][...80] + end: [...293] [ip4][..tcp] [.....172.16.0.1][57494] -> [..192.168.10.50][...80] guessed: [...294] [ip4][..tcp] [.....172.16.0.1][57508] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...294] [ip4][..tcp] [.....172.16.0.1][57508] -> [..192.168.10.50][...80] + end: [...294] [ip4][..tcp] [.....172.16.0.1][57508] -> [..192.168.10.50][...80] guessed: [...295] [ip4][..tcp] [.....172.16.0.1][57522] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...295] [ip4][..tcp] [.....172.16.0.1][57522] -> [..192.168.10.50][...80] + end: [...295] [ip4][..tcp] [.....172.16.0.1][57522] -> [..192.168.10.50][...80] guessed: [...296] [ip4][..tcp] [.....172.16.0.1][57536] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...296] [ip4][..tcp] [.....172.16.0.1][57536] -> [..192.168.10.50][...80] + end: [...296] [ip4][..tcp] [.....172.16.0.1][57536] -> [..192.168.10.50][...80] guessed: [...297] [ip4][..tcp] [.....172.16.0.1][57550] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...297] [ip4][..tcp] [.....172.16.0.1][57550] -> [..192.168.10.50][...80] - new: [...372] [ip4][..tcp] [.....172.16.0.1][58906] -> [..192.168.10.50][...80] - new: [...373] [ip4][..tcp] [.....172.16.0.1][58920] -> [..192.168.10.50][...80] - new: [...374] [ip4][..tcp] [.....172.16.0.1][58946] -> [..192.168.10.50][...80] - new: [...375] [ip4][..tcp] [.....172.16.0.1][58960] -> [..192.168.10.50][...80] - new: [...376] [ip4][..tcp] [.....172.16.0.1][58974] -> [..192.168.10.50][...80] - new: [...377] [ip4][..tcp] [.....172.16.0.1][58988] -> [..192.168.10.50][...80] - new: [...378] [ip4][..tcp] [.....172.16.0.1][59002] -> [..192.168.10.50][...80] + end: [...297] [ip4][..tcp] [.....172.16.0.1][57550] -> [..192.168.10.50][...80] + new: [...372] [ip4][..tcp] [.....172.16.0.1][58906] -> [..192.168.10.50][...80] + new: [...373] [ip4][..tcp] [.....172.16.0.1][58920] -> [..192.168.10.50][...80] + new: [...374] [ip4][..tcp] [.....172.16.0.1][58946] -> [..192.168.10.50][...80] + new: [...375] [ip4][..tcp] [.....172.16.0.1][58960] -> [..192.168.10.50][...80] + new: [...376] [ip4][..tcp] [.....172.16.0.1][58974] -> [..192.168.10.50][...80] + new: [...377] [ip4][..tcp] [.....172.16.0.1][58988] -> [..192.168.10.50][...80] + new: [...378] [ip4][..tcp] [.....172.16.0.1][59002] -> [..192.168.10.50][...80] end: [...265] [ip4][..tcp] [.....172.16.0.1][56994] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...298] [ip4][..tcp] [.....172.16.0.1][57576] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...298] [ip4][..tcp] [.....172.16.0.1][57576] -> [..192.168.10.50][...80] + end: [...298] [ip4][..tcp] [.....172.16.0.1][57576] -> [..192.168.10.50][...80] guessed: [...299] [ip4][..tcp] [.....172.16.0.1][57590] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...299] [ip4][..tcp] [.....172.16.0.1][57590] -> [..192.168.10.50][...80] + end: [...299] [ip4][..tcp] [.....172.16.0.1][57590] -> [..192.168.10.50][...80] guessed: [...300] [ip4][..tcp] [.....172.16.0.1][57604] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...300] [ip4][..tcp] [.....172.16.0.1][57604] -> [..192.168.10.50][...80] + end: [...300] [ip4][..tcp] [.....172.16.0.1][57604] -> [..192.168.10.50][...80] guessed: [...301] [ip4][..tcp] [.....172.16.0.1][57630] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...301] [ip4][..tcp] [.....172.16.0.1][57630] -> [..192.168.10.50][...80] + end: [...301] [ip4][..tcp] [.....172.16.0.1][57630] -> [..192.168.10.50][...80] guessed: [...302] [ip4][..tcp] [.....172.16.0.1][57644] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...302] [ip4][..tcp] [.....172.16.0.1][57644] -> [..192.168.10.50][...80] + end: [...302] [ip4][..tcp] [.....172.16.0.1][57644] -> [..192.168.10.50][...80] guessed: [...303] [ip4][..tcp] [.....172.16.0.1][57658] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...303] [ip4][..tcp] [.....172.16.0.1][57658] -> [..192.168.10.50][...80] - new: [...379] [ip4][..tcp] [.....172.16.0.1][59016] -> [..192.168.10.50][...80] - new: [...380] [ip4][..tcp] [.....172.16.0.1][59042] -> [..192.168.10.50][...80] - new: [...381] [ip4][..tcp] [.....172.16.0.1][59056] -> [..192.168.10.50][...80] - new: [...382] [ip4][..tcp] [.....172.16.0.1][59070] -> [..192.168.10.50][...80] + end: [...303] [ip4][..tcp] [.....172.16.0.1][57658] -> [..192.168.10.50][...80] + new: [...379] [ip4][..tcp] [.....172.16.0.1][59016] -> [..192.168.10.50][...80] + new: [...380] [ip4][..tcp] [.....172.16.0.1][59042] -> [..192.168.10.50][...80] + new: [...381] [ip4][..tcp] [.....172.16.0.1][59056] -> [..192.168.10.50][...80] + new: [...382] [ip4][..tcp] [.....172.16.0.1][59070] -> [..192.168.10.50][...80] detected: [...380] [ip4][..tcp] [.....172.16.0.1][59042] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...383] [ip4][..tcp] [.....172.16.0.1][59096] -> [..192.168.10.50][...80] - new: [...384] [ip4][..tcp] [.....172.16.0.1][59110] -> [..192.168.10.50][...80] + new: [...383] [ip4][..tcp] [.....172.16.0.1][59096] -> [..192.168.10.50][...80] + new: [...384] [ip4][..tcp] [.....172.16.0.1][59110] -> [..192.168.10.50][...80] guessed: [...305] [ip4][..tcp] [.....172.16.0.1][57698] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...305] [ip4][..tcp] [.....172.16.0.1][57698] -> [..192.168.10.50][...80] + end: [...305] [ip4][..tcp] [.....172.16.0.1][57698] -> [..192.168.10.50][...80] guessed: [...306] [ip4][..tcp] [.....172.16.0.1][57712] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...306] [ip4][..tcp] [.....172.16.0.1][57712] -> [..192.168.10.50][...80] + end: [...306] [ip4][..tcp] [.....172.16.0.1][57712] -> [..192.168.10.50][...80] guessed: [...307] [ip4][..tcp] [.....172.16.0.1][57738] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...307] [ip4][..tcp] [.....172.16.0.1][57738] -> [..192.168.10.50][...80] + end: [...307] [ip4][..tcp] [.....172.16.0.1][57738] -> [..192.168.10.50][...80] guessed: [...308] [ip4][..tcp] [.....172.16.0.1][57752] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...308] [ip4][..tcp] [.....172.16.0.1][57752] -> [..192.168.10.50][...80] - new: [...385] [ip4][..tcp] [.....172.16.0.1][59124] -> [..192.168.10.50][...80] + end: [...308] [ip4][..tcp] [.....172.16.0.1][57752] -> [..192.168.10.50][...80] + new: [...385] [ip4][..tcp] [.....172.16.0.1][59124] -> [..192.168.10.50][...80] analyse: [...380] [ip4][..tcp] [.....172.16.0.1][59042] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.823| 0.637| 1.173| 1374936.236| 3.400] @@ -1152,121 +1152,121 @@ [IATS(ms)....: 0.1,1.1,4821.8,4822.9,2.9,6.0,222.0,227.9,5.0,1.0,1005.0,1011.2,4.1,265.5,269.3,3.6,1019.9,1023.5,4.0,238.2,242.3,4.8,1006.0,1010.7,4.0,237.9,242.4,5.0,1011.0,1016.0,5.0] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1921,52,52,435,1822,52,637,1919,52,435,1822,52,637,1921,52,435,1822,52,637,1919,52,435,1822,52] [ENTROPIES...: 4.6,5.1,4.9,5.9,4.8,7.7,4.9,6.0,7.8,4.9,4.9,5.8,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.7,5.0,5.9,7.7,5.0] - new: [...386] [ip4][..tcp] [.....172.16.0.1][59150] -> [..192.168.10.50][...80] - new: [...387] [ip4][..tcp] [.....172.16.0.1][59164] -> [..192.168.10.50][...80] - new: [...388] [ip4][..tcp] [.....172.16.0.1][59178] -> [..192.168.10.50][...80] - new: [...389] [ip4][..tcp] [.....172.16.0.1][59192] -> [..192.168.10.50][...80] - new: [...390] [ip4][..tcp] [.....172.16.0.1][59206] -> [..192.168.10.50][...80] - new: [...391] [ip4][..tcp] [.....172.16.0.1][59220] -> [..192.168.10.50][...80] + new: [...386] [ip4][..tcp] [.....172.16.0.1][59150] -> [..192.168.10.50][...80] + new: [...387] [ip4][..tcp] [.....172.16.0.1][59164] -> [..192.168.10.50][...80] + new: [...388] [ip4][..tcp] [.....172.16.0.1][59178] -> [..192.168.10.50][...80] + new: [...389] [ip4][..tcp] [.....172.16.0.1][59192] -> [..192.168.10.50][...80] + new: [...390] [ip4][..tcp] [.....172.16.0.1][59206] -> [..192.168.10.50][...80] + new: [...391] [ip4][..tcp] [.....172.16.0.1][59220] -> [..192.168.10.50][...80] guessed: [...309] [ip4][..tcp] [.....172.16.0.1][57778] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...309] [ip4][..tcp] [.....172.16.0.1][57778] -> [..192.168.10.50][...80] + end: [...309] [ip4][..tcp] [.....172.16.0.1][57778] -> [..192.168.10.50][...80] guessed: [...310] [ip4][..tcp] [.....172.16.0.1][57792] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...310] [ip4][..tcp] [.....172.16.0.1][57792] -> [..192.168.10.50][...80] + end: [...310] [ip4][..tcp] [.....172.16.0.1][57792] -> [..192.168.10.50][...80] guessed: [...311] [ip4][..tcp] [.....172.16.0.1][57806] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...311] [ip4][..tcp] [.....172.16.0.1][57806] -> [..192.168.10.50][...80] + end: [...311] [ip4][..tcp] [.....172.16.0.1][57806] -> [..192.168.10.50][...80] guessed: [...312] [ip4][..tcp] [.....172.16.0.1][57832] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...312] [ip4][..tcp] [.....172.16.0.1][57832] -> [..192.168.10.50][...80] + end: [...312] [ip4][..tcp] [.....172.16.0.1][57832] -> [..192.168.10.50][...80] guessed: [...313] [ip4][..tcp] [.....172.16.0.1][57846] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...313] [ip4][..tcp] [.....172.16.0.1][57846] -> [..192.168.10.50][...80] + end: [...313] [ip4][..tcp] [.....172.16.0.1][57846] -> [..192.168.10.50][...80] guessed: [...314] [ip4][..tcp] [.....172.16.0.1][57860] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...314] [ip4][..tcp] [.....172.16.0.1][57860] -> [..192.168.10.50][...80] - new: [...392] [ip4][..tcp] [.....172.16.0.1][59246] -> [..192.168.10.50][...80] - new: [...393] [ip4][..tcp] [.....172.16.0.1][59260] -> [..192.168.10.50][...80] - new: [...394] [ip4][..tcp] [.....172.16.0.1][59274] -> [..192.168.10.50][...80] - new: [...395] [ip4][..tcp] [.....172.16.0.1][59300] -> [..192.168.10.50][...80] - new: [...396] [ip4][..tcp] [.....172.16.0.1][59314] -> [..192.168.10.50][...80] - new: [...397] [ip4][..tcp] [.....172.16.0.1][59328] -> [..192.168.10.50][...80] + end: [...314] [ip4][..tcp] [.....172.16.0.1][57860] -> [..192.168.10.50][...80] + new: [...392] [ip4][..tcp] [.....172.16.0.1][59246] -> [..192.168.10.50][...80] + new: [...393] [ip4][..tcp] [.....172.16.0.1][59260] -> [..192.168.10.50][...80] + new: [...394] [ip4][..tcp] [.....172.16.0.1][59274] -> [..192.168.10.50][...80] + new: [...395] [ip4][..tcp] [.....172.16.0.1][59300] -> [..192.168.10.50][...80] + new: [...396] [ip4][..tcp] [.....172.16.0.1][59314] -> [..192.168.10.50][...80] + new: [...397] [ip4][..tcp] [.....172.16.0.1][59328] -> [..192.168.10.50][...80] guessed: [...315] [ip4][..tcp] [.....172.16.0.1][57886] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...315] [ip4][..tcp] [.....172.16.0.1][57886] -> [..192.168.10.50][...80] + end: [...315] [ip4][..tcp] [.....172.16.0.1][57886] -> [..192.168.10.50][...80] guessed: [...316] [ip4][..tcp] [.....172.16.0.1][57900] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...316] [ip4][..tcp] [.....172.16.0.1][57900] -> [..192.168.10.50][...80] + end: [...316] [ip4][..tcp] [.....172.16.0.1][57900] -> [..192.168.10.50][...80] guessed: [...317] [ip4][..tcp] [.....172.16.0.1][57914] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...317] [ip4][..tcp] [.....172.16.0.1][57914] -> [..192.168.10.50][...80] + end: [...317] [ip4][..tcp] [.....172.16.0.1][57914] -> [..192.168.10.50][...80] guessed: [...318] [ip4][..tcp] [.....172.16.0.1][57940] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...318] [ip4][..tcp] [.....172.16.0.1][57940] -> [..192.168.10.50][...80] + end: [...318] [ip4][..tcp] [.....172.16.0.1][57940] -> [..192.168.10.50][...80] guessed: [...319] [ip4][..tcp] [.....172.16.0.1][57954] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...319] [ip4][..tcp] [.....172.16.0.1][57954] -> [..192.168.10.50][...80] + end: [...319] [ip4][..tcp] [.....172.16.0.1][57954] -> [..192.168.10.50][...80] guessed: [...320] [ip4][..tcp] [.....172.16.0.1][57980] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...320] [ip4][..tcp] [.....172.16.0.1][57980] -> [..192.168.10.50][...80] - new: [...398] [ip4][..tcp] [.....172.16.0.1][59354] -> [..192.168.10.50][...80] - new: [...399] [ip4][..tcp] [.....172.16.0.1][59368] -> [..192.168.10.50][...80] - new: [...400] [ip4][..tcp] [.....172.16.0.1][59382] -> [..192.168.10.50][...80] - new: [...401] [ip4][..tcp] [.....172.16.0.1][59408] -> [..192.168.10.50][...80] - new: [...402] [ip4][..tcp] [.....172.16.0.1][59422] -> [..192.168.10.50][...80] - new: [...403] [ip4][..tcp] [.....172.16.0.1][59436] -> [..192.168.10.50][...80] + end: [...320] [ip4][..tcp] [.....172.16.0.1][57980] -> [..192.168.10.50][...80] + new: [...398] [ip4][..tcp] [.....172.16.0.1][59354] -> [..192.168.10.50][...80] + new: [...399] [ip4][..tcp] [.....172.16.0.1][59368] -> [..192.168.10.50][...80] + new: [...400] [ip4][..tcp] [.....172.16.0.1][59382] -> [..192.168.10.50][...80] + new: [...401] [ip4][..tcp] [.....172.16.0.1][59408] -> [..192.168.10.50][...80] + new: [...402] [ip4][..tcp] [.....172.16.0.1][59422] -> [..192.168.10.50][...80] + new: [...403] [ip4][..tcp] [.....172.16.0.1][59436] -> [..192.168.10.50][...80] guessed: [...321] [ip4][..tcp] [.....172.16.0.1][57994] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...321] [ip4][..tcp] [.....172.16.0.1][57994] -> [..192.168.10.50][...80] + end: [...321] [ip4][..tcp] [.....172.16.0.1][57994] -> [..192.168.10.50][...80] guessed: [...322] [ip4][..tcp] [.....172.16.0.1][58008] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...322] [ip4][..tcp] [.....172.16.0.1][58008] -> [..192.168.10.50][...80] + end: [...322] [ip4][..tcp] [.....172.16.0.1][58008] -> [..192.168.10.50][...80] guessed: [...323] [ip4][..tcp] [.....172.16.0.1][58034] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...323] [ip4][..tcp] [.....172.16.0.1][58034] -> [..192.168.10.50][...80] + end: [...323] [ip4][..tcp] [.....172.16.0.1][58034] -> [..192.168.10.50][...80] guessed: [...324] [ip4][..tcp] [.....172.16.0.1][58048] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...324] [ip4][..tcp] [.....172.16.0.1][58048] -> [..192.168.10.50][...80] + end: [...324] [ip4][..tcp] [.....172.16.0.1][58048] -> [..192.168.10.50][...80] guessed: [...325] [ip4][..tcp] [.....172.16.0.1][58062] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...325] [ip4][..tcp] [.....172.16.0.1][58062] -> [..192.168.10.50][...80] + end: [...325] [ip4][..tcp] [.....172.16.0.1][58062] -> [..192.168.10.50][...80] guessed: [...326] [ip4][..tcp] [.....172.16.0.1][58088] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...326] [ip4][..tcp] [.....172.16.0.1][58088] -> [..192.168.10.50][...80] - new: [...404] [ip4][..tcp] [.....172.16.0.1][59462] -> [..192.168.10.50][...80] - new: [...405] [ip4][..tcp] [.....172.16.0.1][59476] -> [..192.168.10.50][...80] - new: [...406] [ip4][..tcp] [.....172.16.0.1][59502] -> [..192.168.10.50][...80] - new: [...407] [ip4][..tcp] [.....172.16.0.1][59516] -> [..192.168.10.50][...80] - new: [...408] [ip4][..tcp] [.....172.16.0.1][59530] -> [..192.168.10.50][...80] + end: [...326] [ip4][..tcp] [.....172.16.0.1][58088] -> [..192.168.10.50][...80] + new: [...404] [ip4][..tcp] [.....172.16.0.1][59462] -> [..192.168.10.50][...80] + new: [...405] [ip4][..tcp] [.....172.16.0.1][59476] -> [..192.168.10.50][...80] + new: [...406] [ip4][..tcp] [.....172.16.0.1][59502] -> [..192.168.10.50][...80] + new: [...407] [ip4][..tcp] [.....172.16.0.1][59516] -> [..192.168.10.50][...80] + new: [...408] [ip4][..tcp] [.....172.16.0.1][59530] -> [..192.168.10.50][...80] guessed: [...327] [ip4][..tcp] [.....172.16.0.1][58102] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...327] [ip4][..tcp] [.....172.16.0.1][58102] -> [..192.168.10.50][...80] + end: [...327] [ip4][..tcp] [.....172.16.0.1][58102] -> [..192.168.10.50][...80] guessed: [...328] [ip4][..tcp] [.....172.16.0.1][58116] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...328] [ip4][..tcp] [.....172.16.0.1][58116] -> [..192.168.10.50][...80] + end: [...328] [ip4][..tcp] [.....172.16.0.1][58116] -> [..192.168.10.50][...80] guessed: [...329] [ip4][..tcp] [.....172.16.0.1][58130] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...329] [ip4][..tcp] [.....172.16.0.1][58130] -> [..192.168.10.50][...80] + end: [...329] [ip4][..tcp] [.....172.16.0.1][58130] -> [..192.168.10.50][...80] guessed: [...330] [ip4][..tcp] [.....172.16.0.1][58144] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...330] [ip4][..tcp] [.....172.16.0.1][58144] -> [..192.168.10.50][...80] + end: [...330] [ip4][..tcp] [.....172.16.0.1][58144] -> [..192.168.10.50][...80] guessed: [...331] [ip4][..tcp] [.....172.16.0.1][58158] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...331] [ip4][..tcp] [.....172.16.0.1][58158] -> [..192.168.10.50][...80] + end: [...331] [ip4][..tcp] [.....172.16.0.1][58158] -> [..192.168.10.50][...80] guessed: [...332] [ip4][..tcp] [.....172.16.0.1][58184] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...332] [ip4][..tcp] [.....172.16.0.1][58184] -> [..192.168.10.50][...80] + end: [...332] [ip4][..tcp] [.....172.16.0.1][58184] -> [..192.168.10.50][...80] guessed: [...333] [ip4][..tcp] [.....172.16.0.1][58198] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...333] [ip4][..tcp] [.....172.16.0.1][58198] -> [..192.168.10.50][...80] - new: [...409] [ip4][..tcp] [.....172.16.0.1][59556] -> [..192.168.10.50][...80] - new: [...410] [ip4][..tcp] [.....172.16.0.1][59570] -> [..192.168.10.50][...80] - new: [...411] [ip4][..tcp] [.....172.16.0.1][59584] -> [..192.168.10.50][...80] - new: [...412] [ip4][..tcp] [.....172.16.0.1][59610] -> [..192.168.10.50][...80] - new: [...413] [ip4][..tcp] [.....172.16.0.1][59624] -> [..192.168.10.50][...80] - new: [...414] [ip4][..tcp] [.....172.16.0.1][59650] -> [..192.168.10.50][...80] + end: [...333] [ip4][..tcp] [.....172.16.0.1][58198] -> [..192.168.10.50][...80] + new: [...409] [ip4][..tcp] [.....172.16.0.1][59556] -> [..192.168.10.50][...80] + new: [...410] [ip4][..tcp] [.....172.16.0.1][59570] -> [..192.168.10.50][...80] + new: [...411] [ip4][..tcp] [.....172.16.0.1][59584] -> [..192.168.10.50][...80] + new: [...412] [ip4][..tcp] [.....172.16.0.1][59610] -> [..192.168.10.50][...80] + new: [...413] [ip4][..tcp] [.....172.16.0.1][59624] -> [..192.168.10.50][...80] + new: [...414] [ip4][..tcp] [.....172.16.0.1][59650] -> [..192.168.10.50][...80] guessed: [...334] [ip4][..tcp] [.....172.16.0.1][58224] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...334] [ip4][..tcp] [.....172.16.0.1][58224] -> [..192.168.10.50][...80] + end: [...334] [ip4][..tcp] [.....172.16.0.1][58224] -> [..192.168.10.50][...80] guessed: [...335] [ip4][..tcp] [.....172.16.0.1][58238] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...335] [ip4][..tcp] [.....172.16.0.1][58238] -> [..192.168.10.50][...80] + end: [...335] [ip4][..tcp] [.....172.16.0.1][58238] -> [..192.168.10.50][...80] guessed: [...336] [ip4][..tcp] [.....172.16.0.1][58252] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...336] [ip4][..tcp] [.....172.16.0.1][58252] -> [..192.168.10.50][...80] + end: [...336] [ip4][..tcp] [.....172.16.0.1][58252] -> [..192.168.10.50][...80] guessed: [...337] [ip4][..tcp] [.....172.16.0.1][58278] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...337] [ip4][..tcp] [.....172.16.0.1][58278] -> [..192.168.10.50][...80] + end: [...337] [ip4][..tcp] [.....172.16.0.1][58278] -> [..192.168.10.50][...80] guessed: [...338] [ip4][..tcp] [.....172.16.0.1][58292] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...338] [ip4][..tcp] [.....172.16.0.1][58292] -> [..192.168.10.50][...80] + end: [...338] [ip4][..tcp] [.....172.16.0.1][58292] -> [..192.168.10.50][...80] guessed: [...339] [ip4][..tcp] [.....172.16.0.1][58306] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...339] [ip4][..tcp] [.....172.16.0.1][58306] -> [..192.168.10.50][...80] - new: [...415] [ip4][..tcp] [.....172.16.0.1][59664] -> [..192.168.10.50][...80] - new: [...416] [ip4][..tcp] [.....172.16.0.1][59678] -> [..192.168.10.50][...80] - new: [...417] [ip4][..tcp] [.....172.16.0.1][59704] -> [..192.168.10.50][...80] - new: [...418] [ip4][..tcp] [.....172.16.0.1][59718] -> [..192.168.10.50][...80] - new: [...419] [ip4][..tcp] [.....172.16.0.1][59732] -> [..192.168.10.50][...80] - new: [...420] [ip4][..tcp] [.....172.16.0.1][59758] -> [..192.168.10.50][...80] + end: [...339] [ip4][..tcp] [.....172.16.0.1][58306] -> [..192.168.10.50][...80] + new: [...415] [ip4][..tcp] [.....172.16.0.1][59664] -> [..192.168.10.50][...80] + new: [...416] [ip4][..tcp] [.....172.16.0.1][59678] -> [..192.168.10.50][...80] + new: [...417] [ip4][..tcp] [.....172.16.0.1][59704] -> [..192.168.10.50][...80] + new: [...418] [ip4][..tcp] [.....172.16.0.1][59718] -> [..192.168.10.50][...80] + new: [...419] [ip4][..tcp] [.....172.16.0.1][59732] -> [..192.168.10.50][...80] + new: [...420] [ip4][..tcp] [.....172.16.0.1][59758] -> [..192.168.10.50][...80] end: [...304] [ip4][..tcp] [.....172.16.0.1][57684] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...340] [ip4][..tcp] [.....172.16.0.1][58332] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...340] [ip4][..tcp] [.....172.16.0.1][58332] -> [..192.168.10.50][...80] + end: [...340] [ip4][..tcp] [.....172.16.0.1][58332] -> [..192.168.10.50][...80] guessed: [...341] [ip4][..tcp] [.....172.16.0.1][58346] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...341] [ip4][..tcp] [.....172.16.0.1][58346] -> [..192.168.10.50][...80] + end: [...341] [ip4][..tcp] [.....172.16.0.1][58346] -> [..192.168.10.50][...80] guessed: [...343] [ip4][..tcp] [.....172.16.0.1][58386] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...343] [ip4][..tcp] [.....172.16.0.1][58386] -> [..192.168.10.50][...80] + end: [...343] [ip4][..tcp] [.....172.16.0.1][58386] -> [..192.168.10.50][...80] guessed: [...344] [ip4][..tcp] [.....172.16.0.1][58400] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...344] [ip4][..tcp] [.....172.16.0.1][58400] -> [..192.168.10.50][...80] + end: [...344] [ip4][..tcp] [.....172.16.0.1][58400] -> [..192.168.10.50][...80] guessed: [...345] [ip4][..tcp] [.....172.16.0.1][58414] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...345] [ip4][..tcp] [.....172.16.0.1][58414] -> [..192.168.10.50][...80] - new: [...421] [ip4][..tcp] [.....172.16.0.1][59772] -> [..192.168.10.50][...80] + end: [...345] [ip4][..tcp] [.....172.16.0.1][58414] -> [..192.168.10.50][...80] + new: [...421] [ip4][..tcp] [.....172.16.0.1][59772] -> [..192.168.10.50][...80] detected: [...419] [ip4][..tcp] [.....172.16.0.1][59732] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...422] [ip4][..tcp] [.....172.16.0.1][59786] -> [..192.168.10.50][...80] - new: [...423] [ip4][..tcp] [.....172.16.0.1][59812] -> [..192.168.10.50][...80] - new: [...424] [ip4][..tcp] [.....172.16.0.1][59826] -> [..192.168.10.50][...80] + new: [...422] [ip4][..tcp] [.....172.16.0.1][59786] -> [..192.168.10.50][...80] + new: [...423] [ip4][..tcp] [.....172.16.0.1][59812] -> [..192.168.10.50][...80] + new: [...424] [ip4][..tcp] [.....172.16.0.1][59826] -> [..192.168.10.50][...80] analyse: [...419] [ip4][..tcp] [.....172.16.0.1][59732] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.767| 0.604| 0.933| 871184.138| 3.700] @@ -1277,135 +1277,135 @@ [IATS(ms)....: 0.1,0.7,3766.4,3767.0,3.5,4.2,1039.9,1045.4,5.5,227.3,230.9,3.6,1037.1,1040.9,3.8,252.9,256.6,3.8,1024.0,1027.8,3.7,237.3,241.0,3.6,1007.8,1011.5,3.7,235.0,238.7,3.7,1007.2] [PKTLENS.....: 60,60,52,637,52,1920,52,435,1822,52,637,1918,52,435,1822,52,637,1921,52,435,1822,52,637,1919,52,435,1822,52,637,1920,52,435] [ENTROPIES...: 4.6,5.1,4.9,6.0,4.9,7.8,4.9,5.9,7.7,5.0,6.0,7.8,4.8,5.9,7.7,4.9,6.0,7.8,4.8,5.9,7.7,4.9,6.0,7.8,4.8,5.9,7.7,4.9,6.0,7.8,4.9,5.9] - new: [...425] [ip4][..tcp] [.....172.16.0.1][59852] -> [..192.168.10.50][...80] - new: [...426] [ip4][..tcp] [.....172.16.0.1][59866] -> [..192.168.10.50][...80] + new: [...425] [ip4][..tcp] [.....172.16.0.1][59852] -> [..192.168.10.50][...80] + new: [...426] [ip4][..tcp] [.....172.16.0.1][59866] -> [..192.168.10.50][...80] guessed: [...346] [ip4][..tcp] [.....172.16.0.1][58440] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...346] [ip4][..tcp] [.....172.16.0.1][58440] -> [..192.168.10.50][...80] + end: [...346] [ip4][..tcp] [.....172.16.0.1][58440] -> [..192.168.10.50][...80] guessed: [...347] [ip4][..tcp] [.....172.16.0.1][58454] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...347] [ip4][..tcp] [.....172.16.0.1][58454] -> [..192.168.10.50][...80] + end: [...347] [ip4][..tcp] [.....172.16.0.1][58454] -> [..192.168.10.50][...80] guessed: [...348] [ip4][..tcp] [.....172.16.0.1][58468] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...348] [ip4][..tcp] [.....172.16.0.1][58468] -> [..192.168.10.50][...80] + end: [...348] [ip4][..tcp] [.....172.16.0.1][58468] -> [..192.168.10.50][...80] guessed: [...349] [ip4][..tcp] [.....172.16.0.1][58482] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...349] [ip4][..tcp] [.....172.16.0.1][58482] -> [..192.168.10.50][...80] + end: [...349] [ip4][..tcp] [.....172.16.0.1][58482] -> [..192.168.10.50][...80] guessed: [...350] [ip4][..tcp] [.....172.16.0.1][58496] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...350] [ip4][..tcp] [.....172.16.0.1][58496] -> [..192.168.10.50][...80] + end: [...350] [ip4][..tcp] [.....172.16.0.1][58496] -> [..192.168.10.50][...80] guessed: [...351] [ip4][..tcp] [.....172.16.0.1][58510] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...351] [ip4][..tcp] [.....172.16.0.1][58510] -> [..192.168.10.50][...80] - new: [...427] [ip4][..tcp] [.....172.16.0.1][59880] -> [..192.168.10.50][...80] - new: [...428] [ip4][..tcp] [.....172.16.0.1][59906] -> [..192.168.10.50][...80] - new: [...429] [ip4][..tcp] [.....172.16.0.1][59920] -> [..192.168.10.50][...80] - new: [...430] [ip4][..tcp] [.....172.16.0.1][59934] -> [..192.168.10.50][...80] - new: [...431] [ip4][..tcp] [.....172.16.0.1][59960] -> [..192.168.10.50][...80] - new: [...432] [ip4][..tcp] [.....172.16.0.1][59974] -> [..192.168.10.50][...80] + end: [...351] [ip4][..tcp] [.....172.16.0.1][58510] -> [..192.168.10.50][...80] + new: [...427] [ip4][..tcp] [.....172.16.0.1][59880] -> [..192.168.10.50][...80] + new: [...428] [ip4][..tcp] [.....172.16.0.1][59906] -> [..192.168.10.50][...80] + new: [...429] [ip4][..tcp] [.....172.16.0.1][59920] -> [..192.168.10.50][...80] + new: [...430] [ip4][..tcp] [.....172.16.0.1][59934] -> [..192.168.10.50][...80] + new: [...431] [ip4][..tcp] [.....172.16.0.1][59960] -> [..192.168.10.50][...80] + new: [...432] [ip4][..tcp] [.....172.16.0.1][59974] -> [..192.168.10.50][...80] guessed: [...352] [ip4][..tcp] [.....172.16.0.1][58536] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...352] [ip4][..tcp] [.....172.16.0.1][58536] -> [..192.168.10.50][...80] + end: [...352] [ip4][..tcp] [.....172.16.0.1][58536] -> [..192.168.10.50][...80] guessed: [...353] [ip4][..tcp] [.....172.16.0.1][58550] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...353] [ip4][..tcp] [.....172.16.0.1][58550] -> [..192.168.10.50][...80] + end: [...353] [ip4][..tcp] [.....172.16.0.1][58550] -> [..192.168.10.50][...80] guessed: [...354] [ip4][..tcp] [.....172.16.0.1][58564] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...354] [ip4][..tcp] [.....172.16.0.1][58564] -> [..192.168.10.50][...80] + end: [...354] [ip4][..tcp] [.....172.16.0.1][58564] -> [..192.168.10.50][...80] guessed: [...355] [ip4][..tcp] [.....172.16.0.1][58590] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...355] [ip4][..tcp] [.....172.16.0.1][58590] -> [..192.168.10.50][...80] + end: [...355] [ip4][..tcp] [.....172.16.0.1][58590] -> [..192.168.10.50][...80] guessed: [...356] [ip4][..tcp] [.....172.16.0.1][58604] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...356] [ip4][..tcp] [.....172.16.0.1][58604] -> [..192.168.10.50][...80] + end: [...356] [ip4][..tcp] [.....172.16.0.1][58604] -> [..192.168.10.50][...80] guessed: [...357] [ip4][..tcp] [.....172.16.0.1][58630] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...357] [ip4][..tcp] [.....172.16.0.1][58630] -> [..192.168.10.50][...80] - new: [...433] [ip4][..tcp] [.....172.16.0.1][59988] -> [..192.168.10.50][...80] - new: [...434] [ip4][..tcp] [.....172.16.0.1][60014] -> [..192.168.10.50][...80] - new: [...435] [ip4][..tcp] [.....172.16.0.1][60028] -> [..192.168.10.50][...80] - new: [...436] [ip4][..tcp] [.....172.16.0.1][60042] -> [..192.168.10.50][...80] - new: [...437] [ip4][..tcp] [.....172.16.0.1][60056] -> [..192.168.10.50][...80] - new: [...438] [ip4][..tcp] [.....172.16.0.1][60084] -> [..192.168.10.50][...80] + end: [...357] [ip4][..tcp] [.....172.16.0.1][58630] -> [..192.168.10.50][...80] + new: [...433] [ip4][..tcp] [.....172.16.0.1][59988] -> [..192.168.10.50][...80] + new: [...434] [ip4][..tcp] [.....172.16.0.1][60014] -> [..192.168.10.50][...80] + new: [...435] [ip4][..tcp] [.....172.16.0.1][60028] -> [..192.168.10.50][...80] + new: [...436] [ip4][..tcp] [.....172.16.0.1][60042] -> [..192.168.10.50][...80] + new: [...437] [ip4][..tcp] [.....172.16.0.1][60056] -> [..192.168.10.50][...80] + new: [...438] [ip4][..tcp] [.....172.16.0.1][60084] -> [..192.168.10.50][...80] guessed: [...358] [ip4][..tcp] [.....172.16.0.1][58650] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...358] [ip4][..tcp] [.....172.16.0.1][58650] -> [..192.168.10.50][...80] + end: [...358] [ip4][..tcp] [.....172.16.0.1][58650] -> [..192.168.10.50][...80] guessed: [...359] [ip4][..tcp] [.....172.16.0.1][58664] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...359] [ip4][..tcp] [.....172.16.0.1][58664] -> [..192.168.10.50][...80] + end: [...359] [ip4][..tcp] [.....172.16.0.1][58664] -> [..192.168.10.50][...80] guessed: [...360] [ip4][..tcp] [.....172.16.0.1][58690] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...360] [ip4][..tcp] [.....172.16.0.1][58690] -> [..192.168.10.50][...80] + end: [...360] [ip4][..tcp] [.....172.16.0.1][58690] -> [..192.168.10.50][...80] guessed: [...361] [ip4][..tcp] [.....172.16.0.1][58704] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...361] [ip4][..tcp] [.....172.16.0.1][58704] -> [..192.168.10.50][...80] + end: [...361] [ip4][..tcp] [.....172.16.0.1][58704] -> [..192.168.10.50][...80] guessed: [...362] [ip4][..tcp] [.....172.16.0.1][58718] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...362] [ip4][..tcp] [.....172.16.0.1][58718] -> [..192.168.10.50][...80] + end: [...362] [ip4][..tcp] [.....172.16.0.1][58718] -> [..192.168.10.50][...80] guessed: [...363] [ip4][..tcp] [.....172.16.0.1][58744] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...363] [ip4][..tcp] [.....172.16.0.1][58744] -> [..192.168.10.50][...80] - new: [...439] [ip4][..tcp] [.....172.16.0.1][60134] -> [..192.168.10.50][...80] - new: [...440] [ip4][..tcp] [.....172.16.0.1][60136] -> [..192.168.10.50][...80] - new: [...441] [ip4][..tcp] [.....172.16.0.1][60154] -> [..192.168.10.50][...80] - new: [...442] [ip4][..tcp] [.....172.16.0.1][60180] -> [..192.168.10.50][...80] - new: [...443] [ip4][..tcp] [.....172.16.0.1][60194] -> [..192.168.10.50][...80] - new: [...444] [ip4][..tcp] [.....172.16.0.1][60220] -> [..192.168.10.50][...80] + end: [...363] [ip4][..tcp] [.....172.16.0.1][58744] -> [..192.168.10.50][...80] + new: [...439] [ip4][..tcp] [.....172.16.0.1][60134] -> [..192.168.10.50][...80] + new: [...440] [ip4][..tcp] [.....172.16.0.1][60136] -> [..192.168.10.50][...80] + new: [...441] [ip4][..tcp] [.....172.16.0.1][60154] -> [..192.168.10.50][...80] + new: [...442] [ip4][..tcp] [.....172.16.0.1][60180] -> [..192.168.10.50][...80] + new: [...443] [ip4][..tcp] [.....172.16.0.1][60194] -> [..192.168.10.50][...80] + new: [...444] [ip4][..tcp] [.....172.16.0.1][60220] -> [..192.168.10.50][...80] guessed: [...364] [ip4][..tcp] [.....172.16.0.1][58758] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...364] [ip4][..tcp] [.....172.16.0.1][58758] -> [..192.168.10.50][...80] + end: [...364] [ip4][..tcp] [.....172.16.0.1][58758] -> [..192.168.10.50][...80] guessed: [...365] [ip4][..tcp] [.....172.16.0.1][58772] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...365] [ip4][..tcp] [.....172.16.0.1][58772] -> [..192.168.10.50][...80] + end: [...365] [ip4][..tcp] [.....172.16.0.1][58772] -> [..192.168.10.50][...80] guessed: [...366] [ip4][..tcp] [.....172.16.0.1][58798] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...366] [ip4][..tcp] [.....172.16.0.1][58798] -> [..192.168.10.50][...80] + end: [...366] [ip4][..tcp] [.....172.16.0.1][58798] -> [..192.168.10.50][...80] guessed: [...367] [ip4][..tcp] [.....172.16.0.1][58812] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...367] [ip4][..tcp] [.....172.16.0.1][58812] -> [..192.168.10.50][...80] + end: [...367] [ip4][..tcp] [.....172.16.0.1][58812] -> [..192.168.10.50][...80] guessed: [...368] [ip4][..tcp] [.....172.16.0.1][58838] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...368] [ip4][..tcp] [.....172.16.0.1][58838] -> [..192.168.10.50][...80] + end: [...368] [ip4][..tcp] [.....172.16.0.1][58838] -> [..192.168.10.50][...80] guessed: [...369] [ip4][..tcp] [.....172.16.0.1][58852] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...369] [ip4][..tcp] [.....172.16.0.1][58852] -> [..192.168.10.50][...80] + end: [...369] [ip4][..tcp] [.....172.16.0.1][58852] -> [..192.168.10.50][...80] guessed: [...370] [ip4][..tcp] [.....172.16.0.1][58866] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...370] [ip4][..tcp] [.....172.16.0.1][58866] -> [..192.168.10.50][...80] - new: [...445] [ip4][..tcp] [.....172.16.0.1][60234] -> [..192.168.10.50][...80] - new: [...446] [ip4][..tcp] [.....172.16.0.1][60260] -> [..192.168.10.50][...80] - new: [...447] [ip4][..tcp] [.....172.16.0.1][60274] -> [..192.168.10.50][...80] - new: [...448] [ip4][..tcp] [.....172.16.0.1][60288] -> [..192.168.10.50][...80] - new: [...449] [ip4][..tcp] [.....172.16.0.1][60314] -> [..192.168.10.50][...80] - new: [...450] [ip4][..tcp] [.....172.16.0.1][60328] -> [..192.168.10.50][...80] + end: [...370] [ip4][..tcp] [.....172.16.0.1][58866] -> [..192.168.10.50][...80] + new: [...445] [ip4][..tcp] [.....172.16.0.1][60234] -> [..192.168.10.50][...80] + new: [...446] [ip4][..tcp] [.....172.16.0.1][60260] -> [..192.168.10.50][...80] + new: [...447] [ip4][..tcp] [.....172.16.0.1][60274] -> [..192.168.10.50][...80] + new: [...448] [ip4][..tcp] [.....172.16.0.1][60288] -> [..192.168.10.50][...80] + new: [...449] [ip4][..tcp] [.....172.16.0.1][60314] -> [..192.168.10.50][...80] + new: [...450] [ip4][..tcp] [.....172.16.0.1][60328] -> [..192.168.10.50][...80] guessed: [...374] [ip4][..tcp] [.....172.16.0.1][58946] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...374] [ip4][..tcp] [.....172.16.0.1][58946] -> [..192.168.10.50][...80] + end: [...374] [ip4][..tcp] [.....172.16.0.1][58946] -> [..192.168.10.50][...80] guessed: [...375] [ip4][..tcp] [.....172.16.0.1][58960] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...375] [ip4][..tcp] [.....172.16.0.1][58960] -> [..192.168.10.50][...80] + end: [...375] [ip4][..tcp] [.....172.16.0.1][58960] -> [..192.168.10.50][...80] guessed: [...376] [ip4][..tcp] [.....172.16.0.1][58974] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...376] [ip4][..tcp] [.....172.16.0.1][58974] -> [..192.168.10.50][...80] + end: [...376] [ip4][..tcp] [.....172.16.0.1][58974] -> [..192.168.10.50][...80] guessed: [...371] [ip4][..tcp] [.....172.16.0.1][58892] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...371] [ip4][..tcp] [.....172.16.0.1][58892] -> [..192.168.10.50][...80] + end: [...371] [ip4][..tcp] [.....172.16.0.1][58892] -> [..192.168.10.50][...80] guessed: [...372] [ip4][..tcp] [.....172.16.0.1][58906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...372] [ip4][..tcp] [.....172.16.0.1][58906] -> [..192.168.10.50][...80] + end: [...372] [ip4][..tcp] [.....172.16.0.1][58906] -> [..192.168.10.50][...80] guessed: [...373] [ip4][..tcp] [.....172.16.0.1][58920] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...373] [ip4][..tcp] [.....172.16.0.1][58920] -> [..192.168.10.50][...80] - new: [...451] [ip4][..tcp] [.....172.16.0.1][60342] -> [..192.168.10.50][...80] - new: [...452] [ip4][..tcp] [.....172.16.0.1][60356] -> [..192.168.10.50][...80] - new: [...453] [ip4][..tcp] [.....172.16.0.1][60370] -> [..192.168.10.50][...80] - new: [...454] [ip4][..tcp] [.....172.16.0.1][60384] -> [..192.168.10.50][...80] - new: [...455] [ip4][..tcp] [.....172.16.0.1][60410] -> [..192.168.10.50][...80] - new: [...456] [ip4][..tcp] [.....172.16.0.1][60424] -> [..192.168.10.50][...80] - new: [...457] [ip4][..tcp] [.....172.16.0.1][60438] -> [..192.168.10.50][...80] + end: [...373] [ip4][..tcp] [.....172.16.0.1][58920] -> [..192.168.10.50][...80] + new: [...451] [ip4][..tcp] [.....172.16.0.1][60342] -> [..192.168.10.50][...80] + new: [...452] [ip4][..tcp] [.....172.16.0.1][60356] -> [..192.168.10.50][...80] + new: [...453] [ip4][..tcp] [.....172.16.0.1][60370] -> [..192.168.10.50][...80] + new: [...454] [ip4][..tcp] [.....172.16.0.1][60384] -> [..192.168.10.50][...80] + new: [...455] [ip4][..tcp] [.....172.16.0.1][60410] -> [..192.168.10.50][...80] + new: [...456] [ip4][..tcp] [.....172.16.0.1][60424] -> [..192.168.10.50][...80] + new: [...457] [ip4][..tcp] [.....172.16.0.1][60438] -> [..192.168.10.50][...80] guessed: [...377] [ip4][..tcp] [.....172.16.0.1][58988] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...377] [ip4][..tcp] [.....172.16.0.1][58988] -> [..192.168.10.50][...80] + end: [...377] [ip4][..tcp] [.....172.16.0.1][58988] -> [..192.168.10.50][...80] guessed: [...378] [ip4][..tcp] [.....172.16.0.1][59002] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...378] [ip4][..tcp] [.....172.16.0.1][59002] -> [..192.168.10.50][...80] + end: [...378] [ip4][..tcp] [.....172.16.0.1][59002] -> [..192.168.10.50][...80] guessed: [...379] [ip4][..tcp] [.....172.16.0.1][59016] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...379] [ip4][..tcp] [.....172.16.0.1][59016] -> [..192.168.10.50][...80] + end: [...379] [ip4][..tcp] [.....172.16.0.1][59016] -> [..192.168.10.50][...80] guessed: [...381] [ip4][..tcp] [.....172.16.0.1][59056] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...381] [ip4][..tcp] [.....172.16.0.1][59056] -> [..192.168.10.50][...80] + end: [...381] [ip4][..tcp] [.....172.16.0.1][59056] -> [..192.168.10.50][...80] guessed: [...382] [ip4][..tcp] [.....172.16.0.1][59070] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...382] [ip4][..tcp] [.....172.16.0.1][59070] -> [..192.168.10.50][...80] + end: [...382] [ip4][..tcp] [.....172.16.0.1][59070] -> [..192.168.10.50][...80] end: [...342] [ip4][..tcp] [.....172.16.0.1][58360] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...458] [ip4][..tcp] [.....172.16.0.1][60464] -> [..192.168.10.50][...80] - new: [...459] [ip4][..tcp] [.....172.16.0.1][60478] -> [..192.168.10.50][...80] + new: [...458] [ip4][..tcp] [.....172.16.0.1][60464] -> [..192.168.10.50][...80] + new: [...459] [ip4][..tcp] [.....172.16.0.1][60478] -> [..192.168.10.50][...80] detected: [...458] [ip4][..tcp] [.....172.16.0.1][60464] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...460] [ip4][..tcp] [.....172.16.0.1][60504] -> [..192.168.10.50][...80] - new: [...461] [ip4][..tcp] [.....172.16.0.1][60518] -> [..192.168.10.50][...80] - new: [...462] [ip4][..tcp] [.....172.16.0.1][60532] -> [..192.168.10.50][...80] + new: [...460] [ip4][..tcp] [.....172.16.0.1][60504] -> [..192.168.10.50][...80] + new: [...461] [ip4][..tcp] [.....172.16.0.1][60518] -> [..192.168.10.50][...80] + new: [...462] [ip4][..tcp] [.....172.16.0.1][60532] -> [..192.168.10.50][...80] guessed: [...383] [ip4][..tcp] [.....172.16.0.1][59096] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...383] [ip4][..tcp] [.....172.16.0.1][59096] -> [..192.168.10.50][...80] + end: [...383] [ip4][..tcp] [.....172.16.0.1][59096] -> [..192.168.10.50][...80] guessed: [...384] [ip4][..tcp] [.....172.16.0.1][59110] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...384] [ip4][..tcp] [.....172.16.0.1][59110] -> [..192.168.10.50][...80] + end: [...384] [ip4][..tcp] [.....172.16.0.1][59110] -> [..192.168.10.50][...80] guessed: [...385] [ip4][..tcp] [.....172.16.0.1][59124] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...385] [ip4][..tcp] [.....172.16.0.1][59124] -> [..192.168.10.50][...80] + end: [...385] [ip4][..tcp] [.....172.16.0.1][59124] -> [..192.168.10.50][...80] guessed: [...386] [ip4][..tcp] [.....172.16.0.1][59150] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...386] [ip4][..tcp] [.....172.16.0.1][59150] -> [..192.168.10.50][...80] + end: [...386] [ip4][..tcp] [.....172.16.0.1][59150] -> [..192.168.10.50][...80] guessed: [...387] [ip4][..tcp] [.....172.16.0.1][59164] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...387] [ip4][..tcp] [.....172.16.0.1][59164] -> [..192.168.10.50][...80] + end: [...387] [ip4][..tcp] [.....172.16.0.1][59164] -> [..192.168.10.50][...80] guessed: [...388] [ip4][..tcp] [.....172.16.0.1][59178] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...388] [ip4][..tcp] [.....172.16.0.1][59178] -> [..192.168.10.50][...80] + end: [...388] [ip4][..tcp] [.....172.16.0.1][59178] -> [..192.168.10.50][...80] guessed: [...389] [ip4][..tcp] [.....172.16.0.1][59192] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...389] [ip4][..tcp] [.....172.16.0.1][59192] -> [..192.168.10.50][...80] - new: [...463] [ip4][..tcp] [.....172.16.0.1][60558] -> [..192.168.10.50][...80] + end: [...389] [ip4][..tcp] [.....172.16.0.1][59192] -> [..192.168.10.50][...80] + new: [...463] [ip4][..tcp] [.....172.16.0.1][60558] -> [..192.168.10.50][...80] analyse: [...458] [ip4][..tcp] [.....172.16.0.1][60464] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.582| 0.571| 0.887| 786468.045| 3.700] @@ -1416,116 +1416,116 @@ [IATS(ms)....: 0.1,0.9,3581.2,3582.1,3.3,4.1,271.0,275.6,4.6,1007.5,1011.3,3.8,268.9,273.0,4.1,1007.5,1011.6,4.2,263.6,267.5,3.9,1019.8,1023.7,4.0,253.2,261.2,7.9,1002.9,1011.8,8.9,255.9] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1919,52,435,1822,52,637,1920,52,435,1822,52,637,1917,52,435,1822,52,637,1920,52,435,1822,52,637] [ENTROPIES...: 4.6,5.1,4.9,5.9,4.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,5.0,5.8,7.7,4.9,6.0] - new: [...464] [ip4][..tcp] [.....172.16.0.1][60572] -> [..192.168.10.50][...80] - new: [...465] [ip4][..tcp] [.....172.16.0.1][60598] -> [..192.168.10.50][...80] - new: [...466] [ip4][..tcp] [.....172.16.0.1][60612] -> [..192.168.10.50][...80] - new: [...467] [ip4][..tcp] [.....172.16.0.1][60626] -> [..192.168.10.50][...80] - new: [...468] [ip4][..tcp] [.....172.16.0.1][60652] -> [..192.168.10.50][...80] + new: [...464] [ip4][..tcp] [.....172.16.0.1][60572] -> [..192.168.10.50][...80] + new: [...465] [ip4][..tcp] [.....172.16.0.1][60598] -> [..192.168.10.50][...80] + new: [...466] [ip4][..tcp] [.....172.16.0.1][60612] -> [..192.168.10.50][...80] + new: [...467] [ip4][..tcp] [.....172.16.0.1][60626] -> [..192.168.10.50][...80] + new: [...468] [ip4][..tcp] [.....172.16.0.1][60652] -> [..192.168.10.50][...80] guessed: [...390] [ip4][..tcp] [.....172.16.0.1][59206] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...390] [ip4][..tcp] [.....172.16.0.1][59206] -> [..192.168.10.50][...80] + end: [...390] [ip4][..tcp] [.....172.16.0.1][59206] -> [..192.168.10.50][...80] guessed: [...391] [ip4][..tcp] [.....172.16.0.1][59220] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...391] [ip4][..tcp] [.....172.16.0.1][59220] -> [..192.168.10.50][...80] + end: [...391] [ip4][..tcp] [.....172.16.0.1][59220] -> [..192.168.10.50][...80] guessed: [...392] [ip4][..tcp] [.....172.16.0.1][59246] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...392] [ip4][..tcp] [.....172.16.0.1][59246] -> [..192.168.10.50][...80] + end: [...392] [ip4][..tcp] [.....172.16.0.1][59246] -> [..192.168.10.50][...80] guessed: [...393] [ip4][..tcp] [.....172.16.0.1][59260] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...393] [ip4][..tcp] [.....172.16.0.1][59260] -> [..192.168.10.50][...80] + end: [...393] [ip4][..tcp] [.....172.16.0.1][59260] -> [..192.168.10.50][...80] guessed: [...394] [ip4][..tcp] [.....172.16.0.1][59274] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...394] [ip4][..tcp] [.....172.16.0.1][59274] -> [..192.168.10.50][...80] + end: [...394] [ip4][..tcp] [.....172.16.0.1][59274] -> [..192.168.10.50][...80] guessed: [...395] [ip4][..tcp] [.....172.16.0.1][59300] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...395] [ip4][..tcp] [.....172.16.0.1][59300] -> [..192.168.10.50][...80] + end: [...395] [ip4][..tcp] [.....172.16.0.1][59300] -> [..192.168.10.50][...80] guessed: [...396] [ip4][..tcp] [.....172.16.0.1][59314] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...396] [ip4][..tcp] [.....172.16.0.1][59314] -> [..192.168.10.50][...80] - new: [...469] [ip4][..tcp] [.....172.16.0.1][60666] -> [..192.168.10.50][...80] - new: [...470] [ip4][..tcp] [.....172.16.0.1][60692] -> [..192.168.10.50][...80] - new: [...471] [ip4][..tcp] [.....172.16.0.1][60706] -> [..192.168.10.50][...80] - new: [...472] [ip4][..tcp] [.....172.16.0.1][60720] -> [..192.168.10.50][...80] - new: [...473] [ip4][..tcp] [.....172.16.0.1][60734] -> [..192.168.10.50][...80] - new: [...474] [ip4][..tcp] [.....172.16.0.1][60748] -> [..192.168.10.50][...80] - new: [...475] [ip4][..tcp] [.....172.16.0.1][60762] -> [..192.168.10.50][...80] + end: [...396] [ip4][..tcp] [.....172.16.0.1][59314] -> [..192.168.10.50][...80] + new: [...469] [ip4][..tcp] [.....172.16.0.1][60666] -> [..192.168.10.50][...80] + new: [...470] [ip4][..tcp] [.....172.16.0.1][60692] -> [..192.168.10.50][...80] + new: [...471] [ip4][..tcp] [.....172.16.0.1][60706] -> [..192.168.10.50][...80] + new: [...472] [ip4][..tcp] [.....172.16.0.1][60720] -> [..192.168.10.50][...80] + new: [...473] [ip4][..tcp] [.....172.16.0.1][60734] -> [..192.168.10.50][...80] + new: [...474] [ip4][..tcp] [.....172.16.0.1][60748] -> [..192.168.10.50][...80] + new: [...475] [ip4][..tcp] [.....172.16.0.1][60762] -> [..192.168.10.50][...80] guessed: [...397] [ip4][..tcp] [.....172.16.0.1][59328] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...397] [ip4][..tcp] [.....172.16.0.1][59328] -> [..192.168.10.50][...80] + end: [...397] [ip4][..tcp] [.....172.16.0.1][59328] -> [..192.168.10.50][...80] guessed: [...398] [ip4][..tcp] [.....172.16.0.1][59354] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...398] [ip4][..tcp] [.....172.16.0.1][59354] -> [..192.168.10.50][...80] + end: [...398] [ip4][..tcp] [.....172.16.0.1][59354] -> [..192.168.10.50][...80] guessed: [...399] [ip4][..tcp] [.....172.16.0.1][59368] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...399] [ip4][..tcp] [.....172.16.0.1][59368] -> [..192.168.10.50][...80] + end: [...399] [ip4][..tcp] [.....172.16.0.1][59368] -> [..192.168.10.50][...80] guessed: [...400] [ip4][..tcp] [.....172.16.0.1][59382] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...400] [ip4][..tcp] [.....172.16.0.1][59382] -> [..192.168.10.50][...80] + end: [...400] [ip4][..tcp] [.....172.16.0.1][59382] -> [..192.168.10.50][...80] guessed: [...401] [ip4][..tcp] [.....172.16.0.1][59408] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...401] [ip4][..tcp] [.....172.16.0.1][59408] -> [..192.168.10.50][...80] + end: [...401] [ip4][..tcp] [.....172.16.0.1][59408] -> [..192.168.10.50][...80] guessed: [...402] [ip4][..tcp] [.....172.16.0.1][59422] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...402] [ip4][..tcp] [.....172.16.0.1][59422] -> [..192.168.10.50][...80] - new: [...476] [ip4][..tcp] [.....172.16.0.1][60788] -> [..192.168.10.50][...80] - new: [...477] [ip4][..tcp] [.....172.16.0.1][60802] -> [..192.168.10.50][...80] - new: [...478] [ip4][..tcp] [.....172.16.0.1][60816] -> [..192.168.10.50][...80] - new: [...479] [ip4][..tcp] [.....172.16.0.1][60842] -> [..192.168.10.50][...80] - new: [...480] [ip4][..tcp] [.....172.16.0.1][60856] -> [..192.168.10.50][...80] + end: [...402] [ip4][..tcp] [.....172.16.0.1][59422] -> [..192.168.10.50][...80] + new: [...476] [ip4][..tcp] [.....172.16.0.1][60788] -> [..192.168.10.50][...80] + new: [...477] [ip4][..tcp] [.....172.16.0.1][60802] -> [..192.168.10.50][...80] + new: [...478] [ip4][..tcp] [.....172.16.0.1][60816] -> [..192.168.10.50][...80] + new: [...479] [ip4][..tcp] [.....172.16.0.1][60842] -> [..192.168.10.50][...80] + new: [...480] [ip4][..tcp] [.....172.16.0.1][60856] -> [..192.168.10.50][...80] guessed: [...403] [ip4][..tcp] [.....172.16.0.1][59436] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...403] [ip4][..tcp] [.....172.16.0.1][59436] -> [..192.168.10.50][...80] + end: [...403] [ip4][..tcp] [.....172.16.0.1][59436] -> [..192.168.10.50][...80] guessed: [...404] [ip4][..tcp] [.....172.16.0.1][59462] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...404] [ip4][..tcp] [.....172.16.0.1][59462] -> [..192.168.10.50][...80] + end: [...404] [ip4][..tcp] [.....172.16.0.1][59462] -> [..192.168.10.50][...80] guessed: [...405] [ip4][..tcp] [.....172.16.0.1][59476] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...405] [ip4][..tcp] [.....172.16.0.1][59476] -> [..192.168.10.50][...80] + end: [...405] [ip4][..tcp] [.....172.16.0.1][59476] -> [..192.168.10.50][...80] guessed: [...406] [ip4][..tcp] [.....172.16.0.1][59502] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...406] [ip4][..tcp] [.....172.16.0.1][59502] -> [..192.168.10.50][...80] + end: [...406] [ip4][..tcp] [.....172.16.0.1][59502] -> [..192.168.10.50][...80] guessed: [...407] [ip4][..tcp] [.....172.16.0.1][59516] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...407] [ip4][..tcp] [.....172.16.0.1][59516] -> [..192.168.10.50][...80] + end: [...407] [ip4][..tcp] [.....172.16.0.1][59516] -> [..192.168.10.50][...80] guessed: [...408] [ip4][..tcp] [.....172.16.0.1][59530] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...408] [ip4][..tcp] [.....172.16.0.1][59530] -> [..192.168.10.50][...80] - new: [...481] [ip4][..tcp] [.....172.16.0.1][60882] -> [..192.168.10.50][...80] - new: [...482] [ip4][..tcp] [.....172.16.0.1][60896] -> [..192.168.10.50][...80] - new: [...483] [ip4][..tcp] [.....172.16.0.1][60922] -> [..192.168.10.50][...80] - new: [...484] [ip4][..tcp] [.....172.16.0.1][60936] -> [..192.168.10.50][...80] - new: [...485] [ip4][..tcp] [.....172.16.0.1][60950] -> [..192.168.10.50][...80] - new: [...486] [ip4][..tcp] [.....172.16.0.1][60976] -> [..192.168.10.50][...80] + end: [...408] [ip4][..tcp] [.....172.16.0.1][59530] -> [..192.168.10.50][...80] + new: [...481] [ip4][..tcp] [.....172.16.0.1][60882] -> [..192.168.10.50][...80] + new: [...482] [ip4][..tcp] [.....172.16.0.1][60896] -> [..192.168.10.50][...80] + new: [...483] [ip4][..tcp] [.....172.16.0.1][60922] -> [..192.168.10.50][...80] + new: [...484] [ip4][..tcp] [.....172.16.0.1][60936] -> [..192.168.10.50][...80] + new: [...485] [ip4][..tcp] [.....172.16.0.1][60950] -> [..192.168.10.50][...80] + new: [...486] [ip4][..tcp] [.....172.16.0.1][60976] -> [..192.168.10.50][...80] guessed: [...409] [ip4][..tcp] [.....172.16.0.1][59556] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...409] [ip4][..tcp] [.....172.16.0.1][59556] -> [..192.168.10.50][...80] + end: [...409] [ip4][..tcp] [.....172.16.0.1][59556] -> [..192.168.10.50][...80] guessed: [...410] [ip4][..tcp] [.....172.16.0.1][59570] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...410] [ip4][..tcp] [.....172.16.0.1][59570] -> [..192.168.10.50][...80] + end: [...410] [ip4][..tcp] [.....172.16.0.1][59570] -> [..192.168.10.50][...80] guessed: [...411] [ip4][..tcp] [.....172.16.0.1][59584] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...411] [ip4][..tcp] [.....172.16.0.1][59584] -> [..192.168.10.50][...80] + end: [...411] [ip4][..tcp] [.....172.16.0.1][59584] -> [..192.168.10.50][...80] guessed: [...412] [ip4][..tcp] [.....172.16.0.1][59610] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...412] [ip4][..tcp] [.....172.16.0.1][59610] -> [..192.168.10.50][...80] + end: [...412] [ip4][..tcp] [.....172.16.0.1][59610] -> [..192.168.10.50][...80] guessed: [...413] [ip4][..tcp] [.....172.16.0.1][59624] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...413] [ip4][..tcp] [.....172.16.0.1][59624] -> [..192.168.10.50][...80] - new: [...487] [ip4][..tcp] [.....172.16.0.1][60990] -> [..192.168.10.50][...80] - new: [...488] [ip4][..tcp] [.....172.16.0.1][32784] -> [..192.168.10.50][...80] - new: [...489] [ip4][..tcp] [.....172.16.0.1][32798] -> [..192.168.10.50][...80] - new: [...490] [ip4][..tcp] [.....172.16.0.1][32812] -> [..192.168.10.50][...80] - new: [...491] [ip4][..tcp] [.....172.16.0.1][32838] -> [..192.168.10.50][...80] - new: [...492] [ip4][..tcp] [.....172.16.0.1][32852] -> [..192.168.10.50][...80] + end: [...413] [ip4][..tcp] [.....172.16.0.1][59624] -> [..192.168.10.50][...80] + new: [...487] [ip4][..tcp] [.....172.16.0.1][60990] -> [..192.168.10.50][...80] + new: [...488] [ip4][..tcp] [.....172.16.0.1][32784] -> [..192.168.10.50][...80] + new: [...489] [ip4][..tcp] [.....172.16.0.1][32798] -> [..192.168.10.50][...80] + new: [...490] [ip4][..tcp] [.....172.16.0.1][32812] -> [..192.168.10.50][...80] + new: [...491] [ip4][..tcp] [.....172.16.0.1][32838] -> [..192.168.10.50][...80] + new: [...492] [ip4][..tcp] [.....172.16.0.1][32852] -> [..192.168.10.50][...80] end: [...380] [ip4][..tcp] [.....172.16.0.1][59042] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...414] [ip4][..tcp] [.....172.16.0.1][59650] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...414] [ip4][..tcp] [.....172.16.0.1][59650] -> [..192.168.10.50][...80] + end: [...414] [ip4][..tcp] [.....172.16.0.1][59650] -> [..192.168.10.50][...80] guessed: [...415] [ip4][..tcp] [.....172.16.0.1][59664] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...415] [ip4][..tcp] [.....172.16.0.1][59664] -> [..192.168.10.50][...80] + end: [...415] [ip4][..tcp] [.....172.16.0.1][59664] -> [..192.168.10.50][...80] guessed: [...416] [ip4][..tcp] [.....172.16.0.1][59678] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...416] [ip4][..tcp] [.....172.16.0.1][59678] -> [..192.168.10.50][...80] + end: [...416] [ip4][..tcp] [.....172.16.0.1][59678] -> [..192.168.10.50][...80] guessed: [...417] [ip4][..tcp] [.....172.16.0.1][59704] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...417] [ip4][..tcp] [.....172.16.0.1][59704] -> [..192.168.10.50][...80] + end: [...417] [ip4][..tcp] [.....172.16.0.1][59704] -> [..192.168.10.50][...80] guessed: [...418] [ip4][..tcp] [.....172.16.0.1][59718] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...418] [ip4][..tcp] [.....172.16.0.1][59718] -> [..192.168.10.50][...80] - new: [...493] [ip4][..tcp] [.....172.16.0.1][32878] -> [..192.168.10.50][...80] - new: [...494] [ip4][..tcp] [.....172.16.0.1][32892] -> [..192.168.10.50][...80] - new: [...495] [ip4][..tcp] [.....172.16.0.1][32906] -> [..192.168.10.50][...80] - new: [...496] [ip4][..tcp] [.....172.16.0.1][32932] -> [..192.168.10.50][...80] - new: [...497] [ip4][..tcp] [.....172.16.0.1][32946] -> [..192.168.10.50][...80] + end: [...418] [ip4][..tcp] [.....172.16.0.1][59718] -> [..192.168.10.50][...80] + new: [...493] [ip4][..tcp] [.....172.16.0.1][32878] -> [..192.168.10.50][...80] + new: [...494] [ip4][..tcp] [.....172.16.0.1][32892] -> [..192.168.10.50][...80] + new: [...495] [ip4][..tcp] [.....172.16.0.1][32906] -> [..192.168.10.50][...80] + new: [...496] [ip4][..tcp] [.....172.16.0.1][32932] -> [..192.168.10.50][...80] + new: [...497] [ip4][..tcp] [.....172.16.0.1][32946] -> [..192.168.10.50][...80] detected: [...495] [ip4][..tcp] [.....172.16.0.1][32906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...498] [ip4][..tcp] [.....172.16.0.1][32960] -> [..192.168.10.50][...80] + new: [...498] [ip4][..tcp] [.....172.16.0.1][32960] -> [..192.168.10.50][...80] guessed: [...420] [ip4][..tcp] [.....172.16.0.1][59758] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...420] [ip4][..tcp] [.....172.16.0.1][59758] -> [..192.168.10.50][...80] + end: [...420] [ip4][..tcp] [.....172.16.0.1][59758] -> [..192.168.10.50][...80] guessed: [...421] [ip4][..tcp] [.....172.16.0.1][59772] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...421] [ip4][..tcp] [.....172.16.0.1][59772] -> [..192.168.10.50][...80] + end: [...421] [ip4][..tcp] [.....172.16.0.1][59772] -> [..192.168.10.50][...80] guessed: [...422] [ip4][..tcp] [.....172.16.0.1][59786] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...422] [ip4][..tcp] [.....172.16.0.1][59786] -> [..192.168.10.50][...80] + end: [...422] [ip4][..tcp] [.....172.16.0.1][59786] -> [..192.168.10.50][...80] guessed: [...423] [ip4][..tcp] [.....172.16.0.1][59812] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...423] [ip4][..tcp] [.....172.16.0.1][59812] -> [..192.168.10.50][...80] + end: [...423] [ip4][..tcp] [.....172.16.0.1][59812] -> [..192.168.10.50][...80] guessed: [...424] [ip4][..tcp] [.....172.16.0.1][59826] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...424] [ip4][..tcp] [.....172.16.0.1][59826] -> [..192.168.10.50][...80] - new: [...499] [ip4][..tcp] [.....172.16.0.1][32974] -> [..192.168.10.50][...80] - new: [...500] [ip4][..tcp] [.....172.16.0.1][32988] -> [..192.168.10.50][...80] - new: [...501] [ip4][..tcp] [.....172.16.0.1][33002] -> [..192.168.10.50][...80] + end: [...424] [ip4][..tcp] [.....172.16.0.1][59826] -> [..192.168.10.50][...80] + new: [...499] [ip4][..tcp] [.....172.16.0.1][32974] -> [..192.168.10.50][...80] + new: [...500] [ip4][..tcp] [.....172.16.0.1][32988] -> [..192.168.10.50][...80] + new: [...501] [ip4][..tcp] [.....172.16.0.1][33002] -> [..192.168.10.50][...80] analyse: [...495] [ip4][..tcp] [.....172.16.0.1][32906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.862| 0.614| 0.953| 908128.223| 3.700] @@ -1536,120 +1536,120 @@ [IATS(ms)....: 0.2,0.9,3861.2,3862.0,3.2,4.0,1007.4,1011.0,3.7,256.9,260.5,3.6,1018.3,1022.0,3.6,243.4,247.0,3.6,1033.5,1037.2,3.7,244.2,248.3,4.1,1037.5,1041.7,4.2,261.5,265.1,3.6,1039.0] [PKTLENS.....: 60,60,52,637,52,1920,52,435,1822,52,637,1920,52,435,1822,52,637,1920,52,435,1822,52,637,1916,52,435,1822,52,637,1921,52,435] [ENTROPIES...: 4.5,5.1,4.9,6.0,4.9,7.8,4.9,5.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.8,6.0,7.8,4.9,5.9,7.7,4.9,6.1,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9] - new: [...502] [ip4][..tcp] [.....172.16.0.1][33028] -> [..192.168.10.50][...80] - new: [...503] [ip4][..tcp] [.....172.16.0.1][33042] -> [..192.168.10.50][...80] - new: [...504] [ip4][..tcp] [.....172.16.0.1][33068] -> [..192.168.10.50][...80] + new: [...502] [ip4][..tcp] [.....172.16.0.1][33028] -> [..192.168.10.50][...80] + new: [...503] [ip4][..tcp] [.....172.16.0.1][33042] -> [..192.168.10.50][...80] + new: [...504] [ip4][..tcp] [.....172.16.0.1][33068] -> [..192.168.10.50][...80] guessed: [...425] [ip4][..tcp] [.....172.16.0.1][59852] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...425] [ip4][..tcp] [.....172.16.0.1][59852] -> [..192.168.10.50][...80] + end: [...425] [ip4][..tcp] [.....172.16.0.1][59852] -> [..192.168.10.50][...80] guessed: [...426] [ip4][..tcp] [.....172.16.0.1][59866] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...426] [ip4][..tcp] [.....172.16.0.1][59866] -> [..192.168.10.50][...80] + end: [...426] [ip4][..tcp] [.....172.16.0.1][59866] -> [..192.168.10.50][...80] guessed: [...427] [ip4][..tcp] [.....172.16.0.1][59880] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...427] [ip4][..tcp] [.....172.16.0.1][59880] -> [..192.168.10.50][...80] + end: [...427] [ip4][..tcp] [.....172.16.0.1][59880] -> [..192.168.10.50][...80] guessed: [...428] [ip4][..tcp] [.....172.16.0.1][59906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...428] [ip4][..tcp] [.....172.16.0.1][59906] -> [..192.168.10.50][...80] + end: [...428] [ip4][..tcp] [.....172.16.0.1][59906] -> [..192.168.10.50][...80] guessed: [...429] [ip4][..tcp] [.....172.16.0.1][59920] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...429] [ip4][..tcp] [.....172.16.0.1][59920] -> [..192.168.10.50][...80] + end: [...429] [ip4][..tcp] [.....172.16.0.1][59920] -> [..192.168.10.50][...80] guessed: [...430] [ip4][..tcp] [.....172.16.0.1][59934] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...430] [ip4][..tcp] [.....172.16.0.1][59934] -> [..192.168.10.50][...80] + end: [...430] [ip4][..tcp] [.....172.16.0.1][59934] -> [..192.168.10.50][...80] guessed: [...431] [ip4][..tcp] [.....172.16.0.1][59960] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...431] [ip4][..tcp] [.....172.16.0.1][59960] -> [..192.168.10.50][...80] - new: [...505] [ip4][..tcp] [.....172.16.0.1][33082] -> [..192.168.10.50][...80] - new: [...506] [ip4][..tcp] [.....172.16.0.1][33096] -> [..192.168.10.50][...80] - new: [...507] [ip4][..tcp] [.....172.16.0.1][33122] -> [..192.168.10.50][...80] - new: [...508] [ip4][..tcp] [.....172.16.0.1][33136] -> [..192.168.10.50][...80] - new: [...509] [ip4][..tcp] [.....172.16.0.1][33162] -> [..192.168.10.50][...80] - new: [...510] [ip4][..tcp] [.....172.16.0.1][33176] -> [..192.168.10.50][...80] + end: [...431] [ip4][..tcp] [.....172.16.0.1][59960] -> [..192.168.10.50][...80] + new: [...505] [ip4][..tcp] [.....172.16.0.1][33082] -> [..192.168.10.50][...80] + new: [...506] [ip4][..tcp] [.....172.16.0.1][33096] -> [..192.168.10.50][...80] + new: [...507] [ip4][..tcp] [.....172.16.0.1][33122] -> [..192.168.10.50][...80] + new: [...508] [ip4][..tcp] [.....172.16.0.1][33136] -> [..192.168.10.50][...80] + new: [...509] [ip4][..tcp] [.....172.16.0.1][33162] -> [..192.168.10.50][...80] + new: [...510] [ip4][..tcp] [.....172.16.0.1][33176] -> [..192.168.10.50][...80] guessed: [...432] [ip4][..tcp] [.....172.16.0.1][59974] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...432] [ip4][..tcp] [.....172.16.0.1][59974] -> [..192.168.10.50][...80] + end: [...432] [ip4][..tcp] [.....172.16.0.1][59974] -> [..192.168.10.50][...80] guessed: [...433] [ip4][..tcp] [.....172.16.0.1][59988] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...433] [ip4][..tcp] [.....172.16.0.1][59988] -> [..192.168.10.50][...80] + end: [...433] [ip4][..tcp] [.....172.16.0.1][59988] -> [..192.168.10.50][...80] guessed: [...434] [ip4][..tcp] [.....172.16.0.1][60014] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...434] [ip4][..tcp] [.....172.16.0.1][60014] -> [..192.168.10.50][...80] + end: [...434] [ip4][..tcp] [.....172.16.0.1][60014] -> [..192.168.10.50][...80] guessed: [...435] [ip4][..tcp] [.....172.16.0.1][60028] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...435] [ip4][..tcp] [.....172.16.0.1][60028] -> [..192.168.10.50][...80] + end: [...435] [ip4][..tcp] [.....172.16.0.1][60028] -> [..192.168.10.50][...80] guessed: [...436] [ip4][..tcp] [.....172.16.0.1][60042] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...436] [ip4][..tcp] [.....172.16.0.1][60042] -> [..192.168.10.50][...80] + end: [...436] [ip4][..tcp] [.....172.16.0.1][60042] -> [..192.168.10.50][...80] guessed: [...437] [ip4][..tcp] [.....172.16.0.1][60056] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...437] [ip4][..tcp] [.....172.16.0.1][60056] -> [..192.168.10.50][...80] - new: [...511] [ip4][..tcp] [.....172.16.0.1][33202] -> [..192.168.10.50][...80] - new: [...512] [ip4][..tcp] [.....172.16.0.1][33216] -> [..192.168.10.50][...80] - new: [...513] [ip4][..tcp] [.....172.16.0.1][33230] -> [..192.168.10.50][...80] - new: [...514] [ip4][..tcp] [.....172.16.0.1][33256] -> [..192.168.10.50][...80] - new: [...515] [ip4][..tcp] [.....172.16.0.1][33270] -> [..192.168.10.50][...80] + end: [...437] [ip4][..tcp] [.....172.16.0.1][60056] -> [..192.168.10.50][...80] + new: [...511] [ip4][..tcp] [.....172.16.0.1][33202] -> [..192.168.10.50][...80] + new: [...512] [ip4][..tcp] [.....172.16.0.1][33216] -> [..192.168.10.50][...80] + new: [...513] [ip4][..tcp] [.....172.16.0.1][33230] -> [..192.168.10.50][...80] + new: [...514] [ip4][..tcp] [.....172.16.0.1][33256] -> [..192.168.10.50][...80] + new: [...515] [ip4][..tcp] [.....172.16.0.1][33270] -> [..192.168.10.50][...80] guessed: [...438] [ip4][..tcp] [.....172.16.0.1][60084] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...438] [ip4][..tcp] [.....172.16.0.1][60084] -> [..192.168.10.50][...80] + end: [...438] [ip4][..tcp] [.....172.16.0.1][60084] -> [..192.168.10.50][...80] guessed: [...439] [ip4][..tcp] [.....172.16.0.1][60134] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...439] [ip4][..tcp] [.....172.16.0.1][60134] -> [..192.168.10.50][...80] + end: [...439] [ip4][..tcp] [.....172.16.0.1][60134] -> [..192.168.10.50][...80] guessed: [...440] [ip4][..tcp] [.....172.16.0.1][60136] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...440] [ip4][..tcp] [.....172.16.0.1][60136] -> [..192.168.10.50][...80] + end: [...440] [ip4][..tcp] [.....172.16.0.1][60136] -> [..192.168.10.50][...80] guessed: [...441] [ip4][..tcp] [.....172.16.0.1][60154] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...441] [ip4][..tcp] [.....172.16.0.1][60154] -> [..192.168.10.50][...80] + end: [...441] [ip4][..tcp] [.....172.16.0.1][60154] -> [..192.168.10.50][...80] guessed: [...442] [ip4][..tcp] [.....172.16.0.1][60180] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...442] [ip4][..tcp] [.....172.16.0.1][60180] -> [..192.168.10.50][...80] + end: [...442] [ip4][..tcp] [.....172.16.0.1][60180] -> [..192.168.10.50][...80] guessed: [...443] [ip4][..tcp] [.....172.16.0.1][60194] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...443] [ip4][..tcp] [.....172.16.0.1][60194] -> [..192.168.10.50][...80] - new: [...516] [ip4][..tcp] [.....172.16.0.1][33296] -> [..192.168.10.50][...80] - new: [...517] [ip4][..tcp] [.....172.16.0.1][33310] -> [..192.168.10.50][...80] - new: [...518] [ip4][..tcp] [.....172.16.0.1][33324] -> [..192.168.10.50][...80] - new: [...519] [ip4][..tcp] [.....172.16.0.1][33350] -> [..192.168.10.50][...80] - new: [...520] [ip4][..tcp] [.....172.16.0.1][33364] -> [..192.168.10.50][...80] - new: [...521] [ip4][..tcp] [.....172.16.0.1][33378] -> [..192.168.10.50][...80] + end: [...443] [ip4][..tcp] [.....172.16.0.1][60194] -> [..192.168.10.50][...80] + new: [...516] [ip4][..tcp] [.....172.16.0.1][33296] -> [..192.168.10.50][...80] + new: [...517] [ip4][..tcp] [.....172.16.0.1][33310] -> [..192.168.10.50][...80] + new: [...518] [ip4][..tcp] [.....172.16.0.1][33324] -> [..192.168.10.50][...80] + new: [...519] [ip4][..tcp] [.....172.16.0.1][33350] -> [..192.168.10.50][...80] + new: [...520] [ip4][..tcp] [.....172.16.0.1][33364] -> [..192.168.10.50][...80] + new: [...521] [ip4][..tcp] [.....172.16.0.1][33378] -> [..192.168.10.50][...80] guessed: [...444] [ip4][..tcp] [.....172.16.0.1][60220] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...444] [ip4][..tcp] [.....172.16.0.1][60220] -> [..192.168.10.50][...80] + end: [...444] [ip4][..tcp] [.....172.16.0.1][60220] -> [..192.168.10.50][...80] guessed: [...445] [ip4][..tcp] [.....172.16.0.1][60234] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...445] [ip4][..tcp] [.....172.16.0.1][60234] -> [..192.168.10.50][...80] + end: [...445] [ip4][..tcp] [.....172.16.0.1][60234] -> [..192.168.10.50][...80] guessed: [...446] [ip4][..tcp] [.....172.16.0.1][60260] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...446] [ip4][..tcp] [.....172.16.0.1][60260] -> [..192.168.10.50][...80] + end: [...446] [ip4][..tcp] [.....172.16.0.1][60260] -> [..192.168.10.50][...80] guessed: [...447] [ip4][..tcp] [.....172.16.0.1][60274] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...447] [ip4][..tcp] [.....172.16.0.1][60274] -> [..192.168.10.50][...80] + end: [...447] [ip4][..tcp] [.....172.16.0.1][60274] -> [..192.168.10.50][...80] guessed: [...448] [ip4][..tcp] [.....172.16.0.1][60288] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...448] [ip4][..tcp] [.....172.16.0.1][60288] -> [..192.168.10.50][...80] - new: [...522] [ip4][..tcp] [.....172.16.0.1][33404] -> [..192.168.10.50][...80] - new: [...523] [ip4][..tcp] [.....172.16.0.1][33418] -> [..192.168.10.50][...80] - new: [...524] [ip4][..tcp] [.....172.16.0.1][33444] -> [..192.168.10.50][...80] - new: [...525] [ip4][..tcp] [.....172.16.0.1][33458] -> [..192.168.10.50][...80] - new: [...526] [ip4][..tcp] [.....172.16.0.1][33472] -> [..192.168.10.50][...80] - new: [...527] [ip4][..tcp] [.....172.16.0.1][33486] -> [..192.168.10.50][...80] - new: [...528] [ip4][..tcp] [.....172.16.0.1][33500] -> [..192.168.10.50][...80] + end: [...448] [ip4][..tcp] [.....172.16.0.1][60288] -> [..192.168.10.50][...80] + new: [...522] [ip4][..tcp] [.....172.16.0.1][33404] -> [..192.168.10.50][...80] + new: [...523] [ip4][..tcp] [.....172.16.0.1][33418] -> [..192.168.10.50][...80] + new: [...524] [ip4][..tcp] [.....172.16.0.1][33444] -> [..192.168.10.50][...80] + new: [...525] [ip4][..tcp] [.....172.16.0.1][33458] -> [..192.168.10.50][...80] + new: [...526] [ip4][..tcp] [.....172.16.0.1][33472] -> [..192.168.10.50][...80] + new: [...527] [ip4][..tcp] [.....172.16.0.1][33486] -> [..192.168.10.50][...80] + new: [...528] [ip4][..tcp] [.....172.16.0.1][33500] -> [..192.168.10.50][...80] guessed: [...449] [ip4][..tcp] [.....172.16.0.1][60314] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...449] [ip4][..tcp] [.....172.16.0.1][60314] -> [..192.168.10.50][...80] + end: [...449] [ip4][..tcp] [.....172.16.0.1][60314] -> [..192.168.10.50][...80] guessed: [...450] [ip4][..tcp] [.....172.16.0.1][60328] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...450] [ip4][..tcp] [.....172.16.0.1][60328] -> [..192.168.10.50][...80] + end: [...450] [ip4][..tcp] [.....172.16.0.1][60328] -> [..192.168.10.50][...80] guessed: [...451] [ip4][..tcp] [.....172.16.0.1][60342] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...451] [ip4][..tcp] [.....172.16.0.1][60342] -> [..192.168.10.50][...80] + end: [...451] [ip4][..tcp] [.....172.16.0.1][60342] -> [..192.168.10.50][...80] guessed: [...452] [ip4][..tcp] [.....172.16.0.1][60356] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...452] [ip4][..tcp] [.....172.16.0.1][60356] -> [..192.168.10.50][...80] + end: [...452] [ip4][..tcp] [.....172.16.0.1][60356] -> [..192.168.10.50][...80] guessed: [...453] [ip4][..tcp] [.....172.16.0.1][60370] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...453] [ip4][..tcp] [.....172.16.0.1][60370] -> [..192.168.10.50][...80] + end: [...453] [ip4][..tcp] [.....172.16.0.1][60370] -> [..192.168.10.50][...80] guessed: [...454] [ip4][..tcp] [.....172.16.0.1][60384] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...454] [ip4][..tcp] [.....172.16.0.1][60384] -> [..192.168.10.50][...80] + end: [...454] [ip4][..tcp] [.....172.16.0.1][60384] -> [..192.168.10.50][...80] guessed: [...455] [ip4][..tcp] [.....172.16.0.1][60410] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...455] [ip4][..tcp] [.....172.16.0.1][60410] -> [..192.168.10.50][...80] + end: [...455] [ip4][..tcp] [.....172.16.0.1][60410] -> [..192.168.10.50][...80] guessed: [...456] [ip4][..tcp] [.....172.16.0.1][60424] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...456] [ip4][..tcp] [.....172.16.0.1][60424] -> [..192.168.10.50][...80] - new: [...529] [ip4][..tcp] [.....172.16.0.1][33526] -> [..192.168.10.50][...80] - new: [...530] [ip4][..tcp] [.....172.16.0.1][33540] -> [..192.168.10.50][...80] - new: [...531] [ip4][..tcp] [.....172.16.0.1][33554] -> [..192.168.10.50][...80] - new: [...532] [ip4][..tcp] [.....172.16.0.1][33580] -> [..192.168.10.50][...80] - new: [...533] [ip4][..tcp] [.....172.16.0.1][33594] -> [..192.168.10.50][...80] - new: [...534] [ip4][..tcp] [.....172.16.0.1][33608] -> [..192.168.10.50][...80] + end: [...456] [ip4][..tcp] [.....172.16.0.1][60424] -> [..192.168.10.50][...80] + new: [...529] [ip4][..tcp] [.....172.16.0.1][33526] -> [..192.168.10.50][...80] + new: [...530] [ip4][..tcp] [.....172.16.0.1][33540] -> [..192.168.10.50][...80] + new: [...531] [ip4][..tcp] [.....172.16.0.1][33554] -> [..192.168.10.50][...80] + new: [...532] [ip4][..tcp] [.....172.16.0.1][33580] -> [..192.168.10.50][...80] + new: [...533] [ip4][..tcp] [.....172.16.0.1][33594] -> [..192.168.10.50][...80] + new: [...534] [ip4][..tcp] [.....172.16.0.1][33608] -> [..192.168.10.50][...80] end: [...419] [ip4][..tcp] [.....172.16.0.1][59732] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...457] [ip4][..tcp] [.....172.16.0.1][60438] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...457] [ip4][..tcp] [.....172.16.0.1][60438] -> [..192.168.10.50][...80] + end: [...457] [ip4][..tcp] [.....172.16.0.1][60438] -> [..192.168.10.50][...80] guessed: [...459] [ip4][..tcp] [.....172.16.0.1][60478] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...459] [ip4][..tcp] [.....172.16.0.1][60478] -> [..192.168.10.50][...80] + end: [...459] [ip4][..tcp] [.....172.16.0.1][60478] -> [..192.168.10.50][...80] guessed: [...460] [ip4][..tcp] [.....172.16.0.1][60504] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...460] [ip4][..tcp] [.....172.16.0.1][60504] -> [..192.168.10.50][...80] + end: [...460] [ip4][..tcp] [.....172.16.0.1][60504] -> [..192.168.10.50][...80] guessed: [...461] [ip4][..tcp] [.....172.16.0.1][60518] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...461] [ip4][..tcp] [.....172.16.0.1][60518] -> [..192.168.10.50][...80] + end: [...461] [ip4][..tcp] [.....172.16.0.1][60518] -> [..192.168.10.50][...80] guessed: [...462] [ip4][..tcp] [.....172.16.0.1][60532] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...462] [ip4][..tcp] [.....172.16.0.1][60532] -> [..192.168.10.50][...80] + end: [...462] [ip4][..tcp] [.....172.16.0.1][60532] -> [..192.168.10.50][...80] detected: [...532] [ip4][..tcp] [.....172.16.0.1][33580] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...535] [ip4][..tcp] [.....172.16.0.1][33634] -> [..192.168.10.50][...80] - new: [...536] [ip4][..tcp] [.....172.16.0.1][33648] -> [..192.168.10.50][...80] - new: [...537] [ip4][..tcp] [.....172.16.0.1][33674] -> [..192.168.10.50][...80] + new: [...535] [ip4][..tcp] [.....172.16.0.1][33634] -> [..192.168.10.50][...80] + new: [...536] [ip4][..tcp] [.....172.16.0.1][33648] -> [..192.168.10.50][...80] + new: [...537] [ip4][..tcp] [.....172.16.0.1][33674] -> [..192.168.10.50][...80] analyse: [...532] [ip4][..tcp] [.....172.16.0.1][33580] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.841| 0.651| 1.171| 1372280.717| 3.500] @@ -1660,114 +1660,114 @@ [IATS(ms)....: 0.1,0.9,4839.8,4840.6,3.7,4.5,263.2,266.8,3.7,1005.3,1009.1,3.8,260.6,264.4,3.8,1025.0,1028.7,3.7,266.1,269.7,3.7,1007.6,1011.9,4.3,260.9,265.1,4.2,1006.7,1010.8,4.2,244.8] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1919,52,435,1822,52,637,1921,52,435,1822,52,637,1918,52,435,1822,52,637,1920,52,435,1822,52,637] [ENTROPIES...: 4.6,5.1,4.9,5.9,4.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.0] - new: [...538] [ip4][..tcp] [.....172.16.0.1][33688] -> [..192.168.10.50][...80] - new: [...539] [ip4][..tcp] [.....172.16.0.1][33702] -> [..192.168.10.50][...80] + new: [...538] [ip4][..tcp] [.....172.16.0.1][33688] -> [..192.168.10.50][...80] + new: [...539] [ip4][..tcp] [.....172.16.0.1][33702] -> [..192.168.10.50][...80] guessed: [...463] [ip4][..tcp] [.....172.16.0.1][60558] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...463] [ip4][..tcp] [.....172.16.0.1][60558] -> [..192.168.10.50][...80] + end: [...463] [ip4][..tcp] [.....172.16.0.1][60558] -> [..192.168.10.50][...80] guessed: [...464] [ip4][..tcp] [.....172.16.0.1][60572] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...464] [ip4][..tcp] [.....172.16.0.1][60572] -> [..192.168.10.50][...80] + end: [...464] [ip4][..tcp] [.....172.16.0.1][60572] -> [..192.168.10.50][...80] guessed: [...465] [ip4][..tcp] [.....172.16.0.1][60598] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...465] [ip4][..tcp] [.....172.16.0.1][60598] -> [..192.168.10.50][...80] + end: [...465] [ip4][..tcp] [.....172.16.0.1][60598] -> [..192.168.10.50][...80] guessed: [...466] [ip4][..tcp] [.....172.16.0.1][60612] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...466] [ip4][..tcp] [.....172.16.0.1][60612] -> [..192.168.10.50][...80] + end: [...466] [ip4][..tcp] [.....172.16.0.1][60612] -> [..192.168.10.50][...80] guessed: [...467] [ip4][..tcp] [.....172.16.0.1][60626] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...467] [ip4][..tcp] [.....172.16.0.1][60626] -> [..192.168.10.50][...80] - new: [...540] [ip4][..tcp] [.....172.16.0.1][33728] -> [..192.168.10.50][...80] - new: [...541] [ip4][..tcp] [.....172.16.0.1][33742] -> [..192.168.10.50][...80] - new: [...542] [ip4][..tcp] [.....172.16.0.1][33768] -> [..192.168.10.50][...80] - new: [...543] [ip4][..tcp] [.....172.16.0.1][33782] -> [..192.168.10.50][...80] - new: [...544] [ip4][..tcp] [.....172.16.0.1][33808] -> [..192.168.10.50][...80] - new: [...545] [ip4][..tcp] [.....172.16.0.1][33822] -> [..192.168.10.50][...80] + end: [...467] [ip4][..tcp] [.....172.16.0.1][60626] -> [..192.168.10.50][...80] + new: [...540] [ip4][..tcp] [.....172.16.0.1][33728] -> [..192.168.10.50][...80] + new: [...541] [ip4][..tcp] [.....172.16.0.1][33742] -> [..192.168.10.50][...80] + new: [...542] [ip4][..tcp] [.....172.16.0.1][33768] -> [..192.168.10.50][...80] + new: [...543] [ip4][..tcp] [.....172.16.0.1][33782] -> [..192.168.10.50][...80] + new: [...544] [ip4][..tcp] [.....172.16.0.1][33808] -> [..192.168.10.50][...80] + new: [...545] [ip4][..tcp] [.....172.16.0.1][33822] -> [..192.168.10.50][...80] guessed: [...468] [ip4][..tcp] [.....172.16.0.1][60652] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...468] [ip4][..tcp] [.....172.16.0.1][60652] -> [..192.168.10.50][...80] + end: [...468] [ip4][..tcp] [.....172.16.0.1][60652] -> [..192.168.10.50][...80] guessed: [...469] [ip4][..tcp] [.....172.16.0.1][60666] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...469] [ip4][..tcp] [.....172.16.0.1][60666] -> [..192.168.10.50][...80] + end: [...469] [ip4][..tcp] [.....172.16.0.1][60666] -> [..192.168.10.50][...80] guessed: [...470] [ip4][..tcp] [.....172.16.0.1][60692] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...470] [ip4][..tcp] [.....172.16.0.1][60692] -> [..192.168.10.50][...80] + end: [...470] [ip4][..tcp] [.....172.16.0.1][60692] -> [..192.168.10.50][...80] guessed: [...471] [ip4][..tcp] [.....172.16.0.1][60706] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...471] [ip4][..tcp] [.....172.16.0.1][60706] -> [..192.168.10.50][...80] + end: [...471] [ip4][..tcp] [.....172.16.0.1][60706] -> [..192.168.10.50][...80] guessed: [...472] [ip4][..tcp] [.....172.16.0.1][60720] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...472] [ip4][..tcp] [.....172.16.0.1][60720] -> [..192.168.10.50][...80] + end: [...472] [ip4][..tcp] [.....172.16.0.1][60720] -> [..192.168.10.50][...80] guessed: [...473] [ip4][..tcp] [.....172.16.0.1][60734] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...473] [ip4][..tcp] [.....172.16.0.1][60734] -> [..192.168.10.50][...80] + end: [...473] [ip4][..tcp] [.....172.16.0.1][60734] -> [..192.168.10.50][...80] guessed: [...474] [ip4][..tcp] [.....172.16.0.1][60748] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...474] [ip4][..tcp] [.....172.16.0.1][60748] -> [..192.168.10.50][...80] - new: [...546] [ip4][..tcp] [.....172.16.0.1][33836] -> [..192.168.10.50][...80] - new: [...547] [ip4][..tcp] [.....172.16.0.1][33862] -> [..192.168.10.50][...80] - new: [...548] [ip4][..tcp] [.....172.16.0.1][33876] -> [..192.168.10.50][...80] - new: [...549] [ip4][..tcp] [.....172.16.0.1][33902] -> [..192.168.10.50][...80] - new: [...550] [ip4][..tcp] [.....172.16.0.1][33916] -> [..192.168.10.50][...80] - new: [...551] [ip4][..tcp] [.....172.16.0.1][33930] -> [..192.168.10.50][...80] + end: [...474] [ip4][..tcp] [.....172.16.0.1][60748] -> [..192.168.10.50][...80] + new: [...546] [ip4][..tcp] [.....172.16.0.1][33836] -> [..192.168.10.50][...80] + new: [...547] [ip4][..tcp] [.....172.16.0.1][33862] -> [..192.168.10.50][...80] + new: [...548] [ip4][..tcp] [.....172.16.0.1][33876] -> [..192.168.10.50][...80] + new: [...549] [ip4][..tcp] [.....172.16.0.1][33902] -> [..192.168.10.50][...80] + new: [...550] [ip4][..tcp] [.....172.16.0.1][33916] -> [..192.168.10.50][...80] + new: [...551] [ip4][..tcp] [.....172.16.0.1][33930] -> [..192.168.10.50][...80] guessed: [...475] [ip4][..tcp] [.....172.16.0.1][60762] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...475] [ip4][..tcp] [.....172.16.0.1][60762] -> [..192.168.10.50][...80] + end: [...475] [ip4][..tcp] [.....172.16.0.1][60762] -> [..192.168.10.50][...80] guessed: [...476] [ip4][..tcp] [.....172.16.0.1][60788] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...476] [ip4][..tcp] [.....172.16.0.1][60788] -> [..192.168.10.50][...80] + end: [...476] [ip4][..tcp] [.....172.16.0.1][60788] -> [..192.168.10.50][...80] guessed: [...477] [ip4][..tcp] [.....172.16.0.1][60802] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...477] [ip4][..tcp] [.....172.16.0.1][60802] -> [..192.168.10.50][...80] + end: [...477] [ip4][..tcp] [.....172.16.0.1][60802] -> [..192.168.10.50][...80] guessed: [...478] [ip4][..tcp] [.....172.16.0.1][60816] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...478] [ip4][..tcp] [.....172.16.0.1][60816] -> [..192.168.10.50][...80] + end: [...478] [ip4][..tcp] [.....172.16.0.1][60816] -> [..192.168.10.50][...80] guessed: [...479] [ip4][..tcp] [.....172.16.0.1][60842] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...479] [ip4][..tcp] [.....172.16.0.1][60842] -> [..192.168.10.50][...80] + end: [...479] [ip4][..tcp] [.....172.16.0.1][60842] -> [..192.168.10.50][...80] guessed: [...480] [ip4][..tcp] [.....172.16.0.1][60856] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...480] [ip4][..tcp] [.....172.16.0.1][60856] -> [..192.168.10.50][...80] - new: [...552] [ip4][..tcp] [.....172.16.0.1][33956] -> [..192.168.10.50][...80] - new: [...553] [ip4][..tcp] [.....172.16.0.1][33970] -> [..192.168.10.50][...80] - new: [...554] [ip4][..tcp] [.....172.16.0.1][33996] -> [..192.168.10.50][...80] - new: [...555] [ip4][..tcp] [.....172.16.0.1][34010] -> [..192.168.10.50][...80] - new: [...556] [ip4][..tcp] [.....172.16.0.1][34024] -> [..192.168.10.50][...80] + end: [...480] [ip4][..tcp] [.....172.16.0.1][60856] -> [..192.168.10.50][...80] + new: [...552] [ip4][..tcp] [.....172.16.0.1][33956] -> [..192.168.10.50][...80] + new: [...553] [ip4][..tcp] [.....172.16.0.1][33970] -> [..192.168.10.50][...80] + new: [...554] [ip4][..tcp] [.....172.16.0.1][33996] -> [..192.168.10.50][...80] + new: [...555] [ip4][..tcp] [.....172.16.0.1][34010] -> [..192.168.10.50][...80] + new: [...556] [ip4][..tcp] [.....172.16.0.1][34024] -> [..192.168.10.50][...80] guessed: [...481] [ip4][..tcp] [.....172.16.0.1][60882] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...481] [ip4][..tcp] [.....172.16.0.1][60882] -> [..192.168.10.50][...80] + end: [...481] [ip4][..tcp] [.....172.16.0.1][60882] -> [..192.168.10.50][...80] guessed: [...482] [ip4][..tcp] [.....172.16.0.1][60896] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...482] [ip4][..tcp] [.....172.16.0.1][60896] -> [..192.168.10.50][...80] + end: [...482] [ip4][..tcp] [.....172.16.0.1][60896] -> [..192.168.10.50][...80] guessed: [...483] [ip4][..tcp] [.....172.16.0.1][60922] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...483] [ip4][..tcp] [.....172.16.0.1][60922] -> [..192.168.10.50][...80] + end: [...483] [ip4][..tcp] [.....172.16.0.1][60922] -> [..192.168.10.50][...80] guessed: [...484] [ip4][..tcp] [.....172.16.0.1][60936] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...484] [ip4][..tcp] [.....172.16.0.1][60936] -> [..192.168.10.50][...80] + end: [...484] [ip4][..tcp] [.....172.16.0.1][60936] -> [..192.168.10.50][...80] guessed: [...485] [ip4][..tcp] [.....172.16.0.1][60950] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...485] [ip4][..tcp] [.....172.16.0.1][60950] -> [..192.168.10.50][...80] - new: [...557] [ip4][..tcp] [.....172.16.0.1][34050] -> [..192.168.10.50][...80] - new: [...558] [ip4][..tcp] [.....172.16.0.1][34064] -> [..192.168.10.50][...80] - new: [...559] [ip4][..tcp] [.....172.16.0.1][34090] -> [..192.168.10.50][...80] - new: [...560] [ip4][..tcp] [.....172.16.0.1][34104] -> [..192.168.10.50][...80] - new: [...561] [ip4][..tcp] [.....172.16.0.1][34118] -> [..192.168.10.50][...80] - new: [...562] [ip4][..tcp] [.....172.16.0.1][34144] -> [..192.168.10.50][...80] + end: [...485] [ip4][..tcp] [.....172.16.0.1][60950] -> [..192.168.10.50][...80] + new: [...557] [ip4][..tcp] [.....172.16.0.1][34050] -> [..192.168.10.50][...80] + new: [...558] [ip4][..tcp] [.....172.16.0.1][34064] -> [..192.168.10.50][...80] + new: [...559] [ip4][..tcp] [.....172.16.0.1][34090] -> [..192.168.10.50][...80] + new: [...560] [ip4][..tcp] [.....172.16.0.1][34104] -> [..192.168.10.50][...80] + new: [...561] [ip4][..tcp] [.....172.16.0.1][34118] -> [..192.168.10.50][...80] + new: [...562] [ip4][..tcp] [.....172.16.0.1][34144] -> [..192.168.10.50][...80] guessed: [...487] [ip4][..tcp] [.....172.16.0.1][60990] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...487] [ip4][..tcp] [.....172.16.0.1][60990] -> [..192.168.10.50][...80] + end: [...487] [ip4][..tcp] [.....172.16.0.1][60990] -> [..192.168.10.50][...80] guessed: [...488] [ip4][..tcp] [.....172.16.0.1][32784] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...488] [ip4][..tcp] [.....172.16.0.1][32784] -> [..192.168.10.50][...80] + end: [...488] [ip4][..tcp] [.....172.16.0.1][32784] -> [..192.168.10.50][...80] guessed: [...489] [ip4][..tcp] [.....172.16.0.1][32798] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...489] [ip4][..tcp] [.....172.16.0.1][32798] -> [..192.168.10.50][...80] + end: [...489] [ip4][..tcp] [.....172.16.0.1][32798] -> [..192.168.10.50][...80] guessed: [...490] [ip4][..tcp] [.....172.16.0.1][32812] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...490] [ip4][..tcp] [.....172.16.0.1][32812] -> [..192.168.10.50][...80] + end: [...490] [ip4][..tcp] [.....172.16.0.1][32812] -> [..192.168.10.50][...80] guessed: [...491] [ip4][..tcp] [.....172.16.0.1][32838] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...491] [ip4][..tcp] [.....172.16.0.1][32838] -> [..192.168.10.50][...80] + end: [...491] [ip4][..tcp] [.....172.16.0.1][32838] -> [..192.168.10.50][...80] guessed: [...486] [ip4][..tcp] [.....172.16.0.1][60976] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...486] [ip4][..tcp] [.....172.16.0.1][60976] -> [..192.168.10.50][...80] - new: [...563] [ip4][..tcp] [.....172.16.0.1][34158] -> [..192.168.10.50][...80] - new: [...564] [ip4][..tcp] [.....172.16.0.1][34184] -> [..192.168.10.50][...80] - new: [...565] [ip4][..tcp] [.....172.16.0.1][34198] -> [..192.168.10.50][...80] - new: [...566] [ip4][..tcp] [.....172.16.0.1][34224] -> [..192.168.10.50][...80] - new: [...567] [ip4][..tcp] [.....172.16.0.1][34238] -> [..192.168.10.50][...80] - new: [...568] [ip4][..tcp] [.....172.16.0.1][34252] -> [..192.168.10.50][...80] + end: [...486] [ip4][..tcp] [.....172.16.0.1][60976] -> [..192.168.10.50][...80] + new: [...563] [ip4][..tcp] [.....172.16.0.1][34158] -> [..192.168.10.50][...80] + new: [...564] [ip4][..tcp] [.....172.16.0.1][34184] -> [..192.168.10.50][...80] + new: [...565] [ip4][..tcp] [.....172.16.0.1][34198] -> [..192.168.10.50][...80] + new: [...566] [ip4][..tcp] [.....172.16.0.1][34224] -> [..192.168.10.50][...80] + new: [...567] [ip4][..tcp] [.....172.16.0.1][34238] -> [..192.168.10.50][...80] + new: [...568] [ip4][..tcp] [.....172.16.0.1][34252] -> [..192.168.10.50][...80] guessed: [...492] [ip4][..tcp] [.....172.16.0.1][32852] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...492] [ip4][..tcp] [.....172.16.0.1][32852] -> [..192.168.10.50][...80] + end: [...492] [ip4][..tcp] [.....172.16.0.1][32852] -> [..192.168.10.50][...80] guessed: [...493] [ip4][..tcp] [.....172.16.0.1][32878] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...493] [ip4][..tcp] [.....172.16.0.1][32878] -> [..192.168.10.50][...80] + end: [...493] [ip4][..tcp] [.....172.16.0.1][32878] -> [..192.168.10.50][...80] guessed: [...494] [ip4][..tcp] [.....172.16.0.1][32892] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...494] [ip4][..tcp] [.....172.16.0.1][32892] -> [..192.168.10.50][...80] + end: [...494] [ip4][..tcp] [.....172.16.0.1][32892] -> [..192.168.10.50][...80] guessed: [...496] [ip4][..tcp] [.....172.16.0.1][32932] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...496] [ip4][..tcp] [.....172.16.0.1][32932] -> [..192.168.10.50][...80] + end: [...496] [ip4][..tcp] [.....172.16.0.1][32932] -> [..192.168.10.50][...80] guessed: [...497] [ip4][..tcp] [.....172.16.0.1][32946] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...497] [ip4][..tcp] [.....172.16.0.1][32946] -> [..192.168.10.50][...80] + end: [...497] [ip4][..tcp] [.....172.16.0.1][32946] -> [..192.168.10.50][...80] end: [...458] [ip4][..tcp] [.....172.16.0.1][60464] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...569] [ip4][..tcp] [.....172.16.0.1][34278] -> [..192.168.10.50][...80] - new: [...570] [ip4][..tcp] [.....172.16.0.1][34292] -> [..192.168.10.50][...80] + new: [...569] [ip4][..tcp] [.....172.16.0.1][34278] -> [..192.168.10.50][...80] + new: [...570] [ip4][..tcp] [.....172.16.0.1][34292] -> [..192.168.10.50][...80] detected: [...569] [ip4][..tcp] [.....172.16.0.1][34278] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...571] [ip4][..tcp] [.....172.16.0.1][34318] -> [..192.168.10.50][...80] - new: [...572] [ip4][..tcp] [.....172.16.0.1][34332] -> [..192.168.10.50][...80] - new: [...573] [ip4][..tcp] [.....172.16.0.1][34346] -> [..192.168.10.50][...80] + new: [...571] [ip4][..tcp] [.....172.16.0.1][34318] -> [..192.168.10.50][...80] + new: [...572] [ip4][..tcp] [.....172.16.0.1][34332] -> [..192.168.10.50][...80] + new: [...573] [ip4][..tcp] [.....172.16.0.1][34346] -> [..192.168.10.50][...80] analyse: [...569] [ip4][..tcp] [.....172.16.0.1][34278] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.588| 0.498| 0.689| 474371.129| 3.700] @@ -1779,130 +1779,130 @@ [PKTLENS.....: 60,60,52,637,52,1918,52,435,1822,52,637,1918,52,435,1822,52,637,1919,52,435,1822,52,637,1920,52,52,435,1822,52,637,1918,52] [ENTROPIES...: 4.6,5.0,5.0,6.0,4.9,7.8,4.9,5.9,7.7,4.9,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,4.9,6.0,7.8,4.9,4.9,5.9,7.7,4.8,6.0,7.7,4.9] guessed: [...498] [ip4][..tcp] [.....172.16.0.1][32960] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...498] [ip4][..tcp] [.....172.16.0.1][32960] -> [..192.168.10.50][...80] + end: [...498] [ip4][..tcp] [.....172.16.0.1][32960] -> [..192.168.10.50][...80] guessed: [...499] [ip4][..tcp] [.....172.16.0.1][32974] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...499] [ip4][..tcp] [.....172.16.0.1][32974] -> [..192.168.10.50][...80] + end: [...499] [ip4][..tcp] [.....172.16.0.1][32974] -> [..192.168.10.50][...80] guessed: [...500] [ip4][..tcp] [.....172.16.0.1][32988] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...500] [ip4][..tcp] [.....172.16.0.1][32988] -> [..192.168.10.50][...80] + end: [...500] [ip4][..tcp] [.....172.16.0.1][32988] -> [..192.168.10.50][...80] guessed: [...501] [ip4][..tcp] [.....172.16.0.1][33002] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...501] [ip4][..tcp] [.....172.16.0.1][33002] -> [..192.168.10.50][...80] + end: [...501] [ip4][..tcp] [.....172.16.0.1][33002] -> [..192.168.10.50][...80] guessed: [...502] [ip4][..tcp] [.....172.16.0.1][33028] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...502] [ip4][..tcp] [.....172.16.0.1][33028] -> [..192.168.10.50][...80] + end: [...502] [ip4][..tcp] [.....172.16.0.1][33028] -> [..192.168.10.50][...80] guessed: [...503] [ip4][..tcp] [.....172.16.0.1][33042] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...503] [ip4][..tcp] [.....172.16.0.1][33042] -> [..192.168.10.50][...80] - new: [...574] [ip4][..tcp] [.....172.16.0.1][34372] -> [..192.168.10.50][...80] - new: [...575] [ip4][..tcp] [.....172.16.0.1][34386] -> [..192.168.10.50][...80] - new: [...576] [ip4][..tcp] [.....172.16.0.1][34412] -> [..192.168.10.50][...80] - new: [...577] [ip4][..tcp] [.....172.16.0.1][34426] -> [..192.168.10.50][...80] - new: [...578] [ip4][..tcp] [.....172.16.0.1][34440] -> [..192.168.10.50][...80] - new: [...579] [ip4][..tcp] [.....172.16.0.1][34466] -> [..192.168.10.50][...80] + end: [...503] [ip4][..tcp] [.....172.16.0.1][33042] -> [..192.168.10.50][...80] + new: [...574] [ip4][..tcp] [.....172.16.0.1][34372] -> [..192.168.10.50][...80] + new: [...575] [ip4][..tcp] [.....172.16.0.1][34386] -> [..192.168.10.50][...80] + new: [...576] [ip4][..tcp] [.....172.16.0.1][34412] -> [..192.168.10.50][...80] + new: [...577] [ip4][..tcp] [.....172.16.0.1][34426] -> [..192.168.10.50][...80] + new: [...578] [ip4][..tcp] [.....172.16.0.1][34440] -> [..192.168.10.50][...80] + new: [...579] [ip4][..tcp] [.....172.16.0.1][34466] -> [..192.168.10.50][...80] guessed: [...504] [ip4][..tcp] [.....172.16.0.1][33068] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...504] [ip4][..tcp] [.....172.16.0.1][33068] -> [..192.168.10.50][...80] + end: [...504] [ip4][..tcp] [.....172.16.0.1][33068] -> [..192.168.10.50][...80] guessed: [...505] [ip4][..tcp] [.....172.16.0.1][33082] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...505] [ip4][..tcp] [.....172.16.0.1][33082] -> [..192.168.10.50][...80] + end: [...505] [ip4][..tcp] [.....172.16.0.1][33082] -> [..192.168.10.50][...80] guessed: [...506] [ip4][..tcp] [.....172.16.0.1][33096] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...506] [ip4][..tcp] [.....172.16.0.1][33096] -> [..192.168.10.50][...80] + end: [...506] [ip4][..tcp] [.....172.16.0.1][33096] -> [..192.168.10.50][...80] guessed: [...507] [ip4][..tcp] [.....172.16.0.1][33122] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...507] [ip4][..tcp] [.....172.16.0.1][33122] -> [..192.168.10.50][...80] + end: [...507] [ip4][..tcp] [.....172.16.0.1][33122] -> [..192.168.10.50][...80] guessed: [...508] [ip4][..tcp] [.....172.16.0.1][33136] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...508] [ip4][..tcp] [.....172.16.0.1][33136] -> [..192.168.10.50][...80] + end: [...508] [ip4][..tcp] [.....172.16.0.1][33136] -> [..192.168.10.50][...80] guessed: [...509] [ip4][..tcp] [.....172.16.0.1][33162] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...509] [ip4][..tcp] [.....172.16.0.1][33162] -> [..192.168.10.50][...80] - new: [...580] [ip4][..tcp] [.....172.16.0.1][34480] -> [..192.168.10.50][...80] - new: [...581] [ip4][..tcp] [.....172.16.0.1][34506] -> [..192.168.10.50][...80] - new: [...582] [ip4][..tcp] [.....172.16.0.1][34520] -> [..192.168.10.50][...80] - new: [...583] [ip4][..tcp] [.....172.16.0.1][34534] -> [..192.168.10.50][...80] - new: [...584] [ip4][..tcp] [.....172.16.0.1][34548] -> [..192.168.10.50][...80] - new: [...585] [ip4][..tcp] [.....172.16.0.1][34562] -> [..192.168.10.50][...80] - new: [...586] [ip4][..tcp] [.....172.16.0.1][34576] -> [..192.168.10.50][...80] + end: [...509] [ip4][..tcp] [.....172.16.0.1][33162] -> [..192.168.10.50][...80] + new: [...580] [ip4][..tcp] [.....172.16.0.1][34480] -> [..192.168.10.50][...80] + new: [...581] [ip4][..tcp] [.....172.16.0.1][34506] -> [..192.168.10.50][...80] + new: [...582] [ip4][..tcp] [.....172.16.0.1][34520] -> [..192.168.10.50][...80] + new: [...583] [ip4][..tcp] [.....172.16.0.1][34534] -> [..192.168.10.50][...80] + new: [...584] [ip4][..tcp] [.....172.16.0.1][34548] -> [..192.168.10.50][...80] + new: [...585] [ip4][..tcp] [.....172.16.0.1][34562] -> [..192.168.10.50][...80] + new: [...586] [ip4][..tcp] [.....172.16.0.1][34576] -> [..192.168.10.50][...80] guessed: [...510] [ip4][..tcp] [.....172.16.0.1][33176] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...510] [ip4][..tcp] [.....172.16.0.1][33176] -> [..192.168.10.50][...80] + end: [...510] [ip4][..tcp] [.....172.16.0.1][33176] -> [..192.168.10.50][...80] guessed: [...511] [ip4][..tcp] [.....172.16.0.1][33202] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...511] [ip4][..tcp] [.....172.16.0.1][33202] -> [..192.168.10.50][...80] + end: [...511] [ip4][..tcp] [.....172.16.0.1][33202] -> [..192.168.10.50][...80] guessed: [...512] [ip4][..tcp] [.....172.16.0.1][33216] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...512] [ip4][..tcp] [.....172.16.0.1][33216] -> [..192.168.10.50][...80] + end: [...512] [ip4][..tcp] [.....172.16.0.1][33216] -> [..192.168.10.50][...80] guessed: [...513] [ip4][..tcp] [.....172.16.0.1][33230] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...513] [ip4][..tcp] [.....172.16.0.1][33230] -> [..192.168.10.50][...80] + end: [...513] [ip4][..tcp] [.....172.16.0.1][33230] -> [..192.168.10.50][...80] guessed: [...514] [ip4][..tcp] [.....172.16.0.1][33256] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...514] [ip4][..tcp] [.....172.16.0.1][33256] -> [..192.168.10.50][...80] + end: [...514] [ip4][..tcp] [.....172.16.0.1][33256] -> [..192.168.10.50][...80] guessed: [...515] [ip4][..tcp] [.....172.16.0.1][33270] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...515] [ip4][..tcp] [.....172.16.0.1][33270] -> [..192.168.10.50][...80] - new: [...587] [ip4][..tcp] [.....172.16.0.1][34602] -> [..192.168.10.50][...80] - new: [...588] [ip4][..tcp] [.....172.16.0.1][34616] -> [..192.168.10.50][...80] - new: [...589] [ip4][..tcp] [.....172.16.0.1][34642] -> [..192.168.10.50][...80] - new: [...590] [ip4][..tcp] [.....172.16.0.1][34656] -> [..192.168.10.50][...80] - new: [...591] [ip4][..tcp] [.....172.16.0.1][34670] -> [..192.168.10.50][...80] + end: [...515] [ip4][..tcp] [.....172.16.0.1][33270] -> [..192.168.10.50][...80] + new: [...587] [ip4][..tcp] [.....172.16.0.1][34602] -> [..192.168.10.50][...80] + new: [...588] [ip4][..tcp] [.....172.16.0.1][34616] -> [..192.168.10.50][...80] + new: [...589] [ip4][..tcp] [.....172.16.0.1][34642] -> [..192.168.10.50][...80] + new: [...590] [ip4][..tcp] [.....172.16.0.1][34656] -> [..192.168.10.50][...80] + new: [...591] [ip4][..tcp] [.....172.16.0.1][34670] -> [..192.168.10.50][...80] guessed: [...516] [ip4][..tcp] [.....172.16.0.1][33296] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...516] [ip4][..tcp] [.....172.16.0.1][33296] -> [..192.168.10.50][...80] + end: [...516] [ip4][..tcp] [.....172.16.0.1][33296] -> [..192.168.10.50][...80] guessed: [...517] [ip4][..tcp] [.....172.16.0.1][33310] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...517] [ip4][..tcp] [.....172.16.0.1][33310] -> [..192.168.10.50][...80] + end: [...517] [ip4][..tcp] [.....172.16.0.1][33310] -> [..192.168.10.50][...80] guessed: [...518] [ip4][..tcp] [.....172.16.0.1][33324] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...518] [ip4][..tcp] [.....172.16.0.1][33324] -> [..192.168.10.50][...80] + end: [...518] [ip4][..tcp] [.....172.16.0.1][33324] -> [..192.168.10.50][...80] guessed: [...519] [ip4][..tcp] [.....172.16.0.1][33350] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...519] [ip4][..tcp] [.....172.16.0.1][33350] -> [..192.168.10.50][...80] + end: [...519] [ip4][..tcp] [.....172.16.0.1][33350] -> [..192.168.10.50][...80] guessed: [...520] [ip4][..tcp] [.....172.16.0.1][33364] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...520] [ip4][..tcp] [.....172.16.0.1][33364] -> [..192.168.10.50][...80] + end: [...520] [ip4][..tcp] [.....172.16.0.1][33364] -> [..192.168.10.50][...80] guessed: [...521] [ip4][..tcp] [.....172.16.0.1][33378] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...521] [ip4][..tcp] [.....172.16.0.1][33378] -> [..192.168.10.50][...80] - new: [...592] [ip4][..tcp] [.....172.16.0.1][34696] -> [..192.168.10.50][...80] - new: [...593] [ip4][..tcp] [.....172.16.0.1][34710] -> [..192.168.10.50][...80] - new: [...594] [ip4][..tcp] [.....172.16.0.1][34724] -> [..192.168.10.50][...80] - new: [...595] [ip4][..tcp] [.....172.16.0.1][34738] -> [..192.168.10.50][...80] - new: [...596] [ip4][..tcp] [.....172.16.0.1][34752] -> [..192.168.10.50][...80] - new: [...597] [ip4][..tcp] [.....172.16.0.1][34766] -> [..192.168.10.50][...80] - new: [...598] [ip4][..tcp] [.....172.16.0.1][34792] -> [..192.168.10.50][...80] + end: [...521] [ip4][..tcp] [.....172.16.0.1][33378] -> [..192.168.10.50][...80] + new: [...592] [ip4][..tcp] [.....172.16.0.1][34696] -> [..192.168.10.50][...80] + new: [...593] [ip4][..tcp] [.....172.16.0.1][34710] -> [..192.168.10.50][...80] + new: [...594] [ip4][..tcp] [.....172.16.0.1][34724] -> [..192.168.10.50][...80] + new: [...595] [ip4][..tcp] [.....172.16.0.1][34738] -> [..192.168.10.50][...80] + new: [...596] [ip4][..tcp] [.....172.16.0.1][34752] -> [..192.168.10.50][...80] + new: [...597] [ip4][..tcp] [.....172.16.0.1][34766] -> [..192.168.10.50][...80] + new: [...598] [ip4][..tcp] [.....172.16.0.1][34792] -> [..192.168.10.50][...80] guessed: [...522] [ip4][..tcp] [.....172.16.0.1][33404] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...522] [ip4][..tcp] [.....172.16.0.1][33404] -> [..192.168.10.50][...80] + end: [...522] [ip4][..tcp] [.....172.16.0.1][33404] -> [..192.168.10.50][...80] guessed: [...523] [ip4][..tcp] [.....172.16.0.1][33418] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...523] [ip4][..tcp] [.....172.16.0.1][33418] -> [..192.168.10.50][...80] + end: [...523] [ip4][..tcp] [.....172.16.0.1][33418] -> [..192.168.10.50][...80] guessed: [...524] [ip4][..tcp] [.....172.16.0.1][33444] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...524] [ip4][..tcp] [.....172.16.0.1][33444] -> [..192.168.10.50][...80] + end: [...524] [ip4][..tcp] [.....172.16.0.1][33444] -> [..192.168.10.50][...80] guessed: [...525] [ip4][..tcp] [.....172.16.0.1][33458] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...525] [ip4][..tcp] [.....172.16.0.1][33458] -> [..192.168.10.50][...80] + end: [...525] [ip4][..tcp] [.....172.16.0.1][33458] -> [..192.168.10.50][...80] guessed: [...526] [ip4][..tcp] [.....172.16.0.1][33472] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...526] [ip4][..tcp] [.....172.16.0.1][33472] -> [..192.168.10.50][...80] + end: [...526] [ip4][..tcp] [.....172.16.0.1][33472] -> [..192.168.10.50][...80] guessed: [...527] [ip4][..tcp] [.....172.16.0.1][33486] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...527] [ip4][..tcp] [.....172.16.0.1][33486] -> [..192.168.10.50][...80] - new: [...599] [ip4][..tcp] [.....172.16.0.1][34806] -> [..192.168.10.50][...80] - new: [...600] [ip4][..tcp] [.....172.16.0.1][34832] -> [..192.168.10.50][...80] - new: [...601] [ip4][..tcp] [.....172.16.0.1][34846] -> [..192.168.10.50][...80] - new: [...602] [ip4][..tcp] [.....172.16.0.1][34860] -> [..192.168.10.50][...80] - new: [...603] [ip4][..tcp] [.....172.16.0.1][34886] -> [..192.168.10.50][...80] - new: [...604] [ip4][..tcp] [.....172.16.0.1][34900] -> [..192.168.10.50][...80] + end: [...527] [ip4][..tcp] [.....172.16.0.1][33486] -> [..192.168.10.50][...80] + new: [...599] [ip4][..tcp] [.....172.16.0.1][34806] -> [..192.168.10.50][...80] + new: [...600] [ip4][..tcp] [.....172.16.0.1][34832] -> [..192.168.10.50][...80] + new: [...601] [ip4][..tcp] [.....172.16.0.1][34846] -> [..192.168.10.50][...80] + new: [...602] [ip4][..tcp] [.....172.16.0.1][34860] -> [..192.168.10.50][...80] + new: [...603] [ip4][..tcp] [.....172.16.0.1][34886] -> [..192.168.10.50][...80] + new: [...604] [ip4][..tcp] [.....172.16.0.1][34900] -> [..192.168.10.50][...80] end: [...495] [ip4][..tcp] [.....172.16.0.1][32906] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...528] [ip4][..tcp] [.....172.16.0.1][33500] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...528] [ip4][..tcp] [.....172.16.0.1][33500] -> [..192.168.10.50][...80] + end: [...528] [ip4][..tcp] [.....172.16.0.1][33500] -> [..192.168.10.50][...80] guessed: [...529] [ip4][..tcp] [.....172.16.0.1][33526] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...529] [ip4][..tcp] [.....172.16.0.1][33526] -> [..192.168.10.50][...80] + end: [...529] [ip4][..tcp] [.....172.16.0.1][33526] -> [..192.168.10.50][...80] guessed: [...530] [ip4][..tcp] [.....172.16.0.1][33540] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...530] [ip4][..tcp] [.....172.16.0.1][33540] -> [..192.168.10.50][...80] + end: [...530] [ip4][..tcp] [.....172.16.0.1][33540] -> [..192.168.10.50][...80] guessed: [...531] [ip4][..tcp] [.....172.16.0.1][33554] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...531] [ip4][..tcp] [.....172.16.0.1][33554] -> [..192.168.10.50][...80] + end: [...531] [ip4][..tcp] [.....172.16.0.1][33554] -> [..192.168.10.50][...80] guessed: [...533] [ip4][..tcp] [.....172.16.0.1][33594] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...533] [ip4][..tcp] [.....172.16.0.1][33594] -> [..192.168.10.50][...80] - new: [...605] [ip4][..tcp] [.....172.16.0.1][34926] -> [..192.168.10.50][...80] - new: [...606] [ip4][..tcp] [.....172.16.0.1][34940] -> [..192.168.10.50][...80] - new: [...607] [ip4][..tcp] [.....172.16.0.1][34954] -> [..192.168.10.50][...80] - new: [...608] [ip4][..tcp] [.....172.16.0.1][34980] -> [..192.168.10.50][...80] + end: [...533] [ip4][..tcp] [.....172.16.0.1][33594] -> [..192.168.10.50][...80] + new: [...605] [ip4][..tcp] [.....172.16.0.1][34926] -> [..192.168.10.50][...80] + new: [...606] [ip4][..tcp] [.....172.16.0.1][34940] -> [..192.168.10.50][...80] + new: [...607] [ip4][..tcp] [.....172.16.0.1][34954] -> [..192.168.10.50][...80] + new: [...608] [ip4][..tcp] [.....172.16.0.1][34980] -> [..192.168.10.50][...80] detected: [...606] [ip4][..tcp] [.....172.16.0.1][34940] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...609] [ip4][..tcp] [.....172.16.0.1][34994] -> [..192.168.10.50][...80] + new: [...609] [ip4][..tcp] [.....172.16.0.1][34994] -> [..192.168.10.50][...80] guessed: [...534] [ip4][..tcp] [.....172.16.0.1][33608] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...534] [ip4][..tcp] [.....172.16.0.1][33608] -> [..192.168.10.50][...80] + end: [...534] [ip4][..tcp] [.....172.16.0.1][33608] -> [..192.168.10.50][...80] guessed: [...535] [ip4][..tcp] [.....172.16.0.1][33634] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...535] [ip4][..tcp] [.....172.16.0.1][33634] -> [..192.168.10.50][...80] + end: [...535] [ip4][..tcp] [.....172.16.0.1][33634] -> [..192.168.10.50][...80] guessed: [...536] [ip4][..tcp] [.....172.16.0.1][33648] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...536] [ip4][..tcp] [.....172.16.0.1][33648] -> [..192.168.10.50][...80] + end: [...536] [ip4][..tcp] [.....172.16.0.1][33648] -> [..192.168.10.50][...80] guessed: [...537] [ip4][..tcp] [.....172.16.0.1][33674] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...537] [ip4][..tcp] [.....172.16.0.1][33674] -> [..192.168.10.50][...80] + end: [...537] [ip4][..tcp] [.....172.16.0.1][33674] -> [..192.168.10.50][...80] guessed: [...538] [ip4][..tcp] [.....172.16.0.1][33688] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...538] [ip4][..tcp] [.....172.16.0.1][33688] -> [..192.168.10.50][...80] + end: [...538] [ip4][..tcp] [.....172.16.0.1][33688] -> [..192.168.10.50][...80] guessed: [...539] [ip4][..tcp] [.....172.16.0.1][33702] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...539] [ip4][..tcp] [.....172.16.0.1][33702] -> [..192.168.10.50][...80] - new: [...610] [ip4][..tcp] [.....172.16.0.1][35020] -> [..192.168.10.50][...80] - new: [...611] [ip4][..tcp] [.....172.16.0.1][35034] -> [..192.168.10.50][...80] - new: [...612] [ip4][..tcp] [.....172.16.0.1][35048] -> [..192.168.10.50][...80] + end: [...539] [ip4][..tcp] [.....172.16.0.1][33702] -> [..192.168.10.50][...80] + new: [...610] [ip4][..tcp] [.....172.16.0.1][35020] -> [..192.168.10.50][...80] + new: [...611] [ip4][..tcp] [.....172.16.0.1][35034] -> [..192.168.10.50][...80] + new: [...612] [ip4][..tcp] [.....172.16.0.1][35048] -> [..192.168.10.50][...80] analyse: [...606] [ip4][..tcp] [.....172.16.0.1][34940] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.897| 0.655| 1.187| 1408178.323| 3.500] @@ -1913,113 +1913,113 @@ [IATS(ms)....: 0.2,0.9,4896.4,4897.2,3.1,3.9,250.4,254.5,4.1,1006.9,1011.0,4.1,267.3,271.2,3.9,1008.0,1012.0,4.0,246.8,250.4,3.6,1038.7,1042.4,3.7,241.6,245.2,3.6,1046.3,1049.9,3.8,242.0] [PKTLENS.....: 60,60,52,435,52,1823,52,637,1920,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1920,52,435,1822,52,637] [ENTROPIES...: 4.6,5.1,5.0,5.9,4.9,7.7,4.9,6.0,7.8,4.9,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,5.0,6.0,7.8,4.9,5.9,7.7,5.0,6.0] - new: [...613] [ip4][..tcp] [.....172.16.0.1][35074] -> [..192.168.10.50][...80] - new: [...614] [ip4][..tcp] [.....172.16.0.1][35088] -> [..192.168.10.50][...80] - new: [...615] [ip4][..tcp] [.....172.16.0.1][35114] -> [..192.168.10.50][...80] + new: [...613] [ip4][..tcp] [.....172.16.0.1][35074] -> [..192.168.10.50][...80] + new: [...614] [ip4][..tcp] [.....172.16.0.1][35088] -> [..192.168.10.50][...80] + new: [...615] [ip4][..tcp] [.....172.16.0.1][35114] -> [..192.168.10.50][...80] guessed: [...540] [ip4][..tcp] [.....172.16.0.1][33728] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...540] [ip4][..tcp] [.....172.16.0.1][33728] -> [..192.168.10.50][...80] + end: [...540] [ip4][..tcp] [.....172.16.0.1][33728] -> [..192.168.10.50][...80] guessed: [...541] [ip4][..tcp] [.....172.16.0.1][33742] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...541] [ip4][..tcp] [.....172.16.0.1][33742] -> [..192.168.10.50][...80] + end: [...541] [ip4][..tcp] [.....172.16.0.1][33742] -> [..192.168.10.50][...80] guessed: [...542] [ip4][..tcp] [.....172.16.0.1][33768] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...542] [ip4][..tcp] [.....172.16.0.1][33768] -> [..192.168.10.50][...80] + end: [...542] [ip4][..tcp] [.....172.16.0.1][33768] -> [..192.168.10.50][...80] guessed: [...543] [ip4][..tcp] [.....172.16.0.1][33782] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...543] [ip4][..tcp] [.....172.16.0.1][33782] -> [..192.168.10.50][...80] - new: [...616] [ip4][..tcp] [.....172.16.0.1][35128] -> [..192.168.10.50][...80] - new: [...617] [ip4][..tcp] [.....172.16.0.1][35142] -> [..192.168.10.50][...80] - new: [...618] [ip4][..tcp] [.....172.16.0.1][35168] -> [..192.168.10.50][...80] - new: [...619] [ip4][..tcp] [.....172.16.0.1][35182] -> [..192.168.10.50][...80] - new: [...620] [ip4][..tcp] [.....172.16.0.1][35208] -> [..192.168.10.50][...80] - new: [...621] [ip4][..tcp] [.....172.16.0.1][35222] -> [..192.168.10.50][...80] + end: [...543] [ip4][..tcp] [.....172.16.0.1][33782] -> [..192.168.10.50][...80] + new: [...616] [ip4][..tcp] [.....172.16.0.1][35128] -> [..192.168.10.50][...80] + new: [...617] [ip4][..tcp] [.....172.16.0.1][35142] -> [..192.168.10.50][...80] + new: [...618] [ip4][..tcp] [.....172.16.0.1][35168] -> [..192.168.10.50][...80] + new: [...619] [ip4][..tcp] [.....172.16.0.1][35182] -> [..192.168.10.50][...80] + new: [...620] [ip4][..tcp] [.....172.16.0.1][35208] -> [..192.168.10.50][...80] + new: [...621] [ip4][..tcp] [.....172.16.0.1][35222] -> [..192.168.10.50][...80] guessed: [...544] [ip4][..tcp] [.....172.16.0.1][33808] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...544] [ip4][..tcp] [.....172.16.0.1][33808] -> [..192.168.10.50][...80] + end: [...544] [ip4][..tcp] [.....172.16.0.1][33808] -> [..192.168.10.50][...80] guessed: [...545] [ip4][..tcp] [.....172.16.0.1][33822] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...545] [ip4][..tcp] [.....172.16.0.1][33822] -> [..192.168.10.50][...80] + end: [...545] [ip4][..tcp] [.....172.16.0.1][33822] -> [..192.168.10.50][...80] guessed: [...546] [ip4][..tcp] [.....172.16.0.1][33836] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...546] [ip4][..tcp] [.....172.16.0.1][33836] -> [..192.168.10.50][...80] + end: [...546] [ip4][..tcp] [.....172.16.0.1][33836] -> [..192.168.10.50][...80] guessed: [...547] [ip4][..tcp] [.....172.16.0.1][33862] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...547] [ip4][..tcp] [.....172.16.0.1][33862] -> [..192.168.10.50][...80] + end: [...547] [ip4][..tcp] [.....172.16.0.1][33862] -> [..192.168.10.50][...80] guessed: [...548] [ip4][..tcp] [.....172.16.0.1][33876] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...548] [ip4][..tcp] [.....172.16.0.1][33876] -> [..192.168.10.50][...80] + end: [...548] [ip4][..tcp] [.....172.16.0.1][33876] -> [..192.168.10.50][...80] guessed: [...549] [ip4][..tcp] [.....172.16.0.1][33902] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...549] [ip4][..tcp] [.....172.16.0.1][33902] -> [..192.168.10.50][...80] + end: [...549] [ip4][..tcp] [.....172.16.0.1][33902] -> [..192.168.10.50][...80] guessed: [...550] [ip4][..tcp] [.....172.16.0.1][33916] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...550] [ip4][..tcp] [.....172.16.0.1][33916] -> [..192.168.10.50][...80] - new: [...622] [ip4][..tcp] [.....172.16.0.1][35236] -> [..192.168.10.50][...80] - new: [...623] [ip4][..tcp] [.....172.16.0.1][35262] -> [..192.168.10.50][...80] - new: [...624] [ip4][..tcp] [.....172.16.0.1][35276] -> [..192.168.10.50][...80] - new: [...625] [ip4][..tcp] [.....172.16.0.1][35302] -> [..192.168.10.50][...80] - new: [...626] [ip4][..tcp] [.....172.16.0.1][35316] -> [..192.168.10.50][...80] + end: [...550] [ip4][..tcp] [.....172.16.0.1][33916] -> [..192.168.10.50][...80] + new: [...622] [ip4][..tcp] [.....172.16.0.1][35236] -> [..192.168.10.50][...80] + new: [...623] [ip4][..tcp] [.....172.16.0.1][35262] -> [..192.168.10.50][...80] + new: [...624] [ip4][..tcp] [.....172.16.0.1][35276] -> [..192.168.10.50][...80] + new: [...625] [ip4][..tcp] [.....172.16.0.1][35302] -> [..192.168.10.50][...80] + new: [...626] [ip4][..tcp] [.....172.16.0.1][35316] -> [..192.168.10.50][...80] guessed: [...551] [ip4][..tcp] [.....172.16.0.1][33930] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...551] [ip4][..tcp] [.....172.16.0.1][33930] -> [..192.168.10.50][...80] + end: [...551] [ip4][..tcp] [.....172.16.0.1][33930] -> [..192.168.10.50][...80] guessed: [...552] [ip4][..tcp] [.....172.16.0.1][33956] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...552] [ip4][..tcp] [.....172.16.0.1][33956] -> [..192.168.10.50][...80] + end: [...552] [ip4][..tcp] [.....172.16.0.1][33956] -> [..192.168.10.50][...80] guessed: [...553] [ip4][..tcp] [.....172.16.0.1][33970] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...553] [ip4][..tcp] [.....172.16.0.1][33970] -> [..192.168.10.50][...80] + end: [...553] [ip4][..tcp] [.....172.16.0.1][33970] -> [..192.168.10.50][...80] guessed: [...554] [ip4][..tcp] [.....172.16.0.1][33996] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...554] [ip4][..tcp] [.....172.16.0.1][33996] -> [..192.168.10.50][...80] + end: [...554] [ip4][..tcp] [.....172.16.0.1][33996] -> [..192.168.10.50][...80] guessed: [...555] [ip4][..tcp] [.....172.16.0.1][34010] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...555] [ip4][..tcp] [.....172.16.0.1][34010] -> [..192.168.10.50][...80] + end: [...555] [ip4][..tcp] [.....172.16.0.1][34010] -> [..192.168.10.50][...80] guessed: [...556] [ip4][..tcp] [.....172.16.0.1][34024] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...556] [ip4][..tcp] [.....172.16.0.1][34024] -> [..192.168.10.50][...80] - new: [...627] [ip4][..tcp] [.....172.16.0.1][35342] -> [..192.168.10.50][...80] - new: [...628] [ip4][..tcp] [.....172.16.0.1][35356] -> [..192.168.10.50][...80] - new: [...629] [ip4][..tcp] [.....172.16.0.1][35370] -> [..192.168.10.50][...80] - new: [...630] [ip4][..tcp] [.....172.16.0.1][35396] -> [..192.168.10.50][...80] - new: [...631] [ip4][..tcp] [.....172.16.0.1][35410] -> [..192.168.10.50][...80] - new: [...632] [ip4][..tcp] [.....172.16.0.1][35436] -> [..192.168.10.50][...80] + end: [...556] [ip4][..tcp] [.....172.16.0.1][34024] -> [..192.168.10.50][...80] + new: [...627] [ip4][..tcp] [.....172.16.0.1][35342] -> [..192.168.10.50][...80] + new: [...628] [ip4][..tcp] [.....172.16.0.1][35356] -> [..192.168.10.50][...80] + new: [...629] [ip4][..tcp] [.....172.16.0.1][35370] -> [..192.168.10.50][...80] + new: [...630] [ip4][..tcp] [.....172.16.0.1][35396] -> [..192.168.10.50][...80] + new: [...631] [ip4][..tcp] [.....172.16.0.1][35410] -> [..192.168.10.50][...80] + new: [...632] [ip4][..tcp] [.....172.16.0.1][35436] -> [..192.168.10.50][...80] guessed: [...557] [ip4][..tcp] [.....172.16.0.1][34050] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...557] [ip4][..tcp] [.....172.16.0.1][34050] -> [..192.168.10.50][...80] + end: [...557] [ip4][..tcp] [.....172.16.0.1][34050] -> [..192.168.10.50][...80] guessed: [...558] [ip4][..tcp] [.....172.16.0.1][34064] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...558] [ip4][..tcp] [.....172.16.0.1][34064] -> [..192.168.10.50][...80] + end: [...558] [ip4][..tcp] [.....172.16.0.1][34064] -> [..192.168.10.50][...80] guessed: [...559] [ip4][..tcp] [.....172.16.0.1][34090] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...559] [ip4][..tcp] [.....172.16.0.1][34090] -> [..192.168.10.50][...80] + end: [...559] [ip4][..tcp] [.....172.16.0.1][34090] -> [..192.168.10.50][...80] guessed: [...560] [ip4][..tcp] [.....172.16.0.1][34104] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...560] [ip4][..tcp] [.....172.16.0.1][34104] -> [..192.168.10.50][...80] + end: [...560] [ip4][..tcp] [.....172.16.0.1][34104] -> [..192.168.10.50][...80] guessed: [...561] [ip4][..tcp] [.....172.16.0.1][34118] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...561] [ip4][..tcp] [.....172.16.0.1][34118] -> [..192.168.10.50][...80] - new: [...633] [ip4][..tcp] [.....172.16.0.1][35450] -> [..192.168.10.50][...80] - new: [...634] [ip4][..tcp] [.....172.16.0.1][35464] -> [..192.168.10.50][...80] - new: [...635] [ip4][..tcp] [.....172.16.0.1][35490] -> [..192.168.10.50][...80] - new: [...636] [ip4][..tcp] [.....172.16.0.1][35504] -> [..192.168.10.50][...80] - new: [...637] [ip4][..tcp] [.....172.16.0.1][35518] -> [..192.168.10.50][...80] - new: [...638] [ip4][..tcp] [.....172.16.0.1][35532] -> [..192.168.10.50][...80] - new: [...639] [ip4][..tcp] [.....172.16.0.1][35546] -> [..192.168.10.50][...80] + end: [...561] [ip4][..tcp] [.....172.16.0.1][34118] -> [..192.168.10.50][...80] + new: [...633] [ip4][..tcp] [.....172.16.0.1][35450] -> [..192.168.10.50][...80] + new: [...634] [ip4][..tcp] [.....172.16.0.1][35464] -> [..192.168.10.50][...80] + new: [...635] [ip4][..tcp] [.....172.16.0.1][35490] -> [..192.168.10.50][...80] + new: [...636] [ip4][..tcp] [.....172.16.0.1][35504] -> [..192.168.10.50][...80] + new: [...637] [ip4][..tcp] [.....172.16.0.1][35518] -> [..192.168.10.50][...80] + new: [...638] [ip4][..tcp] [.....172.16.0.1][35532] -> [..192.168.10.50][...80] + new: [...639] [ip4][..tcp] [.....172.16.0.1][35546] -> [..192.168.10.50][...80] guessed: [...562] [ip4][..tcp] [.....172.16.0.1][34144] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...562] [ip4][..tcp] [.....172.16.0.1][34144] -> [..192.168.10.50][...80] + end: [...562] [ip4][..tcp] [.....172.16.0.1][34144] -> [..192.168.10.50][...80] guessed: [...563] [ip4][..tcp] [.....172.16.0.1][34158] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...563] [ip4][..tcp] [.....172.16.0.1][34158] -> [..192.168.10.50][...80] + end: [...563] [ip4][..tcp] [.....172.16.0.1][34158] -> [..192.168.10.50][...80] guessed: [...564] [ip4][..tcp] [.....172.16.0.1][34184] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...564] [ip4][..tcp] [.....172.16.0.1][34184] -> [..192.168.10.50][...80] + end: [...564] [ip4][..tcp] [.....172.16.0.1][34184] -> [..192.168.10.50][...80] guessed: [...565] [ip4][..tcp] [.....172.16.0.1][34198] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...565] [ip4][..tcp] [.....172.16.0.1][34198] -> [..192.168.10.50][...80] + end: [...565] [ip4][..tcp] [.....172.16.0.1][34198] -> [..192.168.10.50][...80] guessed: [...566] [ip4][..tcp] [.....172.16.0.1][34224] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...566] [ip4][..tcp] [.....172.16.0.1][34224] -> [..192.168.10.50][...80] + end: [...566] [ip4][..tcp] [.....172.16.0.1][34224] -> [..192.168.10.50][...80] guessed: [...567] [ip4][..tcp] [.....172.16.0.1][34238] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...567] [ip4][..tcp] [.....172.16.0.1][34238] -> [..192.168.10.50][...80] - new: [...640] [ip4][..tcp] [.....172.16.0.1][35560] -> [..192.168.10.50][...80] - new: [...641] [ip4][..tcp] [.....172.16.0.1][35586] -> [..192.168.10.50][...80] - new: [...642] [ip4][..tcp] [.....172.16.0.1][35600] -> [..192.168.10.50][...80] - new: [...643] [ip4][..tcp] [.....172.16.0.1][35626] -> [..192.168.10.50][...80] - new: [...644] [ip4][..tcp] [.....172.16.0.1][35640] -> [..192.168.10.50][...80] - new: [...645] [ip4][..tcp] [.....172.16.0.1][35654] -> [..192.168.10.50][...80] + end: [...567] [ip4][..tcp] [.....172.16.0.1][34238] -> [..192.168.10.50][...80] + new: [...640] [ip4][..tcp] [.....172.16.0.1][35560] -> [..192.168.10.50][...80] + new: [...641] [ip4][..tcp] [.....172.16.0.1][35586] -> [..192.168.10.50][...80] + new: [...642] [ip4][..tcp] [.....172.16.0.1][35600] -> [..192.168.10.50][...80] + new: [...643] [ip4][..tcp] [.....172.16.0.1][35626] -> [..192.168.10.50][...80] + new: [...644] [ip4][..tcp] [.....172.16.0.1][35640] -> [..192.168.10.50][...80] + new: [...645] [ip4][..tcp] [.....172.16.0.1][35654] -> [..192.168.10.50][...80] end: [...532] [ip4][..tcp] [.....172.16.0.1][33580] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...568] [ip4][..tcp] [.....172.16.0.1][34252] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...568] [ip4][..tcp] [.....172.16.0.1][34252] -> [..192.168.10.50][...80] + end: [...568] [ip4][..tcp] [.....172.16.0.1][34252] -> [..192.168.10.50][...80] guessed: [...570] [ip4][..tcp] [.....172.16.0.1][34292] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...570] [ip4][..tcp] [.....172.16.0.1][34292] -> [..192.168.10.50][...80] + end: [...570] [ip4][..tcp] [.....172.16.0.1][34292] -> [..192.168.10.50][...80] guessed: [...571] [ip4][..tcp] [.....172.16.0.1][34318] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...571] [ip4][..tcp] [.....172.16.0.1][34318] -> [..192.168.10.50][...80] + end: [...571] [ip4][..tcp] [.....172.16.0.1][34318] -> [..192.168.10.50][...80] guessed: [...572] [ip4][..tcp] [.....172.16.0.1][34332] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...572] [ip4][..tcp] [.....172.16.0.1][34332] -> [..192.168.10.50][...80] + end: [...572] [ip4][..tcp] [.....172.16.0.1][34332] -> [..192.168.10.50][...80] guessed: [...573] [ip4][..tcp] [.....172.16.0.1][34346] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...573] [ip4][..tcp] [.....172.16.0.1][34346] -> [..192.168.10.50][...80] - new: [...646] [ip4][..tcp] [.....172.16.0.1][35668] -> [..192.168.10.50][...80] + end: [...573] [ip4][..tcp] [.....172.16.0.1][34346] -> [..192.168.10.50][...80] + new: [...646] [ip4][..tcp] [.....172.16.0.1][35668] -> [..192.168.10.50][...80] detected: [...643] [ip4][..tcp] [.....172.16.0.1][35626] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][205.174.165.68] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header - new: [...647] [ip4][..tcp] [.....172.16.0.1][35682] -> [..192.168.10.50][...80] - new: [...648] [ip4][..tcp] [.....172.16.0.1][35696] -> [..192.168.10.50][...80] - new: [...649] [ip4][..tcp] [.....172.16.0.1][35722] -> [..192.168.10.50][...80] + new: [...647] [ip4][..tcp] [.....172.16.0.1][35682] -> [..192.168.10.50][...80] + new: [...648] [ip4][..tcp] [.....172.16.0.1][35696] -> [..192.168.10.50][...80] + new: [...649] [ip4][..tcp] [.....172.16.0.1][35722] -> [..192.168.10.50][...80] analyse: [...643] [ip4][..tcp] [.....172.16.0.1][35626] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.954| 0.620| 0.972| 945707.024| 3.700] @@ -2030,194 +2030,194 @@ [IATS(ms)....: 0.1,0.7,3953.2,3953.8,3.0,3.8,1020.6,1024.3,3.7,248.2,252.3,4.2,1041.7,1046.0,4.3,255.1,258.8,3.6,1007.1,1010.8,3.7,252.7,256.2,3.6,1010.5,1014.2,3.8,262.9,266.7,3.8,1039.9] [PKTLENS.....: 60,60,52,637,52,1920,52,435,1822,52,637,1918,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435,1822,52,637,1919,52,435] [ENTROPIES...: 4.6,5.1,5.0,6.0,4.9,7.8,5.0,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,5.0,6.0,7.8,5.0,5.9,7.7,4.9,6.0,7.8,4.9,5.9] - new: [...650] [ip4][..tcp] [.....172.16.0.1][35736] -> [..192.168.10.50][...80] - new: [...651] [ip4][..tcp] [.....172.16.0.1][35762] -> [..192.168.10.50][...80] + new: [...650] [ip4][..tcp] [.....172.16.0.1][35736] -> [..192.168.10.50][...80] + new: [...651] [ip4][..tcp] [.....172.16.0.1][35762] -> [..192.168.10.50][...80] guessed: [...574] [ip4][..tcp] [.....172.16.0.1][34372] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...574] [ip4][..tcp] [.....172.16.0.1][34372] -> [..192.168.10.50][...80] + end: [...574] [ip4][..tcp] [.....172.16.0.1][34372] -> [..192.168.10.50][...80] guessed: [...575] [ip4][..tcp] [.....172.16.0.1][34386] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...575] [ip4][..tcp] [.....172.16.0.1][34386] -> [..192.168.10.50][...80] + end: [...575] [ip4][..tcp] [.....172.16.0.1][34386] -> [..192.168.10.50][...80] guessed: [...576] [ip4][..tcp] [.....172.16.0.1][34412] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...576] [ip4][..tcp] [.....172.16.0.1][34412] -> [..192.168.10.50][...80] + end: [...576] [ip4][..tcp] [.....172.16.0.1][34412] -> [..192.168.10.50][...80] guessed: [...577] [ip4][..tcp] [.....172.16.0.1][34426] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...577] [ip4][..tcp] [.....172.16.0.1][34426] -> [..192.168.10.50][...80] + end: [...577] [ip4][..tcp] [.....172.16.0.1][34426] -> [..192.168.10.50][...80] guessed: [...578] [ip4][..tcp] [.....172.16.0.1][34440] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...578] [ip4][..tcp] [.....172.16.0.1][34440] -> [..192.168.10.50][...80] - new: [...652] [ip4][..tcp] [.....172.16.0.1][35776] -> [..192.168.10.50][...80] - new: [...653] [ip4][..tcp] [.....172.16.0.1][35790] -> [..192.168.10.50][...80] - new: [...654] [ip4][..tcp] [.....172.16.0.1][35816] -> [..192.168.10.50][...80] - new: [...655] [ip4][..tcp] [.....172.16.0.1][35830] -> [..192.168.10.50][...80] - new: [...656] [ip4][..tcp] [.....172.16.0.1][35856] -> [..192.168.10.50][...80] - new: [...657] [ip4][..tcp] [.....172.16.0.1][35870] -> [..192.168.10.50][...80] + end: [...578] [ip4][..tcp] [.....172.16.0.1][34440] -> [..192.168.10.50][...80] + new: [...652] [ip4][..tcp] [.....172.16.0.1][35776] -> [..192.168.10.50][...80] + new: [...653] [ip4][..tcp] [.....172.16.0.1][35790] -> [..192.168.10.50][...80] + new: [...654] [ip4][..tcp] [.....172.16.0.1][35816] -> [..192.168.10.50][...80] + new: [...655] [ip4][..tcp] [.....172.16.0.1][35830] -> [..192.168.10.50][...80] + new: [...656] [ip4][..tcp] [.....172.16.0.1][35856] -> [..192.168.10.50][...80] + new: [...657] [ip4][..tcp] [.....172.16.0.1][35870] -> [..192.168.10.50][...80] guessed: [...579] [ip4][..tcp] [.....172.16.0.1][34466] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...579] [ip4][..tcp] [.....172.16.0.1][34466] -> [..192.168.10.50][...80] + end: [...579] [ip4][..tcp] [.....172.16.0.1][34466] -> [..192.168.10.50][...80] guessed: [...580] [ip4][..tcp] [.....172.16.0.1][34480] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...580] [ip4][..tcp] [.....172.16.0.1][34480] -> [..192.168.10.50][...80] + end: [...580] [ip4][..tcp] [.....172.16.0.1][34480] -> [..192.168.10.50][...80] guessed: [...581] [ip4][..tcp] [.....172.16.0.1][34506] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...581] [ip4][..tcp] [.....172.16.0.1][34506] -> [..192.168.10.50][...80] + end: [...581] [ip4][..tcp] [.....172.16.0.1][34506] -> [..192.168.10.50][...80] guessed: [...582] [ip4][..tcp] [.....172.16.0.1][34520] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...582] [ip4][..tcp] [.....172.16.0.1][34520] -> [..192.168.10.50][...80] + end: [...582] [ip4][..tcp] [.....172.16.0.1][34520] -> [..192.168.10.50][...80] guessed: [...583] [ip4][..tcp] [.....172.16.0.1][34534] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...583] [ip4][..tcp] [.....172.16.0.1][34534] -> [..192.168.10.50][...80] + end: [...583] [ip4][..tcp] [.....172.16.0.1][34534] -> [..192.168.10.50][...80] guessed: [...584] [ip4][..tcp] [.....172.16.0.1][34548] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...584] [ip4][..tcp] [.....172.16.0.1][34548] -> [..192.168.10.50][...80] + end: [...584] [ip4][..tcp] [.....172.16.0.1][34548] -> [..192.168.10.50][...80] guessed: [...585] [ip4][..tcp] [.....172.16.0.1][34562] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...585] [ip4][..tcp] [.....172.16.0.1][34562] -> [..192.168.10.50][...80] - new: [...658] [ip4][..tcp] [.....172.16.0.1][35884] -> [..192.168.10.50][...80] - new: [...659] [ip4][..tcp] [.....172.16.0.1][35910] -> [..192.168.10.50][...80] - new: [...660] [ip4][..tcp] [.....172.16.0.1][35924] -> [..192.168.10.50][...80] - new: [...661] [ip4][..tcp] [.....172.16.0.1][35950] -> [..192.168.10.50][...80] + end: [...585] [ip4][..tcp] [.....172.16.0.1][34562] -> [..192.168.10.50][...80] + new: [...658] [ip4][..tcp] [.....172.16.0.1][35884] -> [..192.168.10.50][...80] + new: [...659] [ip4][..tcp] [.....172.16.0.1][35910] -> [..192.168.10.50][...80] + new: [...660] [ip4][..tcp] [.....172.16.0.1][35924] -> [..192.168.10.50][...80] + new: [...661] [ip4][..tcp] [.....172.16.0.1][35950] -> [..192.168.10.50][...80] guessed: [...586] [ip4][..tcp] [.....172.16.0.1][34576] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...586] [ip4][..tcp] [.....172.16.0.1][34576] -> [..192.168.10.50][...80] + end: [...586] [ip4][..tcp] [.....172.16.0.1][34576] -> [..192.168.10.50][...80] guessed: [...587] [ip4][..tcp] [.....172.16.0.1][34602] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...587] [ip4][..tcp] [.....172.16.0.1][34602] -> [..192.168.10.50][...80] + end: [...587] [ip4][..tcp] [.....172.16.0.1][34602] -> [..192.168.10.50][...80] guessed: [...588] [ip4][..tcp] [.....172.16.0.1][34616] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...588] [ip4][..tcp] [.....172.16.0.1][34616] -> [..192.168.10.50][...80] + end: [...588] [ip4][..tcp] [.....172.16.0.1][34616] -> [..192.168.10.50][...80] guessed: [...589] [ip4][..tcp] [.....172.16.0.1][34642] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...589] [ip4][..tcp] [.....172.16.0.1][34642] -> [..192.168.10.50][...80] + end: [...589] [ip4][..tcp] [.....172.16.0.1][34642] -> [..192.168.10.50][...80] guessed: [...590] [ip4][..tcp] [.....172.16.0.1][34656] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...590] [ip4][..tcp] [.....172.16.0.1][34656] -> [..192.168.10.50][...80] + end: [...590] [ip4][..tcp] [.....172.16.0.1][34656] -> [..192.168.10.50][...80] guessed: [...591] [ip4][..tcp] [.....172.16.0.1][34670] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...591] [ip4][..tcp] [.....172.16.0.1][34670] -> [..192.168.10.50][...80] + end: [...591] [ip4][..tcp] [.....172.16.0.1][34670] -> [..192.168.10.50][...80] guessed: [...592] [ip4][..tcp] [.....172.16.0.1][34696] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...592] [ip4][..tcp] [.....172.16.0.1][34696] -> [..192.168.10.50][...80] + end: [...592] [ip4][..tcp] [.....172.16.0.1][34696] -> [..192.168.10.50][...80] guessed: [...593] [ip4][..tcp] [.....172.16.0.1][34710] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...593] [ip4][..tcp] [.....172.16.0.1][34710] -> [..192.168.10.50][...80] + end: [...593] [ip4][..tcp] [.....172.16.0.1][34710] -> [..192.168.10.50][...80] guessed: [...594] [ip4][..tcp] [.....172.16.0.1][34724] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...594] [ip4][..tcp] [.....172.16.0.1][34724] -> [..192.168.10.50][...80] + end: [...594] [ip4][..tcp] [.....172.16.0.1][34724] -> [..192.168.10.50][...80] guessed: [...595] [ip4][..tcp] [.....172.16.0.1][34738] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...595] [ip4][..tcp] [.....172.16.0.1][34738] -> [..192.168.10.50][...80] + end: [...595] [ip4][..tcp] [.....172.16.0.1][34738] -> [..192.168.10.50][...80] guessed: [...596] [ip4][..tcp] [.....172.16.0.1][34752] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...596] [ip4][..tcp] [.....172.16.0.1][34752] -> [..192.168.10.50][...80] + end: [...596] [ip4][..tcp] [.....172.16.0.1][34752] -> [..192.168.10.50][...80] guessed: [...597] [ip4][..tcp] [.....172.16.0.1][34766] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...597] [ip4][..tcp] [.....172.16.0.1][34766] -> [..192.168.10.50][...80] + end: [...597] [ip4][..tcp] [.....172.16.0.1][34766] -> [..192.168.10.50][...80] guessed: [...598] [ip4][..tcp] [.....172.16.0.1][34792] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...598] [ip4][..tcp] [.....172.16.0.1][34792] -> [..192.168.10.50][...80] + end: [...598] [ip4][..tcp] [.....172.16.0.1][34792] -> [..192.168.10.50][...80] guessed: [...599] [ip4][..tcp] [.....172.16.0.1][34806] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...599] [ip4][..tcp] [.....172.16.0.1][34806] -> [..192.168.10.50][...80] + end: [...599] [ip4][..tcp] [.....172.16.0.1][34806] -> [..192.168.10.50][...80] guessed: [...600] [ip4][..tcp] [.....172.16.0.1][34832] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...600] [ip4][..tcp] [.....172.16.0.1][34832] -> [..192.168.10.50][...80] + end: [...600] [ip4][..tcp] [.....172.16.0.1][34832] -> [..192.168.10.50][...80] guessed: [...601] [ip4][..tcp] [.....172.16.0.1][34846] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...601] [ip4][..tcp] [.....172.16.0.1][34846] -> [..192.168.10.50][...80] + end: [...601] [ip4][..tcp] [.....172.16.0.1][34846] -> [..192.168.10.50][...80] guessed: [...602] [ip4][..tcp] [.....172.16.0.1][34860] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...602] [ip4][..tcp] [.....172.16.0.1][34860] -> [..192.168.10.50][...80] + end: [...602] [ip4][..tcp] [.....172.16.0.1][34860] -> [..192.168.10.50][...80] guessed: [...603] [ip4][..tcp] [.....172.16.0.1][34886] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...603] [ip4][..tcp] [.....172.16.0.1][34886] -> [..192.168.10.50][...80] + end: [...603] [ip4][..tcp] [.....172.16.0.1][34886] -> [..192.168.10.50][...80] guessed: [...604] [ip4][..tcp] [.....172.16.0.1][34900] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...604] [ip4][..tcp] [.....172.16.0.1][34900] -> [..192.168.10.50][...80] + end: [...604] [ip4][..tcp] [.....172.16.0.1][34900] -> [..192.168.10.50][...80] guessed: [...605] [ip4][..tcp] [.....172.16.0.1][34926] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...605] [ip4][..tcp] [.....172.16.0.1][34926] -> [..192.168.10.50][...80] + end: [...605] [ip4][..tcp] [.....172.16.0.1][34926] -> [..192.168.10.50][...80] end: [...606] [ip4][..tcp] [.....172.16.0.1][34940] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...607] [ip4][..tcp] [.....172.16.0.1][34954] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...607] [ip4][..tcp] [.....172.16.0.1][34954] -> [..192.168.10.50][...80] + end: [...607] [ip4][..tcp] [.....172.16.0.1][34954] -> [..192.168.10.50][...80] guessed: [...608] [ip4][..tcp] [.....172.16.0.1][34980] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...608] [ip4][..tcp] [.....172.16.0.1][34980] -> [..192.168.10.50][...80] + end: [...608] [ip4][..tcp] [.....172.16.0.1][34980] -> [..192.168.10.50][...80] guessed: [...609] [ip4][..tcp] [.....172.16.0.1][34994] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...609] [ip4][..tcp] [.....172.16.0.1][34994] -> [..192.168.10.50][...80] + end: [...609] [ip4][..tcp] [.....172.16.0.1][34994] -> [..192.168.10.50][...80] guessed: [...610] [ip4][..tcp] [.....172.16.0.1][35020] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...610] [ip4][..tcp] [.....172.16.0.1][35020] -> [..192.168.10.50][...80] + end: [...610] [ip4][..tcp] [.....172.16.0.1][35020] -> [..192.168.10.50][...80] guessed: [...611] [ip4][..tcp] [.....172.16.0.1][35034] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...611] [ip4][..tcp] [.....172.16.0.1][35034] -> [..192.168.10.50][...80] + end: [...611] [ip4][..tcp] [.....172.16.0.1][35034] -> [..192.168.10.50][...80] guessed: [...612] [ip4][..tcp] [.....172.16.0.1][35048] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...612] [ip4][..tcp] [.....172.16.0.1][35048] -> [..192.168.10.50][...80] + end: [...612] [ip4][..tcp] [.....172.16.0.1][35048] -> [..192.168.10.50][...80] guessed: [...613] [ip4][..tcp] [.....172.16.0.1][35074] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...613] [ip4][..tcp] [.....172.16.0.1][35074] -> [..192.168.10.50][...80] + end: [...613] [ip4][..tcp] [.....172.16.0.1][35074] -> [..192.168.10.50][...80] guessed: [...614] [ip4][..tcp] [.....172.16.0.1][35088] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...614] [ip4][..tcp] [.....172.16.0.1][35088] -> [..192.168.10.50][...80] + end: [...614] [ip4][..tcp] [.....172.16.0.1][35088] -> [..192.168.10.50][...80] guessed: [...615] [ip4][..tcp] [.....172.16.0.1][35114] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...615] [ip4][..tcp] [.....172.16.0.1][35114] -> [..192.168.10.50][...80] + end: [...615] [ip4][..tcp] [.....172.16.0.1][35114] -> [..192.168.10.50][...80] guessed: [...616] [ip4][..tcp] [.....172.16.0.1][35128] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...616] [ip4][..tcp] [.....172.16.0.1][35128] -> [..192.168.10.50][...80] + end: [...616] [ip4][..tcp] [.....172.16.0.1][35128] -> [..192.168.10.50][...80] guessed: [...617] [ip4][..tcp] [.....172.16.0.1][35142] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...617] [ip4][..tcp] [.....172.16.0.1][35142] -> [..192.168.10.50][...80] + end: [...617] [ip4][..tcp] [.....172.16.0.1][35142] -> [..192.168.10.50][...80] guessed: [...618] [ip4][..tcp] [.....172.16.0.1][35168] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...618] [ip4][..tcp] [.....172.16.0.1][35168] -> [..192.168.10.50][...80] + end: [...618] [ip4][..tcp] [.....172.16.0.1][35168] -> [..192.168.10.50][...80] guessed: [...619] [ip4][..tcp] [.....172.16.0.1][35182] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...619] [ip4][..tcp] [.....172.16.0.1][35182] -> [..192.168.10.50][...80] + end: [...619] [ip4][..tcp] [.....172.16.0.1][35182] -> [..192.168.10.50][...80] guessed: [...620] [ip4][..tcp] [.....172.16.0.1][35208] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...620] [ip4][..tcp] [.....172.16.0.1][35208] -> [..192.168.10.50][...80] + end: [...620] [ip4][..tcp] [.....172.16.0.1][35208] -> [..192.168.10.50][...80] guessed: [...621] [ip4][..tcp] [.....172.16.0.1][35222] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...621] [ip4][..tcp] [.....172.16.0.1][35222] -> [..192.168.10.50][...80] + end: [...621] [ip4][..tcp] [.....172.16.0.1][35222] -> [..192.168.10.50][...80] guessed: [...622] [ip4][..tcp] [.....172.16.0.1][35236] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...622] [ip4][..tcp] [.....172.16.0.1][35236] -> [..192.168.10.50][...80] + end: [...622] [ip4][..tcp] [.....172.16.0.1][35236] -> [..192.168.10.50][...80] guessed: [...623] [ip4][..tcp] [.....172.16.0.1][35262] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...623] [ip4][..tcp] [.....172.16.0.1][35262] -> [..192.168.10.50][...80] + end: [...623] [ip4][..tcp] [.....172.16.0.1][35262] -> [..192.168.10.50][...80] guessed: [...624] [ip4][..tcp] [.....172.16.0.1][35276] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...624] [ip4][..tcp] [.....172.16.0.1][35276] -> [..192.168.10.50][...80] + end: [...624] [ip4][..tcp] [.....172.16.0.1][35276] -> [..192.168.10.50][...80] guessed: [...625] [ip4][..tcp] [.....172.16.0.1][35302] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...625] [ip4][..tcp] [.....172.16.0.1][35302] -> [..192.168.10.50][...80] + end: [...625] [ip4][..tcp] [.....172.16.0.1][35302] -> [..192.168.10.50][...80] guessed: [...626] [ip4][..tcp] [.....172.16.0.1][35316] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...626] [ip4][..tcp] [.....172.16.0.1][35316] -> [..192.168.10.50][...80] + end: [...626] [ip4][..tcp] [.....172.16.0.1][35316] -> [..192.168.10.50][...80] guessed: [...627] [ip4][..tcp] [.....172.16.0.1][35342] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...627] [ip4][..tcp] [.....172.16.0.1][35342] -> [..192.168.10.50][...80] + end: [...627] [ip4][..tcp] [.....172.16.0.1][35342] -> [..192.168.10.50][...80] guessed: [...628] [ip4][..tcp] [.....172.16.0.1][35356] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...628] [ip4][..tcp] [.....172.16.0.1][35356] -> [..192.168.10.50][...80] + end: [...628] [ip4][..tcp] [.....172.16.0.1][35356] -> [..192.168.10.50][...80] guessed: [...629] [ip4][..tcp] [.....172.16.0.1][35370] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...629] [ip4][..tcp] [.....172.16.0.1][35370] -> [..192.168.10.50][...80] + end: [...629] [ip4][..tcp] [.....172.16.0.1][35370] -> [..192.168.10.50][...80] guessed: [...630] [ip4][..tcp] [.....172.16.0.1][35396] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...630] [ip4][..tcp] [.....172.16.0.1][35396] -> [..192.168.10.50][...80] + end: [...630] [ip4][..tcp] [.....172.16.0.1][35396] -> [..192.168.10.50][...80] guessed: [...631] [ip4][..tcp] [.....172.16.0.1][35410] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...631] [ip4][..tcp] [.....172.16.0.1][35410] -> [..192.168.10.50][...80] + end: [...631] [ip4][..tcp] [.....172.16.0.1][35410] -> [..192.168.10.50][...80] guessed: [...632] [ip4][..tcp] [.....172.16.0.1][35436] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...632] [ip4][..tcp] [.....172.16.0.1][35436] -> [..192.168.10.50][...80] + end: [...632] [ip4][..tcp] [.....172.16.0.1][35436] -> [..192.168.10.50][...80] guessed: [...633] [ip4][..tcp] [.....172.16.0.1][35450] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...633] [ip4][..tcp] [.....172.16.0.1][35450] -> [..192.168.10.50][...80] + end: [...633] [ip4][..tcp] [.....172.16.0.1][35450] -> [..192.168.10.50][...80] guessed: [...634] [ip4][..tcp] [.....172.16.0.1][35464] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...634] [ip4][..tcp] [.....172.16.0.1][35464] -> [..192.168.10.50][...80] + end: [...634] [ip4][..tcp] [.....172.16.0.1][35464] -> [..192.168.10.50][...80] guessed: [...635] [ip4][..tcp] [.....172.16.0.1][35490] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...635] [ip4][..tcp] [.....172.16.0.1][35490] -> [..192.168.10.50][...80] + end: [...635] [ip4][..tcp] [.....172.16.0.1][35490] -> [..192.168.10.50][...80] guessed: [...636] [ip4][..tcp] [.....172.16.0.1][35504] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...636] [ip4][..tcp] [.....172.16.0.1][35504] -> [..192.168.10.50][...80] + end: [...636] [ip4][..tcp] [.....172.16.0.1][35504] -> [..192.168.10.50][...80] guessed: [...637] [ip4][..tcp] [.....172.16.0.1][35518] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...637] [ip4][..tcp] [.....172.16.0.1][35518] -> [..192.168.10.50][...80] + end: [...637] [ip4][..tcp] [.....172.16.0.1][35518] -> [..192.168.10.50][...80] guessed: [...638] [ip4][..tcp] [.....172.16.0.1][35532] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...638] [ip4][..tcp] [.....172.16.0.1][35532] -> [..192.168.10.50][...80] + end: [...638] [ip4][..tcp] [.....172.16.0.1][35532] -> [..192.168.10.50][...80] guessed: [...639] [ip4][..tcp] [.....172.16.0.1][35546] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...639] [ip4][..tcp] [.....172.16.0.1][35546] -> [..192.168.10.50][...80] + end: [...639] [ip4][..tcp] [.....172.16.0.1][35546] -> [..192.168.10.50][...80] guessed: [...640] [ip4][..tcp] [.....172.16.0.1][35560] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...640] [ip4][..tcp] [.....172.16.0.1][35560] -> [..192.168.10.50][...80] + end: [...640] [ip4][..tcp] [.....172.16.0.1][35560] -> [..192.168.10.50][...80] guessed: [...641] [ip4][..tcp] [.....172.16.0.1][35586] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...641] [ip4][..tcp] [.....172.16.0.1][35586] -> [..192.168.10.50][...80] + end: [...641] [ip4][..tcp] [.....172.16.0.1][35586] -> [..192.168.10.50][...80] guessed: [...642] [ip4][..tcp] [.....172.16.0.1][35600] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...642] [ip4][..tcp] [.....172.16.0.1][35600] -> [..192.168.10.50][...80] + end: [...642] [ip4][..tcp] [.....172.16.0.1][35600] -> [..192.168.10.50][...80] idle: [...643] [ip4][..tcp] [.....172.16.0.1][35626] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header guessed: [...644] [ip4][..tcp] [.....172.16.0.1][35640] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...644] [ip4][..tcp] [.....172.16.0.1][35640] -> [..192.168.10.50][...80] + end: [...644] [ip4][..tcp] [.....172.16.0.1][35640] -> [..192.168.10.50][...80] guessed: [...645] [ip4][..tcp] [.....172.16.0.1][35654] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...645] [ip4][..tcp] [.....172.16.0.1][35654] -> [..192.168.10.50][...80] + end: [...645] [ip4][..tcp] [.....172.16.0.1][35654] -> [..192.168.10.50][...80] guessed: [...646] [ip4][..tcp] [.....172.16.0.1][35668] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...646] [ip4][..tcp] [.....172.16.0.1][35668] -> [..192.168.10.50][...80] + end: [...646] [ip4][..tcp] [.....172.16.0.1][35668] -> [..192.168.10.50][...80] guessed: [...647] [ip4][..tcp] [.....172.16.0.1][35682] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...647] [ip4][..tcp] [.....172.16.0.1][35682] -> [..192.168.10.50][...80] + end: [...647] [ip4][..tcp] [.....172.16.0.1][35682] -> [..192.168.10.50][...80] guessed: [...648] [ip4][..tcp] [.....172.16.0.1][35696] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...648] [ip4][..tcp] [.....172.16.0.1][35696] -> [..192.168.10.50][...80] + end: [...648] [ip4][..tcp] [.....172.16.0.1][35696] -> [..192.168.10.50][...80] guessed: [...649] [ip4][..tcp] [.....172.16.0.1][35722] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...649] [ip4][..tcp] [.....172.16.0.1][35722] -> [..192.168.10.50][...80] + end: [...649] [ip4][..tcp] [.....172.16.0.1][35722] -> [..192.168.10.50][...80] guessed: [...650] [ip4][..tcp] [.....172.16.0.1][35736] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...650] [ip4][..tcp] [.....172.16.0.1][35736] -> [..192.168.10.50][...80] + end: [...650] [ip4][..tcp] [.....172.16.0.1][35736] -> [..192.168.10.50][...80] guessed: [...651] [ip4][..tcp] [.....172.16.0.1][35762] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...651] [ip4][..tcp] [.....172.16.0.1][35762] -> [..192.168.10.50][...80] + end: [...651] [ip4][..tcp] [.....172.16.0.1][35762] -> [..192.168.10.50][...80] guessed: [...652] [ip4][..tcp] [.....172.16.0.1][35776] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...652] [ip4][..tcp] [.....172.16.0.1][35776] -> [..192.168.10.50][...80] + end: [...652] [ip4][..tcp] [.....172.16.0.1][35776] -> [..192.168.10.50][...80] guessed: [...653] [ip4][..tcp] [.....172.16.0.1][35790] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...653] [ip4][..tcp] [.....172.16.0.1][35790] -> [..192.168.10.50][...80] + end: [...653] [ip4][..tcp] [.....172.16.0.1][35790] -> [..192.168.10.50][...80] guessed: [...654] [ip4][..tcp] [.....172.16.0.1][35816] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...654] [ip4][..tcp] [.....172.16.0.1][35816] -> [..192.168.10.50][...80] + end: [...654] [ip4][..tcp] [.....172.16.0.1][35816] -> [..192.168.10.50][...80] guessed: [...655] [ip4][..tcp] [.....172.16.0.1][35830] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...655] [ip4][..tcp] [.....172.16.0.1][35830] -> [..192.168.10.50][...80] + end: [...655] [ip4][..tcp] [.....172.16.0.1][35830] -> [..192.168.10.50][...80] guessed: [...656] [ip4][..tcp] [.....172.16.0.1][35856] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...656] [ip4][..tcp] [.....172.16.0.1][35856] -> [..192.168.10.50][...80] + end: [...656] [ip4][..tcp] [.....172.16.0.1][35856] -> [..192.168.10.50][...80] guessed: [...657] [ip4][..tcp] [.....172.16.0.1][35870] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...657] [ip4][..tcp] [.....172.16.0.1][35870] -> [..192.168.10.50][...80] + end: [...657] [ip4][..tcp] [.....172.16.0.1][35870] -> [..192.168.10.50][...80] guessed: [...658] [ip4][..tcp] [.....172.16.0.1][35884] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - end: [...658] [ip4][..tcp] [.....172.16.0.1][35884] -> [..192.168.10.50][...80] + end: [...658] [ip4][..tcp] [.....172.16.0.1][35884] -> [..192.168.10.50][...80] guessed: [...659] [ip4][..tcp] [.....172.16.0.1][35910] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [...659] [ip4][..tcp] [.....172.16.0.1][35910] -> [..192.168.10.50][...80] + idle: [...659] [ip4][..tcp] [.....172.16.0.1][35910] -> [..192.168.10.50][...80] guessed: [...660] [ip4][..tcp] [.....172.16.0.1][35924] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [...660] [ip4][..tcp] [.....172.16.0.1][35924] -> [..192.168.10.50][...80] + idle: [...660] [ip4][..tcp] [.....172.16.0.1][35924] -> [..192.168.10.50][...80] guessed: [...661] [ip4][..tcp] [.....172.16.0.1][35950] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [...661] [ip4][..tcp] [.....172.16.0.1][35950] -> [..192.168.10.50][...80] + idle: [...661] [ip4][..tcp] [.....172.16.0.1][35950] -> [..192.168.10.50][...80] end: [...569] [ip4][..tcp] [.....172.16.0.1][34278] -> [..192.168.10.50][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/activision.pcap.out b/test/results/flow-info/default/activision.pcap.out index 1ae6f6b68..6b358608a 100644 --- a/test/results/flow-info/default/activision.pcap.out +++ b/test/results/flow-info/default/activision.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][.3074] -> [..108.61.235.31][33441] + new: [.....1] [ip4][..udp] [..192.168.2.100][.3074] -> [..108.61.235.31][33441] detected: [.....1] [ip4][..udp] [..192.168.2.100][.3074] -> [..108.61.235.31][33441] [Activision][Unknown][Game][Fun] - new: [.....2] [ip4][..udp] [..192.168.2.100][.3074] -> [...45.63.112.54][34741] + new: [.....2] [ip4][..udp] [..192.168.2.100][.3074] -> [...45.63.112.54][34741] detected: [.....2] [ip4][..udp] [..192.168.2.100][.3074] -> [...45.63.112.54][34741] [Activision][Unknown][Game][Fun] update: [.....1] [ip4][..udp] [..192.168.2.100][.3074] -> [..108.61.235.31][33441] [Activision][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [..192.168.2.100][.3074] -> [.148.72.173.162][34311] + new: [.....3] [ip4][..udp] [..192.168.2.100][.3074] -> [.148.72.173.162][34311] detected: [.....3] [ip4][..udp] [..192.168.2.100][.3074] -> [.148.72.173.162][34311] [Activision][Unknown][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][.3074] -> [...45.63.112.54][34741] [Activision][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][.3074] -> [..108.61.235.31][33441] [Activision][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....4] [ip4][..udp] [..192.168.2.100][.3074] -> [...173.199.67.5][37081] + new: [.....4] [ip4][..udp] [..192.168.2.100][.3074] -> [...173.199.67.5][37081] detected: [.....4] [ip4][..udp] [..192.168.2.100][.3074] -> [...173.199.67.5][37081] [Activision][Unknown][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][.3074] -> [.148.72.173.162][34311] [Activision][Unknown][Game][Fun] idle: [.....4] [ip4][..udp] [..192.168.2.100][.3074] -> [...173.199.67.5][37081] [Activision][Unknown][Game][Fun] diff --git a/test/results/flow-info/default/adult_content.pcap.out b/test/results/flow-info/default/adult_content.pcap.out index 0c4dfe783..82234805e 100644 --- a/test/results/flow-info/default/adult_content.pcap.out +++ b/test/results/flow-info/default/adult_content.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.199][42759] -> [...31.220.27.69][...80] + new: [.....1] [ip4][..udp] [..192.168.1.199][42759] -> [...31.220.27.69][...80] detected: [.....1] [ip4][..udp] [..192.168.1.199][42759] -> [...31.220.27.69][...80] [STUN][Unknown][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [..192.168.1.199][42759] -> [...31.220.27.69][...80] [STUN.AdultContent][Unknown][AdultContent][Acceptable][b-eu14.stripcdn.com] diff --git a/test/results/flow-info/default/afp.pcap.out b/test/results/flow-info/default/afp.pcap.out index e950969bb..9e7837478 100644 --- a/test/results/flow-info/default/afp.pcap.out +++ b/test/results/flow-info/default/afp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.27.57][64987] -> [.192.168.27.139][..548] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.27.57][64987] -> [.192.168.27.139][..548] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.27.57][64987] -> [.192.168.27.139][..548] [AFP][Unknown][DataTransfer][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.27.57][64987] -> [.192.168.27.139][..548] [AFP][Unknown][DataTransfer][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/agora-sd-rtn.pcap.out b/test/results/flow-info/default/agora-sd-rtn.pcap.out index 469460414..104f79df2 100644 --- a/test/results/flow-info/default/agora-sd-rtn.pcap.out +++ b/test/results/flow-info/default/agora-sd-rtn.pcap.out @@ -1,28 +1,28 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] + new: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] detected: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] - new: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] + new: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] detected: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable][104-166-161-75.edge.agora.io] - new: [.....3] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.75][.8130] + new: [.....3] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.75][.8130] detected: [.....3] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable][104-166-161-75.edge.agora.io] - new: [.....4] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.19][.8130] + new: [.....4] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.19][.8130] detected: [.....4] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.19][.8130] [SD-RTN][Unknown][Media][Acceptable][104-166-161-19.edge.agora.io] update: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [.....5] [ip4][..udp] [..192.168.2.100][44131] -> [....128.1.77.66][.8130] + new: [.....5] [ip4][..udp] [..192.168.2.100][44131] -> [....128.1.77.66][.8130] detected: [.....5] [ip4][..udp] [..192.168.2.100][44131] -> [....128.1.77.66][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-77-66.edge.agora.io] - new: [.....6] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.179][.8130] + new: [.....6] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.179][.8130] detected: [.....6] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] - new: [.....7] [ip4][..udp] [..192.168.2.100][46798] -> [.23.248.186.179][.8130] + new: [.....7] [ip4][..udp] [..192.168.2.100][46798] -> [.23.248.186.179][.8130] detected: [.....7] [ip4][..udp] [..192.168.2.100][46798] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] update: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [.....3] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [.....4] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.19][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [.....5] [ip4][..udp] [..192.168.2.100][44131] -> [....128.1.77.66][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [.....8] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.180][.8130] + new: [.....8] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.180][.8130] detected: [.....8] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.180][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-180.edge.agora.io] idle: [.....2] [ip4][..udp] [..192.168.2.100][35778] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [.....1] [ip4][..udp] [..192.168.2.100][35778] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] @@ -33,11 +33,11 @@ update: [.....7] [ip4][..udp] [..192.168.2.100][46798] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] DAEMON-EVENT: [Processed: 120 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 12] - new: [.....9] [ip4][..udp] [..192.168.2.100][40393] -> [.23.248.186.179][.8130] + new: [.....9] [ip4][..udp] [..192.168.2.100][40393] -> [.23.248.186.179][.8130] detected: [.....9] [ip4][..udp] [..192.168.2.100][40393] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] - new: [....10] [ip4][..udp] [..192.168.2.100][47453] -> [.23.248.186.179][.8130] + new: [....10] [ip4][..udp] [..192.168.2.100][47453] -> [.23.248.186.179][.8130] detected: [....10] [ip4][..udp] [..192.168.2.100][47453] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] - new: [....11] [ip4][..udp] [..192.168.2.100][40393] -> [.104.166.161.75][.8130] + new: [....11] [ip4][..udp] [..192.168.2.100][40393] -> [.104.166.161.75][.8130] detected: [....11] [ip4][..udp] [..192.168.2.100][40393] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable][104-166-161-75.edge.agora.io] idle: [.....4] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.19][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [.....3] [ip4][..udp] [..192.168.2.100][44131] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] @@ -45,11 +45,11 @@ idle: [.....6] [ip4][..udp] [..192.168.2.100][44131] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [.....5] [ip4][..udp] [..192.168.2.100][44131] -> [....128.1.77.66][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [.....7] [ip4][..udp] [..192.168.2.100][46798] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....12] [ip4][..udp] [..192.168.2.100][55322] -> [.104.166.161.75][.8130] + new: [....12] [ip4][..udp] [..192.168.2.100][55322] -> [.104.166.161.75][.8130] detected: [....12] [ip4][..udp] [..192.168.2.100][55322] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable][104-166-161-75.edge.agora.io] - new: [....13] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.233.218][.8130] + new: [....13] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.233.218][.8130] detected: [....13] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.233.218][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-233-218.edge.agora.io] - new: [....14] [ip4][..udp] [..192.168.2.100][55322] -> [.193.118.52.182][.8130] + new: [....14] [ip4][..udp] [..192.168.2.100][55322] -> [.193.118.52.182][.8130] detected: [....14] [ip4][..udp] [..192.168.2.100][55322] -> [.193.118.52.182][.8130] [SD-RTN][Unknown][Media][Acceptable][193-118-52-182.edge.agora.io] update: [....10] [ip4][..udp] [..192.168.2.100][47453] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [....11] [ip4][..udp] [..192.168.2.100][40393] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] @@ -62,15 +62,15 @@ idle: [.....9] [ip4][..udp] [..192.168.2.100][40393] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [....14] [ip4][..udp] [..192.168.2.100][55322] -> [.193.118.52.182][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [....12] [ip4][..udp] [..192.168.2.100][55322] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....15] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.223][.8130] + new: [....15] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.223][.8130] detected: [....15] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-193-223.edge.agora.io] - new: [....16] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.180][.8130] + new: [....16] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.180][.8130] detected: [....16] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.180][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-180.edge.agora.io] update: [....12] [ip4][..udp] [..192.168.2.100][55322] -> [.104.166.161.75][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....17] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.224][.8130] + new: [....17] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.224][.8130] detected: [....17] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.224][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-193-224.edge.agora.io] update: [....15] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....18] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.179][.8130] + new: [....18] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.179][.8130] detected: [....18] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] idle: [....16] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.180][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [....15] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable] @@ -78,27 +78,27 @@ update: [....17] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.224][.8130] [SD-RTN][Unknown][Media][Acceptable] DAEMON-EVENT: [Processed: 285 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 18|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 19] - new: [....19] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.223][.8130] + new: [....19] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.223][.8130] detected: [....19] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-193-223.edge.agora.io] - new: [....20] [ip4][..udp] [..192.168.2.100][47805] -> [.202.226.25.166][.8130] + new: [....20] [ip4][..udp] [..192.168.2.100][47805] -> [.202.226.25.166][.8130] detected: [....20] [ip4][..udp] [..192.168.2.100][47805] -> [.202.226.25.166][.8130] [SD-RTN][Unknown][Media][Acceptable][202-226-25-166.edge.agora.io] idle: [....18] [ip4][..udp] [..192.168.2.100][55322] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable] idle: [....17] [ip4][..udp] [..192.168.2.100][55322] -> [..128.1.193.224][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....21] [ip4][..udp] [..192.168.2.100][47805] -> [103.104.168.244][.8130] + new: [....21] [ip4][..udp] [..192.168.2.100][47805] -> [103.104.168.244][.8130] detected: [....21] [ip4][..udp] [..192.168.2.100][47805] -> [103.104.168.244][.8130] [SD-RTN][Unknown][Media][Acceptable][103-104-168-244.edge.agora.io] - new: [....22] [ip4][..udp] [..192.168.2.100][47805] -> [.199.190.44.135][.8130] + new: [....22] [ip4][..udp] [..192.168.2.100][47805] -> [.199.190.44.135][.8130] detected: [....22] [ip4][..udp] [..192.168.2.100][47805] -> [.199.190.44.135][.8130] [SD-RTN][Unknown][Media][Acceptable][199-190-44-135.edge.agora.io] - new: [....23] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.224][.8130] + new: [....23] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.224][.8130] detected: [....23] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.224][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-193-224.edge.agora.io] - new: [....24] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.179][.8130] + new: [....24] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.179][.8130] detected: [....24] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.179][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-179.edge.agora.io] - new: [....25] [ip4][..udp] [..192.168.2.100][55094] -> [..128.1.193.223][.8130] + new: [....25] [ip4][..udp] [..192.168.2.100][55094] -> [..128.1.193.223][.8130] detected: [....25] [ip4][..udp] [..192.168.2.100][55094] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable][128-1-193-223.edge.agora.io] update: [....22] [ip4][..udp] [..192.168.2.100][47805] -> [.199.190.44.135][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [....21] [ip4][..udp] [..192.168.2.100][47805] -> [103.104.168.244][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [....19] [ip4][..udp] [..192.168.2.100][47805] -> [..128.1.193.223][.8130] [SD-RTN][Unknown][Media][Acceptable] update: [....20] [ip4][..udp] [..192.168.2.100][47805] -> [.202.226.25.166][.8130] [SD-RTN][Unknown][Media][Acceptable] - new: [....26] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.180][.8130] + new: [....26] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.180][.8130] detected: [....26] [ip4][..udp] [..192.168.2.100][47805] -> [.23.248.186.180][.8130] [SD-RTN][Unknown][Media][Acceptable][23-248-186-180.edge.agora.io] DAEMON-EVENT: [Processed: 400 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 26|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 23] diff --git a/test/results/flow-info/default/ah.pcapng.out b/test/results/flow-info/default/ah.pcapng.out index 3da67bba6..107b6f101 100644 --- a/test/results/flow-info/default/ah.pcapng.out +++ b/test/results/flow-info/default/ah.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] + new: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] detected: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] [IPSec][Unknown][VPN][Safe] - new: [.....2] [ip4][...51] [.......10.2.3.2] -> [.......10.3.4.4] + new: [.....2] [ip4][...51] [.......10.2.3.2] -> [.......10.3.4.4] detected: [.....2] [ip4][...51] [.......10.2.3.2] -> [.......10.3.4.4] [IPSec][Unknown][VPN][Safe] idle: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] [IPSec][Unknown][VPN][Safe] idle: [.....2] [ip4][...51] [.......10.2.3.2] -> [.......10.3.4.4] [IPSec][Unknown][VPN][Safe] diff --git a/test/results/flow-info/default/ajp.pcap.out b/test/results/flow-info/default/ajp.pcap.out index 7adb8cb22..deb88f49b 100644 --- a/test/results/flow-info/default/ajp.pcap.out +++ b/test/results/flow-info/default/ajp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8009] + new: [.....1] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8009] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] detected: [.....1] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8009] [AJP][Unknown][Web][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] @@ -9,7 +9,7 @@ ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] - new: [.....2] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8010] + new: [.....2] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8010] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [7/16] detected: [.....2] [ip4][..tcp] [...172.29.9.146][38856] -> [...172.29.9.147][.8010] [AJP][Unknown][Web][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [8/16] diff --git a/test/results/flow-info/default/alexa-app.pcapng.out b/test/results/flow-info/default/alexa-app.pcapng.out index ed83023d5..899fb370e 100644 --- a/test/results/flow-info/default/alexa-app.pcapng.out +++ b/test/results/flow-info/default/alexa-app.pcapng.out @@ -3,119 +3,119 @@ DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] - new: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffd3:fbc2] + new: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffd3:fbc2] detected: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffd3:fbc2] [ICMPV6][Unknown][Network][Acceptable] - new: [.....2] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] + new: [.....2] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] detected: [.....2] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....3] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....3] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][android-1c1335ec95a27318] - new: [.....4] [ip4][..udp] [....172.16.42.1][...67] -> [..172.16.42.216][...68] + new: [.....4] [ip4][..udp] [....172.16.42.1][...67] -> [..172.16.42.216][...68] detected: [.....4] [ip4][..udp] [....172.16.42.1][...67] -> [..172.16.42.216][...68] [DHCP][Unknown][Network][Acceptable][] - new: [.....5] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [................................ff02::2] + new: [.....5] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [................................ff02::2] detected: [.....5] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] + new: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] detected: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.android.com] detection-update: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.android.com] - new: [.....7] [ip4][..udp] [..172.16.42.216][55619] -> [....172.16.42.1][...53] + new: [.....7] [ip4][..udp] [..172.16.42.216][55619] -> [....172.16.42.1][...53] detected: [.....7] [ip4][..udp] [..172.16.42.216][55619] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.android.com] detection-update: [.....7] [ip4][..udp] [..172.16.42.216][55619] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.android.com] - new: [.....8] [ip4][..tcp] [..172.16.42.216][60246] -> [..172.217.9.142][...80] + new: [.....8] [ip4][..tcp] [..172.16.42.216][60246] -> [..172.217.9.142][...80] detected: [.....8] [ip4][..tcp] [..172.16.42.216][60246] -> [..172.217.9.142][...80] [HTTP.Google][Google][ConnCheck][Acceptable][connectivitycheck.android.com] - new: [.....9] [ip4][..udp] [..172.16.42.216][53188] -> [....172.16.42.1][...53] + new: [.....9] [ip4][..udp] [..172.16.42.216][53188] -> [....172.16.42.1][...53] detected: [.....9] [ip4][..udp] [..172.16.42.216][53188] -> [....172.16.42.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][mtalk.google.com] - new: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] + new: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] detected: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [.....9] [ip4][..udp] [..172.16.42.216][53188] -> [....172.16.42.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][mtalk.google.com] - new: [....11] [ip4][..tcp] [..172.16.42.216][42878] -> [173.194.223.188][.5228] + new: [....11] [ip4][..tcp] [..172.16.42.216][42878] -> [173.194.223.188][.5228] detected: [....11] [ip4][..tcp] [..172.16.42.216][42878] -> [173.194.223.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [....11] [ip4][..tcp] [..172.16.42.216][42878] -> [173.194.223.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [....12] [ip4][..udp] [..172.16.42.216][10462] -> [....172.16.42.1][...53] + new: [....12] [ip4][..udp] [..172.16.42.216][10462] -> [....172.16.42.1][...53] detected: [....12] [ip4][..udp] [..172.16.42.216][10462] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [....12] [ip4][..udp] [..172.16.42.216][10462] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] - new: [....13] [ip4][..tcp] [..172.16.42.216][35540] -> [..172.217.9.142][...80] + new: [....13] [ip4][..tcp] [..172.16.42.216][35540] -> [..172.217.9.142][...80] detected: [....13] [ip4][..tcp] [..172.16.42.216][35540] -> [..172.217.9.142][...80] [HTTP.Google][Google][ConnCheck][Acceptable][connectivitycheck.android.com] - new: [....14] [ip4][.icmp] [....172.16.42.1] -> [..172.16.42.216] + new: [....14] [ip4][.icmp] [....172.16.42.1] -> [..172.16.42.216] detected: [....14] [ip4][.icmp] [....172.16.42.1] -> [..172.16.42.216] [ICMP][Unknown][Network][Acceptable] - new: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] + new: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] detected: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] detection-update: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] - new: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] + new: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] detected: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] + new: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] detected: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][mads.amazon-adsystem.com] detection-update: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][mads.amazon-adsystem.com] - new: [....18] [ip4][..tcp] [..172.16.42.216][33556] -> [....52.94.232.0][..443] + new: [....18] [ip4][..tcp] [..172.16.42.216][33556] -> [....52.94.232.0][..443] detected: [....18] [ip4][..tcp] [..172.16.42.216][33556] -> [....52.94.232.0][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][mads.amazon-adsystem.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....18] [ip4][..tcp] [..172.16.42.216][33556] -> [....52.94.232.0][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][mads.amazon-adsystem.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....18] [ip4][..tcp] [..172.16.42.216][33556] -> [....52.94.232.0][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][mads.amazon-adsystem.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] + new: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] detected: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][firs-ta-g7g.amazon.com] detection-update: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][firs-ta-g7g.amazon.com] - new: [....20] [ip4][..tcp] [..172.16.42.216][53682] -> [..54.239.22.185][..443] + new: [....20] [ip4][..tcp] [..172.16.42.216][53682] -> [..54.239.22.185][..443] detected: [....20] [ip4][..tcp] [..172.16.42.216][53682] -> [..54.239.22.185][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][firs-ta-g7g.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....20] [ip4][..tcp] [..172.16.42.216][53682] -> [..54.239.22.185][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][firs-ta-g7g.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....20] [ip4][..tcp] [..172.16.42.216][53682] -> [..54.239.22.185][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][firs-ta-g7g.amazon.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....21] [ip4][..udp] [..172.16.42.216][41030] -> [....172.16.42.1][...53] + new: [....21] [ip4][..udp] [..172.16.42.216][41030] -> [....172.16.42.1][...53] detected: [....21] [ip4][..udp] [..172.16.42.216][41030] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] detection-update: [....21] [ip4][..udp] [..172.16.42.216][41030] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] - new: [....22] [ip4][..tcp] [..172.16.42.216][49572] -> [..52.94.232.134][...80] + new: [....22] [ip4][..tcp] [..172.16.42.216][49572] -> [..52.94.232.134][...80] detected: [....22] [ip4][..tcp] [..172.16.42.216][49572] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable][alexa.amazon.com] - new: [....23] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [...............................ff02::16] + new: [....23] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [...............................ff02::16] detected: [....23] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....24] [ip4][..udp] [..172.16.42.216][23559] -> [....172.16.42.1][...53] + new: [....24] [ip4][..udp] [..172.16.42.216][23559] -> [....172.16.42.1][...53] detected: [....24] [ip4][..udp] [..172.16.42.216][23559] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....24] [ip4][..udp] [..172.16.42.216][23559] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][cognito-identity.us-east-1.amazonaws.com] - new: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] + new: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] detected: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] - new: [....26] [ip4][..tcp] [..172.16.42.216][38364] -> [..34.199.52.240][..443] + new: [....26] [ip4][..tcp] [..172.16.42.216][38364] -> [..34.199.52.240][..443] detected: [....26] [ip4][..tcp] [..172.16.42.216][38364] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....26] [ip4][..tcp] [..172.16.42.216][38364] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] - new: [....27] [ip4][..udp] [..172.16.42.216][54886] -> [....172.16.42.1][...53] + new: [....27] [ip4][..udp] [..172.16.42.216][54886] -> [....172.16.42.1][...53] detected: [....27] [ip4][..udp] [..172.16.42.216][54886] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] detection-update: [....27] [ip4][..udp] [..172.16.42.216][54886] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] - new: [....28] [ip4][..tcp] [..172.16.42.216][45661] -> [..52.94.232.134][..443] + new: [....28] [ip4][..tcp] [..172.16.42.216][45661] -> [..52.94.232.134][..443] detected: [....28] [ip4][..tcp] [..172.16.42.216][45661] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....28] [ip4][..tcp] [..172.16.42.216][45661] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....29] [ip4][..tcp] [..172.16.42.216][45662] -> [..52.94.232.134][..443] - new: [....30] [ip4][..tcp] [..172.16.42.216][45663] -> [..52.94.232.134][..443] - new: [....31] [ip4][..tcp] [..172.16.42.216][40200] -> [.10.201.126.241][.8080] - new: [....32] [ip4][..tcp] [..172.16.42.216][38391] -> [...192.168.11.1][.8080] + new: [....29] [ip4][..tcp] [..172.16.42.216][45662] -> [..52.94.232.134][..443] + new: [....30] [ip4][..tcp] [..172.16.42.216][45663] -> [..52.94.232.134][..443] + new: [....31] [ip4][..tcp] [..172.16.42.216][40200] -> [.10.201.126.241][.8080] + new: [....32] [ip4][..tcp] [..172.16.42.216][38391] -> [...192.168.11.1][.8080] detected: [....29] [ip4][..tcp] [..172.16.42.216][45662] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....30] [ip4][..tcp] [..172.16.42.216][45663] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....30] [ip4][..tcp] [..172.16.42.216][45663] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher detection-update: [....29] [ip4][..tcp] [..172.16.42.216][45662] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....33] [ip4][..tcp] [..172.16.42.216][40202] -> [.10.201.126.241][.8080] - new: [....34] [ip4][..udp] [..172.16.42.216][21391] -> [....172.16.42.1][...53] + new: [....33] [ip4][..tcp] [..172.16.42.216][40202] -> [.10.201.126.241][.8080] + new: [....34] [ip4][..udp] [..172.16.42.216][21391] -> [....172.16.42.1][...53] detected: [....34] [ip4][..udp] [..172.16.42.216][21391] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [....35] [ip4][..udp] [..172.16.42.216][52077] -> [....172.16.42.1][...53] + new: [....35] [ip4][..udp] [..172.16.42.216][52077] -> [....172.16.42.1][...53] detected: [....35] [ip4][..udp] [..172.16.42.216][52077] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] detection-update: [....34] [ip4][..udp] [..172.16.42.216][21391] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [....36] [ip4][..tcp] [..172.16.42.216][34019] -> [..54.239.24.186][..443] + new: [....36] [ip4][..tcp] [..172.16.42.216][34019] -> [..54.239.24.186][..443] detection-update: [....35] [ip4][..udp] [..172.16.42.216][52077] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] - new: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] - new: [....38] [ip4][..tcp] [..172.16.42.216][54412] -> [..52.85.209.216][..443] + new: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] + new: [....38] [ip4][..tcp] [..172.16.42.216][54412] -> [..52.85.209.216][..443] detected: [....36] [ip4][..tcp] [..172.16.42.216][34019] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detected: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] - new: [....39] [ip4][..tcp] [..172.16.42.216][54413] -> [..52.85.209.216][..443] + new: [....39] [ip4][..tcp] [..172.16.42.216][54413] -> [..52.85.209.216][..443] detected: [....38] [ip4][..tcp] [..172.16.42.216][54412] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] @@ -134,7 +134,7 @@ detection-update: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [....36] [ip4][..tcp] [..172.16.42.216][34019] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....36] [ip4][..tcp] [..172.16.42.216][34019] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [....40] [ip4][..udp] [..172.16.42.216][43350] -> [....172.16.42.1][...53] + new: [....40] [ip4][..udp] [..172.16.42.216][43350] -> [....172.16.42.1][...53] detected: [....40] [ip4][..udp] [..172.16.42.216][43350] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][fls-na.amazon.com] ERROR-EVENT: Unknown packet type [1/16] analyse: [....28] [ip4][..tcp] [..172.16.42.216][45661] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -148,25 +148,25 @@ [PKTLENS.....: 60,48,40,247,1500,1500,385,40,40,40,366,46,99,40,1122,46,941,40,1106,1106,46,493,40,1154,46,877,40,40,46,40,46,40] [ENTROPIES...: 4.6,5.1,4.8,5.5,6.8,7.3,7.4,4.8,4.8,4.7,7.3,4.7,6.0,4.9,7.8,4.5,7.8,4.8,7.8,7.8,4.6,7.6,4.8,7.8,4.6,7.7,4.9,4.9,4.5,4.8,4.5,4.8] detection-update: [....40] [ip4][..udp] [..172.16.42.216][43350] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][fls-na.amazon.com] - new: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] - new: [....42] [ip4][..tcp] [..172.16.42.216][42130] -> [..72.21.206.135][..443] + new: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] + new: [....42] [ip4][..tcp] [..172.16.42.216][42130] -> [..72.21.206.135][..443] detected: [....42] [ip4][..tcp] [..172.16.42.216][42130] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detected: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detection-update: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detection-update: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] - new: [....43] [ip4][..tcp] [..172.16.42.216][45673] -> [..52.94.232.134][..443] - new: [....44] [ip4][..tcp] [..172.16.42.216][45674] -> [..52.94.232.134][..443] + new: [....43] [ip4][..tcp] [..172.16.42.216][45673] -> [..52.94.232.134][..443] + new: [....44] [ip4][..tcp] [..172.16.42.216][45674] -> [..52.94.232.134][..443] detected: [....43] [ip4][..tcp] [..172.16.42.216][45673] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....44] [ip4][..tcp] [..172.16.42.216][45674] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....43] [ip4][..tcp] [..172.16.42.216][45673] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher detection-update: [....44] [ip4][..tcp] [..172.16.42.216][45674] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....45] [ip4][..tcp] [..172.16.42.216][49589] -> [..52.94.232.134][...80] - new: [....46] [ip4][..tcp] [..172.16.42.216][45676] -> [..52.94.232.134][..443] - new: [....47] [ip4][..tcp] [..172.16.42.216][45677] -> [..52.94.232.134][..443] - new: [....48] [ip4][..tcp] [..172.16.42.216][45678] -> [..52.94.232.134][..443] - new: [....49] [ip4][..tcp] [..172.16.42.216][45679] -> [..52.94.232.134][..443] + new: [....45] [ip4][..tcp] [..172.16.42.216][49589] -> [..52.94.232.134][...80] + new: [....46] [ip4][..tcp] [..172.16.42.216][45676] -> [..52.94.232.134][..443] + new: [....47] [ip4][..tcp] [..172.16.42.216][45677] -> [..52.94.232.134][..443] + new: [....48] [ip4][..tcp] [..172.16.42.216][45678] -> [..52.94.232.134][..443] + new: [....49] [ip4][..tcp] [..172.16.42.216][45679] -> [..52.94.232.134][..443] detected: [....45] [ip4][..tcp] [..172.16.42.216][49589] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable][alexa.amazon.com] detected: [....46] [ip4][..tcp] [..172.16.42.216][45676] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....47] [ip4][..tcp] [..172.16.42.216][45677] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -195,22 +195,22 @@ [PKTLENS.....: 60,48,40,245,46,245,245,46,1500,1500,1500,674,40,40,40,40,166,1500,91,468,46,46,466,40,1500,1196,46,343,40,40,46,40] [ENTROPIES...: 4.6,5.1,4.9,5.6,4.5,5.6,5.6,4.6,7.1,7.3,7.4,7.6,4.8,4.9,4.8,4.8,6.3,7.9,5.9,7.5,4.6,4.6,7.5,4.8,7.9,7.8,4.6,7.4,4.9,4.9,4.6,4.9] detection-update: [....42] [ip4][..tcp] [..172.16.42.216][42130] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] - new: [....50] [ip4][..tcp] [..172.16.42.216][45680] -> [..52.94.232.134][..443] + new: [....50] [ip4][..tcp] [..172.16.42.216][45680] -> [..52.94.232.134][..443] detected: [....50] [ip4][..tcp] [..172.16.42.216][45680] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....50] [ip4][..tcp] [..172.16.42.216][45680] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....51] [ip4][..tcp] [..172.16.42.216][34033] -> [..54.239.24.186][..443] - new: [....52] [ip4][..tcp] [..172.16.42.216][34034] -> [..54.239.24.186][..443] + new: [....51] [ip4][..tcp] [..172.16.42.216][34033] -> [..54.239.24.186][..443] + new: [....52] [ip4][..tcp] [..172.16.42.216][34034] -> [..54.239.24.186][..443] detected: [....51] [ip4][..tcp] [..172.16.42.216][34033] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [....53] [ip4][..tcp] [..172.16.42.216][45683] -> [..52.94.232.134][..443] + new: [....53] [ip4][..tcp] [..172.16.42.216][45683] -> [..52.94.232.134][..443] detected: [....52] [ip4][..tcp] [..172.16.42.216][34034] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....51] [ip4][..tcp] [..172.16.42.216][34033] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detected: [....53] [ip4][..tcp] [..172.16.42.216][45683] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....52] [ip4][..tcp] [..172.16.42.216][34034] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....53] [ip4][..tcp] [..172.16.42.216][45683] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....54] [ip4][..tcp] [..172.16.42.216][54427] -> [..52.85.209.216][..443] - new: [....55] [ip4][..tcp] [..172.16.42.216][42143] -> [..72.21.206.135][..443] + new: [....54] [ip4][..tcp] [..172.16.42.216][54427] -> [..52.85.209.216][..443] + new: [....55] [ip4][..tcp] [..172.16.42.216][42143] -> [..72.21.206.135][..443] detected: [....54] [ip4][..tcp] [..172.16.42.216][54427] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detected: [....55] [ip4][..tcp] [..172.16.42.216][42143] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detection-update: [....54] [ip4][..tcp] [..172.16.42.216][54427] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] @@ -225,40 +225,40 @@ [IATS(ms)....: 57.0,58.6,1.8,56.8,4.8,0.1,59.3,0.3,22.9,80.0,5.9,71.8,0.3,0.1,0.6,0.3,0.2,1.4,0.3,0.1,67.8,34.8,23.9,352.1,295.3,0.1,57.7,0.7,60.6,0.1,59.8] [PKTLENS.....: 60,48,40,299,46,46,196,40,91,806,46,550,1500,1425,1500,1500,1500,1500,1500,1500,69,46,46,46,1500,46,46,1500,1500,46,46,1500] [ENTROPIES...: 4.7,5.1,4.8,6.0,4.6,4.5,6.4,4.8,5.3,7.7,4.6,7.6,7.9,7.9,7.8,7.9,7.9,7.9,7.9,7.9,5.7,4.5,4.5,4.5,7.9,4.6,4.6,7.9,7.9,4.6,4.6,7.9] - new: [....56] [ip4][..tcp] [..172.16.42.216][42144] -> [..72.21.206.135][..443] + new: [....56] [ip4][..tcp] [..172.16.42.216][42144] -> [..72.21.206.135][..443] detected: [....56] [ip4][..tcp] [..172.16.42.216][42144] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detection-update: [....56] [ip4][..tcp] [..172.16.42.216][42144] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] ERROR-EVENT: Unknown packet type [2/16] - new: [....57] [ip4][..tcp] [..172.16.42.216][45687] -> [..52.94.232.134][..443] + new: [....57] [ip4][..tcp] [..172.16.42.216][45687] -> [..52.94.232.134][..443] detected: [....57] [ip4][..tcp] [..172.16.42.216][45687] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....57] [ip4][..tcp] [..172.16.42.216][45687] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....58] [ip4][....2] [........0.0.0.0] -> [......224.0.0.1] + new: [....58] [ip4][....2] [........0.0.0.0] -> [......224.0.0.1] detected: [....58] [ip4][....2] [........0.0.0.0] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [....59] [ip4][..tcp] [..172.16.42.216][45688] -> [..52.94.232.134][..443] + new: [....59] [ip4][..tcp] [..172.16.42.216][45688] -> [..52.94.232.134][..443] detected: [....59] [ip4][..tcp] [..172.16.42.216][45688] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....59] [ip4][..tcp] [..172.16.42.216][45688] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....60] [ip4][..tcp] [..172.16.42.216][34041] -> [..54.239.24.186][..443] + new: [....60] [ip4][..tcp] [..172.16.42.216][34041] -> [..54.239.24.186][..443] detected: [....60] [ip4][..tcp] [..172.16.42.216][34041] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....60] [ip4][..tcp] [..172.16.42.216][34041] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] update: [....14] [ip4][.icmp] [....172.16.42.1] -> [..172.16.42.216] [ICMP][Unknown][Network][Acceptable] update: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffd3:fbc2] [ICMPV6][Unknown][Network][Acceptable] update: [.....2] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] update: [.....5] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [....61] [ip4][..tcp] [..172.16.42.216][42148] -> [..72.21.206.135][..443] - new: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] + new: [....61] [ip4][..tcp] [..172.16.42.216][42148] -> [..72.21.206.135][..443] + new: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] detected: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] detected: [....61] [ip4][..tcp] [..172.16.42.216][42148] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detection-update: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] - new: [....63] [ip4][..tcp] [..172.16.42.216][54434] -> [..52.85.209.216][..443] + new: [....63] [ip4][..tcp] [..172.16.42.216][54434] -> [..52.85.209.216][..443] detection-update: [....61] [ip4][..tcp] [..172.16.42.216][42148] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] detected: [....63] [ip4][..tcp] [..172.16.42.216][54434] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [....63] [ip4][..tcp] [..172.16.42.216][54434] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] - new: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] + new: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] detected: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][api.amazon.com] detection-update: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][api.amazon.com] - new: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] + new: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] detected: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][api.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][api.amazon.com] @@ -287,19 +287,19 @@ [ENTROPIES...: 4.7,5.1,4.7,5.4,4.6,4.6,7.2,7.3,7.4,4.8,4.8,4.8,6.6,5.8,4.7,7.9,7.6,4.7,7.9,4.5,4.5,7.8,7.9,7.9,7.0,7.8,7.9,7.9,7.0,7.8,7.8,7.9] detection-update: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][api.amazon.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....66] [ip4][..tcp] [..172.16.42.216][49606] -> [..52.94.232.134][...80] - new: [....67] [ip4][..tcp] [..172.16.42.216][45693] -> [..52.94.232.134][..443] - new: [....68] [ip4][..tcp] [..172.16.42.216][45694] -> [..52.94.232.134][..443] - new: [....69] [ip4][..udp] [..172.16.42.216][25081] -> [....172.16.42.1][...53] + new: [....66] [ip4][..tcp] [..172.16.42.216][49606] -> [..52.94.232.134][...80] + new: [....67] [ip4][..tcp] [..172.16.42.216][45693] -> [..52.94.232.134][..443] + new: [....68] [ip4][..tcp] [..172.16.42.216][45694] -> [..52.94.232.134][..443] + new: [....69] [ip4][..udp] [..172.16.42.216][25081] -> [....172.16.42.1][...53] detected: [....69] [ip4][..udp] [..172.16.42.216][25081] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] detected: [....66] [ip4][..tcp] [..172.16.42.216][49606] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable][alexa.amazon.com] - new: [....70] [ip4][..tcp] [..172.16.42.216][45695] -> [..52.94.232.134][..443] + new: [....70] [ip4][..tcp] [..172.16.42.216][45695] -> [..52.94.232.134][..443] detected: [....68] [ip4][..tcp] [..172.16.42.216][45694] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....67] [ip4][..tcp] [..172.16.42.216][45693] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] - new: [....71] [ip4][..tcp] [..172.16.42.216][45696] -> [..52.94.232.134][..443] - new: [....72] [ip4][..tcp] [..172.16.42.216][45697] -> [..52.94.232.134][..443] + new: [....71] [ip4][..tcp] [..172.16.42.216][45696] -> [..52.94.232.134][..443] + new: [....72] [ip4][..tcp] [..172.16.42.216][45697] -> [..52.94.232.134][..443] detection-update: [....69] [ip4][..udp] [..172.16.42.216][25081] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] - new: [....73] [ip4][..tcp] [..172.16.42.216][59698] -> [..52.94.232.134][..443] + new: [....73] [ip4][..tcp] [..172.16.42.216][59698] -> [..52.94.232.134][..443] detection-update: [....68] [ip4][..tcp] [..172.16.42.216][45694] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher detected: [....71] [ip4][..tcp] [..172.16.42.216][45696] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -315,7 +315,7 @@ RISK: Weak TLS Cipher detection-update: [....73] [ip4][..tcp] [..172.16.42.216][59698] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][] RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn - new: [....74] [ip4][..tcp] [..172.16.42.216][45698] -> [..52.94.232.134][..443] + new: [....74] [ip4][..tcp] [..172.16.42.216][45698] -> [..52.94.232.134][..443] detected: [....74] [ip4][..tcp] [..172.16.42.216][45698] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....74] [ip4][..tcp] [..172.16.42.216][45698] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher @@ -329,19 +329,19 @@ update: [....23] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] update: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] - new: [....75] [ip4][..tcp] [..172.16.42.216][37113] -> [..52.94.232.134][..443] + new: [....75] [ip4][..tcp] [..172.16.42.216][37113] -> [..52.94.232.134][..443] detected: [....75] [ip4][..tcp] [..172.16.42.216][37113] -> [..52.94.232.134][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....75] [ip4][..tcp] [..172.16.42.216][37113] -> [..52.94.232.134][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....76] [ip4][..tcp] [..172.16.42.216][49613] -> [..52.94.232.134][...80] + new: [....76] [ip4][..tcp] [..172.16.42.216][49613] -> [..52.94.232.134][...80] detected: [....76] [ip4][..tcp] [..172.16.42.216][49613] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable][alexa.amazon.com] - new: [....77] [ip4][..tcp] [..172.16.42.216][38404] -> [..34.199.52.240][..443] + new: [....77] [ip4][..tcp] [..172.16.42.216][38404] -> [..34.199.52.240][..443] detected: [....77] [ip4][..tcp] [..172.16.42.216][38404] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....77] [ip4][..tcp] [..172.16.42.216][38404] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] detection-update: [....77] [ip4][..tcp] [..172.16.42.216][38404] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][cognito-identity.us-east-1.amazonaws.com] - new: [....78] [ip4][..tcp] [..172.16.42.216][34053] -> [..54.239.24.186][..443] - new: [....79] [ip4][..tcp] [..172.16.42.216][34054] -> [..54.239.24.186][..443] + new: [....78] [ip4][..tcp] [..172.16.42.216][34053] -> [..54.239.24.186][..443] + new: [....79] [ip4][..tcp] [..172.16.42.216][34054] -> [..54.239.24.186][..443] detected: [....78] [ip4][..tcp] [..172.16.42.216][34053] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....78] [ip4][..tcp] [..172.16.42.216][34053] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] update: [....21] [ip4][..udp] [..172.16.42.216][41030] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable] @@ -349,12 +349,12 @@ update: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] - new: [....80] [ip4][..tcp] [..172.16.42.216][45703] -> [..52.94.232.134][..443] - new: [....81] [ip4][..tcp] [..172.16.42.216][45704] -> [..52.94.232.134][..443] - new: [....82] [ip4][..tcp] [..172.16.42.216][45705] -> [..52.94.232.134][..443] - new: [....83] [ip4][..tcp] [..172.16.42.216][40242] -> [.10.201.126.241][.8080] - new: [....84] [ip4][..tcp] [..172.16.42.216][45707] -> [..52.94.232.134][..443] - new: [....85] [ip4][..tcp] [..172.16.42.216][38434] -> [...192.168.11.1][.8080] + new: [....80] [ip4][..tcp] [..172.16.42.216][45703] -> [..52.94.232.134][..443] + new: [....81] [ip4][..tcp] [..172.16.42.216][45704] -> [..52.94.232.134][..443] + new: [....82] [ip4][..tcp] [..172.16.42.216][45705] -> [..52.94.232.134][..443] + new: [....83] [ip4][..tcp] [..172.16.42.216][40242] -> [.10.201.126.241][.8080] + new: [....84] [ip4][..tcp] [..172.16.42.216][45707] -> [..52.94.232.134][..443] + new: [....85] [ip4][..tcp] [..172.16.42.216][38434] -> [...192.168.11.1][.8080] detected: [....80] [ip4][..tcp] [..172.16.42.216][45703] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....81] [ip4][..tcp] [..172.16.42.216][45704] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....80] [ip4][..tcp] [..172.16.42.216][45703] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -364,16 +364,16 @@ detected: [....82] [ip4][..tcp] [..172.16.42.216][45705] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [....82] [ip4][..tcp] [..172.16.42.216][45705] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [....86] [ip4][..tcp] [..172.16.42.216][45709] -> [..52.94.232.134][..443] - new: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] + new: [....86] [ip4][..tcp] [..172.16.42.216][45709] -> [..52.94.232.134][..443] + new: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] detected: [....86] [ip4][..tcp] [..172.16.42.216][45709] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] - new: [....88] [ip4][..tcp] [..172.16.42.216][45711] -> [..52.94.232.134][..443] - new: [....89] [ip4][..tcp] [..172.16.42.216][45712] -> [..52.94.232.134][..443] - new: [....90] [ip4][..tcp] [..172.16.42.216][49627] -> [..52.94.232.134][...80] - new: [....91] [ip4][..tcp] [..172.16.42.216][45714] -> [..52.94.232.134][..443] - new: [....92] [ip4][..tcp] [..172.16.42.216][45715] -> [..52.94.232.134][..443] - new: [....93] [ip4][..tcp] [..172.16.42.216][49630] -> [..52.94.232.134][...80] + new: [....88] [ip4][..tcp] [..172.16.42.216][45711] -> [..52.94.232.134][..443] + new: [....89] [ip4][..tcp] [..172.16.42.216][45712] -> [..52.94.232.134][..443] + new: [....90] [ip4][..tcp] [..172.16.42.216][49627] -> [..52.94.232.134][...80] + new: [....91] [ip4][..tcp] [..172.16.42.216][45714] -> [..52.94.232.134][..443] + new: [....92] [ip4][..tcp] [..172.16.42.216][45715] -> [..52.94.232.134][..443] + new: [....93] [ip4][..tcp] [..172.16.42.216][49630] -> [..52.94.232.134][...80] detection-update: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher detection-update: [....86] [ip4][..tcp] [..172.16.42.216][45709] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -401,14 +401,14 @@ RISK: Weak TLS Cipher detection-update: [....93] [ip4][..tcp] [..172.16.42.216][49630] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable][alexa.amazon.com] RISK: Error Code - new: [....94] [ip4][..tcp] [..172.16.42.216][34069] -> [..54.239.24.186][..443] + new: [....94] [ip4][..tcp] [..172.16.42.216][34069] -> [..54.239.24.186][..443] detected: [....94] [ip4][..tcp] [..172.16.42.216][34069] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [....95] [ip4][..udp] [..172.16.42.216][35726] -> [....172.16.42.1][...53] + new: [....95] [ip4][..udp] [..172.16.42.216][35726] -> [....172.16.42.1][...53] detected: [....95] [ip4][..udp] [..172.16.42.216][35726] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][s3-external-2.amazonaws.com] detection-update: [....94] [ip4][..tcp] [..172.16.42.216][34069] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [....95] [ip4][..udp] [..172.16.42.216][35726] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][s3-external-2.amazonaws.com] - new: [....96] [ip4][..tcp] [..172.16.42.216][41820] -> [...54.231.72.88][..443] - new: [....97] [ip4][..tcp] [..172.16.42.216][41821] -> [...54.231.72.88][..443] + new: [....96] [ip4][..tcp] [..172.16.42.216][41820] -> [...54.231.72.88][..443] + new: [....97] [ip4][..tcp] [..172.16.42.216][41821] -> [...54.231.72.88][..443] detected: [....96] [ip4][..tcp] [..172.16.42.216][41820] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][s3-external-2.amazonaws.com] analyse: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] min| max| avg| stddev| variance| entropy @@ -432,10 +432,10 @@ [IATS(ms)....: 1005.7,1080.3,210.2,18.7,169.7,18.0,105.0,0.1,107.2,0.3,11.7,34.8,0.1,215.2,0.3,0.1,21.7,195.6,0.3,202.8,0.7,212.9,0.3,205.8,11.0,236.3,754.7,0.3,888.9,405.4,377.3] [PKTLENS.....: 60,60,48,40,279,48,40,125,93,40,40,99,1500,254,46,46,46,541,1500,206,46,701,1500,238,46,557,40,1500,206,46,1500,46] [ENTROPIES...: 4.7,4.6,5.1,4.8,5.9,5.1,4.9,6.0,6.1,4.8,4.9,5.8,7.9,7.2,4.7,4.6,4.6,7.6,7.9,7.0,4.7,7.7,7.9,7.1,4.6,7.6,4.9,7.9,6.9,4.5,7.9,4.5] - new: [....98] [ip4][..udp] [..172.16.42.216][41639] -> [....172.16.42.1][...53] + new: [....98] [ip4][..udp] [..172.16.42.216][41639] -> [....172.16.42.1][...53] detected: [....98] [ip4][..udp] [..172.16.42.216][41639] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][dp-gw-na-js.amazon.com] detection-update: [....98] [ip4][..udp] [..172.16.42.216][41639] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][dp-gw-na-js.amazon.com] - new: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] + new: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] detected: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][dp-gw-na-js.amazon.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][dp-gw-na-js.amazon.com] @@ -451,22 +451,22 @@ update: [....34] [ip4][..udp] [..172.16.42.216][21391] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable] detection-update: [....88] [ip4][..tcp] [..172.16.42.216][45711] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [...100] [ip4][..tcp] [..172.16.42.216][34073] -> [..54.239.24.186][..443] - new: [...101] [ip4][..tcp] [..172.16.42.216][34074] -> [..54.239.24.186][..443] - new: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] + new: [...100] [ip4][..tcp] [..172.16.42.216][34073] -> [..54.239.24.186][..443] + new: [...101] [ip4][..tcp] [..172.16.42.216][34074] -> [..54.239.24.186][..443] + new: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] detected: [...101] [ip4][..tcp] [..172.16.42.216][34074] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detected: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][s3-external-2.amazonaws.com] detection-update: [...101] [ip4][..tcp] [..172.16.42.216][34074] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][s3-external-2.amazonaws.com] detection-update: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][s3-external-2.amazonaws.com] update: [....23] [ip6][icmp6] [..............fe80::7af8:82ff:fed3:fbc2] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [...103] [ip4][..udp] [..172.16.42.216][14476] -> [....172.16.42.1][...53] + new: [...103] [ip4][..udp] [..172.16.42.216][14476] -> [....172.16.42.1][...53] detected: [...103] [ip4][..udp] [..172.16.42.216][14476] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][skills-store.amazon.com] detection-update: [...103] [ip4][..udp] [..172.16.42.216][14476] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][skills-store.amazon.com] - new: [...104] [ip4][..tcp] [..172.16.42.216][40853] -> [..54.239.29.253][..443] - new: [...105] [ip4][..tcp] [..172.16.42.216][40854] -> [..54.239.29.253][..443] - new: [...106] [ip4][..tcp] [..172.16.42.216][40855] -> [..54.239.29.253][..443] - new: [...107] [ip4][..tcp] [..172.16.42.216][40856] -> [..54.239.29.253][..443] + new: [...104] [ip4][..tcp] [..172.16.42.216][40853] -> [..54.239.29.253][..443] + new: [...105] [ip4][..tcp] [..172.16.42.216][40854] -> [..54.239.29.253][..443] + new: [...106] [ip4][..tcp] [..172.16.42.216][40855] -> [..54.239.29.253][..443] + new: [...107] [ip4][..tcp] [..172.16.42.216][40856] -> [..54.239.29.253][..443] detected: [...105] [ip4][..tcp] [..172.16.42.216][40854] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] detected: [...104] [ip4][..tcp] [..172.16.42.216][40853] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] detected: [...107] [ip4][..tcp] [..172.16.42.216][40856] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] @@ -518,14 +518,14 @@ [ENTROPIES...: 4.7,5.1,4.8,5.5,4.6,7.2,7.3,7.6,5.5,5.5,4.8,4.9,4.7,6.3,4.5,4.5,4.8,5.6,4.8,7.9,7.2,4.5,6.8,6.0,7.1,7.0,6.9,4.5,4.6,7.0,4.8,7.3] detection-update: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][dp-gw-na-js.amazon.com] RISK: TLS (probably) Not Carrying HTTPS - new: [...108] [ip4][..udp] [..172.16.42.216][20922] -> [....172.16.42.1][...53] + new: [...108] [ip4][..udp] [..172.16.42.216][20922] -> [....172.16.42.1][...53] detected: [...108] [ip4][..udp] [..172.16.42.216][20922] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] detection-update: [...108] [ip4][..udp] [..172.16.42.216][20922] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] - new: [...109] [ip4][..tcp] [..172.16.42.216][45728] -> [..52.94.232.134][..443] - new: [...110] [ip4][..tcp] [..172.16.42.216][45729] -> [..52.94.232.134][..443] - new: [...111] [ip4][..tcp] [..172.16.42.216][45730] -> [..52.94.232.134][..443] - new: [...112] [ip4][..tcp] [..172.16.42.216][45731] -> [..52.94.232.134][..443] - new: [...113] [ip4][..tcp] [..172.16.42.216][45732] -> [..52.94.232.134][..443] + new: [...109] [ip4][..tcp] [..172.16.42.216][45728] -> [..52.94.232.134][..443] + new: [...110] [ip4][..tcp] [..172.16.42.216][45729] -> [..52.94.232.134][..443] + new: [...111] [ip4][..tcp] [..172.16.42.216][45730] -> [..52.94.232.134][..443] + new: [...112] [ip4][..tcp] [..172.16.42.216][45731] -> [..52.94.232.134][..443] + new: [...113] [ip4][..tcp] [..172.16.42.216][45732] -> [..52.94.232.134][..443] detected: [...110] [ip4][..tcp] [..172.16.42.216][45729] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [...109] [ip4][..tcp] [..172.16.42.216][45728] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [...111] [ip4][..tcp] [..172.16.42.216][45730] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -541,11 +541,11 @@ RISK: Weak TLS Cipher detection-update: [...113] [ip4][..tcp] [..172.16.42.216][45732] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [...114] [ip4][..udp] [..172.16.42.216][28614] -> [....172.16.42.1][...53] + new: [...114] [ip4][..udp] [..172.16.42.216][28614] -> [....172.16.42.1][...53] detected: [...114] [ip4][..udp] [..172.16.42.216][28614] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [...114] [ip4][..udp] [..172.16.42.216][28614] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [...115] [ip4][..tcp] [..172.16.42.216][37551] -> [..54.239.24.180][..443] - new: [...116] [ip4][..tcp] [..172.16.42.216][37552] -> [..54.239.24.180][..443] + new: [...115] [ip4][..tcp] [..172.16.42.216][37551] -> [..54.239.24.180][..443] + new: [...116] [ip4][..tcp] [..172.16.42.216][37552] -> [..54.239.24.180][..443] detected: [...115] [ip4][..tcp] [..172.16.42.216][37551] -> [..54.239.24.180][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] update: [....69] [ip4][..udp] [..172.16.42.216][25081] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable] update: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] @@ -558,19 +558,19 @@ update: [.....7] [ip4][..udp] [..172.16.42.216][55619] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [.....6] [ip4][..udp] [..172.16.42.216][.3440] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] - new: [...117] [ip4][..tcp] [..172.16.42.216][40864] -> [..54.239.29.253][..443] + new: [...117] [ip4][..tcp] [..172.16.42.216][40864] -> [..54.239.29.253][..443] detected: [...117] [ip4][..tcp] [..172.16.42.216][40864] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] detection-update: [...117] [ip4][..tcp] [..172.16.42.216][40864] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] RISK: Weak TLS Cipher - new: [...118] [ip4][..udp] [..172.16.42.216][.4920] -> [....172.16.42.1][...53] + new: [...118] [ip4][..udp] [..172.16.42.216][.4920] -> [....172.16.42.1][...53] detected: [...118] [ip4][..udp] [..172.16.42.216][.4920] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][ecx.images-amazon.com] detection-update: [...118] [ip4][..udp] [..172.16.42.216][.4920] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][ecx.images-amazon.com] - new: [...119] [ip4][..tcp] [..172.16.42.216][51985] -> [....52.84.63.56][...80] - new: [...120] [ip4][..tcp] [..172.16.42.216][51986] -> [....52.84.63.56][...80] - new: [...121] [ip4][..tcp] [..172.16.42.216][51987] -> [....52.84.63.56][...80] - new: [...122] [ip4][..tcp] [..172.16.42.216][51988] -> [....52.84.63.56][...80] - new: [...123] [ip4][..tcp] [..172.16.42.216][51989] -> [....52.84.63.56][...80] - new: [...124] [ip4][..tcp] [..172.16.42.216][51990] -> [....52.84.63.56][...80] + new: [...119] [ip4][..tcp] [..172.16.42.216][51985] -> [....52.84.63.56][...80] + new: [...120] [ip4][..tcp] [..172.16.42.216][51986] -> [....52.84.63.56][...80] + new: [...121] [ip4][..tcp] [..172.16.42.216][51987] -> [....52.84.63.56][...80] + new: [...122] [ip4][..tcp] [..172.16.42.216][51988] -> [....52.84.63.56][...80] + new: [...123] [ip4][..tcp] [..172.16.42.216][51989] -> [....52.84.63.56][...80] + new: [...124] [ip4][..tcp] [..172.16.42.216][51990] -> [....52.84.63.56][...80] detected: [...123] [ip4][..tcp] [..172.16.42.216][51989] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] detected: [...122] [ip4][..tcp] [..172.16.42.216][51988] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] detected: [...119] [ip4][..tcp] [..172.16.42.216][51985] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] @@ -587,7 +587,7 @@ [IATS(ms)....: 58.0,60.3,1.6,154.7,0.4,0.4,0.4,0.5,0.5,0.2,0.4,156.7,0.3,4.1,0.1,3.4,0.2,0.1,0.2,0.1,0.1,0.1,7.0,268.3,295.2,18.3,286.3,0.5,0.4,286.6,4.3] [PKTLENS.....: 60,60,52,599,52,1500,1500,1500,1500,1500,1500,1500,52,52,1500,427,52,52,52,52,52,52,52,599,599,427,64,592,1500,1500,52,52] [ENTROPIES...: 4.7,5.2,5.0,6.0,5.1,7.1,7.8,7.8,7.9,7.8,7.8,7.8,5.0,5.0,7.8,6.5,5.0,5.0,5.0,5.0,5.0,5.0,5.0,6.0,6.0,6.5,5.0,5.9,7.5,7.8,5.0,5.0] - new: [...125] [ip4][..tcp] [..172.16.42.216][40871] -> [..54.239.29.253][..443] + new: [...125] [ip4][..tcp] [..172.16.42.216][40871] -> [..54.239.29.253][..443] detected: [...125] [ip4][..tcp] [..172.16.42.216][40871] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] detection-update: [...125] [ip4][..tcp] [..172.16.42.216][40871] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] RISK: Weak TLS Cipher @@ -601,12 +601,12 @@ [IATS(ms)....: 111.1,112.4,0.8,179.9,0.1,0.0,179.9,2.9,0.3,3.3,0.5,135.1,0.2,170.2,502.2,1107.1,16.8,0.2,0.2,0.0,0.0,0.0,706.6,0.4,9.7,355.9,0.3,629.2,147.8,0.1,0.1] [PKTLENS.....: 60,48,40,283,46,125,93,40,40,99,1500,286,46,46,1500,1500,46,1500,121,1500,153,429,77,40,40,40,1500,318,46,1021,589,589] [ENTROPIES...: 4.7,5.1,4.8,5.9,4.5,6.2,6.0,4.8,4.9,6.0,7.9,7.1,4.5,4.6,7.9,7.9,4.6,7.9,6.4,7.9,6.6,7.5,5.8,4.8,4.8,4.7,7.9,7.3,4.6,7.8,7.6,7.7] - new: [...126] [ip4][..tcp] [..172.16.42.216][51992] -> [....52.84.63.56][...80] - new: [...127] [ip4][..tcp] [..172.16.42.216][51993] -> [....52.84.63.56][...80] - new: [...128] [ip4][..tcp] [..172.16.42.216][51994] -> [....52.84.63.56][...80] - new: [...129] [ip4][..tcp] [..172.16.42.216][51995] -> [....52.84.63.56][...80] - new: [...130] [ip4][..tcp] [..172.16.42.216][51996] -> [....52.84.63.56][...80] - new: [...131] [ip4][..tcp] [..172.16.42.216][51997] -> [....52.84.63.56][...80] + new: [...126] [ip4][..tcp] [..172.16.42.216][51992] -> [....52.84.63.56][...80] + new: [...127] [ip4][..tcp] [..172.16.42.216][51993] -> [....52.84.63.56][...80] + new: [...128] [ip4][..tcp] [..172.16.42.216][51994] -> [....52.84.63.56][...80] + new: [...129] [ip4][..tcp] [..172.16.42.216][51995] -> [....52.84.63.56][...80] + new: [...130] [ip4][..tcp] [..172.16.42.216][51996] -> [....52.84.63.56][...80] + new: [...131] [ip4][..tcp] [..172.16.42.216][51997] -> [....52.84.63.56][...80] detected: [...126] [ip4][..tcp] [..172.16.42.216][51992] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] detected: [...128] [ip4][..tcp] [..172.16.42.216][51994] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] detected: [...129] [ip4][..tcp] [..172.16.42.216][51995] -> [....52.84.63.56][...80] [HTTP.Amazon][AmazonAWS][Web][Acceptable][ecx.images-amazon.com] @@ -649,11 +649,11 @@ [IATS(ms)....: 25.0,26.3,0.4,110.2,0.1,0.2,0.3,0.4,0.4,1.1,0.5,0.4,0.4,114.9,0.2,0.1,0.1,3.5,0.1,26.3,0.3,0.1,0.1,0.1,0.2,4.7,62.5,45.1,368.8,510.9,0.4] [PKTLENS.....: 60,60,52,599,52,52,1500,1500,1500,1500,1500,1500,1500,1500,52,52,52,52,1500,1295,52,52,52,52,52,52,599,1295,64,599,1500,1500] [ENTROPIES...: 4.7,5.2,5.1,6.0,5.0,5.0,7.1,7.8,7.8,7.8,7.8,7.8,7.8,7.8,5.0,5.0,4.9,5.0,7.8,7.6,5.0,5.0,5.0,5.0,5.0,5.0,6.0,7.6,5.2,6.0,7.1,7.8] - new: [...132] [ip4][..tcp] [..172.16.42.216][40878] -> [..54.239.29.253][..443] + new: [...132] [ip4][..tcp] [..172.16.42.216][40878] -> [..54.239.29.253][..443] detected: [...132] [ip4][..tcp] [..172.16.42.216][40878] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] detection-update: [...132] [ip4][..tcp] [..172.16.42.216][40878] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][skills-store.amazon.com] RISK: Weak TLS Cipher - new: [...133] [ip4][..tcp] [..172.16.42.216][45750] -> [..52.94.232.134][..443] + new: [...133] [ip4][..tcp] [..172.16.42.216][45750] -> [..52.94.232.134][..443] detected: [...133] [ip4][..tcp] [..172.16.42.216][45750] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [...133] [ip4][..tcp] [..172.16.42.216][45750] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher @@ -671,7 +671,7 @@ [ENTROPIES...: 4.7,5.3,5.0,5.4,5.1,7.0,7.2,7.6,5.0,5.1,5.0,6.6,7.2,5.0,7.9,7.9,5.1,7.9,7.3,6.1,5.8,5.1,5.1,7.9,7.8,5.1,5.1,7.9,5.9,5.1,5.6,5.1] detection-update: [....16] [ip4][..tcp] [..172.16.42.216][55242] -> [..52.85.209.197][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] RISK: TLS (probably) Not Carrying HTTPS - new: [...134] [ip4][..tcp] [..172.16.42.216][45751] -> [..52.94.232.134][..443] + new: [...134] [ip4][..tcp] [..172.16.42.216][45751] -> [..52.94.232.134][..443] detected: [...134] [ip4][..tcp] [..172.16.42.216][45751] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [...134] [ip4][..tcp] [..172.16.42.216][45751] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher @@ -682,15 +682,15 @@ end: [....25] [ip4][..tcp] [..172.16.42.216][38363] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] update: [...103] [ip4][..udp] [..172.16.42.216][14476] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [...108] [ip4][..udp] [..172.16.42.216][20922] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] - new: [...135] [ip4][..udp] [..172.16.42.216][64073] -> [....172.16.42.1][...53] + new: [...135] [ip4][..udp] [..172.16.42.216][64073] -> [....172.16.42.1][...53] detected: [...135] [ip4][..udp] [..172.16.42.216][64073] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] detection-update: [...135] [ip4][..udp] [..172.16.42.216][64073] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] - new: [...136] [ip4][..tcp] [..172.16.42.216][39750] -> [..52.94.232.134][..443] + new: [...136] [ip4][..tcp] [..172.16.42.216][39750] -> [..52.94.232.134][..443] detected: [...136] [ip4][..tcp] [..172.16.42.216][39750] -> [..52.94.232.134][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [...136] [ip4][..tcp] [..172.16.42.216][39750] -> [..52.94.232.134][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [...137] [ip4][..tcp] [..172.16.42.216][45752] -> [..52.94.232.134][..443] + new: [...137] [ip4][..tcp] [..172.16.42.216][45752] -> [..52.94.232.134][..443] detected: [...137] [ip4][..tcp] [..172.16.42.216][45752] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [...137] [ip4][..tcp] [..172.16.42.216][45752] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher @@ -721,7 +721,7 @@ end: [....37] [ip4][..tcp] [..172.16.42.216][54411] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] end: [....38] [ip4][..tcp] [..172.16.42.216][54412] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] guessed: [....39] [ip4][..tcp] [..172.16.42.216][54413] -> [..52.85.209.216][..443] [TLS][AmazonAWS][Web][Safe] - end: [....39] [ip4][..tcp] [..172.16.42.216][54413] -> [..52.85.209.216][..443] + end: [....39] [ip4][..tcp] [..172.16.42.216][54413] -> [..52.85.209.216][..443] end: [....54] [ip4][..tcp] [..172.16.42.216][54427] -> [..52.85.209.216][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] end: [....41] [ip4][..tcp] [..172.16.42.216][42129] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] end: [....42] [ip4][..tcp] [..172.16.42.216][42130] -> [..72.21.206.135][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -732,7 +732,7 @@ end: [....52] [ip4][..tcp] [..172.16.42.216][34034] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] guessed: [....32] [ip4][..tcp] [..172.16.42.216][38391] -> [...192.168.11.1][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: TCP Connection Issues - end: [....32] [ip4][..tcp] [..172.16.42.216][38391] -> [...192.168.11.1][.8080] + end: [....32] [ip4][..tcp] [..172.16.42.216][38391] -> [...192.168.11.1][.8080] end: [....26] [ip4][..tcp] [..172.16.42.216][38364] -> [..34.199.52.240][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] update: [.....3] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [..172.16.42.216][53188] -> [....172.16.42.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable] @@ -745,15 +745,15 @@ update: [....10] [ip4][..udp] [..172.16.42.216][52603] -> [....172.16.42.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] - new: [...138] [ip4][..udp] [..172.16.42.216][.4312] -> [....172.16.42.1][...53] + new: [...138] [ip4][..udp] [..172.16.42.216][.4312] -> [....172.16.42.1][...53] detected: [...138] [ip4][..udp] [..172.16.42.216][.4312] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] detection-update: [...138] [ip4][..udp] [..172.16.42.216][.4312] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][pitangui.amazon.com] - new: [...139] [ip4][..tcp] [..172.16.42.216][50796] -> [..54.239.28.178][..443] - new: [...140] [ip4][..tcp] [..172.16.42.216][50797] -> [..54.239.28.178][..443] - new: [...141] [ip4][..tcp] [..172.16.42.216][50798] -> [..54.239.28.178][..443] + new: [...139] [ip4][..tcp] [..172.16.42.216][50796] -> [..54.239.28.178][..443] + new: [...140] [ip4][..tcp] [..172.16.42.216][50797] -> [..54.239.28.178][..443] + new: [...141] [ip4][..tcp] [..172.16.42.216][50798] -> [..54.239.28.178][..443] detected: [...139] [ip4][..tcp] [..172.16.42.216][50796] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detected: [...140] [ip4][..tcp] [..172.16.42.216][50797] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] - new: [...142] [ip4][..tcp] [..172.16.42.216][50799] -> [..54.239.28.178][..443] + new: [...142] [ip4][..tcp] [..172.16.42.216][50799] -> [..54.239.28.178][..443] detection-update: [...139] [ip4][..tcp] [..172.16.42.216][50796] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher detection-update: [...140] [ip4][..tcp] [..172.16.42.216][50797] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] @@ -767,21 +767,21 @@ RISK: Weak TLS Cipher end: [....60] [ip4][..tcp] [..172.16.42.216][34041] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] update: [...118] [ip4][..udp] [..172.16.42.216][.4920] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] - new: [...143] [ip4][..tcp] [..172.16.42.216][50800] -> [..54.239.28.178][..443] + new: [...143] [ip4][..tcp] [..172.16.42.216][50800] -> [..54.239.28.178][..443] detected: [...143] [ip4][..tcp] [..172.16.42.216][50800] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] detection-update: [...143] [ip4][..tcp] [..172.16.42.216][50800] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][pitangui.amazon.com] RISK: Weak TLS Cipher - new: [...144] [ip4][..udp] [..172.16.42.216][.8669] -> [....172.16.42.1][...53] + new: [...144] [ip4][..udp] [..172.16.42.216][.8669] -> [....172.16.42.1][...53] detected: [...144] [ip4][..udp] [..172.16.42.216][.8669] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [...144] [ip4][..udp] [..172.16.42.216][.8669] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] + new: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] detected: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] detection-update: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable][mobileanalytics.us-east-1.amazonaws.com] - new: [...146] [ip4][..udp] [..172.16.42.216][59908] -> [....172.16.42.1][...53] + new: [...146] [ip4][..udp] [..172.16.42.216][59908] -> [....172.16.42.1][...53] detected: [...146] [ip4][..udp] [..172.16.42.216][59908] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] detection-update: [...146] [ip4][..udp] [..172.16.42.216][59908] -> [....172.16.42.1][...53] [DNS.AmazonAlexa][Unknown][Network][Acceptable][alexa.amazon.com] - new: [...147] [ip4][..tcp] [..172.16.42.216][38757] -> [..54.239.28.178][..443] + new: [...147] [ip4][..tcp] [..172.16.42.216][38757] -> [..54.239.28.178][..443] analyse: [...142] [ip4][..tcp] [..172.16.42.216][50799] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 8.001| 0.664| 1.905| 3629965.115| 2.500] @@ -798,17 +798,17 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [...147] [ip4][..tcp] [..172.16.42.216][38757] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [...148] [ip4][..udp] [..172.16.42.216][14934] -> [....172.16.42.1][...53] + new: [...148] [ip4][..udp] [..172.16.42.216][14934] -> [....172.16.42.1][...53] detected: [...148] [ip4][..udp] [..172.16.42.216][14934] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] detection-update: [...148] [ip4][..udp] [..172.16.42.216][14934] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][www.amazon.com] - new: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] - new: [...150] [ip4][..udp] [..172.16.42.216][40425] -> [....172.16.42.1][...53] + new: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] + new: [...150] [ip4][..udp] [..172.16.42.216][40425] -> [....172.16.42.1][...53] detected: [...150] [ip4][..udp] [..172.16.42.216][40425] -> [....172.16.42.1][...53] [DNS.PlayStore][Unknown][Network][Safe][android.clients.google.com] detected: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] detection-update: [...150] [ip4][..udp] [..172.16.42.216][40425] -> [....172.16.42.1][...53] [DNS.PlayStore][Unknown][Network][Safe][android.clients.google.com] - new: [...151] [ip4][..tcp] [..172.16.42.216][49067] -> [..216.58.194.78][..443] + new: [...151] [ip4][..tcp] [..172.16.42.216][49067] -> [..216.58.194.78][..443] detected: [...151] [ip4][..tcp] [..172.16.42.216][49067] -> [..216.58.194.78][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [...151] [ip4][..tcp] [..172.16.42.216][49067] -> [..216.58.194.78][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] @@ -826,16 +826,16 @@ [PKTLENS.....: 60,60,52,254,52,1500,1500,1500,819,52,52,52,52,178,1500,767,64,178,1500,64,306,52,52,1500,1500,1500,683,594,129,52,149,52] [ENTROPIES...: 4.7,5.2,5.0,5.6,5.0,6.9,7.2,7.5,7.6,5.1,4.9,5.0,4.9,6.3,7.9,7.7,5.2,6.3,7.9,5.1,7.1,5.0,5.0,7.9,7.9,7.9,7.7,7.6,6.3,5.0,6.5,4.8] detection-update: [...149] [ip4][..tcp] [..172.16.42.216][41828] -> [..52.85.209.143][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][www.amazon.com] - new: [...152] [ip4][..udp] [..172.16.42.216][.4612] -> [....172.16.42.1][...53] + new: [...152] [ip4][..udp] [..172.16.42.216][.4612] -> [....172.16.42.1][...53] detected: [...152] [ip4][..udp] [..172.16.42.216][.4612] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][images-na.ssl-images-amazon.com] detection-update: [...152] [ip4][..udp] [..172.16.42.216][.4612] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][images-na.ssl-images-amazon.com] - new: [...153] [ip4][..tcp] [..172.16.42.216][41912] -> [...52.84.62.115][..443] - new: [...154] [ip4][..tcp] [..172.16.42.216][41913] -> [...52.84.62.115][..443] - new: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] + new: [...153] [ip4][..tcp] [..172.16.42.216][41912] -> [...52.84.62.115][..443] + new: [...154] [ip4][..tcp] [..172.16.42.216][41913] -> [...52.84.62.115][..443] + new: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] detected: [...154] [ip4][..tcp] [..172.16.42.216][41913] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] detected: [...153] [ip4][..tcp] [..172.16.42.216][41912] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] detected: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] - new: [...156] [ip4][..tcp] [..172.16.42.216][58048] -> [..54.239.28.178][..443] + new: [...156] [ip4][..tcp] [..172.16.42.216][58048] -> [..54.239.28.178][..443] detection-update: [...154] [ip4][..tcp] [..172.16.42.216][41913] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] detection-update: [...154] [ip4][..tcp] [..172.16.42.216][41913] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] detection-update: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] @@ -872,7 +872,7 @@ update: [....15] [ip4][..udp] [..172.16.42.216][48155] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] update: [....17] [ip4][..udp] [..172.16.42.216][19967] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] - new: [...157] [ip4][..tcp] [..172.16.42.216][38483] -> [..52.85.209.143][..443] + new: [...157] [ip4][..tcp] [..172.16.42.216][38483] -> [..52.85.209.143][..443] detected: [...157] [ip4][..tcp] [..172.16.42.216][38483] -> [..52.85.209.143][..443] [TLS][AmazonAWS][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [...157] [ip4][..tcp] [..172.16.42.216][38483] -> [..52.85.209.143][..443] [TLS][AmazonAWS][Web][Safe][] @@ -889,7 +889,7 @@ [IATS(ms)....: 34.0,35.1,2.2,37.9,5.1,0.5,0.2,42.9,0.3,0.1,30.8,68.8,38.4,227.1,241.4,50.1,58.4,55.5,3.8,2.0,4.4,1.6,0.7,7.8,0.1,0.1,9.0,0.3,3.1,0.8,10.2] [PKTLENS.....: 60,60,52,246,52,1500,1500,618,52,52,52,178,103,718,718,103,64,52,1096,427,256,815,905,441,1500,177,557,1500,1500,1500,1500,1500] [ENTROPIES...: 4.7,5.2,5.1,5.4,5.2,7.0,7.3,7.7,5.0,5.1,5.1,6.6,6.1,7.7,7.7,6.1,5.1,5.2,7.8,7.4,7.1,7.7,7.8,7.5,7.9,6.8,7.6,7.9,7.9,7.9,7.9,7.9] - new: [...158] [ip4][..udp] [..172.16.42.216][.2707] -> [....172.16.42.1][...53] + new: [...158] [ip4][..udp] [..172.16.42.216][.2707] -> [....172.16.42.1][...53] detected: [...158] [ip4][..udp] [..172.16.42.216][.2707] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][fls-na.amazon.com] analyse: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] min| max| avg| stddev| variance| entropy @@ -903,9 +903,9 @@ [ENTROPIES...: 4.7,5.3,5.1,5.7,5.1,7.1,7.3,7.5,7.6,5.1,5.0,5.1,5.0,6.4,7.2,7.9,7.2,5.0,7.9,7.9,7.8,5.8,5.8,5.1,5.1,5.1,7.8,7.9,7.9,7.5,5.1,5.1] detection-update: [...155] [ip4][..tcp] [..172.16.42.216][41914] -> [...52.84.62.115][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][images-na.ssl-images-amazon.com] detection-update: [...158] [ip4][..udp] [..172.16.42.216][.2707] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable][fls-na.amazon.com] - new: [...159] [ip4][..tcp] [..172.16.42.216][47605] -> [..72.21.206.121][..443] + new: [...159] [ip4][..tcp] [..172.16.42.216][47605] -> [..72.21.206.121][..443] detected: [...159] [ip4][..tcp] [..172.16.42.216][47605] -> [..72.21.206.121][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable][fls-na.amazon.com] - new: [...160] [ip4][..tcp] [..172.16.42.216][47606] -> [..72.21.206.121][..443] + new: [...160] [ip4][..tcp] [..172.16.42.216][47606] -> [..72.21.206.121][..443] analyse: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 7.471| 0.614| 1.478| 2183643.136| 2.800] @@ -928,7 +928,7 @@ idle: [...140] [ip4][..tcp] [..172.16.42.216][50797] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher guessed: [...141] [ip4][..tcp] [..172.16.42.216][50798] -> [..54.239.28.178][..443] [TLS][AmazonAWS][Web][Safe] - end: [...141] [ip4][..tcp] [..172.16.42.216][50798] -> [..54.239.28.178][..443] + end: [...141] [ip4][..tcp] [..172.16.42.216][50798] -> [..54.239.28.178][..443] end: [...142] [ip4][..tcp] [..172.16.42.216][50799] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher idle: [...143] [ip4][..tcp] [..172.16.42.216][50800] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -951,7 +951,7 @@ idle: [...147] [ip4][..tcp] [..172.16.42.216][38757] -> [..54.239.28.178][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher guessed: [....90] [ip4][..tcp] [..172.16.42.216][49627] -> [..52.94.232.134][...80] [HTTP][AmazonAWS][Web][Acceptable][] - end: [....90] [ip4][..tcp] [..172.16.42.216][49627] -> [..52.94.232.134][...80] + end: [....90] [ip4][..tcp] [..172.16.42.216][49627] -> [..52.94.232.134][...80] end: [...145] [ip4][..tcp] [..172.16.42.216][44912] -> [...54.239.23.94][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] end: [....93] [ip4][..tcp] [..172.16.42.216][49630] -> [..52.94.232.134][...80] [HTTP.AmazonAlexa][AmazonAWS][VirtAssistant][Acceptable] RISK: Error Code @@ -960,7 +960,7 @@ end: [...105] [ip4][..tcp] [..172.16.42.216][40854] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher guessed: [...106] [ip4][..tcp] [..172.16.42.216][40855] -> [..54.239.29.253][..443] [TLS][AmazonAWS][Web][Safe] - end: [...106] [ip4][..tcp] [..172.16.42.216][40855] -> [..54.239.29.253][..443] + end: [...106] [ip4][..tcp] [..172.16.42.216][40855] -> [..54.239.29.253][..443] end: [...107] [ip4][..tcp] [..172.16.42.216][40856] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher end: [...117] [ip4][..tcp] [..172.16.42.216][40864] -> [..54.239.29.253][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -995,7 +995,7 @@ end: [....82] [ip4][..tcp] [..172.16.42.216][45705] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher guessed: [....84] [ip4][..tcp] [..172.16.42.216][45707] -> [..52.94.232.134][..443] [TLS][AmazonAWS][Web][Safe] - end: [....84] [ip4][..tcp] [..172.16.42.216][45707] -> [..52.94.232.134][..443] + end: [....84] [ip4][..tcp] [..172.16.42.216][45707] -> [..52.94.232.134][..443] end: [....86] [ip4][..tcp] [..172.16.42.216][45709] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: Weak TLS Cipher end: [....87] [ip4][..tcp] [..172.16.42.216][45710] -> [..52.94.232.134][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -1041,7 +1041,7 @@ idle: [....98] [ip4][..udp] [..172.16.42.216][41639] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] end: [...115] [ip4][..tcp] [..172.16.42.216][37551] -> [..54.239.24.180][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] guessed: [...116] [ip4][..tcp] [..172.16.42.216][37552] -> [..54.239.24.180][..443] [TLS][AmazonAWS][Web][Safe] - end: [...116] [ip4][..tcp] [..172.16.42.216][37552] -> [..54.239.24.180][..443] + end: [...116] [ip4][..tcp] [..172.16.42.216][37552] -> [..54.239.24.180][..443] end: [...156] [ip4][..tcp] [..172.16.42.216][58048] -> [..54.239.28.178][..443] [TLS][AmazonAWS][Web][Safe] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher end: [....65] [ip4][..tcp] [..172.16.42.216][41691] -> [..54.239.29.146][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] @@ -1051,7 +1051,7 @@ RISK: TLS (probably) Not Carrying HTTPS end: [....96] [ip4][..tcp] [..172.16.42.216][41820] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] guessed: [....97] [ip4][..tcp] [..172.16.42.216][41821] -> [...54.231.72.88][..443] [TLS][AmazonAWS][Web][Safe] - end: [....97] [ip4][..tcp] [..172.16.42.216][41821] -> [...54.231.72.88][..443] + end: [....97] [ip4][..tcp] [..172.16.42.216][41821] -> [...54.231.72.88][..443] end: [...102] [ip4][..tcp] [..172.16.42.216][41825] -> [...54.231.72.88][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] idle: [....35] [ip4][..udp] [..172.16.42.216][52077] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] idle: [....95] [ip4][..udp] [..172.16.42.216][35726] -> [....172.16.42.1][...53] [DNS.AmazonAWS][Unknown][Network][Acceptable] @@ -1064,20 +1064,20 @@ idle: [.....8] [ip4][..tcp] [..172.16.42.216][60246] -> [..172.217.9.142][...80] [HTTP.Google][Google][ConnCheck][Acceptable] guessed: [....31] [ip4][..tcp] [..172.16.42.216][40200] -> [.10.201.126.241][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....31] [ip4][..tcp] [..172.16.42.216][40200] -> [.10.201.126.241][.8080] + end: [....31] [ip4][..tcp] [..172.16.42.216][40200] -> [.10.201.126.241][.8080] guessed: [....33] [ip4][..tcp] [..172.16.42.216][40202] -> [.10.201.126.241][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....33] [ip4][..tcp] [..172.16.42.216][40202] -> [.10.201.126.241][.8080] + end: [....33] [ip4][..tcp] [..172.16.42.216][40202] -> [.10.201.126.241][.8080] idle: [....19] [ip4][..udp] [..172.16.42.216][.7358] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] guessed: [....83] [ip4][..tcp] [..172.16.42.216][40242] -> [.10.201.126.241][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....83] [ip4][..tcp] [..172.16.42.216][40242] -> [.10.201.126.241][.8080] + idle: [....83] [ip4][..tcp] [..172.16.42.216][40242] -> [.10.201.126.241][.8080] end: [....78] [ip4][..tcp] [..172.16.42.216][34053] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] guessed: [....79] [ip4][..tcp] [..172.16.42.216][34054] -> [..54.239.24.186][..443] [TLS][AmazonAWS][Web][Safe] - end: [....79] [ip4][..tcp] [..172.16.42.216][34054] -> [..54.239.24.186][..443] + end: [....79] [ip4][..tcp] [..172.16.42.216][34054] -> [..54.239.24.186][..443] end: [....94] [ip4][..tcp] [..172.16.42.216][34069] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] guessed: [...100] [ip4][..tcp] [..172.16.42.216][34073] -> [..54.239.24.186][..443] [TLS][AmazonAWS][Web][Safe] - end: [...100] [ip4][..tcp] [..172.16.42.216][34073] -> [..54.239.24.186][..443] + end: [...100] [ip4][..tcp] [..172.16.42.216][34073] -> [..54.239.24.186][..443] end: [...101] [ip4][..tcp] [..172.16.42.216][34074] -> [..54.239.24.186][..443] [TLS.AmazonAWS][AmazonAWS][Cloud][Acceptable] end: [....99] [ip4][..tcp] [..172.16.42.216][44001] -> [..176.32.101.52][..443] [TLS.Amazon][AmazonAWS][Web][Acceptable] RISK: TLS (probably) Not Carrying HTTPS @@ -1086,7 +1086,7 @@ idle: [....64] [ip4][..udp] [..172.16.42.216][60804] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] guessed: [....85] [ip4][..tcp] [..172.16.42.216][38434] -> [...192.168.11.1][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: TCP Connection Issues - end: [....85] [ip4][..tcp] [..172.16.42.216][38434] -> [...192.168.11.1][.8080] + end: [....85] [ip4][..tcp] [..172.16.42.216][38434] -> [...192.168.11.1][.8080] idle: [....11] [ip4][..tcp] [..172.16.42.216][42878] -> [173.194.223.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS idle: [....62] [ip4][..udp] [..172.16.42.216][44475] -> [....172.16.42.1][...53] [DNS.Amazon][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/alicloud.pcap.out b/test/results/flow-info/default/alicloud.pcap.out index fd5fca679..ec8804dba 100644 --- a/test/results/flow-info/default/alicloud.pcap.out +++ b/test/results/flow-info/default/alicloud.pcap.out @@ -1,72 +1,72 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][39018] -> [...8.209.104.12][.8999] + new: [.....1] [ip4][..tcp] [..192.168.2.100][39018] -> [...8.209.104.12][.8999] detected: [.....1] [ip4][..tcp] [..192.168.2.100][39018] -> [...8.209.104.12][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][41056] -> [...8.209.73.197][.8999] + new: [.....2] [ip4][..tcp] [..192.168.2.100][41056] -> [...8.209.73.197][.8999] detected: [.....2] [ip4][..tcp] [..192.168.2.100][41056] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.2.100][39018] -> [...8.209.104.12][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..192.168.2.100][38094] -> [..8.209.104.159][.8999] + new: [.....3] [ip4][..tcp] [..192.168.2.100][38094] -> [..8.209.104.159][.8999] detected: [.....3] [ip4][..tcp] [..192.168.2.100][38094] -> [..8.209.104.159][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....2] [ip4][..tcp] [..192.168.2.100][41056] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] - new: [.....4] [ip4][..tcp] [..192.168.2.100][45078] -> [..8.209.105.125][.8999] + new: [.....4] [ip4][..tcp] [..192.168.2.100][45078] -> [..8.209.105.125][.8999] detected: [.....4] [ip4][..tcp] [..192.168.2.100][45078] -> [..8.209.105.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] - new: [.....5] [ip4][..tcp] [..192.168.2.100][42430] -> [..8.209.104.130][.8999] + new: [.....5] [ip4][..tcp] [..192.168.2.100][42430] -> [..8.209.104.130][.8999] detected: [.....5] [ip4][..tcp] [..192.168.2.100][42430] -> [..8.209.104.130][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][55484] -> [..8.209.107.157][.8999] + new: [.....6] [ip4][..tcp] [..192.168.2.100][55484] -> [..8.209.107.157][.8999] detected: [.....6] [ip4][..tcp] [..192.168.2.100][55484] -> [..8.209.107.157][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....3] [ip4][..tcp] [..192.168.2.100][38094] -> [..8.209.104.159][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....5] [ip4][..tcp] [..192.168.2.100][42430] -> [..8.209.104.130][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....4] [ip4][..tcp] [..192.168.2.100][45078] -> [..8.209.105.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.2.100][40154] -> [..8.209.104.159][.8999] + new: [.....7] [ip4][..tcp] [..192.168.2.100][40154] -> [..8.209.104.159][.8999] detected: [.....7] [ip4][..tcp] [..192.168.2.100][40154] -> [..8.209.104.159][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....6] [ip4][..tcp] [..192.168.2.100][55484] -> [..8.209.107.157][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 105 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..tcp] [..192.168.2.100][42600] -> [..8.209.105.125][.8999] + new: [.....8] [ip4][..tcp] [..192.168.2.100][42600] -> [..8.209.105.125][.8999] detected: [.....8] [ip4][..tcp] [..192.168.2.100][42600] -> [..8.209.105.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....7] [ip4][..tcp] [..192.168.2.100][40154] -> [..8.209.104.159][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 120 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.2.100][51682] -> [...8.209.73.197][.8999] + new: [.....9] [ip4][..tcp] [..192.168.2.100][51682] -> [...8.209.73.197][.8999] detected: [.....9] [ip4][..tcp] [..192.168.2.100][51682] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....8] [ip4][..tcp] [..192.168.2.100][42600] -> [..8.209.105.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 135 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..tcp] [..192.168.2.100][52228] -> [...8.209.73.197][.8999] + new: [....10] [ip4][..tcp] [..192.168.2.100][52228] -> [...8.209.73.197][.8999] detected: [....10] [ip4][..tcp] [..192.168.2.100][52228] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 150 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....11] [ip4][..tcp] [..192.168.2.100][44388] -> [..8.209.107.125][.8999] + new: [....11] [ip4][..tcp] [..192.168.2.100][44388] -> [..8.209.107.125][.8999] detected: [....11] [ip4][..tcp] [..192.168.2.100][44388] -> [..8.209.107.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....10] [ip4][..tcp] [..192.168.2.100][52228] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [.....9] [ip4][..tcp] [..192.168.2.100][51682] -> [...8.209.73.197][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 165 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....12] [ip4][..tcp] [..192.168.2.100][37160] -> [..8.209.107.125][.8999] + new: [....12] [ip4][..tcp] [..192.168.2.100][37160] -> [..8.209.107.125][.8999] detected: [....12] [ip4][..tcp] [..192.168.2.100][37160] -> [..8.209.107.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....11] [ip4][..tcp] [..192.168.2.100][44388] -> [..8.209.107.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 180 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....13] [ip4][..tcp] [..192.168.2.100][45094] -> [...8.209.76.194][.8999] + new: [....13] [ip4][..tcp] [..192.168.2.100][45094] -> [...8.209.76.194][.8999] detected: [....13] [ip4][..tcp] [..192.168.2.100][45094] -> [...8.209.76.194][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....12] [ip4][..tcp] [..192.168.2.100][37160] -> [..8.209.107.125][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 195 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 13|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....14] [ip4][..tcp] [..192.168.2.100][57322] -> [..8.209.107.122][.8999] + new: [....14] [ip4][..tcp] [..192.168.2.100][57322] -> [..8.209.107.122][.8999] detected: [....14] [ip4][..tcp] [..192.168.2.100][57322] -> [..8.209.107.122][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....13] [ip4][..tcp] [..192.168.2.100][45094] -> [...8.209.76.194][.8999] [AliCloud][Alibaba][Cloud][Acceptable] DAEMON-EVENT: [Processed: 210 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 14|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....15] [ip4][..tcp] [..192.168.2.100][51774] -> [....8.209.77.36][.8999] + new: [....15] [ip4][..tcp] [..192.168.2.100][51774] -> [....8.209.77.36][.8999] detected: [....15] [ip4][..tcp] [..192.168.2.100][51774] -> [....8.209.77.36][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....14] [ip4][..tcp] [..192.168.2.100][57322] -> [..8.209.107.122][.8999] [AliCloud][Alibaba][Cloud][Acceptable] idle: [....15] [ip4][..tcp] [..192.168.2.100][51774] -> [....8.209.77.36][.8999] [AliCloud][Alibaba][Cloud][Acceptable] diff --git a/test/results/flow-info/default/among_us.pcap.out b/test/results/flow-info/default/among_us.pcap.out index c7fde65a8..88cdb83e1 100644 --- a/test/results/flow-info/default/among_us.pcap.out +++ b/test/results/flow-info/default/among_us.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.0.0.1][64260] -> [172.105.251.170][22023] + new: [.....1] [ip4][..udp] [.......10.0.0.1][64260] -> [172.105.251.170][22023] detected: [.....1] [ip4][..udp] [.......10.0.0.1][64260] -> [172.105.251.170][22023] [AmongUs][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [.......10.0.0.1][64260] -> [172.105.251.170][22023] [AmongUs][Unknown][Game][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/amqp.pcap.out b/test/results/flow-info/default/amqp.pcap.out index 197291127..75665e258 100644 --- a/test/results/flow-info/default/amqp.pcap.out +++ b/test/results/flow-info/default/amqp.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][44205] -> [......127.0.1.1][.5672] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [......127.0.0.1][44205] -> [......127.0.1.1][.5672] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [......127.0.0.1][44205] -> [......127.0.1.1][.5672] [AMQP][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..tcp] [......127.0.1.1][.5672] -> [......127.0.0.1][44204] [MIDSTREAM] - new: [.....3] [ip4][..tcp] [......127.0.0.1][44206] -> [......127.0.1.1][.5672] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [......127.0.1.1][.5672] -> [......127.0.0.1][44204] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [......127.0.0.1][44206] -> [......127.0.1.1][.5672] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [......127.0.0.1][44206] -> [......127.0.1.1][.5672] [AMQP][Unknown][RPC][Acceptable] detected: [.....2] [ip4][..tcp] [......127.0.1.1][.5672] -> [......127.0.0.1][44204] [AMQP][Unknown][RPC][Acceptable] analyse: [.....1] [ip4][..tcp] [......127.0.0.1][44205] -> [......127.0.1.1][.5672] [AMQP][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/android.pcap.out b/test/results/flow-info/default/android.pcap.out index 0b6746d2b..e9a77f4a6 100644 --- a/test/results/flow-info/default/android.pcap.out +++ b/test/results/flow-info/default/android.pcap.out @@ -1,62 +1,62 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...95.101.24.53][..443] -> [...192.168.2.17][50677] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...95.101.24.53][..443] -> [...192.168.2.17][50677] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...95.101.24.53][..443] -> [...192.168.2.17][50677] [TLS][Unknown][Web][Safe] - new: [.....2] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50584] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50584] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50584] [TLS][Apple][Web][Safe] detection-update: [.....2] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50584] [TLS][Apple][Web][Safe] RISK: Unidirectional Traffic - new: [.....3] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50580] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50580] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50580] [TLS][Apple][Web][Safe] detection-update: [.....3] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50580] [TLS][Apple][Web][Safe] RISK: Unidirectional Traffic - new: [.....4] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....4] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....4] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [.....5] [ip4][..tcp] [..17.248.185.10][..443] -> [...192.168.2.17][50702] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..17.248.185.10][..443] -> [...192.168.2.17][50702] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..17.248.185.10][..443] -> [...192.168.2.17][50702] [TLS][Apple][Web][Safe] - new: [.....6] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [.....6] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [.....6] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....7] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....7] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....7] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....8] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] + new: [.....8] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] detected: [.....8] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_spotify-connect._tcp.local] - new: [.....9] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] + new: [.....9] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] detected: [.....9] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_spotify-connect._tcp.local] - new: [....10] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] + new: [....10] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] detected: [....10] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....11] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] + new: [....11] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] detected: [....11] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] update: [.....4] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [.....6] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [.....7] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [....12] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff9f:f627] + new: [....12] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff9f:f627] detected: [....12] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff9f:f627] [ICMPV6][Unknown][Network][Acceptable] - new: [....13] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] + new: [....13] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] detected: [....13] [ip6][icmp6] [.....................................::] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....14] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.16][...68] + new: [....14] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.16][...68] detected: [....14] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.16][...68] [DHCP][Unknown][Network][Acceptable][] - new: [....15] [ip6][..udp] [..............fe80::4e6a:f6ff:fe9f:f627][..546] -> [..............................ff02::1:2][..547] + new: [....15] [ip6][..udp] [..............fe80::4e6a:f6ff:fe9f:f627][..546] -> [..............................ff02::1:2][..547] detected: [....15] [ip6][..udp] [..............fe80::4e6a:f6ff:fe9f:f627][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [....16] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [...............................ff02::16] + new: [....16] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [...............................ff02::16] detected: [....16] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....17] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [................................ff02::2] + new: [....17] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [................................ff02::2] detected: [....17] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [....18] [ip4][..udp] [...192.168.2.16][52953] -> [....192.168.2.1][...53] + new: [....18] [ip4][..udp] [...192.168.2.16][52953] -> [....192.168.2.1][...53] detected: [....18] [ip4][..udp] [...192.168.2.16][52953] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com] detection-update: [....18] [ip4][..udp] [...192.168.2.16][52953] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com] - new: [....19] [ip4][..tcp] [...192.168.2.16][58338] -> [..17.253.53.201][...80] + new: [....19] [ip4][..tcp] [...192.168.2.16][58338] -> [..17.253.53.201][...80] detected: [....19] [ip4][..tcp] [...192.168.2.16][58338] -> [..17.253.53.201][...80] [HTTP.Apple][Apple][ConnCheck][Safe][captive.apple.com] - new: [....20] [ip4][..udp] [...192.168.2.16][35825] -> [....192.168.2.1][...53] + new: [....20] [ip4][..udp] [...192.168.2.16][35825] -> [....192.168.2.1][...53] detected: [....20] [ip4][..udp] [...192.168.2.16][35825] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][time.android.com] detection-update: [....20] [ip4][..udp] [...192.168.2.16][35825] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][time.android.com] - new: [....21] [ip4][..udp] [...192.168.2.16][45863] -> [...216.239.35.8][..123] + new: [....21] [ip4][..udp] [...192.168.2.16][45863] -> [...216.239.35.8][..123] detected: [....21] [ip4][..udp] [...192.168.2.16][45863] -> [...216.239.35.8][..123] [NTP][Google][System][Acceptable] - new: [....22] [ip4][..udp] [...192.168.2.16][34540] -> [....192.168.2.1][...53] + new: [....22] [ip4][..udp] [...192.168.2.16][34540] -> [....192.168.2.1][...53] detected: [....22] [ip4][..udp] [...192.168.2.16][34540] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][clients1.google.com] detection-update: [....22] [ip4][..udp] [...192.168.2.16][34540] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][clients1.google.com] - new: [....23] [ip4][..tcp] [...192.168.2.16][32974] -> [.216.239.38.120][..443] - new: [....24] [ip4][..udp] [...192.168.2.16][54837] -> [....192.168.2.1][...53] + new: [....23] [ip4][..tcp] [...192.168.2.16][32974] -> [.216.239.38.120][..443] + new: [....24] [ip4][..udp] [...192.168.2.16][54837] -> [....192.168.2.1][...53] detected: [....24] [ip4][..udp] [...192.168.2.16][54837] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][play.googleapis.com] detected: [....23] [ip4][..tcp] [...192.168.2.16][32974] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][clients1.google.com] RISK: TLS (probably) Not Carrying HTTPS @@ -65,50 +65,50 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....23] [ip4][..tcp] [...192.168.2.16][32974] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][clients1.google.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....25] [ip4][..tcp] [...192.168.2.16][52486] -> [..172.217.20.74][..443] + new: [....25] [ip4][..tcp] [...192.168.2.16][52486] -> [..172.217.20.74][..443] detected: [....25] [ip4][..tcp] [...192.168.2.16][52486] -> [..172.217.20.74][..443] [TLS.GoogleServices][Google][Web][Acceptable][play.googleapis.com] - new: [....26] [ip4][..udp] [...192.168.2.16][47081] -> [....192.168.2.1][...53] + new: [....26] [ip4][..udp] [...192.168.2.16][47081] -> [....192.168.2.1][...53] detected: [....26] [ip4][..udp] [...192.168.2.16][47081] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.gstatic.com] detection-update: [....25] [ip4][..tcp] [...192.168.2.16][52486] -> [..172.217.20.74][..443] [TLS.GoogleServices][Google][Web][Acceptable][play.googleapis.com] detection-update: [....25] [ip4][..tcp] [...192.168.2.16][52486] -> [..172.217.20.74][..443] [TLS.GoogleServices][Google][Web][Acceptable][play.googleapis.com] detection-update: [....26] [ip4][..udp] [...192.168.2.16][47081] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][connectivitycheck.gstatic.com] - new: [....27] [ip4][..tcp] [...192.168.2.16][36888] -> [...172.217.18.3][..443] - new: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] + new: [....27] [ip4][..tcp] [...192.168.2.16][36888] -> [...172.217.18.3][..443] + new: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] detected: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable][connectivitycheck.gstatic.com] - new: [....29] [ip4][..udp] [...192.168.2.16][51430] -> [....192.168.2.1][...53] + new: [....29] [ip4][..udp] [...192.168.2.16][51430] -> [....192.168.2.1][...53] detected: [....29] [ip4][..udp] [...192.168.2.16][51430] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][app-measurement.com] detection-update: [....29] [ip4][..udp] [...192.168.2.16][51430] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][app-measurement.com] detection-update: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable][connectivitycheck.gstatic.com] detection-update: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable][connectivitycheck.gstatic.com] detected: [....27] [ip4][..tcp] [...192.168.2.16][36888] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable][connectivitycheck.gstatic.com] detection-update: [....27] [ip4][..tcp] [...192.168.2.16][36888] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable][connectivitycheck.gstatic.com] - new: [....30] [ip4][..udp] [...192.168.2.16][39008] -> [....192.168.2.1][...53] + new: [....30] [ip4][..udp] [...192.168.2.16][39008] -> [....192.168.2.1][...53] detected: [....30] [ip4][..udp] [...192.168.2.16][39008] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][mtalk.google.com] detection-update: [....30] [ip4][..udp] [...192.168.2.16][39008] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][mtalk.google.com] - new: [....31] [ip4][..tcp] [...192.168.2.16][50384] -> [172.217.168.206][..443] + new: [....31] [ip4][..tcp] [...192.168.2.16][50384] -> [172.217.168.206][..443] detected: [....31] [ip4][..tcp] [...192.168.2.16][50384] -> [172.217.168.206][..443] [TLS.Google][Google][Web][Acceptable][app-measurement.com] - new: [....32] [ip4][..tcp] [...192.168.2.16][49510] -> [.216.239.38.120][.5228] + new: [....32] [ip4][..tcp] [...192.168.2.16][49510] -> [.216.239.38.120][.5228] detection-update: [....31] [ip4][..tcp] [...192.168.2.16][50384] -> [172.217.168.206][..443] [TLS.Google][Google][Web][Acceptable][app-measurement.com] detection-update: [....31] [ip4][..tcp] [...192.168.2.16][50384] -> [172.217.168.206][..443] [TLS.Google][Google][Web][Acceptable][app-measurement.com] - new: [....33] [ip4][..udp] [...192.168.2.16][36613] -> [....192.168.2.1][...53] + new: [....33] [ip4][..udp] [...192.168.2.16][36613] -> [....192.168.2.1][...53] detected: [....33] [ip4][..udp] [...192.168.2.16][36613] -> [....192.168.2.1][...53] [DNS.PlayStore][Unknown][Network][Safe][android.clients.google.com] detection-update: [....33] [ip4][..udp] [...192.168.2.16][36613] -> [....192.168.2.1][...53] [DNS.PlayStore][Unknown][Network][Safe][android.clients.google.com] - new: [....34] [ip4][..tcp] [...192.168.2.16][32986] -> [.216.239.38.120][..443] - new: [....35] [ip4][..udp] [...192.168.2.16][32412] -> [....192.168.2.1][...53] + new: [....34] [ip4][..tcp] [...192.168.2.16][32986] -> [.216.239.38.120][..443] + new: [....35] [ip4][..udp] [...192.168.2.16][32412] -> [....192.168.2.1][...53] detected: [....35] [ip4][..udp] [...192.168.2.16][32412] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][check.googlezip.net] - new: [....36] [ip4][..udp] [...192.168.2.16][.7660] -> [....192.168.2.1][...53] + new: [....36] [ip4][..udp] [...192.168.2.16][.7660] -> [....192.168.2.1][...53] detected: [....36] [ip4][..udp] [...192.168.2.16][.7660] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][datasaver.googleapis.com] - new: [....37] [ip4][..tcp] [...192.168.2.16][32988] -> [.216.239.38.120][..443] - new: [....38] [ip4][..tcp] [...192.168.2.16][32990] -> [.216.239.38.120][..443] + new: [....37] [ip4][..tcp] [...192.168.2.16][32988] -> [.216.239.38.120][..443] + new: [....38] [ip4][..tcp] [...192.168.2.16][32990] -> [.216.239.38.120][..443] detection-update: [....35] [ip4][..udp] [...192.168.2.16][32412] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][check.googlezip.net] - new: [....39] [ip4][..tcp] [...192.168.2.16][36834] -> [.173.194.79.114][...80] + new: [....39] [ip4][..tcp] [...192.168.2.16][36834] -> [.173.194.79.114][...80] detection-update: [....36] [ip4][..udp] [...192.168.2.16][.7660] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][datasaver.googleapis.com] - new: [....40] [ip4][..tcp] [...192.168.2.16][51928] -> [.172.217.21.202][..443] + new: [....40] [ip4][..tcp] [...192.168.2.16][51928] -> [.172.217.21.202][..443] detected: [....38] [ip4][..tcp] [...192.168.2.16][32990] -> [.216.239.38.120][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....34] [ip4][..tcp] [...192.168.2.16][32986] -> [.216.239.38.120][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....41] [ip4][..udp] [...192.168.2.16][40580] -> [....192.168.2.1][...53] + new: [....41] [ip4][..udp] [...192.168.2.16][40580] -> [....192.168.2.1][...53] detected: [....41] [ip4][..udp] [...192.168.2.16][40580] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [....41] [ip4][..udp] [...192.168.2.16][40580] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detected: [....39] [ip4][..tcp] [...192.168.2.16][36834] -> [.173.194.79.114][...80] [HTTP.DataSaver][Google][Web][Fun][check.googlezip.net] @@ -117,7 +117,7 @@ detection-update: [....34] [ip4][..tcp] [...192.168.2.16][32986] -> [.216.239.38.120][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....40] [ip4][..tcp] [...192.168.2.16][51928] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun][datasaver.googleapis.com] - new: [....42] [ip4][..tcp] [...192.168.2.16][32996] -> [.216.239.38.120][..443] + new: [....42] [ip4][..tcp] [...192.168.2.16][32996] -> [.216.239.38.120][..443] detection-update: [....40] [ip4][..tcp] [...192.168.2.16][51928] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun][datasaver.googleapis.com] detected: [....42] [ip4][..tcp] [...192.168.2.16][32996] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] detected: [....37] [ip4][..tcp] [...192.168.2.16][32988] -> [.216.239.38.120][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] @@ -126,49 +126,49 @@ detection-update: [....42] [ip4][..tcp] [...192.168.2.16][32996] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] detection-update: [....37] [ip4][..tcp] [...192.168.2.16][32988] -> [.216.239.38.120][..443] [TLS.PlayStore][Google][SoftwareUpdate][Safe][android.clients.google.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....43] [ip4][..udp] [...192.168.2.16][46359] -> [....192.168.2.1][...53] + new: [....43] [ip4][..udp] [...192.168.2.16][46359] -> [....192.168.2.1][...53] detected: [....43] [ip4][..udp] [...192.168.2.16][46359] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][accounts.google.com] detection-update: [....43] [ip4][..udp] [...192.168.2.16][46359] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][accounts.google.com] - new: [....44] [ip4][..tcp] [...192.168.2.16][32998] -> [.216.239.38.120][..443] + new: [....44] [ip4][..tcp] [...192.168.2.16][32998] -> [.216.239.38.120][..443] detected: [....44] [ip4][..tcp] [...192.168.2.16][32998] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] - new: [....45] [ip4][..udp] [...192.168.2.16][35689] -> [....192.168.2.1][...53] + new: [....45] [ip4][..udp] [...192.168.2.16][35689] -> [....192.168.2.1][...53] detected: [....45] [ip4][..udp] [...192.168.2.16][35689] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][semanticlocation-pa.googleapis.com] detection-update: [....44] [ip4][..tcp] [...192.168.2.16][32998] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] detection-update: [....45] [ip4][..udp] [...192.168.2.16][35689] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][semanticlocation-pa.googleapis.com] - new: [....46] [ip4][..udp] [...192.168.2.16][22850] -> [....192.168.2.1][...53] + new: [....46] [ip4][..udp] [...192.168.2.16][22850] -> [....192.168.2.1][...53] detected: [....46] [ip4][..udp] [...192.168.2.16][22850] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] detection-update: [....46] [ip4][..udp] [...192.168.2.16][22850] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] - new: [....47] [ip4][..tcp] [...192.168.2.16][43634] -> [..172.217.20.76][..443] - new: [....48] [ip4][..udp] [...192.168.2.16][58892] -> [....192.168.2.1][...53] + new: [....47] [ip4][..tcp] [...192.168.2.16][43634] -> [..172.217.20.76][..443] + new: [....48] [ip4][..udp] [...192.168.2.16][58892] -> [....192.168.2.1][...53] detected: [....48] [ip4][..udp] [...192.168.2.16][58892] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][accounts.google.com] detection-update: [....48] [ip4][..udp] [...192.168.2.16][58892] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][accounts.google.com] detected: [....47] [ip4][..tcp] [...192.168.2.16][43634] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun][proxy.googlezip.net] - new: [....49] [ip4][..tcp] [...192.168.2.16][33002] -> [.216.239.38.120][..443] + new: [....49] [ip4][..tcp] [...192.168.2.16][33002] -> [.216.239.38.120][..443] detection-update: [....47] [ip4][..tcp] [...192.168.2.16][43634] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun][proxy.googlezip.net] detected: [....49] [ip4][..tcp] [...192.168.2.16][33002] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] - new: [....50] [ip4][..udp] [...192.168.2.16][33240] -> [....192.168.2.1][...53] + new: [....50] [ip4][..udp] [...192.168.2.16][33240] -> [....192.168.2.1][...53] detected: [....50] [ip4][..udp] [...192.168.2.16][33240] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][check.googlezip.net] detection-update: [....50] [ip4][..udp] [...192.168.2.16][33240] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][check.googlezip.net] detection-update: [....49] [ip4][..tcp] [...192.168.2.16][33002] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] - new: [....51] [ip4][..tcp] [...192.168.2.16][52514] -> [..172.217.20.74][..443] - new: [....52] [ip4][..tcp] [...192.168.2.16][36848] -> [.173.194.79.114][...80] - new: [....53] [ip4][..tcp] [...192.168.2.16][36850] -> [.173.194.79.114][...80] - new: [....54] [ip4][..udp] [...192.168.2.16][18379] -> [....192.168.2.1][...53] + new: [....51] [ip4][..tcp] [...192.168.2.16][52514] -> [..172.217.20.74][..443] + new: [....52] [ip4][..tcp] [...192.168.2.16][36848] -> [.173.194.79.114][...80] + new: [....53] [ip4][..tcp] [...192.168.2.16][36850] -> [.173.194.79.114][...80] + new: [....54] [ip4][..udp] [...192.168.2.16][18379] -> [....192.168.2.1][...53] detected: [....54] [ip4][..udp] [...192.168.2.16][18379] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][datasaver.googleapis.com] detection-update: [....54] [ip4][..udp] [...192.168.2.16][18379] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][datasaver.googleapis.com] - new: [....55] [ip4][..tcp] [...192.168.2.16][51944] -> [.172.217.21.202][..443] + new: [....55] [ip4][..tcp] [...192.168.2.16][51944] -> [.172.217.21.202][..443] detected: [....52] [ip4][..tcp] [...192.168.2.16][36848] -> [.173.194.79.114][...80] [HTTP.DataSaver][Google][Web][Fun][check.googlezip.net] - new: [....56] [ip4][..udp] [...192.168.2.16][10677] -> [....192.168.2.1][...53] + new: [....56] [ip4][..udp] [...192.168.2.16][10677] -> [....192.168.2.1][...53] detected: [....56] [ip4][..udp] [...192.168.2.16][10677] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] detection-update: [....56] [ip4][..udp] [...192.168.2.16][10677] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] - new: [....57] [ip4][..udp] [...192.168.2.16][32832] -> [....192.168.2.1][...53] + new: [....57] [ip4][..udp] [...192.168.2.16][32832] -> [....192.168.2.1][...53] detected: [....57] [ip4][..udp] [...192.168.2.16][32832] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [....57] [ip4][..udp] [...192.168.2.16][32832] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] - new: [....58] [ip4][..tcp] [...192.168.2.16][43646] -> [..172.217.20.76][..443] - new: [....59] [ip4][..tcp] [...192.168.2.16][33014] -> [.216.239.38.120][..443] + new: [....58] [ip4][..tcp] [...192.168.2.16][43646] -> [..172.217.20.76][..443] + new: [....59] [ip4][..tcp] [...192.168.2.16][33014] -> [.216.239.38.120][..443] detected: [....55] [ip4][..tcp] [...192.168.2.16][51944] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun][datasaver.googleapis.com] detected: [....59] [ip4][..tcp] [...192.168.2.16][33014] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] - new: [....60] [ip4][..udp] [...192.168.2.16][39760] -> [....192.168.2.1][...53] + new: [....60] [ip4][..udp] [...192.168.2.16][39760] -> [....192.168.2.1][...53] detected: [....60] [ip4][..udp] [...192.168.2.16][39760] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][android.googleapis.com] detected: [....58] [ip4][..tcp] [...192.168.2.16][43646] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun][proxy.googlezip.net] analyse: [....42] [ip4][..tcp] [...192.168.2.16][32996] -> [.216.239.38.120][..443] [TLS.Google][Google][Web][Acceptable] @@ -185,14 +185,14 @@ detection-update: [....55] [ip4][..tcp] [...192.168.2.16][51944] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun][datasaver.googleapis.com] detection-update: [....60] [ip4][..udp] [...192.168.2.16][39760] -> [....192.168.2.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][android.googleapis.com] detection-update: [....58] [ip4][..tcp] [...192.168.2.16][43646] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun][proxy.googlezip.net] - new: [....61] [ip4][..tcp] [...192.168.2.16][44374] -> [..172.217.22.10][..443] + new: [....61] [ip4][..tcp] [...192.168.2.16][44374] -> [..172.217.22.10][..443] detected: [....61] [ip4][..tcp] [...192.168.2.16][44374] -> [..172.217.22.10][..443] [TLS.GoogleServices][Google][Web][Acceptable][android.googleapis.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....51] [ip4][..tcp] [...192.168.2.16][52514] -> [..172.217.20.74][..443] [TLS.GoogleServices][Google][Web][Acceptable][semanticlocation-pa.googleapis.com] - new: [....62] [ip4][..udp] [...192.168.2.16][56312] -> [....192.168.2.1][...53] + new: [....62] [ip4][..udp] [...192.168.2.16][56312] -> [....192.168.2.1][...53] detected: [....62] [ip4][..udp] [...192.168.2.16][56312] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] detection-update: [....62] [ip4][..udp] [...192.168.2.16][56312] -> [....192.168.2.1][...53] [DNS.DataSaver][Unknown][Network][Fun][proxy.googlezip.net] - new: [....63] [ip4][..tcp] [...192.168.2.16][43652] -> [..172.217.20.76][..443] + new: [....63] [ip4][..tcp] [...192.168.2.16][43652] -> [..172.217.20.76][..443] detection-update: [....61] [ip4][..tcp] [...192.168.2.16][44374] -> [..172.217.22.10][..443] [TLS.GoogleServices][Google][Web][Acceptable][android.googleapis.com] RISK: TLS (probably) Not Carrying HTTPS end: [.....3] [ip4][..tcp] [..17.248.176.75][..443] -> [...192.168.2.17][50580] [TLS][Apple][Web][Safe] @@ -244,7 +244,7 @@ end: [....39] [ip4][..tcp] [...192.168.2.16][36834] -> [.173.194.79.114][...80] [HTTP.DataSaver][Google][Web][Fun] idle: [....52] [ip4][..tcp] [...192.168.2.16][36848] -> [.173.194.79.114][...80] [HTTP.DataSaver][Google][Web][Fun] guessed: [....53] [ip4][..tcp] [...192.168.2.16][36850] -> [.173.194.79.114][...80] [HTTP][Google][Web][Acceptable][] - idle: [....53] [ip4][..tcp] [...192.168.2.16][36850] -> [.173.194.79.114][...80] + idle: [....53] [ip4][..tcp] [...192.168.2.16][36850] -> [.173.194.79.114][...80] idle: [.....7] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] idle: [....27] [ip4][..tcp] [...192.168.2.16][36888] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable] idle: [....28] [ip4][..tcp] [...192.168.2.16][36890] -> [...172.217.18.3][..443] [TLS.Google][Google][ConnCheck][Acceptable] @@ -256,14 +256,14 @@ idle: [.....1] [ip4][..tcp] [...95.101.24.53][..443] -> [...192.168.2.17][50677] [TLS][Unknown][Web][Safe] guessed: [....32] [ip4][..tcp] [...192.168.2.16][49510] -> [.216.239.38.120][.5228] [Google][Google][Web][Acceptable] RISK: Unidirectional Traffic - idle: [....32] [ip4][..tcp] [...192.168.2.16][49510] -> [.216.239.38.120][.5228] + idle: [....32] [ip4][..tcp] [...192.168.2.16][49510] -> [.216.239.38.120][.5228] idle: [....17] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] idle: [....16] [ip6][icmp6] [..............fe80::4e6a:f6ff:fe9f:f627] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] end: [....47] [ip4][..tcp] [...192.168.2.16][43634] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun] end: [....58] [ip4][..tcp] [...192.168.2.16][43646] -> [..172.217.20.76][..443] [TLS.DataSaver][Google][Web][Fun] guessed: [....63] [ip4][..tcp] [...192.168.2.16][43652] -> [..172.217.20.76][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic - idle: [....63] [ip4][..tcp] [...192.168.2.16][43652] -> [..172.217.20.76][..443] + idle: [....63] [ip4][..tcp] [...192.168.2.16][43652] -> [..172.217.20.76][..443] idle: [....43] [ip4][..udp] [...192.168.2.16][46359] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable] idle: [....40] [ip4][..tcp] [...192.168.2.16][51928] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun] idle: [....55] [ip4][..tcp] [...192.168.2.16][51944] -> [.172.217.21.202][..443] [TLS.DataSaver][Google][Web][Fun] diff --git a/test/results/flow-info/default/anyconnect-vpn.pcap.out b/test/results/flow-info/default/anyconnect-vpn.pcap.out index 496f22342..4e7fbbc0c 100644 --- a/test/results/flow-info/default/anyconnect-vpn.pcap.out +++ b/test/results/flow-info/default/anyconnect-vpn.pcap.out @@ -1,42 +1,42 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.0.0.227][56885] -> [...184.25.56.53][...80] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [.....10.0.0.227][56916] -> [.....10.0.0.151][.8009] - new: [.....3] [ip4][..tcp] [.....10.0.0.227][56320] -> [.....10.0.0.149][.8009] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.....10.0.0.227][56885] -> [...184.25.56.53][...80] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.....10.0.0.227][56916] -> [.....10.0.0.151][.8009] + new: [.....3] [ip4][..tcp] [.....10.0.0.227][56320] -> [.....10.0.0.149][.8009] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [.....10.0.0.227][56320] -> [.....10.0.0.149][.8009] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][....2] [.......10.0.0.1] -> [......224.0.0.1] + new: [.....4] [ip4][....2] [.......10.0.0.1] -> [......224.0.0.1] detected: [.....4] [ip4][....2] [.......10.0.0.1] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [.....5] [ip6][icmp6] [..............fe80::2e7e:81ff:feb0:4aa1] -> [................................ff02::1] + new: [.....5] [ip6][icmp6] [..............fe80::2e7e:81ff:feb0:4aa1] -> [................................ff02::1] detected: [.....5] [ip6][icmp6] [..............fe80::2e7e:81ff:feb0:4aa1] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] - new: [.....6] [ip4][....2] [.....10.0.0.149] -> [....224.0.0.251] + new: [.....6] [ip4][....2] [.....10.0.0.149] -> [....224.0.0.251] detected: [.....6] [ip4][....2] [.....10.0.0.149] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [.....7] [ip4][....2] [.....10.0.0.149] -> [...239.255.3.22] + new: [.....7] [ip4][....2] [.....10.0.0.149] -> [...239.255.3.22] detected: [.....7] [ip4][....2] [.....10.0.0.149] -> [...239.255.3.22] [IGMP][Unknown][Network][Acceptable] - new: [.....8] [ip4][....2] [.....10.0.0.149] -> [239.255.255.250] + new: [.....8] [ip4][....2] [.....10.0.0.149] -> [239.255.255.250] detected: [.....8] [ip4][....2] [.....10.0.0.149] -> [239.255.255.250] [IGMP][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.76.76][...53] + new: [.....9] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.76.76][...53] detected: [.....9] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] detection-update: [.....9] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] - new: [....10] [ip4][..udp] [.....10.0.0.227][61387] -> [....75.75.75.75][...53] + new: [....10] [ip4][..udp] [.....10.0.0.227][61387] -> [....75.75.75.75][...53] detected: [....10] [ip4][..udp] [.....10.0.0.227][61387] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] detection-update: [....10] [ip4][..udp] [.....10.0.0.227][61387] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] - new: [....11] [ip4][..udp] [.....10.0.0.227][62322] -> [....75.75.76.76][...53] + new: [....11] [ip4][..udp] [.....10.0.0.227][62322] -> [....75.75.76.76][...53] detected: [....11] [ip4][..udp] [.....10.0.0.227][62322] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] detection-update: [....11] [ip4][..udp] [.....10.0.0.227][62322] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][vco.pandion.viasat.com] - new: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] + new: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] detected: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Weak TLS Cipher, Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Weak TLS Cipher, Missing SNI TLS Extn, ALPN/SNI Mismatch - new: [....13] [ip4][..tcp] [.....10.0.0.227][56915] -> [..52.37.243.173][..443] [MIDSTREAM] + new: [....13] [ip4][..tcp] [.....10.0.0.227][56915] -> [..52.37.243.173][..443] [MIDSTREAM] detected: [....13] [ip4][..tcp] [.....10.0.0.227][56915] -> [..52.37.243.173][..443] [TLS][AmazonAWS][Web][Safe] - new: [....14] [ip4][..tcp] [.....10.0.0.227][56914] -> [..52.37.243.173][..443] [MIDSTREAM] + new: [....14] [ip4][..tcp] [.....10.0.0.227][56914] -> [..52.37.243.173][..443] [MIDSTREAM] detected: [....14] [ip4][..tcp] [.....10.0.0.227][56914] -> [..52.37.243.173][..443] [TLS][AmazonAWS][Web][Safe] - new: [....15] [ip4][..tcp] [.....10.0.0.227][56919] -> [....8.37.102.91][..443] + new: [....15] [ip4][..tcp] [.....10.0.0.227][56919] -> [....8.37.102.91][..443] detected: [....15] [ip4][..tcp] [.....10.0.0.227][56919] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [....15] [ip4][..tcp] [.....10.0.0.227][56919] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] @@ -55,54 +55,54 @@ [ENTROPIES...: 4.3,5.1,4.8,5.5,4.8,7.3,4.8,7.1,7.2,4.9,4.8,7.4,5.9,4.8,4.8,6.8,7.2,7.5,4.7,4.8,7.6,4.7,6.2,4.8,7.8,4.9,7.3,7.7,5.8,4.9,4.8,4.8] detection-update: [....15] [ip4][..tcp] [.....10.0.0.227][56919] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Weak TLS Cipher, Missing SNI TLS Extn, ALPN/SNI Mismatch - new: [....16] [ip4][..udp] [.....10.0.0.227][63107] -> [....75.75.76.76][...53] + new: [....16] [ip4][..udp] [.....10.0.0.227][63107] -> [....75.75.76.76][...53] detected: [....16] [ip4][..udp] [.....10.0.0.227][63107] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][local] detection-update: [....16] [ip4][..udp] [.....10.0.0.227][63107] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][local] RISK: Error Code - new: [....17] [ip4][.icmp] [.....10.0.0.227] -> [....75.75.76.76] + new: [....17] [ip4][.icmp] [.....10.0.0.227] -> [....75.75.76.76] detected: [....17] [ip4][.icmp] [.....10.0.0.227] -> [....75.75.76.76] [ICMP][Unknown][Network][Acceptable] - new: [....18] [ip4][..udp] [.....10.0.0.213][.5353] -> [....224.0.0.251][.5353] + new: [....18] [ip4][..udp] [.....10.0.0.213][.5353] -> [....224.0.0.251][.5353] detected: [....18] [ip4][..udp] [.....10.0.0.213][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [....19] [ip6][..udp] [...............fe80::408:3e45:3abc:1552][.5353] -> [...............................ff02::fb][.5353] + new: [....19] [ip6][..udp] [...............fe80::408:3e45:3abc:1552][.5353] -> [...............................ff02::fb][.5353] detected: [....19] [ip6][..udp] [...............fe80::408:3e45:3abc:1552][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [....20] [ip4][....2] [.....10.0.0.213] -> [......224.0.0.2] + new: [....20] [ip4][....2] [.....10.0.0.213] -> [......224.0.0.2] detected: [....20] [ip4][....2] [.....10.0.0.213] -> [......224.0.0.2] [IGMP][Unknown][Network][Acceptable] - new: [....21] [ip4][....2] [.....10.0.0.213] -> [....224.0.0.251] + new: [....21] [ip4][....2] [.....10.0.0.213] -> [....224.0.0.251] detected: [....21] [ip4][....2] [.....10.0.0.213] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [....22] [ip4][..udp] [.....10.0.0.227][.5353] -> [.....10.0.0.213][.5353] + new: [....22] [ip4][..udp] [.....10.0.0.227][.5353] -> [.....10.0.0.213][.5353] detected: [....22] [ip4][..udp] [.....10.0.0.227][.5353] -> [.....10.0.0.213][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [....23] [ip6][icmp6] [...............fe80::408:3e45:3abc:1552] -> [...............................ff02::16] + new: [....23] [ip6][icmp6] [...............fe80::408:3e45:3abc:1552] -> [...............................ff02::16] detected: [....23] [ip6][icmp6] [...............fe80::408:3e45:3abc:1552] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....24] [ip4][..tcp] [.....10.0.0.227][56917] -> [...184.25.56.77][...80] [MIDSTREAM] - new: [....25] [ip4][..tcp] [.....10.0.0.227][56884] -> [...184.25.56.77][...80] [MIDSTREAM] - new: [....26] [ip4][..udp] [.....10.0.0.227][54851] -> [....75.75.76.76][...53] + new: [....24] [ip4][..tcp] [.....10.0.0.227][56917] -> [...184.25.56.77][...80] [MIDSTREAM] + new: [....25] [ip4][..tcp] [.....10.0.0.227][56884] -> [...184.25.56.77][...80] [MIDSTREAM] + new: [....26] [ip4][..udp] [.....10.0.0.227][54851] -> [....75.75.76.76][...53] detected: [....26] [ip4][..udp] [.....10.0.0.227][54851] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][print.viasat.com] detection-update: [....26] [ip4][..udp] [.....10.0.0.227][54851] -> [....75.75.76.76][...53] [DNS][Unknown][Network][Acceptable][print.viasat.com] RISK: Error Code - new: [....27] [ip4][..udp] [.....10.0.0.227][58155] -> [....75.75.76.76][...53] + new: [....27] [ip4][..udp] [.....10.0.0.227][58155] -> [....75.75.76.76][...53] detected: [....27] [ip4][..udp] [.....10.0.0.227][58155] -> [....75.75.76.76][...53] [DNS.Slack][Unknown][Network][Acceptable][slack.com] detection-update: [....27] [ip4][..udp] [.....10.0.0.227][58155] -> [....75.75.76.76][...53] [DNS.Slack][Unknown][Network][Acceptable][slack.com] - new: [....28] [ip4][..tcp] [.....10.0.0.227][56920] -> [...99.86.34.156][..443] + new: [....28] [ip4][..tcp] [.....10.0.0.227][56920] -> [...99.86.34.156][..443] detected: [....28] [ip4][..tcp] [.....10.0.0.227][56920] -> [...99.86.34.156][..443] [TLS.Slack][AmazonAWS][Collaborative][Acceptable][slack.com] detection-update: [....28] [ip4][..tcp] [.....10.0.0.227][56920] -> [...99.86.34.156][..443] [TLS.Slack][AmazonAWS][Collaborative][Acceptable][slack.com] - new: [....29] [ip4][..tcp] [.....10.0.0.227][56910] -> [...35.201.124.9][..443] [MIDSTREAM] + new: [....29] [ip4][..tcp] [.....10.0.0.227][56910] -> [...35.201.124.9][..443] [MIDSTREAM] detected: [....29] [ip4][..tcp] [.....10.0.0.227][56910] -> [...35.201.124.9][..443] [TLS][GoogleCloud][Web][Safe] - new: [....30] [ip4][..tcp] [.....10.0.0.227][56921] -> [....8.37.96.194][.4287] + new: [....30] [ip4][..tcp] [.....10.0.0.227][56921] -> [....8.37.96.194][.4287] detected: [....30] [ip4][..tcp] [.....10.0.0.227][56921] -> [....8.37.96.194][.4287] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [....30] [ip4][..tcp] [.....10.0.0.227][56921] -> [....8.37.96.194][.4287] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Self-signed Cert, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, TLS Cert About To Expire - new: [....31] [ip4][..udp] [.....10.0.0.227][64972] -> [....75.75.75.75][...53] + new: [....31] [ip4][..udp] [.....10.0.0.227][64972] -> [....75.75.75.75][...53] detected: [....31] [ip4][..udp] [.....10.0.0.227][64972] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lb._dns-sd._udp.0.128.28.172.in-addr.arpa] - new: [....32] [ip4][..udp] [.....10.0.0.227][61613] -> [....75.75.75.75][...53] + new: [....32] [ip4][..udp] [.....10.0.0.227][61613] -> [....75.75.75.75][...53] detected: [....32] [ip4][..udp] [.....10.0.0.227][61613] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lb._dns-sd._udp.0.0.0.10.in-addr.arpa] detection-update: [....31] [ip4][..udp] [.....10.0.0.227][64972] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lb._dns-sd._udp.0.128.28.172.in-addr.arpa] RISK: Error Code detection-update: [....32] [ip4][..udp] [.....10.0.0.227][61613] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lb._dns-sd._udp.0.0.0.10.in-addr.arpa] RISK: Error Code - new: [....33] [ip4][..udp] [.....10.0.0.227][57261] -> [....75.75.75.75][...53] + new: [....33] [ip4][..udp] [.....10.0.0.227][57261] -> [....75.75.75.75][...53] detected: [....33] [ip4][..udp] [.....10.0.0.227][57261] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][vcacrashplan01.hq.corp.viasat.com] - new: [....34] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.75.75][...53] + new: [....34] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.75.75][...53] detected: [....34] [ip4][..udp] [.....10.0.0.227][52879] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][vcacrashplan01.hq.corp.viasat.com] detection-update: [....33] [ip4][..udp] [.....10.0.0.227][57261] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][vcacrashplan01.hq.corp.viasat.com] RISK: Error Code @@ -110,9 +110,9 @@ RISK: Error Code detection-update: [....18] [ip4][..udp] [.....10.0.0.213][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] detection-update: [....19] [ip6][..udp] [...............fe80::408:3e45:3abc:1552][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....35] [ip4][..udp] [.....10.0.0.227][59222] -> [....75.75.75.75][...53] + new: [....35] [ip4][..udp] [.....10.0.0.227][59222] -> [....75.75.75.75][...53] detected: [....35] [ip4][..udp] [.....10.0.0.227][59222] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lp-rkerur-osx.hsd1.ca.comcast.net] - new: [....36] [ip4][..udp] [.....10.0.0.227][57017] -> [....75.75.75.75][...53] + new: [....36] [ip4][..udp] [.....10.0.0.227][57017] -> [....75.75.75.75][...53] detected: [....36] [ip4][..udp] [.....10.0.0.227][57017] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lp-rkerur-osx.hsd1.ca.comcast.net] detection-update: [....35] [ip4][..udp] [.....10.0.0.227][59222] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][lp-rkerur-osx.hsd1.ca.comcast.net] RISK: Error Code @@ -128,8 +128,8 @@ [IATS(ms)....: 28.5,28.6,0.3,35.2,11.6,46.5,4.2,33.1,3.0,31.9,1.5,30.5,1.7,30.8,254.9,281.1,5.1,31.3,315.0,342.2,26.3,53.5,25.8,25.8,4.8,30.5,2.7,28.4,358.2,384.8,2.1] [PKTLENS.....: 64,64,52,200,52,1360,52,1247,52,103,52,496,52,463,52,363,52,167,52,777,52,1420,52,1160,52,114,52,122,52,110,52,110] [ENTROPIES...: 4.3,5.0,4.8,5.4,5.1,7.4,4.9,7.6,4.9,5.9,4.8,7.5,5.0,7.5,4.9,7.3,5.0,6.5,5.0,7.7,5.0,7.9,4.9,7.8,4.9,6.1,5.0,6.2,4.9,6.0,5.1,6.1] - new: [....37] [ip4][..tcp] [.....10.0.0.227][56881] -> [.162.222.43.153][..443] [MIDSTREAM] - new: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] + new: [....37] [ip4][..tcp] [.....10.0.0.227][56881] -> [.162.222.43.153][..443] [MIDSTREAM] + new: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] detected: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] @@ -148,28 +148,28 @@ [ENTROPIES...: 4.2,5.0,4.7,5.5,4.7,7.3,4.7,7.1,7.2,4.8,4.8,7.4,5.9,4.8,4.8,7.4,6.2,4.8,7.8,4.9,7.9,6.9,7.9,6.9,7.9,6.7,7.8,6.8,4.8,4.8,4.8,4.8] detection-update: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe][] RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn - new: [....39] [ip4][..tcp] [.....10.0.0.227][56865] -> [.....10.0.0.149][.8008] [MIDSTREAM] - new: [....40] [ip4][..tcp] [.....10.0.0.227][56866] -> [.....10.0.0.151][.8060] [MIDSTREAM] - new: [....41] [ip4][..udp] [.....10.0.0.227][57253] -> [....75.75.75.75][...53] + new: [....39] [ip4][..tcp] [.....10.0.0.227][56865] -> [.....10.0.0.149][.8008] [MIDSTREAM] + new: [....40] [ip4][..tcp] [.....10.0.0.227][56866] -> [.....10.0.0.151][.8060] [MIDSTREAM] + new: [....41] [ip4][..udp] [.....10.0.0.227][57253] -> [....75.75.75.75][...53] detected: [....41] [ip4][..udp] [.....10.0.0.227][57253] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][mozilla.org] - new: [....42] [ip4][..udp] [.....10.0.0.227][62427] -> [....75.75.75.75][...53] + new: [....42] [ip4][..udp] [.....10.0.0.227][62427] -> [....75.75.75.75][...53] detected: [....42] [ip4][..udp] [.....10.0.0.227][62427] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][detectportal.firefox.com] detected: [....25] [ip4][..tcp] [.....10.0.0.227][56884] -> [...184.25.56.77][...80] [HTTP][Unknown][ConnCheck][Acceptable][detectportal.firefox.com] detected: [....24] [ip4][..tcp] [.....10.0.0.227][56917] -> [...184.25.56.77][...80] [HTTP][Unknown][ConnCheck][Acceptable][detectportal.firefox.com] detection-update: [....41] [ip4][..udp] [.....10.0.0.227][57253] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][mozilla.org] detection-update: [....42] [ip4][..udp] [.....10.0.0.227][62427] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][detectportal.firefox.com] - new: [....43] [ip4][..tcp] [.....10.0.0.227][56879] -> [..52.10.115.210][..443] [MIDSTREAM] + new: [....43] [ip4][..tcp] [.....10.0.0.227][56879] -> [..52.10.115.210][..443] [MIDSTREAM] detected: [....43] [ip4][..tcp] [.....10.0.0.227][56879] -> [..52.10.115.210][..443] [TLS][AmazonAWS][Web][Safe] - new: [....44] [ip4][..tcp] [.....10.0.0.227][56886] -> [..17.57.144.116][.5223] [MIDSTREAM] - new: [....45] [ip4][..udp] [.....10.0.0.227][60341] -> [....75.75.75.75][...53] + new: [....44] [ip4][..tcp] [.....10.0.0.227][56886] -> [..17.57.144.116][.5223] [MIDSTREAM] + new: [....45] [ip4][..udp] [.....10.0.0.227][60341] -> [....75.75.75.75][...53] detected: [....45] [ip4][..udp] [.....10.0.0.227][60341] -> [....75.75.75.75][...53] [DNS.Apple][Unknown][Network][Safe][www.apple.com] - new: [....46] [ip4][..udp] [.....10.0.0.227][51060] -> [....75.75.75.75][...53] + new: [....46] [ip4][..udp] [.....10.0.0.227][51060] -> [....75.75.75.75][...53] detected: [....46] [ip4][..udp] [.....10.0.0.227][51060] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable][1-courier.push.apple.com] - new: [....47] [ip4][..udp] [.....10.0.0.227][59582] -> [....75.75.75.75][...53] + new: [....47] [ip4][..udp] [.....10.0.0.227][59582] -> [....75.75.75.75][...53] detected: [....47] [ip4][..udp] [.....10.0.0.227][59582] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable][1-courier.sandbox.push.apple.com] - new: [....48] [ip4][..udp] [.....10.0.0.227][64193] -> [....75.75.75.75][...53] + new: [....48] [ip4][..udp] [.....10.0.0.227][64193] -> [....75.75.75.75][...53] detected: [....48] [ip4][..udp] [.....10.0.0.227][64193] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable][24-courier.push.apple.com] - new: [....49] [ip4][..udp] [.....10.0.0.227][51990] -> [....75.75.75.75][...53] + new: [....49] [ip4][..udp] [.....10.0.0.227][51990] -> [....75.75.75.75][...53] detected: [....49] [ip4][..udp] [.....10.0.0.227][51990] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][mail.viasat.com] detection-update: [....45] [ip4][..udp] [.....10.0.0.227][60341] -> [....75.75.75.75][...53] [DNS.Apple][Unknown][Network][Safe][www.apple.com] detection-update: [....47] [ip4][..udp] [.....10.0.0.227][59582] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable][1-courier.sandbox.push.apple.com] @@ -177,62 +177,62 @@ detected: [....44] [ip4][..tcp] [.....10.0.0.227][56886] -> [..17.57.144.116][.5223] [TLS][Apple][Web][Safe] RISK: Known Proto on Non Std Port detection-update: [....48] [ip4][..udp] [.....10.0.0.227][64193] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable][24-courier.push.apple.com] - new: [....50] [ip4][..udp] [.....10.0.0.227][49781] -> [....75.75.75.75][...53] + new: [....50] [ip4][..udp] [.....10.0.0.227][49781] -> [....75.75.75.75][...53] detected: [....50] [ip4][..udp] [.....10.0.0.227][49781] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][apple.com] - new: [....51] [ip4][..tcp] [.....10.0.0.227][56871] -> [...8.37.103.196][..443] [MIDSTREAM] + new: [....51] [ip4][..tcp] [.....10.0.0.227][56871] -> [...8.37.103.196][..443] [MIDSTREAM] detection-update: [....50] [ip4][..udp] [.....10.0.0.227][49781] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][apple.com] detection-update: [....49] [ip4][..udp] [.....10.0.0.227][51990] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable][mail.viasat.com] - new: [....52] [ip4][..udp] [.....10.0.0.227][58074] -> [....75.75.75.75][...53] + new: [....52] [ip4][..udp] [.....10.0.0.227][58074] -> [....75.75.75.75][...53] detected: [....52] [ip4][..udp] [.....10.0.0.227][58074] -> [....75.75.75.75][...53] [DNS.Outlook][Unknown][Network][Acceptable][www.outlook.com] detection-update: [....52] [ip4][..udp] [.....10.0.0.227][58074] -> [....75.75.75.75][...53] [DNS.Outlook][Unknown][Network][Acceptable][www.outlook.com] - new: [....53] [ip4][..tcp] [.....10.0.0.227][56874] -> [.74.125.197.188][..443] [MIDSTREAM] - new: [....54] [ip4][..udp] [.....10.0.0.227][61328] -> [239.255.255.250][.1900] + new: [....53] [ip4][..tcp] [.....10.0.0.227][56874] -> [.74.125.197.188][..443] [MIDSTREAM] + new: [....54] [ip4][..udp] [.....10.0.0.227][61328] -> [239.255.255.250][.1900] detected: [....54] [ip4][..udp] [.....10.0.0.227][61328] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....55] [ip4][..udp] [.....10.0.0.149][38616] -> [.....10.0.0.227][61328] + new: [....55] [ip4][..udp] [.....10.0.0.149][38616] -> [.....10.0.0.227][61328] detected: [....55] [ip4][..udp] [.....10.0.0.149][38616] -> [.....10.0.0.227][61328] [SSDP][Unknown][System][Acceptable][] - new: [....56] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][61328] + new: [....56] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][61328] detected: [....56] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][61328] [SSDP][Unknown][System][Acceptable][] - new: [....57] [ip4][..udp] [.....10.0.0.227][57547] -> [239.255.255.250][.1900] + new: [....57] [ip4][..udp] [.....10.0.0.227][57547] -> [239.255.255.250][.1900] detected: [....57] [ip4][..udp] [.....10.0.0.227][57547] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....58] [ip4][..udp] [.....10.0.0.227][54107] -> [....8.37.102.91][..443] + new: [....58] [ip4][..udp] [.....10.0.0.227][54107] -> [....8.37.102.91][..443] detected: [....58] [ip4][..udp] [.....10.0.0.227][54107] -> [....8.37.102.91][..443] [DTLS][Unknown][Web][Safe] RISK: Obsolete TLS (v1.1 or older) - new: [....59] [ip4][..udp] [.....10.0.0.149][50081] -> [.....10.0.0.227][57547] + new: [....59] [ip4][..udp] [.....10.0.0.149][50081] -> [.....10.0.0.227][57547] detected: [....59] [ip4][..udp] [.....10.0.0.149][50081] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable][] detection-update: [....58] [ip4][..udp] [.....10.0.0.227][54107] -> [....8.37.102.91][..443] [DTLS][Unknown][Web][Safe] RISK: Obsolete TLS (v1.1 or older) - new: [....60] [ip4][..udp] [.....10.0.0.227][52595] -> [.......10.0.0.1][..192] - new: [....61] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][57547] + new: [....60] [ip4][..udp] [.....10.0.0.227][52595] -> [.......10.0.0.1][..192] + new: [....61] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][57547] detected: [....61] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable][] - new: [....62] [ip4][..tcp] [.....10.0.0.227][56954] -> [.....10.0.0.149][.8008] - new: [....63] [ip4][..tcp] [.....10.0.0.227][56955] -> [.....10.0.0.151][.8060] + new: [....62] [ip4][..tcp] [.....10.0.0.227][56954] -> [.....10.0.0.149][.8008] + new: [....63] [ip4][..tcp] [.....10.0.0.227][56955] -> [.....10.0.0.151][.8060] detected: [....62] [ip4][..tcp] [.....10.0.0.227][56954] -> [.....10.0.0.149][.8008] [HTTP][Unknown][Web][Acceptable][10.0.0.149] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI detected: [....63] [ip4][..tcp] [.....10.0.0.227][56955] -> [.....10.0.0.151][.8060] [HTTP][Unknown][Web][Acceptable][10.0.0.151] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....64] [ip4][..udp] [.....10.0.0.149][49816] -> [.....10.0.0.227][57547] + new: [....64] [ip4][..udp] [.....10.0.0.149][49816] -> [.....10.0.0.227][57547] detected: [....64] [ip4][..udp] [.....10.0.0.149][49816] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable][] - new: [....65] [ip4][..udp] [.....10.0.0.149][48166] -> [.....10.0.0.227][57547] + new: [....65] [ip4][..udp] [.....10.0.0.149][48166] -> [.....10.0.0.227][57547] detected: [....65] [ip4][..udp] [.....10.0.0.149][48166] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable][] - new: [....66] [ip4][..udp] [.....10.0.0.149][51382] -> [.....10.0.0.227][57547] + new: [....66] [ip4][..udp] [.....10.0.0.149][51382] -> [.....10.0.0.227][57547] detected: [....66] [ip4][..udp] [.....10.0.0.149][51382] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable][] - new: [....67] [ip4][..udp] [.....10.0.0.227][..137] -> [.....10.0.0.255][..137] + new: [....67] [ip4][..udp] [.....10.0.0.227][..137] -> [.....10.0.0.255][..137] detected: [....67] [ip4][..udp] [.....10.0.0.227][..137] -> [.....10.0.0.255][..137] [NetBIOS][Unknown][System][Acceptable][lp-rkerur-osx] update: [.....5] [ip6][icmp6] [..............fe80::2e7e:81ff:feb0:4aa1] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] update: [....17] [ip4][.icmp] [.....10.0.0.227] -> [....75.75.76.76] [ICMP][Unknown][Network][Acceptable] update: [....23] [ip6][icmp6] [...............fe80::408:3e45:3abc:1552] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....68] [ip4][..udp] [.....10.0.0.149][.5353] -> [....224.0.0.251][.5353] + new: [....68] [ip4][..udp] [.....10.0.0.149][.5353] -> [....224.0.0.251][.5353] detected: [....68] [ip4][..udp] [.....10.0.0.149][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlezone._tcp.local] detection-update: [....68] [ip4][..udp] [.....10.0.0.149][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][79d88e83-725c-b71b-bad0-5862d5b22386._googlezone._tcp.local] RISK: Susp DNS Traffic detection-update: [....68] [ip4][..udp] [.....10.0.0.149][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlezone._tcp.local] RISK: Susp DNS Traffic - new: [....69] [ip4][.icmp] [.......10.0.0.1] -> [......224.0.0.1] + new: [....69] [ip4][.icmp] [.......10.0.0.1] -> [......224.0.0.1] detected: [....69] [ip4][.icmp] [.......10.0.0.1] -> [......224.0.0.1] [ICMP][Unknown][Network][Acceptable] idle: [....57] [ip4][..udp] [.....10.0.0.227][57547] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....25] [ip4][..tcp] [.....10.0.0.227][56884] -> [...184.25.56.77][...80] [HTTP][Unknown][ConnCheck][Acceptable] guessed: [.....1] [ip4][..tcp] [.....10.0.0.227][56885] -> [...184.25.56.53][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....1] [ip4][..tcp] [.....10.0.0.227][56885] -> [...184.25.56.53][...80] + end: [.....1] [ip4][..tcp] [.....10.0.0.227][56885] -> [...184.25.56.53][...80] idle: [....61] [ip4][..udp] [.....10.0.0.151][.1900] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable] idle: [....24] [ip4][..tcp] [.....10.0.0.227][56917] -> [...184.25.56.77][...80] [HTTP][Unknown][ConnCheck][Acceptable] idle: [....69] [ip4][.icmp] [.......10.0.0.1] -> [......224.0.0.1] [ICMP][Unknown][Network][Acceptable] @@ -283,7 +283,7 @@ idle: [....47] [ip4][..udp] [.....10.0.0.227][59582] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable] idle: [....59] [ip4][..udp] [.....10.0.0.149][50081] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable] guessed: [....51] [ip4][..tcp] [.....10.0.0.227][56871] -> [...8.37.103.196][..443] [TLS][Unknown][Web][Safe] - end: [....51] [ip4][..tcp] [.....10.0.0.227][56871] -> [...8.37.103.196][..443] + end: [....51] [ip4][..tcp] [.....10.0.0.227][56871] -> [...8.37.103.196][..443] idle: [....65] [ip4][..udp] [.....10.0.0.149][48166] -> [.....10.0.0.227][57547] [SSDP][Unknown][System][Acceptable] end: [....12] [ip4][..tcp] [.....10.0.0.227][56918] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe] RISK: Weak TLS Cipher, Missing SNI TLS Extn, ALPN/SNI Mismatch @@ -292,17 +292,17 @@ idle: [....38] [ip4][..tcp] [.....10.0.0.227][56929] -> [....8.37.102.91][..443] [TLS][Unknown][Web][Safe] RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn guessed: [....53] [ip4][..tcp] [.....10.0.0.227][56874] -> [.74.125.197.188][..443] [TLS][Google][Web][Safe] - end: [....53] [ip4][..tcp] [.....10.0.0.227][56874] -> [.74.125.197.188][..443] + end: [....53] [ip4][..tcp] [.....10.0.0.227][56874] -> [.74.125.197.188][..443] idle: [....14] [ip4][..tcp] [.....10.0.0.227][56914] -> [..52.37.243.173][..443] [TLS][AmazonAWS][Web][Safe] idle: [....13] [ip4][..tcp] [.....10.0.0.227][56915] -> [..52.37.243.173][..443] [TLS][AmazonAWS][Web][Safe] guessed: [....39] [ip4][..tcp] [.....10.0.0.227][56865] -> [.....10.0.0.149][.8008] [CiscoVPN][Unknown][VPN][Acceptable] - end: [....39] [ip4][..tcp] [.....10.0.0.227][56865] -> [.....10.0.0.149][.8008] + end: [....39] [ip4][..tcp] [.....10.0.0.227][56865] -> [.....10.0.0.149][.8008] guessed: [.....2] [ip4][..tcp] [.....10.0.0.227][56916] -> [.....10.0.0.151][.8009] [AJP][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [.....2] [ip4][..tcp] [.....10.0.0.227][56916] -> [.....10.0.0.151][.8009] + idle: [.....2] [ip4][..tcp] [.....10.0.0.227][56916] -> [.....10.0.0.151][.8009] not-detected: [....40] [ip4][..tcp] [.....10.0.0.227][56866] -> [.....10.0.0.151][.8060] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - end: [....40] [ip4][..tcp] [.....10.0.0.227][56866] -> [.....10.0.0.151][.8060] + end: [....40] [ip4][..tcp] [.....10.0.0.227][56866] -> [.....10.0.0.151][.8060] idle: [....62] [ip4][..tcp] [.....10.0.0.227][56954] -> [.....10.0.0.149][.8008] [HTTP][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [....19] [ip6][..udp] [...............fe80::408:3e45:3abc:1552][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] @@ -311,13 +311,13 @@ RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI not-detected: [....60] [ip4][..udp] [.....10.0.0.227][52595] -> [.......10.0.0.1][..192] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....60] [ip4][..udp] [.....10.0.0.227][52595] -> [.......10.0.0.1][..192] + idle: [....60] [ip4][..udp] [.....10.0.0.227][52595] -> [.......10.0.0.1][..192] idle: [....48] [ip4][..udp] [.....10.0.0.227][64193] -> [....75.75.75.75][...53] [DNS.ApplePush][Unknown][Network][Acceptable] idle: [....52] [ip4][..udp] [.....10.0.0.227][58074] -> [....75.75.75.75][...53] [DNS.Outlook][Unknown][Network][Acceptable] end: [....28] [ip4][..tcp] [.....10.0.0.227][56920] -> [...99.86.34.156][..443] [TLS.Slack][AmazonAWS][Collaborative][Acceptable] idle: [....55] [ip4][..udp] [.....10.0.0.149][38616] -> [.....10.0.0.227][61328] [SSDP][Unknown][System][Acceptable] guessed: [....37] [ip4][..tcp] [.....10.0.0.227][56881] -> [.162.222.43.153][..443] [TLS][Unknown][Web][Safe] - idle: [....37] [ip4][..tcp] [.....10.0.0.227][56881] -> [.162.222.43.153][..443] + idle: [....37] [ip4][..tcp] [.....10.0.0.227][56881] -> [.162.222.43.153][..443] idle: [....49] [ip4][..udp] [.....10.0.0.227][51990] -> [....75.75.75.75][...53] [DNS][Unknown][Network][Acceptable] idle: [....27] [ip4][..udp] [.....10.0.0.227][58155] -> [....75.75.76.76][...53] [DNS.Slack][Unknown][Network][Acceptable] idle: [....54] [ip4][..udp] [.....10.0.0.227][61328] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/anydesk.pcapng.out b/test/results/flow-info/default/anydesk.pcapng.out index e627f562e..e7604637b 100644 --- a/test/results/flow-info/default/anydesk.pcapng.out +++ b/test/results/flow-info/default/anydesk.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [192.168.149.129][36351] -> [..51.83.239.144][...80] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [192.168.149.129][36351] -> [..51.83.239.144][...80] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [192.168.149.129][36351] -> [..51.83.239.144][...80] [TLS][AnyDesk][Web][Safe] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..tcp] [192.168.149.129][43535] -> [..51.83.238.219][...80] + new: [.....2] [ip4][..tcp] [192.168.149.129][43535] -> [..51.83.238.219][...80] detected: [.....2] [ip4][..tcp] [192.168.149.129][43535] -> [..51.83.238.219][...80] [TLS][AnyDesk][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....2] [ip4][..tcp] [192.168.149.129][43535] -> [..51.83.238.219][...80] [TLS][AnyDesk][Web][Safe][] @@ -25,22 +25,22 @@ RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, Desktop/File Sharing DAEMON-EVENT: [Processed: 61 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 3|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.1.187][59511] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [..192.168.1.187][59511] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [..192.168.1.187][59511] -> [....192.168.1.1][...53] [DNS.AnyDesk][Unknown][Network][Acceptable][relay-3185a847.net.anydesk.com] detection-update: [.....3] [ip4][..udp] [..192.168.1.187][59511] -> [....192.168.1.1][...53] [DNS.AnyDesk][Unknown][Network][Acceptable][relay-3185a847.net.anydesk.com] - new: [.....4] [ip4][..udp] [..192.168.1.187][55376] -> [....192.168.1.1][...53] + new: [.....4] [ip4][..udp] [..192.168.1.187][55376] -> [....192.168.1.1][...53] detected: [.....4] [ip4][..udp] [..192.168.1.187][55376] -> [....192.168.1.1][...53] [DNS.AnyDesk][Unknown][Network][Acceptable][relay-9b6827f2.net.anydesk.com] detection-update: [.....4] [ip4][..udp] [..192.168.1.187][55376] -> [....192.168.1.1][...53] [DNS.AnyDesk][Unknown][Network][Acceptable][relay-9b6827f2.net.anydesk.com] idle: [.....1] [ip4][..tcp] [192.168.149.129][36351] -> [..51.83.239.144][...80] [TLS][AnyDesk][Web][Safe] RISK: Known Proto on Non Std Port idle: [.....2] [ip4][..tcp] [192.168.149.129][43535] -> [..51.83.238.219][...80] [TLS.AnyDesk][AnyDesk][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, Desktop/File Sharing - new: [.....5] [ip4][..tcp] [..192.168.1.187][54164] -> [..192.168.1.178][.7070] + new: [.....5] [ip4][..tcp] [..192.168.1.187][54164] -> [..192.168.1.178][.7070] detected: [.....5] [ip4][..tcp] [..192.168.1.187][54164] -> [..192.168.1.178][.7070] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....5] [ip4][..tcp] [..192.168.1.187][54164] -> [..192.168.1.178][.7070] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, Desktop/File Sharing - new: [.....6] [ip4][..tcp] [..192.168.1.178][52039] -> [..192.168.1.187][.7070] + new: [.....6] [ip4][..tcp] [..192.168.1.178][52039] -> [..192.168.1.187][.7070] detected: [.....6] [ip4][..tcp] [..192.168.1.178][52039] -> [..192.168.1.187][.7070] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....6] [ip4][..tcp] [..192.168.1.178][52039] -> [..192.168.1.187][.7070] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] @@ -57,7 +57,7 @@ [ENTROPIES...: 4.5,4.7,4.7,5.4,4.2,4.3,7.7,6.2,4.7,7.7,4.3,7.8,5.6,4.6,5.7,4.2,5.5,5.6,4.3,5.6,4.7,8.0,4.2,4.3,4.2,5.7,4.3,6.5,4.6,6.0,4.3,6.2] DAEMON-EVENT: [Processed: 120 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 7|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] RISK: Missing SNI TLS Extn, Desktop/File Sharing, Uncommon TLS ALPN detection-update: [.....7] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] diff --git a/test/results/flow-info/default/avast.pcap.out b/test/results/flow-info/default/avast.pcap.out index a61d7bd4a..844a51f38 100644 --- a/test/results/flow-info/default/avast.pcap.out +++ b/test/results/flow-info/default/avast.pcap.out @@ -1,19 +1,19 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][64357] -> [.....5.62.54.29][...80] + new: [.....1] [ip4][..tcp] [..192.168.2.100][64357] -> [.....5.62.54.29][...80] detected: [.....1] [ip4][..tcp] [..192.168.2.100][64357] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 13 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][64701] -> [.....5.62.53.53][...80] + new: [.....2] [ip4][..tcp] [..192.168.2.100][64701] -> [.....5.62.53.53][...80] detected: [.....2] [ip4][..tcp] [..192.168.2.100][64701] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 28 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..192.168.2.100][64903] -> [.....5.62.53.53][...80] + new: [.....3] [ip4][..tcp] [..192.168.2.100][64903] -> [.....5.62.53.53][...80] detected: [.....3] [ip4][..tcp] [..192.168.2.100][64903] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] idle: [.....1] [ip4][..tcp] [..192.168.2.100][64357] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 39 pkts][ZLib][compressions: 0|diff: 0 / 0] @@ -22,7 +22,7 @@ DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.2.100][58030] -> [.....5.62.54.89][...80] + new: [.....4] [ip4][..tcp] [..192.168.2.100][58030] -> [.....5.62.54.89][...80] detected: [.....4] [ip4][..tcp] [..192.168.2.100][58030] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] idle: [.....2] [ip4][..tcp] [..192.168.2.100][64701] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] idle: [.....3] [ip4][..tcp] [..192.168.2.100][64903] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] @@ -30,7 +30,7 @@ DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][49758] -> [.....5.62.53.53][...80] + new: [.....5] [ip4][..tcp] [..192.168.2.100][49758] -> [.....5.62.53.53][...80] detected: [.....5] [ip4][..tcp] [..192.168.2.100][49758] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] idle: [.....4] [ip4][..tcp] [..192.168.2.100][58030] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 69 pkts][ZLib][compressions: 0|diff: 0 / 0] @@ -39,31 +39,31 @@ DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][49532] -> [.....5.62.54.89][...80] + new: [.....6] [ip4][..tcp] [..192.168.2.100][49532] -> [.....5.62.54.89][...80] detected: [.....6] [ip4][..tcp] [..192.168.2.100][49532] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] idle: [.....5] [ip4][..tcp] [..192.168.2.100][49758] -> [.....5.62.53.53][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 88 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.2.100][58412] -> [.....5.62.54.29][...80] + new: [.....7] [ip4][..tcp] [..192.168.2.100][58412] -> [.....5.62.54.29][...80] detected: [.....7] [ip4][..tcp] [..192.168.2.100][58412] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] idle: [.....6] [ip4][..tcp] [..192.168.2.100][49532] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] - new: [.....8] [ip4][..tcp] [..192.168.2.100][54405] -> [.....5.62.54.89][...80] + new: [.....8] [ip4][..tcp] [..192.168.2.100][54405] -> [.....5.62.54.89][...80] detected: [.....8] [ip4][..tcp] [..192.168.2.100][54405] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 109 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] end: [.....7] [ip4][..tcp] [..192.168.2.100][58412] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 112 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.2.100][57727] -> [.....5.62.54.29][...80] + new: [.....9] [ip4][..tcp] [..192.168.2.100][57727] -> [.....5.62.54.29][...80] detected: [.....9] [ip4][..tcp] [..192.168.2.100][57727] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] end: [.....8] [ip4][..tcp] [..192.168.2.100][54405] -> [.....5.62.54.89][...80] [AVAST][AVAST][Network][Safe] DAEMON-EVENT: [Processed: 123 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] DAEMON-EVENT: [Processed: 127 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..tcp] [..192.168.2.100][62741] -> [....5.62.53.131][...80] + new: [....10] [ip4][..tcp] [..192.168.2.100][62741] -> [....5.62.53.131][...80] detected: [....10] [ip4][..tcp] [..192.168.2.100][62741] -> [....5.62.53.131][...80] [AVAST][AVAST][Network][Safe] idle: [.....9] [ip4][..tcp] [..192.168.2.100][57727] -> [.....5.62.54.29][...80] [AVAST][AVAST][Network][Safe] idle: [....10] [ip4][..tcp] [..192.168.2.100][62741] -> [....5.62.53.131][...80] [AVAST][AVAST][Network][Safe] diff --git a/test/results/flow-info/default/avast_securedns.pcapng.out b/test/results/flow-info/default/avast_securedns.pcapng.out index e5e016a7d..77b80d806 100644 --- a/test/results/flow-info/default/avast_securedns.pcapng.out +++ b/test/results/flow-info/default/avast_securedns.pcapng.out @@ -1,93 +1,93 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][57970] -> [.181.214.35.149][..443] + new: [.....1] [ip4][..udp] [..192.168.2.100][57970] -> [.181.214.35.149][..443] detected: [.....1] [ip4][..udp] [..192.168.2.100][57970] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][61201] -> [.181.214.35.149][..443] + new: [.....2] [ip4][..udp] [..192.168.2.100][61201] -> [.181.214.35.149][..443] detected: [.....2] [ip4][..udp] [..192.168.2.100][61201] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [.....3] [ip4][..udp] [..192.168.2.100][60835] -> [.181.214.35.149][..443] + new: [.....3] [ip4][..udp] [..192.168.2.100][60835] -> [.181.214.35.149][..443] detected: [.....3] [ip4][..udp] [..192.168.2.100][60835] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....1] [ip4][..udp] [..192.168.2.100][57970] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [.....4] [ip4][..udp] [..192.168.2.100][62775] -> [.181.214.35.149][..443] + new: [.....4] [ip4][..udp] [..192.168.2.100][62775] -> [.181.214.35.149][..443] detected: [.....4] [ip4][..udp] [..192.168.2.100][62775] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [..192.168.2.100][56581] -> [.181.214.35.149][..443] + new: [.....5] [ip4][..udp] [..192.168.2.100][56581] -> [.181.214.35.149][..443] detected: [.....5] [ip4][..udp] [..192.168.2.100][56581] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [.....6] [ip4][..udp] [..192.168.2.100][56765] -> [.181.214.35.149][..443] + new: [.....6] [ip4][..udp] [..192.168.2.100][56765] -> [.181.214.35.149][..443] detected: [.....6] [ip4][..udp] [..192.168.2.100][56765] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....2] [ip4][..udp] [..192.168.2.100][61201] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....4] [ip4][..udp] [..192.168.2.100][62775] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....3] [ip4][..udp] [..192.168.2.100][60835] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..udp] [..192.168.2.100][50581] -> [.181.214.35.149][..443] + new: [.....7] [ip4][..udp] [..192.168.2.100][50581] -> [.181.214.35.149][..443] detected: [.....7] [ip4][..udp] [..192.168.2.100][50581] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [.....8] [ip4][..udp] [..192.168.2.100][61107] -> [.181.214.35.149][..443] + new: [.....8] [ip4][..udp] [..192.168.2.100][61107] -> [.181.214.35.149][..443] detected: [.....8] [ip4][..udp] [..192.168.2.100][61107] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....5] [ip4][..udp] [..192.168.2.100][56581] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....6] [ip4][..udp] [..192.168.2.100][56765] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..udp] [..192.168.2.100][64954] -> [.181.214.35.149][..443] + new: [.....9] [ip4][..udp] [..192.168.2.100][64954] -> [.181.214.35.149][..443] detected: [.....9] [ip4][..udp] [..192.168.2.100][64954] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....10] [ip4][..udp] [..192.168.2.100][59621] -> [.181.214.35.149][..443] + new: [....10] [ip4][..udp] [..192.168.2.100][59621] -> [.181.214.35.149][..443] detected: [....10] [ip4][..udp] [..192.168.2.100][59621] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....7] [ip4][..udp] [..192.168.2.100][50581] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....8] [ip4][..udp] [..192.168.2.100][61107] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....11] [ip4][..udp] [..192.168.2.100][52485] -> [.181.214.35.149][..443] + new: [....11] [ip4][..udp] [..192.168.2.100][52485] -> [.181.214.35.149][..443] detected: [....11] [ip4][..udp] [..192.168.2.100][52485] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....12] [ip4][..udp] [..192.168.2.100][54938] -> [.181.214.35.149][..443] + new: [....12] [ip4][..udp] [..192.168.2.100][54938] -> [.181.214.35.149][..443] detected: [....12] [ip4][..udp] [..192.168.2.100][54938] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....10] [ip4][..udp] [..192.168.2.100][59621] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [.....9] [ip4][..udp] [..192.168.2.100][64954] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 24 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....13] [ip4][..udp] [..192.168.2.100][56839] -> [.181.214.35.149][..443] + new: [....13] [ip4][..udp] [..192.168.2.100][56839] -> [.181.214.35.149][..443] detected: [....13] [ip4][..udp] [..192.168.2.100][56839] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....11] [ip4][..udp] [..192.168.2.100][52485] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....12] [ip4][..udp] [..192.168.2.100][54938] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 26 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 13|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....14] [ip4][..udp] [..192.168.2.100][58155] -> [.181.214.35.149][..443] + new: [....14] [ip4][..udp] [..192.168.2.100][58155] -> [.181.214.35.149][..443] detected: [....14] [ip4][..udp] [..192.168.2.100][58155] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....15] [ip4][..udp] [..192.168.2.100][64487] -> [.181.214.35.149][..443] + new: [....15] [ip4][..udp] [..192.168.2.100][64487] -> [.181.214.35.149][..443] detected: [....15] [ip4][..udp] [..192.168.2.100][64487] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....16] [ip4][..udp] [..192.168.2.100][49704] -> [.181.214.35.149][..443] + new: [....16] [ip4][..udp] [..192.168.2.100][49704] -> [.181.214.35.149][..443] detected: [....16] [ip4][..udp] [..192.168.2.100][49704] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....13] [ip4][..udp] [..192.168.2.100][56839] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....17] [ip4][..udp] [..192.168.2.100][55311] -> [.181.214.35.149][..443] + new: [....17] [ip4][..udp] [..192.168.2.100][55311] -> [.181.214.35.149][..443] detected: [....17] [ip4][..udp] [..192.168.2.100][55311] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....18] [ip4][..udp] [..192.168.2.100][56111] -> [.181.214.35.149][..443] + new: [....18] [ip4][..udp] [..192.168.2.100][56111] -> [.181.214.35.149][..443] detected: [....18] [ip4][..udp] [..192.168.2.100][56111] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 36 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 18|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] + new: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] detected: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] + new: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] detected: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....17] [ip4][..udp] [..192.168.2.100][55311] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....16] [ip4][..udp] [..192.168.2.100][49704] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....14] [ip4][..udp] [..192.168.2.100][58155] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....18] [ip4][..udp] [..192.168.2.100][56111] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....15] [ip4][..udp] [..192.168.2.100][64487] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....21] [ip4][..udp] [..192.168.2.100][63776] -> [.181.214.35.149][..443] + new: [....21] [ip4][..udp] [..192.168.2.100][63776] -> [.181.214.35.149][..443] detected: [....21] [ip4][..udp] [..192.168.2.100][63776] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....22] [ip4][..udp] [..192.168.2.100][50008] -> [.181.214.35.149][..443] + new: [....22] [ip4][..udp] [..192.168.2.100][50008] -> [.181.214.35.149][..443] detected: [....22] [ip4][..udp] [..192.168.2.100][50008] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....23] [ip4][..udp] [..192.168.2.100][49737] -> [.181.214.35.149][..443] + new: [....23] [ip4][..udp] [..192.168.2.100][49737] -> [.181.214.35.149][..443] detected: [....23] [ip4][..udp] [..192.168.2.100][49737] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....24] [ip4][..udp] [..192.168.2.100][51887] -> [.181.214.35.149][..443] + new: [....24] [ip4][..udp] [..192.168.2.100][51887] -> [.181.214.35.149][..443] detected: [....24] [ip4][..udp] [..192.168.2.100][51887] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....25] [ip4][..udp] [..192.168.2.100][60127] -> [.181.214.35.149][..443] + new: [....25] [ip4][..udp] [..192.168.2.100][60127] -> [.181.214.35.149][..443] detected: [....25] [ip4][..udp] [..192.168.2.100][60127] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....26] [ip4][..udp] [..192.168.2.100][54546] -> [.181.214.35.149][..443] + new: [....26] [ip4][..udp] [..192.168.2.100][54546] -> [.181.214.35.149][..443] detected: [....26] [ip4][..udp] [..192.168.2.100][54546] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....21] [ip4][..udp] [..192.168.2.100][63776] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] @@ -96,7 +96,7 @@ update: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 52 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 26|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 7] - new: [....27] [ip4][..udp] [..192.168.2.100][64432] -> [.181.214.35.149][..443] + new: [....27] [ip4][..udp] [..192.168.2.100][64432] -> [.181.214.35.149][..443] detected: [....27] [ip4][..udp] [..192.168.2.100][64432] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....20] [ip4][..udp] [..192.168.2.100][51415] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....21] [ip4][..udp] [..192.168.2.100][63776] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] @@ -106,21 +106,21 @@ idle: [....22] [ip4][..udp] [..192.168.2.100][50008] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....19] [ip4][..udp] [..192.168.2.100][64494] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....26] [ip4][..udp] [..192.168.2.100][54546] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....28] [ip4][..udp] [..192.168.2.100][59613] -> [.181.214.35.149][..443] + new: [....28] [ip4][..udp] [..192.168.2.100][59613] -> [.181.214.35.149][..443] detected: [....28] [ip4][..udp] [..192.168.2.100][59613] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....29] [ip4][..udp] [..192.168.2.100][65063] -> [.181.214.35.149][..443] + new: [....29] [ip4][..udp] [..192.168.2.100][65063] -> [.181.214.35.149][..443] detected: [....29] [ip4][..udp] [..192.168.2.100][65063] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....30] [ip4][..udp] [..192.168.2.100][51929] -> [.181.214.35.149][..443] + new: [....30] [ip4][..udp] [..192.168.2.100][51929] -> [.181.214.35.149][..443] detected: [....30] [ip4][..udp] [..192.168.2.100][51929] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....31] [ip4][..udp] [..192.168.2.100][52417] -> [.181.214.35.149][..443] + new: [....31] [ip4][..udp] [..192.168.2.100][52417] -> [.181.214.35.149][..443] detected: [....31] [ip4][..udp] [..192.168.2.100][52417] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....28] [ip4][..udp] [..192.168.2.100][59613] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] update: [....27] [ip4][..udp] [..192.168.2.100][64432] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 62 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 31|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....32] [ip4][..udp] [..192.168.2.100][59474] -> [.181.214.35.149][..443] + new: [....32] [ip4][..udp] [..192.168.2.100][59474] -> [.181.214.35.149][..443] detected: [....32] [ip4][..udp] [..192.168.2.100][59474] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....33] [ip4][..udp] [..192.168.2.100][53839] -> [.181.214.35.149][..443] + new: [....33] [ip4][..udp] [..192.168.2.100][53839] -> [.181.214.35.149][..443] detected: [....33] [ip4][..udp] [..192.168.2.100][53839] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....28] [ip4][..udp] [..192.168.2.100][59613] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....30] [ip4][..udp] [..192.168.2.100][51929] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] @@ -129,21 +129,21 @@ idle: [....29] [ip4][..udp] [..192.168.2.100][65063] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 66 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 33|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....34] [ip4][..udp] [..192.168.2.100][55948] -> [.181.214.35.149][..443] + new: [....34] [ip4][..udp] [..192.168.2.100][55948] -> [.181.214.35.149][..443] detected: [....34] [ip4][..udp] [..192.168.2.100][55948] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....35] [ip4][..udp] [..192.168.2.100][51383] -> [.181.214.35.149][..443] + new: [....35] [ip4][..udp] [..192.168.2.100][51383] -> [.181.214.35.149][..443] detected: [....35] [ip4][..udp] [..192.168.2.100][51383] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....32] [ip4][..udp] [..192.168.2.100][59474] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....33] [ip4][..udp] [..192.168.2.100][53839] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....36] [ip4][..udp] [..192.168.2.100][64700] -> [.181.214.35.149][..443] + new: [....36] [ip4][..udp] [..192.168.2.100][64700] -> [.181.214.35.149][..443] detected: [....36] [ip4][..udp] [..192.168.2.100][64700] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....37] [ip4][..udp] [..192.168.2.100][54549] -> [.181.214.35.149][..443] + new: [....37] [ip4][..udp] [..192.168.2.100][54549] -> [.181.214.35.149][..443] detected: [....37] [ip4][..udp] [..192.168.2.100][54549] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 73 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 37|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....38] [ip4][..udp] [..192.168.2.100][54760] -> [.181.214.35.149][..443] + new: [....38] [ip4][..udp] [..192.168.2.100][54760] -> [.181.214.35.149][..443] detected: [....38] [ip4][..udp] [..192.168.2.100][54760] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] - new: [....39] [ip4][..udp] [..192.168.2.100][49152] -> [.181.214.35.149][..443] + new: [....39] [ip4][..udp] [..192.168.2.100][49152] -> [.181.214.35.149][..443] detected: [....39] [ip4][..udp] [..192.168.2.100][49152] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....39] [ip4][..udp] [..192.168.2.100][49152] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] idle: [....35] [ip4][..udp] [..192.168.2.100][51383] -> [.181.214.35.149][..443] [AVASTSecureDNS][Unknown][Network][Safe] diff --git a/test/results/flow-info/default/bacnet.pcap.out b/test/results/flow-info/default/bacnet.pcap.out index 620d92981..2c15d45c9 100644 --- a/test/results/flow-info/default/bacnet.pcap.out +++ b/test/results/flow-info/default/bacnet.pcap.out @@ -1,44 +1,44 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....65.49.20.98][53234] -> [..90.147.69.219][47808] + new: [.....1] [ip4][..udp] [....65.49.20.98][53234] -> [..90.147.69.219][47808] detected: [.....1] [ip4][..udp] [....65.49.20.98][53234] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] - new: [.....2] [ip4][..udp] [.198.235.24.166][56883] -> [..90.147.69.222][47808] + new: [.....2] [ip4][..udp] [.198.235.24.166][56883] -> [..90.147.69.222][47808] detected: [.....2] [ip4][..udp] [.198.235.24.166][56883] -> [..90.147.69.222][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....1] [ip4][..udp] [....65.49.20.98][53234] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] - new: [.....3] [ip4][..udp] [...64.62.197.26][36992] -> [..90.147.69.221][47808] + new: [.....3] [ip4][..udp] [...64.62.197.26][36992] -> [..90.147.69.221][47808] detected: [.....3] [ip4][..udp] [...64.62.197.26][36992] -> [..90.147.69.221][47808] [BACnet][Unknown][IoT-Scada][Safe] - new: [.....4] [ip4][..udp] [..64.62.197.166][36664] -> [..90.147.69.213][47808] + new: [.....4] [ip4][..udp] [..64.62.197.166][36664] -> [..90.147.69.213][47808] detected: [.....4] [ip4][..udp] [..64.62.197.166][36664] -> [..90.147.69.213][47808] [BACnet][Unknown][IoT-Scada][Safe] update: [.....2] [ip4][..udp] [.198.235.24.166][56883] -> [..90.147.69.222][47808] [BACnet][Unknown][IoT-Scada][Safe] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....5] [ip4][..udp] [..198.235.24.39][54587] -> [..90.147.69.210][47808] + new: [.....5] [ip4][..udp] [..198.235.24.39][54587] -> [..90.147.69.210][47808] detected: [.....5] [ip4][..udp] [..198.235.24.39][54587] -> [..90.147.69.210][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....2] [ip4][..udp] [.198.235.24.166][56883] -> [..90.147.69.222][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....4] [ip4][..udp] [..64.62.197.166][36664] -> [..90.147.69.213][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....3] [ip4][..udp] [...64.62.197.26][36992] -> [..90.147.69.221][47808] [BACnet][Unknown][IoT-Scada][Safe] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....6] [ip4][..udp] [.167.94.138.111][27041] -> [..90.147.69.212][47808] + new: [.....6] [ip4][..udp] [.167.94.138.111][27041] -> [..90.147.69.212][47808] detected: [.....6] [ip4][..udp] [.167.94.138.111][27041] -> [..90.147.69.212][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....5] [ip4][..udp] [..198.235.24.39][54587] -> [..90.147.69.210][47808] [BACnet][Unknown][IoT-Scada][Safe] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....7] [ip4][..udp] [162.142.125.140][63852] -> [..90.147.69.217][47808] + new: [.....7] [ip4][..udp] [162.142.125.140][63852] -> [..90.147.69.217][47808] detected: [.....7] [ip4][..udp] [162.142.125.140][63852] -> [..90.147.69.217][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....6] [ip4][..udp] [.167.94.138.111][27041] -> [..90.147.69.212][47808] [BACnet][Unknown][IoT-Scada][Safe] DAEMON-EVENT: [Processed: 7 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....8] [ip4][..udp] [..198.235.24.45][51922] -> [..90.147.69.219][47808] + new: [.....8] [ip4][..udp] [..198.235.24.45][51922] -> [..90.147.69.219][47808] detected: [.....8] [ip4][..udp] [..198.235.24.45][51922] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....7] [ip4][..udp] [162.142.125.140][63852] -> [..90.147.69.217][47808] [BACnet][Unknown][IoT-Scada][Safe] - new: [.....9] [ip4][..udp] [162.142.125.132][29782] -> [..90.147.69.219][47808] + new: [.....9] [ip4][..udp] [162.142.125.132][29782] -> [..90.147.69.219][47808] detected: [.....9] [ip4][..udp] [162.142.125.132][29782] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] update: [.....8] [ip4][..udp] [..198.235.24.45][51922] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] DAEMON-EVENT: [Processed: 9 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [....10] [ip4][..udp] [204.172.177.255][47808] -> [204.172.177.159][47808] + new: [....10] [ip4][..udp] [204.172.177.255][47808] -> [204.172.177.159][47808] detected: [....10] [ip4][..udp] [204.172.177.255][47808] -> [204.172.177.159][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....9] [ip4][..udp] [162.142.125.132][29782] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] idle: [.....8] [ip4][..udp] [..198.235.24.45][51922] -> [..90.147.69.219][47808] [BACnet][Unknown][IoT-Scada][Safe] diff --git a/test/results/flow-info/default/bad-dns-traffic.pcap.out b/test/results/flow-info/default/bad-dns-traffic.pcap.out index 6268ebc3f..301d636f7 100644 --- a/test/results/flow-info/default/bad-dns-traffic.pcap.out +++ b/test/results/flow-info/default/bad-dns-traffic.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] + new: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] detected: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][05e100a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] RISK: Susp DGA Domain name, Susp DNS Traffic detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] RISK: Susp DGA Domain name, Susp DNS Traffic, Unidirectional Traffic detection-update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][958700a621c3620001636f6e736f6c65202873697276696d65732900.skullseclabs.org] RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name - new: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] + new: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] detected: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][244300fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] RISK: Susp DGA Domain name, Susp DNS Traffic detection-update: [.....2] [ip4][..udp] [..192.168.43.91][56354] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][6b5000fdf525320021636f6d6d616e64202873697276696d65732900.skullseclabs.org] @@ -37,7 +37,7 @@ RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name update: [.....1] [ip4][..udp] [..192.168.43.91][35966] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable] RISK: Susp DGA Domain name, Susp DNS Traffic, Risky Domain Name - new: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] + new: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] detected: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org] RISK: Susp DGA Domain name, Susp DNS Traffic detection-update: [.....3] [ip4][..udp] [..192.168.43.91][46961] -> [........4.2.2.4][...53] [DNS][Unknown][Network][Acceptable][a05700e6da83510001636f6e736f6c65202873697276696d65732900.skullseclabs.org] diff --git a/test/results/flow-info/default/bets.pcapng.out b/test/results/flow-info/default/bets.pcapng.out index 0622a2f1b..09f176f3a 100644 --- a/test/results/flow-info/default/bets.pcapng.out +++ b/test/results/flow-info/default/bets.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.10.2][60099] -> [..13.224.103.22][..443] + new: [.....1] [ip4][..tcp] [...192.168.10.2][60099] -> [..13.224.103.22][..443] detected: [.....1] [ip4][..tcp] [...192.168.10.2][60099] -> [..13.224.103.22][..443] [TLS][AmazonAWS][Web][Safe][www.1084bets10.com] detection-update: [.....1] [ip4][..tcp] [...192.168.10.2][60099] -> [..13.224.103.22][..443] [TLS][AmazonAWS][Web][Safe][www.1084bets10.com] analyse: [.....1] [ip4][..tcp] [...192.168.10.2][60099] -> [..13.224.103.22][..443] [TLS][AmazonAWS][Web][Safe] diff --git a/test/results/flow-info/default/bitcoin.pcap.out b/test/results/flow-info/default/bitcoin.pcap.out index 67ec4c016..a9733f30a 100644 --- a/test/results/flow-info/default/bitcoin.pcap.out +++ b/test/results/flow-info/default/bitcoin.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.142][55317] -> [188.165.213.169][.8333] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.142][55317] -> [188.165.213.169][.8333] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.142][55317] -> [188.165.213.169][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] - new: [.....2] [ip4][..tcp] [..192.168.1.142][55328] -> [..69.118.54.122][.8333] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.1.142][55328] -> [..69.118.54.122][.8333] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.1.142][55328] -> [..69.118.54.122][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] analyse: [.....2] [ip4][..tcp] [..192.168.1.142][55328] -> [..69.118.54.122][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [IATS(ms)....: 52.7,59.2,36072.7,6972.6,71059.7,141657.3,28238.3,0.1,33.0,0.0,0.0,1933.1,0.0,0.0,0.0,0.0,4.5,16.8,0.3,4.1,0.5,12.1,1.1,0.3,10.6,15.7,2.7,0.0,3.1,4.1,7.9] [PKTLENS.....: 157,157,72,113,107,113,96,1500,1500,1500,1500,1031,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500] [ENTROPIES...: 4.3,4.4,4.9,5.2,4.7,5.6,4.9,7.4,7.5,7.5,7.5,7.4,3.6,3.4,3.5,3.5,3.5,3.4,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5] - new: [.....3] [ip4][..tcp] [..192.168.1.142][55348] -> [..74.89.181.229][.8333] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.1.142][55348] -> [..74.89.181.229][.8333] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..192.168.1.142][55348] -> [..74.89.181.229][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] analyse: [.....3] [ip4][..tcp] [..192.168.1.142][55348] -> [..74.89.181.229][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -27,7 +27,7 @@ [IATS(ms)....: 59.2,103.2,9823.2,39766.1,21773.2,100110.7,311.6,29237.0,0.0,63.5,0.0,0.1,1.8,36.3,0.1,10.1,0.0,2.2,0.0,22.5,0.0,0.0,5.4,1.9,16.7,0.1,3.3,3.2,0.1,2.6,1.0] [PKTLENS.....: 157,157,72,168,107,107,96,107,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500] [ENTROPIES...: 4.5,4.5,5.1,5.3,4.9,4.9,5.1,4.8,3.6,3.5,3.6,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5,3.5] - new: [.....4] [ip4][..tcp] [..192.168.1.142][55383] -> [....66.68.83.22][.8333] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.1.142][55383] -> [....66.68.83.22][.8333] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.1.142][55383] -> [....66.68.83.22][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] DAEMON-EVENT: [Processed: 214 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] @@ -41,7 +41,7 @@ [IATS(ms)....: 62.3,90.5,14042.4,39643.2,11452.0,9238.6,22700.4,134322.5,190.5,216.5,0.1,56.8,0.0,0.0,0.0,45582.9,5.5,2.9,79.7,2.4,56.4,14.9,38.3,1.1,29.4,10.2,41.4,0.0,29.6,11.8,15.8] [PKTLENS.....: 157,157,72,113,113,113,168,113,96,1500,1500,1500,1500,1500,1500,317,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500] [ENTROPIES...: 4.3,4.5,5.2,5.6,5.6,5.4,5.2,5.5,5.0,6.6,6.6,6.6,6.6,6.7,6.7,6.2,3.5,3.4,3.5,3.5,3.5,3.5,3.5,3.5,3.4,3.4,3.5,3.5,3.5,3.5,3.5,3.5] - new: [.....5] [ip4][..tcp] [..192.168.1.142][55400] -> [.195.218.16.178][.8333] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..192.168.1.142][55400] -> [.195.218.16.178][.8333] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..192.168.1.142][55400] -> [.195.218.16.178][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] analyse: [.....5] [ip4][..tcp] [..192.168.1.142][55400] -> [.195.218.16.178][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -55,7 +55,7 @@ [ENTROPIES...: 4.4,4.4,5.0,4.7,4.7,4.8,4.8,5.6,5.0,6.6,6.6,6.6,6.6,3.4,3.4,3.3,3.3,3.4,3.4,3.3,3.3,3.3,3.3,3.3,3.3,3.3,3.3,3.3,3.3,3.4,3.4,3.3] DAEMON-EVENT: [Processed: 494 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.1.142][55487] -> [.184.58.165.119][.8333] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.142][55487] -> [.184.58.165.119][.8333] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..192.168.1.142][55487] -> [.184.58.165.119][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] DAEMON-EVENT: [Processed: 621 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] diff --git a/test/results/flow-info/default/bittorrent.pcap.out b/test/results/flow-info/default/bittorrent.pcap.out index 79ba624ea..a7d792b2a 100644 --- a/test/results/flow-info/default/bittorrent.pcap.out +++ b/test/results/flow-info/default/bittorrent.pcap.out @@ -1,66 +1,66 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.1.3][52888] -> [..82.58.216.115][38305] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....192.168.1.3][52888] -> [..82.58.216.115][38305] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [....192.168.1.3][52888] -> [..82.58.216.115][38305] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..tcp] [....192.168.1.3][52887] -> [....82.57.97.83][53137] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [....192.168.1.3][52887] -> [....82.57.97.83][53137] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [....192.168.1.3][52887] -> [....82.57.97.83][53137] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..tcp] [....192.168.1.3][52895] -> [.83.216.184.241][51413] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [....192.168.1.3][52895] -> [.83.216.184.241][51413] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [....192.168.1.3][52895] -> [.83.216.184.241][51413] [BitTorrent][Unknown][Download][Acceptable] - new: [.....4] [ip4][..tcp] [....192.168.1.3][52896] -> [....79.53.228.2][14627] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....192.168.1.3][52896] -> [....79.53.228.2][14627] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [....192.168.1.3][52896] -> [....79.53.228.2][14627] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....5] [ip4][..tcp] [....192.168.1.3][52894] -> [..120.62.33.241][39332] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [....192.168.1.3][52894] -> [..120.62.33.241][39332] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [....192.168.1.3][52894] -> [..120.62.33.241][39332] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....6] [ip4][..tcp] [....192.168.1.3][52897] -> [...151.26.95.30][22673] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [....192.168.1.3][52897] -> [...151.26.95.30][22673] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [....192.168.1.3][52897] -> [...151.26.95.30][22673] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....7] [ip4][..tcp] [....192.168.1.3][52893] -> [...79.55.129.22][12097] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [....192.168.1.3][52893] -> [...79.55.129.22][12097] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [....192.168.1.3][52893] -> [...79.55.129.22][12097] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....8] [ip4][..tcp] [....192.168.1.3][52903] -> [..198.100.146.9][60163] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [....192.168.1.3][52903] -> [..198.100.146.9][60163] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [....192.168.1.3][52903] -> [..198.100.146.9][60163] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....9] [ip4][..tcp] [....192.168.1.3][52902] -> [.190.103.195.56][46633] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [....192.168.1.3][52902] -> [.190.103.195.56][46633] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [....192.168.1.3][52902] -> [.190.103.195.56][46633] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....10] [ip4][..tcp] [....192.168.1.3][52907] -> [..82.58.216.115][38305] [MIDSTREAM] + new: [....10] [ip4][..tcp] [....192.168.1.3][52907] -> [..82.58.216.115][38305] [MIDSTREAM] detected: [....10] [ip4][..tcp] [....192.168.1.3][52907] -> [..82.58.216.115][38305] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....11] [ip4][..tcp] [....192.168.1.3][52906] -> [....82.57.97.83][53137] [MIDSTREAM] + new: [....11] [ip4][..tcp] [....192.168.1.3][52906] -> [....82.57.97.83][53137] [MIDSTREAM] detected: [....11] [ip4][..tcp] [....192.168.1.3][52906] -> [....82.57.97.83][53137] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....12] [ip4][..tcp] [....192.168.1.3][52911] -> [...151.26.95.30][22673] [MIDSTREAM] + new: [....12] [ip4][..tcp] [....192.168.1.3][52911] -> [...151.26.95.30][22673] [MIDSTREAM] detected: [....12] [ip4][..tcp] [....192.168.1.3][52911] -> [...151.26.95.30][22673] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....13] [ip4][..tcp] [....192.168.1.3][52912] -> [.151.72.255.163][59928] [MIDSTREAM] + new: [....13] [ip4][..tcp] [....192.168.1.3][52912] -> [.151.72.255.163][59928] [MIDSTREAM] detected: [....13] [ip4][..tcp] [....192.168.1.3][52912] -> [.151.72.255.163][59928] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....14] [ip4][..tcp] [....192.168.1.3][52909] -> [....79.53.228.2][14627] [MIDSTREAM] + new: [....14] [ip4][..tcp] [....192.168.1.3][52909] -> [....79.53.228.2][14627] [MIDSTREAM] detected: [....14] [ip4][..tcp] [....192.168.1.3][52909] -> [....79.53.228.2][14627] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....15] [ip4][..tcp] [....192.168.1.3][52910] -> [..120.62.33.241][39332] [MIDSTREAM] + new: [....15] [ip4][..tcp] [....192.168.1.3][52910] -> [..120.62.33.241][39332] [MIDSTREAM] detected: [....15] [ip4][..tcp] [....192.168.1.3][52910] -> [..120.62.33.241][39332] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....16] [ip4][..tcp] [....192.168.1.3][52908] -> [...79.55.129.22][12097] [MIDSTREAM] + new: [....16] [ip4][..tcp] [....192.168.1.3][52908] -> [...79.55.129.22][12097] [MIDSTREAM] detected: [....16] [ip4][..tcp] [....192.168.1.3][52908] -> [...79.55.129.22][12097] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....17] [ip4][..tcp] [....192.168.1.3][52915] -> [..198.100.146.9][60163] [MIDSTREAM] + new: [....17] [ip4][..tcp] [....192.168.1.3][52915] -> [..198.100.146.9][60163] [MIDSTREAM] detected: [....17] [ip4][..tcp] [....192.168.1.3][52915] -> [..198.100.146.9][60163] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....18] [ip4][..tcp] [....192.168.1.3][52914] -> [.190.103.195.56][46633] [MIDSTREAM] + new: [....18] [ip4][..tcp] [....192.168.1.3][52914] -> [.190.103.195.56][46633] [MIDSTREAM] detected: [....18] [ip4][..tcp] [....192.168.1.3][52914] -> [.190.103.195.56][46633] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....19] [ip4][..tcp] [....192.168.1.3][52917] -> [..151.15.48.189][47001] [MIDSTREAM] + new: [....19] [ip4][..tcp] [....192.168.1.3][52917] -> [..151.15.48.189][47001] [MIDSTREAM] detected: [....19] [ip4][..tcp] [....192.168.1.3][52917] -> [..151.15.48.189][47001] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....20] [ip4][..tcp] [....192.168.1.3][52921] -> [..95.234.159.16][41205] [MIDSTREAM] + new: [....20] [ip4][..tcp] [....192.168.1.3][52921] -> [..95.234.159.16][41205] [MIDSTREAM] detected: [....20] [ip4][..tcp] [....192.168.1.3][52921] -> [..95.234.159.16][41205] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....21] [ip4][..tcp] [....192.168.1.3][52922] -> [..95.237.193.34][11321] [MIDSTREAM] + new: [....21] [ip4][..tcp] [....192.168.1.3][52922] -> [..95.237.193.34][11321] [MIDSTREAM] detected: [....21] [ip4][..tcp] [....192.168.1.3][52922] -> [..95.237.193.34][11321] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port analyse: [....17] [ip4][..tcp] [....192.168.1.3][52915] -> [..198.100.146.9][60163] [BitTorrent][Unknown][Download][Acceptable] @@ -73,12 +73,12 @@ [IATS(ms)....: 176.8,184.0,361.0,337.3,477.6,920.0,779.8,619.5,619.4,156.9,158.1,151.0,161.2,12.0,185.6,163.5,148.9,165.8,153.5,19.2,148.7,12.8,146.1,495.9,130.3,32.1,133.8,27.3,421.5,129.5,27.4] [PKTLENS.....: 120,132,611,228,66,176,90,86,1492,69,1166,69,609,81,69,389,69,188,609,1492,1492,1492,1492,1492,188,1492,1492,1492,1492,197,1492,1492] [ENTROPIES...: 6.0,6.1,4.9,5.5,4.8,3.9,5.4,4.3,7.8,4.5,7.7,4.6,7.6,4.7,4.6,7.4,4.6,2.9,7.6,4.9,7.7,7.7,7.8,7.8,3.1,7.7,7.8,7.8,7.8,3.1,7.8,7.9] - new: [....22] [ip4][..tcp] [....192.168.1.3][52927] -> [.83.216.184.241][51413] [MIDSTREAM] + new: [....22] [ip4][..tcp] [....192.168.1.3][52927] -> [.83.216.184.241][51413] [MIDSTREAM] detected: [....22] [ip4][..tcp] [....192.168.1.3][52927] -> [.83.216.184.241][51413] [BitTorrent][Unknown][Download][Acceptable] - new: [....23] [ip4][..tcp] [....192.168.1.3][52926] -> [..93.65.249.100][31336] [MIDSTREAM] + new: [....23] [ip4][..tcp] [....192.168.1.3][52926] -> [..93.65.249.100][31336] [MIDSTREAM] detected: [....23] [ip4][..tcp] [....192.168.1.3][52926] -> [..93.65.249.100][31336] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [....24] [ip4][..tcp] [....192.168.1.3][52925] -> [..93.65.227.100][19116] [MIDSTREAM] + new: [....24] [ip4][..tcp] [....192.168.1.3][52925] -> [..93.65.227.100][19116] [MIDSTREAM] detected: [....24] [ip4][..tcp] [....192.168.1.3][52925] -> [..93.65.227.100][19116] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port end: [.....2] [ip4][..tcp] [....192.168.1.3][52887] -> [....82.57.97.83][53137] [BitTorrent][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/bittorrent_tcp_miss.pcapng.out b/test/results/flow-info/default/bittorrent_tcp_miss.pcapng.out index c4a0e9f3d..e29a42414 100644 --- a/test/results/flow-info/default/bittorrent_tcp_miss.pcapng.out +++ b/test/results/flow-info/default/bittorrent_tcp_miss.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] + new: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] detected: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....1] [ip4][..tcp] [.192.168.122.34][48987] -> [...178.71.206.1][.6881] [BitTorrent][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/bittorrent_utp.pcap.out b/test/results/flow-info/default/bittorrent_utp.pcap.out index 04cfc3a0b..017cf2e80 100644 --- a/test/results/flow-info/default/bittorrent_utp.pcap.out +++ b/test/results/flow-info/default/bittorrent_utp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..82.243.113.43][64969] -> [....192.168.1.5][40959] + new: [.....1] [ip4][..udp] [..82.243.113.43][64969] -> [....192.168.1.5][40959] detected: [.....1] [ip4][..udp] [..82.243.113.43][64969] -> [....192.168.1.5][40959] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [..82.243.113.43][64969] -> [....192.168.1.5][40959] [BitTorrent][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/bjnp.pcap.out b/test/results/flow-info/default/bjnp.pcap.out index a711f01c9..c6bdca4a5 100644 --- a/test/results/flow-info/default/bjnp.pcap.out +++ b/test/results/flow-info/default/bjnp.pcap.out @@ -1,25 +1,25 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [192.168.185.141][50087] -> [...192.168.1.17][.8612] + new: [.....1] [ip4][..udp] [192.168.185.141][50087] -> [...192.168.1.17][.8612] detected: [.....1] [ip4][..udp] [192.168.185.141][50087] -> [...192.168.1.17][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....2] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.1][.8612] + new: [.....2] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.1][.8612] detected: [.....2] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.1][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....3] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.2][.8612] + new: [.....3] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.2][.8612] detected: [.....3] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.2][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....4] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.3][.8612] + new: [.....4] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.3][.8612] detected: [.....4] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.3][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....5] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.4][.8612] + new: [.....5] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.4][.8612] detected: [.....5] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.4][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....6] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.5][.8612] + new: [.....6] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.5][.8612] detected: [.....6] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.5][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....7] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.6][.8612] + new: [.....7] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.6][.8612] detected: [.....7] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.6][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....8] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.7][.8612] + new: [.....8] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.7][.8612] detected: [.....8] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.7][.8612] [BJNP][Unknown][System][Acceptable] - new: [.....9] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.8][.8612] + new: [.....9] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.8][.8612] detected: [.....9] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.8][.8612] [BJNP][Unknown][System][Acceptable] - new: [....10] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.9][.8612] + new: [....10] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.9][.8612] detected: [....10] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.9][.8612] [BJNP][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [192.168.185.141][50087] -> [...192.168.1.17][.8612] [BJNP][Unknown][System][Acceptable] idle: [....10] [ip4][..udp] [192.168.185.141][50089] -> [....192.168.1.9][.8612] [BJNP][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/bot.pcap.out b/test/results/flow-info/default/bot.pcap.out index e92fba3b5..128e9ad5a 100644 --- a/test/results/flow-info/default/bot.pcap.out +++ b/test/results/flow-info/default/bot.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...40.77.167.36][64768] -> [...89.31.72.220][...80] + new: [.....1] [ip4][..tcp] [...40.77.167.36][64768] -> [...89.31.72.220][...80] detected: [.....1] [ip4][..tcp] [...40.77.167.36][64768] -> [...89.31.72.220][...80] [HTTP][Azure][Web][Acceptable][atlanteditorino.it] RISK: Crawler/Bot analyse: [.....1] [ip4][..tcp] [...40.77.167.36][64768] -> [...89.31.72.220][...80] [HTTP][Azure][Web][Acceptable] diff --git a/test/results/flow-info/default/bt-dns.pcap.out b/test/results/flow-info/default/bt-dns.pcap.out index fa07a38a0..29f810c64 100644 --- a/test/results/flow-info/default/bt-dns.pcap.out +++ b/test/results/flow-info/default/bt-dns.pcap.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..udp] [......10.0.2.15][59751] -> [.......10.0.2.3][...53] + new: [.....1] [ip4][..udp] [......10.0.2.15][59751] -> [.......10.0.2.3][...53] detected: [.....1] [ip4][..udp] [......10.0.2.15][59751] -> [.......10.0.2.3][...53] [DNS.BitTorrent][Unknown][Network][Acceptable][utorrent.com] detection-update: [.....1] [ip4][..udp] [......10.0.2.15][59751] -> [.......10.0.2.3][...53] [DNS.BitTorrent][Unknown][Network][Acceptable][utorrent.com] idle: [.....1] [ip4][..udp] [......10.0.2.15][59751] -> [.......10.0.2.3][...53] [DNS.BitTorrent][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/bt-http.pcapng.out b/test/results/flow-info/default/bt-http.pcapng.out index 992632ee1..32bfd2319 100644 --- a/test/results/flow-info/default/bt-http.pcapng.out +++ b/test/results/flow-info/default/bt-http.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.128][46882] -> [.176.31.225.118][...80] + new: [.....1] [ip4][..tcp] [..192.168.1.128][46882] -> [.176.31.225.118][...80] detected: [.....1] [ip4][..tcp] [..192.168.1.128][46882] -> [.176.31.225.118][...80] [HTTP.BitTorrent][Unknown][Download][Acceptable][tracker.trackerfix.com] end: [.....1] [ip4][..tcp] [..192.168.1.128][46882] -> [.176.31.225.118][...80] [HTTP.BitTorrent][Unknown][Download][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/bt_search.pcap.out b/test/results/flow-info/default/bt_search.pcap.out index 84bb2d94f..9077062d7 100644 --- a/test/results/flow-info/default/bt_search.pcap.out +++ b/test/results/flow-info/default/bt_search.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.0.102][.6771] -> [239.192.152.143][.6771] + new: [.....1] [ip4][..udp] [..192.168.0.102][.6771] -> [239.192.152.143][.6771] detected: [.....1] [ip4][..udp] [..192.168.0.102][.6771] -> [239.192.152.143][.6771] [BitTorrent][Unknown][Download][Acceptable] idle: [.....1] [ip4][..udp] [..192.168.0.102][.6771] -> [239.192.152.143][.6771] [BitTorrent][Unknown][Download][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/cachefly.pcapng.out b/test/results/flow-info/default/cachefly.pcapng.out index 28d5f3bd8..f3ee48ab7 100644 --- a/test/results/flow-info/default/cachefly.pcapng.out +++ b/test/results/flow-info/default/cachefly.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][43766] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][43766] detected: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][43766] [TLS][Unknown][Web][Safe][apptv.cachefly.net] detection-update: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][43766] [TLS][Unknown][Web][Safe][apptv.cachefly.net] detection-update: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][43766] [TLS.Cachefly][Unknown][Cloud][Acceptable][apptv.cachefly.net] diff --git a/test/results/flow-info/default/can.pcap.out b/test/results/flow-info/default/can.pcap.out index 49d4f2f93..44f4fd497 100644 --- a/test/results/flow-info/default/can.pcap.out +++ b/test/results/flow-info/default/can.pcap.out @@ -1,22 +1,22 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..207.134.64.89][36251] -> [..48.220.224.78][11898] + new: [.....1] [ip4][..udp] [..207.134.64.89][36251] -> [..48.220.224.78][11898] detected: [.....1] [ip4][..udp] [..207.134.64.89][36251] -> [..48.220.224.78][11898] [Controller_Area_Network][Unknown][System][Safe] - new: [.....2] [ip4][..udp] [....55.97.32.36][56551] -> [....61.40.63.42][25353] + new: [.....2] [ip4][..udp] [....55.97.32.36][56551] -> [....61.40.63.42][25353] detected: [.....2] [ip4][..udp] [....55.97.32.36][56551] -> [....61.40.63.42][25353] [Controller_Area_Network][Unknown][System][Safe] update: [.....1] [ip4][..udp] [..207.134.64.89][36251] -> [..48.220.224.78][11898] [Controller_Area_Network][Unknown][System][Safe] - new: [.....3] [ip4][..udp] [..128.244.36.46][34952] -> [.196.77.109.252][11898] + new: [.....3] [ip4][..udp] [..128.244.36.46][34952] -> [.196.77.109.252][11898] detected: [.....3] [ip4][..udp] [..128.244.36.46][34952] -> [.196.77.109.252][11898] [Controller_Area_Network][Unknown][System][Safe] - new: [.....4] [ip4][..udp] [103.183.191.240][46565] -> [..73.121.85.123][63575] + new: [.....4] [ip4][..udp] [103.183.191.240][46565] -> [..73.121.85.123][63575] detected: [.....4] [ip4][..udp] [103.183.191.240][46565] -> [..73.121.85.123][63575] [Controller_Area_Network][Unknown][System][Safe] - new: [.....5] [ip4][..udp] [..247.111.83.65][53276] -> [..172.44.102.53][11898] + new: [.....5] [ip4][..udp] [..247.111.83.65][53276] -> [..172.44.102.53][11898] detected: [.....5] [ip4][..udp] [..247.111.83.65][53276] -> [..172.44.102.53][11898] [Controller_Area_Network][Unknown][System][Safe] - new: [.....6] [ip4][..udp] [.248.12.123.236][39411] -> [..69.120.47.124][..540] + new: [.....6] [ip4][..udp] [.248.12.123.236][39411] -> [..69.120.47.124][..540] detected: [.....6] [ip4][..udp] [.248.12.123.236][39411] -> [..69.120.47.124][..540] [Controller_Area_Network][Unknown][System][Safe] - new: [.....7] [ip4][..udp] [156.187.243.113][52611] -> [.211.116.172.72][11898] + new: [.....7] [ip4][..udp] [156.187.243.113][52611] -> [.211.116.172.72][11898] detected: [.....7] [ip4][..udp] [156.187.243.113][52611] -> [.211.116.172.72][11898] [Controller_Area_Network][Unknown][System][Safe] - new: [.....8] [ip4][..udp] [..140.194.231.1][58665] -> [....89.92.174.8][32367] + new: [.....8] [ip4][..udp] [..140.194.231.1][58665] -> [....89.92.174.8][32367] detected: [.....8] [ip4][..udp] [..140.194.231.1][58665] -> [....89.92.174.8][32367] [Controller_Area_Network][Unknown][System][Safe] idle: [.....3] [ip4][..udp] [..128.244.36.46][34952] -> [.196.77.109.252][11898] [Controller_Area_Network][Unknown][System][Safe] idle: [.....6] [ip4][..udp] [.248.12.123.236][39411] -> [..69.120.47.124][..540] [Controller_Area_Network][Unknown][System][Safe] diff --git a/test/results/flow-info/default/capwap.pcap.out b/test/results/flow-info/default/capwap.pcap.out index 8e0491b1f..47a3f134f 100644 --- a/test/results/flow-info/default/capwap.pcap.out +++ b/test/results/flow-info/default/capwap.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12379] + new: [.....1] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12379] detected: [.....1] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12379] [CAPWAP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [..192.168.10.10][49259] -> [255.255.255.255][...53] + new: [.....2] [ip4][..udp] [..192.168.10.10][49259] -> [255.255.255.255][...53] detected: [.....2] [ip4][..udp] [..192.168.10.10][49259] -> [255.255.255.255][...53] [DNS][Unknown][Network][Acceptable][cisco-capwap-controller] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] @@ -11,9 +11,9 @@ ERROR-EVENT: Unknown packet type [4/16] ERROR-EVENT: Unknown packet type [5/16] ERROR-EVENT: Unknown packet type [6/16] - new: [.....3] [ip4][..udp] [..192.168.10.10][12380] -> [255.255.255.255][.5246] + new: [.....3] [ip4][..udp] [..192.168.10.10][12380] -> [255.255.255.255][.5246] detected: [.....3] [ip4][..udp] [..192.168.10.10][12380] -> [255.255.255.255][.5246] [CAPWAP][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12380] + new: [.....4] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12380] detected: [.....4] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12380] [CAPWAP][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12379] [CAPWAP][Unknown][Network][Acceptable] analyse: [.....4] [ip4][..udp] [...192.168.10.9][.5246] -> [..192.168.10.10][12380] [CAPWAP][Unknown][Network][Acceptable] @@ -26,7 +26,7 @@ [IATS(ms)....: 0.8,9998.4,10093.4,96.4,2.6,0.0,0.1,182.4,0.0,0.0,0.0,0.1,314.1,135.3,2.7,0.2,111.8,0.0,157.3,0.0,325.7,280.1,0.0,39.5,0.0,39.5,0.3,2.1,1.0,0.5,0.5] [PKTLENS.....: 142,142,101,92,133,576,576,346,576,576,165,315,406,123,1485,1485,1485,1437,1021,1437,461,141,109,125,141,125,109,877,141,109,125,861] [ENTROPIES...: 3.9,3.9,4.8,4.6,5.4,6.6,6.9,6.4,6.9,6.8,6.4,7.1,7.1,5.5,7.9,7.9,7.9,7.9,7.8,7.8,7.5,6.3,5.8,6.0,6.3,6.0,5.8,7.8,6.3,5.8,6.1,7.7] - new: [.....5] [ip4][..udp] [..192.168.10.10][12380] -> [...192.168.10.9][.5247] + new: [.....5] [ip4][..udp] [..192.168.10.10][12380] -> [...192.168.10.9][.5247] detected: [.....5] [ip4][..udp] [..192.168.10.10][12380] -> [...192.168.10.9][.5247] [CAPWAP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [..192.168.10.10][49259] -> [255.255.255.255][...53] [DNS][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] diff --git a/test/results/flow-info/default/cassandra.pcap.out b/test/results/flow-info/default/cassandra.pcap.out index 48d881b11..8ebd928cf 100644 --- a/test/results/flow-info/default/cassandra.pcap.out +++ b/test/results/flow-info/default/cassandra.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][46536] -> [......127.0.0.1][.9042] + new: [.....1] [ip4][..tcp] [......127.0.0.1][46536] -> [......127.0.0.1][.9042] detected: [.....1] [ip4][..tcp] [......127.0.0.1][46536] -> [......127.0.0.1][.9042] [Cassandra][Unknown][Database][Acceptable] - new: [.....2] [ip4][..tcp] [......127.0.0.1][46537] -> [......127.0.0.1][.9042] + new: [.....2] [ip4][..tcp] [......127.0.0.1][46537] -> [......127.0.0.1][.9042] detected: [.....2] [ip4][..tcp] [......127.0.0.1][46537] -> [......127.0.0.1][.9042] [Cassandra][Unknown][Database][Acceptable] analyse: [.....1] [ip4][..tcp] [......127.0.0.1][46536] -> [......127.0.0.1][.9042] [Cassandra][Unknown][Database][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/check_mk_new.pcap.out b/test/results/flow-info/default/check_mk_new.pcap.out index 1fa1f4b91..2194b741a 100644 --- a/test/results/flow-info/default/check_mk_new.pcap.out +++ b/test/results/flow-info/default/check_mk_new.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.100.22][58998] -> [.192.168.100.50][.6556] + new: [.....1] [ip4][..tcp] [.192.168.100.22][58998] -> [.192.168.100.50][.6556] detected: [.....1] [ip4][..tcp] [.192.168.100.22][58998] -> [.192.168.100.50][.6556] [CHECKMK][Unknown][DataTransfer][Acceptable] analyse: [.....1] [ip4][..tcp] [.192.168.100.22][58998] -> [.192.168.100.50][.6556] [CHECKMK][Unknown][DataTransfer][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/chrome.pcap.out b/test/results/flow-info/default/chrome.pcap.out index cf650214b..4df73239c 100644 --- a/test/results/flow-info/default/chrome.pcap.out +++ b/test/results/flow-info/default/chrome.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][64393] -> [...146.48.58.18][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][64393] -> [...146.48.58.18][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][64393] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][64393] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] - new: [.....2] [ip4][..tcp] [..192.168.1.178][64394] -> [...146.48.58.18][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.178][64394] -> [...146.48.58.18][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.178][64394] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....2] [ip4][..tcp] [..192.168.1.178][64394] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] - new: [.....3] [ip4][..tcp] [..192.168.1.178][64408] -> [...146.48.58.18][..443] - new: [.....4] [ip4][..tcp] [..192.168.1.178][64409] -> [...146.48.58.18][..443] - new: [.....5] [ip4][..tcp] [..192.168.1.178][64410] -> [...146.48.58.18][..443] - new: [.....6] [ip4][..tcp] [..192.168.1.178][64411] -> [...146.48.58.18][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.178][64408] -> [...146.48.58.18][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.178][64409] -> [...146.48.58.18][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.178][64410] -> [...146.48.58.18][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.178][64411] -> [...146.48.58.18][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.178][64409] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detected: [.....3] [ip4][..tcp] [..192.168.1.178][64408] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detected: [.....5] [ip4][..tcp] [..192.168.1.178][64410] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] diff --git a/test/results/flow-info/default/citrix.pcap.out b/test/results/flow-info/default/citrix.pcap.out index 532c45f9e..aa6633db4 100644 --- a/test/results/flow-info/default/citrix.pcap.out +++ b/test/results/flow-info/default/citrix.pcap.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [.......21.0.0.8][45225] -> [.......22.0.0.7][.1494] + new: [.....1] [ip4][..tcp] [.......21.0.0.8][45225] -> [.......22.0.0.7][.1494] detected: [.....1] [ip4][..tcp] [.......21.0.0.8][45225] -> [.......22.0.0.7][.1494] [Citrix][Unknown][Network][Acceptable] analyse: [.....1] [ip4][..tcp] [.......21.0.0.8][45225] -> [.......22.0.0.7][.1494] [Citrix][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/cloudflare-warp.pcap.out b/test/results/flow-info/default/cloudflare-warp.pcap.out index 622f94a00..6062efd15 100644 --- a/test/results/flow-info/default/cloudflare-warp.pcap.out +++ b/test/results/flow-info/default/cloudflare-warp.pcap.out @@ -1,31 +1,31 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..10.158.134.93][55512] -> [.142.251.42.106][..443] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [.......10.8.0.1][42344] -> [..159.138.85.48][.5223] + new: [.....1] [ip4][..tcp] [..10.158.134.93][55512] -> [.142.251.42.106][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.......10.8.0.1][42344] -> [..159.138.85.48][.5223] detected: [.....2] [ip4][..tcp] [.......10.8.0.1][42344] -> [..159.138.85.48][.5223] [Jabber][Unknown][Web][Acceptable] - new: [.....3] [ip4][..tcp] [.......10.8.0.1][40214] -> [..157.240.16.32][..443] + new: [.....3] [ip4][..tcp] [.......10.8.0.1][40214] -> [..157.240.16.32][..443] detected: [.....3] [ip4][..tcp] [.......10.8.0.1][40214] -> [..157.240.16.32][..443] [TLS.Messenger][Facebook][Chat][Acceptable][mqtt-mini.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [.......10.8.0.1][40214] -> [..157.240.16.32][..443] [TLS.Messenger][Facebook][Chat][Acceptable][mqtt-mini.facebook.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....4] [ip4][..tcp] [..10.158.134.93][40454] -> [..216.58.196.68][..443] [MIDSTREAM] - new: [.....5] [ip4][..tcp] [.......10.8.0.1][45606] -> [..104.18.47.234][..443] + new: [.....4] [ip4][..tcp] [..10.158.134.93][40454] -> [..216.58.196.68][..443] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [.......10.8.0.1][45606] -> [..104.18.47.234][..443] detected: [.....5] [ip4][..tcp] [.......10.8.0.1][45606] -> [..104.18.47.234][..443] [TLS.CloudflareWarp][Cloudflare][VPN][Acceptable][api.cloudflareclient.com] - new: [.....6] [ip4][..tcp] [.......10.8.0.1][45610] -> [..104.18.47.234][..443] + new: [.....6] [ip4][..tcp] [.......10.8.0.1][45610] -> [..104.18.47.234][..443] detected: [.....6] [ip4][..tcp] [.......10.8.0.1][45610] -> [..104.18.47.234][..443] [TLS.CloudflareWarp][Cloudflare][VPN][Acceptable][api.cloudflareclient.com] detection-update: [.....5] [ip4][..tcp] [.......10.8.0.1][45606] -> [..104.18.47.234][..443] [TLS.CloudflareWarp][Cloudflare][VPN][Acceptable][api.cloudflareclient.com] - new: [.....7] [ip4][..tcp] [.......10.8.0.1][51296] -> [142.250.183.163][..443] + new: [.....7] [ip4][..tcp] [.......10.8.0.1][51296] -> [142.250.183.163][..443] detected: [.....7] [ip4][..tcp] [.......10.8.0.1][51296] -> [142.250.183.163][..443] [TLS.GoogleServices][Google][Web][Acceptable][crashlyticsreports-pa.googleapis.com] detection-update: [.....6] [ip4][..tcp] [.......10.8.0.1][45610] -> [..104.18.47.234][..443] [TLS.CloudflareWarp][Cloudflare][VPN][Acceptable][api.cloudflareclient.com] - new: [.....8] [ip4][..tcp] [.......10.8.0.1][43600] -> [172.217.194.188][.5228] + new: [.....8] [ip4][..tcp] [.......10.8.0.1][43600] -> [172.217.194.188][.5228] guessed: [.....8] [ip4][..tcp] [.......10.8.0.1][43600] -> [172.217.194.188][.5228] [Google][Google][Web][Acceptable] - idle: [.....8] [ip4][..tcp] [.......10.8.0.1][43600] -> [172.217.194.188][.5228] + idle: [.....8] [ip4][..tcp] [.......10.8.0.1][43600] -> [172.217.194.188][.5228] guessed: [.....4] [ip4][..tcp] [..10.158.134.93][40454] -> [..216.58.196.68][..443] [TLS][Google][Web][Safe] - end: [.....4] [ip4][..tcp] [..10.158.134.93][40454] -> [..216.58.196.68][..443] + end: [.....4] [ip4][..tcp] [..10.158.134.93][40454] -> [..216.58.196.68][..443] guessed: [.....1] [ip4][..tcp] [..10.158.134.93][55512] -> [.142.251.42.106][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic - end: [.....1] [ip4][..tcp] [..10.158.134.93][55512] -> [.142.251.42.106][..443] + end: [.....1] [ip4][..tcp] [..10.158.134.93][55512] -> [.142.251.42.106][..443] idle: [.....2] [ip4][..tcp] [.......10.8.0.1][42344] -> [..159.138.85.48][.5223] [Jabber][Unknown][Web][Acceptable] idle: [.....7] [ip4][..tcp] [.......10.8.0.1][51296] -> [142.250.183.163][..443] [TLS.GoogleServices][Google][Web][Acceptable] idle: [.....5] [ip4][..tcp] [.......10.8.0.1][45606] -> [..104.18.47.234][..443] [TLS.CloudflareWarp][Cloudflare][VPN][Acceptable] diff --git a/test/results/flow-info/default/coap_mqtt.pcap.out b/test/results/flow-info/default/coap_mqtt.pcap.out index 18f71a3ca..591bb31e6 100644 --- a/test/results/flow-info/default/coap_mqtt.pcap.out +++ b/test/results/flow-info/default/coap_mqtt.pcap.out @@ -1,48 +1,48 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61043] -> [....................2001:620:8:35d9::10][.5683] + new: [.....1] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61043] -> [....................2001:620:8:35d9::10][.5683] detected: [.....1] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61043] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] - new: [.....2] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61044] -> [....................2001:620:8:35d9::10][.5683] + new: [.....2] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61044] -> [....................2001:620:8:35d9::10][.5683] detected: [.....2] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61044] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] - new: [.....3] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61045] -> [....................2001:620:8:35d9::10][.5683] + new: [.....3] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61045] -> [....................2001:620:8:35d9::10][.5683] detected: [.....3] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61045] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] - new: [.....4] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61046] -> [....................2001:620:8:35d9::10][.5683] + new: [.....4] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61046] -> [....................2001:620:8:35d9::10][.5683] detected: [.....4] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61046] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] - new: [.....5] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61047] -> [....................2001:620:8:35d9::10][.5683] + new: [.....5] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61047] -> [....................2001:620:8:35d9::10][.5683] detected: [.....5] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61047] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip6][..udp] [................................bbbb::1][33499] -> [................................bbbb::3][.5683] + new: [.....6] [ip6][..udp] [................................bbbb::1][33499] -> [................................bbbb::3][.5683] detected: [.....6] [ip6][..udp] [................................bbbb::1][33499] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] idle: [.....1] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61043] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] idle: [.....2] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61044] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] idle: [.....3] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61045] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] idle: [.....4] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61046] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] idle: [.....5] [ip6][..udp] [..2001:da8:215:1171:a10b:cb48:8f83:57f6][61047] -> [....................2001:620:8:35d9::10][.5683] [COAP][Unknown][RPC][Safe] - new: [.....7] [ip6][..udp] [................................bbbb::1][50250] -> [................................bbbb::3][.5683] + new: [.....7] [ip6][..udp] [................................bbbb::1][50250] -> [................................bbbb::3][.5683] detected: [.....7] [ip6][..udp] [................................bbbb::1][50250] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] - new: [.....8] [ip6][..udp] [................................bbbb::1][46819] -> [................................bbbb::3][.5683] + new: [.....8] [ip6][..udp] [................................bbbb::1][46819] -> [................................bbbb::3][.5683] detected: [.....8] [ip6][..udp] [................................bbbb::1][46819] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] idle: [.....6] [ip6][..udp] [................................bbbb::1][33499] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] update: [.....7] [ip6][..udp] [................................bbbb::1][50250] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] update: [.....8] [ip6][..udp] [................................bbbb::1][46819] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....9] [ip4][..tcp] [...192.168.56.1][53522] -> [.192.168.56.101][17501] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...192.168.56.1][53522] -> [.192.168.56.101][17501] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...192.168.56.1][53522] -> [.192.168.56.101][17501] [MQTT][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port idle: [.....7] [ip6][..udp] [................................bbbb::1][50250] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] idle: [.....8] [ip6][..udp] [................................bbbb::1][46819] -> [................................bbbb::3][.5683] [COAP][Unknown][RPC][Safe] - new: [....10] [ip4][..tcp] [...192.168.56.1][53523] -> [.192.168.56.101][17501] [MIDSTREAM] + new: [....10] [ip4][..tcp] [...192.168.56.1][53523] -> [.192.168.56.101][17501] [MIDSTREAM] detected: [....10] [ip4][..tcp] [...192.168.56.1][53523] -> [.192.168.56.101][17501] [MQTT][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port - new: [....11] [ip4][..tcp] [...192.168.56.1][53528] -> [.192.168.56.101][17501] + new: [....11] [ip4][..tcp] [...192.168.56.1][53528] -> [.192.168.56.101][17501] detected: [....11] [ip4][..tcp] [...192.168.56.1][53528] -> [.192.168.56.101][17501] [MQTT][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port - new: [....12] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] + new: [....12] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] detected: [....12] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....13] [ip4][..tcp] [.192.168.56.101][17501] -> [...192.168.56.1][53524] [MIDSTREAM] + new: [....13] [ip4][..tcp] [.192.168.56.101][17501] -> [...192.168.56.1][53524] [MIDSTREAM] detected: [....13] [ip4][..tcp] [.192.168.56.101][17501] -> [...192.168.56.1][53524] [MQTT][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port analyse: [....11] [ip4][..tcp] [...192.168.56.1][53528] -> [.192.168.56.101][17501] [MQTT][Unknown][RPC][Acceptable] @@ -85,7 +85,7 @@ [IATS(ms)....: 2.0,38.6,37.1,0.5,2.4,62.3,64.9,0.8,38.7,38.1,0.5,2.3,67.3,69.7,0.7,39.4,39.5,0.9,2.3,63.2,65.6,1.6,40.3,38.7,0.2,6.1,67.2,73.5,2.5,42.4,39.9] [PKTLENS.....: 126,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100,40,44,126,46,46,40,100] [ENTROPIES...: 5.6,4.6,4.6,5.5,4.6,4.7,5.6,4.3,4.6,4.6,5.5,4.5,4.6,5.6,4.3,4.6,4.7,5.5,4.6,4.6,5.6,4.4,4.7,4.6,5.5,4.7,4.8,5.6,4.4,4.6,4.7,5.5] - new: [....14] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] + new: [....14] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] detected: [....14] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [....12] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -97,7 +97,7 @@ [IATS(ms)....: 1.8,103.9,104.0,109.0,108.5,105.4,105.9,113.8,113.7,106.8,107.1,109.4,109.0,108.9,116.0,117.8,112.3,110.6,110.8,109.9,107.9,108.0,108.0,113.1,114.0,110.8,110.4,107.4,111.2,109.5,105.1] [PKTLENS.....: 124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45] [ENTROPIES...: 5.5,5.0,5.5,5.1,5.5,5.0,5.7,5.2,5.6,5.1,5.5,5.0,5.6,5.0,5.5,5.0,5.6,5.1,5.5,5.0,5.5,5.0,5.5,5.0,5.5,5.1,5.5,5.1,5.7,5.3,5.6,5.0] - new: [....15] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] + new: [....15] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] detected: [....15] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [....14] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -109,7 +109,7 @@ [IATS(ms)....: 2.4,112.9,114.3,107.8,108.1,108.0,108.0,109.5,111.4,119.1,118.3,117.0,117.0,127.7,125.1,114.0,113.0,120.2,120.9,111.5,111.3,105.6,107.8,113.8,112.0,122.6,125.5,113.0,110.0,123.5,125.7] [PKTLENS.....: 123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50] [ENTROPIES...: 5.5,5.0,5.6,5.1,5.6,5.0,5.7,5.2,5.5,5.0,5.5,5.0,5.6,5.1,5.6,5.1,5.5,5.1,5.6,5.1,5.6,5.1,5.5,4.9,5.5,5.1,5.5,5.0,5.5,5.1,5.7,5.2] - new: [....16] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] + new: [....16] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] detected: [....16] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [....15] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/collectd.pcap.out b/test/results/flow-info/default/collectd.pcap.out index 9c766565a..66699c08b 100644 --- a/test/results/flow-info/default/collectd.pcap.out +++ b/test/results/flow-info/default/collectd.pcap.out @@ -1,28 +1,28 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][36576] -> [......127.0.0.1][25826] + new: [.....1] [ip4][..udp] [......127.0.0.1][36576] -> [......127.0.0.1][25826] detected: [.....1] [ip4][..udp] [......127.0.0.1][36576] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][devlap.fritz.box] - new: [.....2] [ip4][..udp] [......127.0.0.1][36320] -> [......127.0.0.1][25826] - new: [.....3] [ip4][..udp] [......127.0.0.1][36064] -> [......127.0.0.1][25826] + new: [.....2] [ip4][..udp] [......127.0.0.1][36320] -> [......127.0.0.1][25826] + new: [.....3] [ip4][..udp] [......127.0.0.1][36064] -> [......127.0.0.1][25826] detected: [.....3] [ip4][..udp] [......127.0.0.1][36064] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][devlap.fritz.box] DAEMON-EVENT: [Processed: 3 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] - new: [.....5] [ip4][..udp] [.192.168.178.35][39577] -> [..239.192.74.66][25826] + new: [.....4] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] + new: [.....5] [ip4][..udp] [.192.168.178.35][39577] -> [..239.192.74.66][25826] idle: [.....3] [ip4][..udp] [......127.0.0.1][36064] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] guessed: [.....2] [ip4][..udp] [......127.0.0.1][36320] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][] - idle: [.....2] [ip4][..udp] [......127.0.0.1][36320] -> [......127.0.0.1][25826] + idle: [.....2] [ip4][..udp] [......127.0.0.1][36320] -> [......127.0.0.1][25826] idle: [.....1] [ip4][..udp] [......127.0.0.1][36576] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..udp] [......127.0.0.1][54138] -> [......127.0.0.1][25826] + new: [.....6] [ip4][..udp] [......127.0.0.1][54138] -> [......127.0.0.1][25826] detected: [.....6] [ip4][..udp] [......127.0.0.1][54138] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][devlap.fritz.box] guessed: [.....4] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] [collectd][Unknown][System][Acceptable][] - idle: [.....4] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] + idle: [.....4] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] guessed: [.....5] [ip4][..udp] [.192.168.178.35][39577] -> [..239.192.74.66][25826] [collectd][Unknown][System][Acceptable][] - idle: [.....5] [ip4][..udp] [.192.168.178.35][39577] -> [..239.192.74.66][25826] - new: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] + idle: [.....5] [ip4][..udp] [.192.168.178.35][39577] -> [..239.192.74.66][25826] + new: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] detected: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][devlap.fritz.box] update: [.....6] [ip4][..udp] [......127.0.0.1][54138] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] update: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] @@ -45,7 +45,7 @@ [ENTROPIES...: 4.5,4.6,4.6,4.7,4.5,4.5,4.4,4.6,4.6,4.6,4.6,4.5,4.5,4.5,4.6,4.6,4.6,4.6,4.5,4.5,4.4,4.6,4.5,4.6,4.6,4.6,4.6,4.5,4.6,4.6,4.6,4.6] update: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] update: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] - new: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] + new: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] detected: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable][devlap.fritz.box] update: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] update: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] @@ -54,7 +54,7 @@ DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 3|detection-updates: 0|updates: 13] update: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] update: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] - new: [.....9] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] + new: [.....9] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] detected: [.....9] [ip4][..udp] [.192.168.178.35][39576] -> [..239.192.74.66][25826] [collectd][Unknown][System][Acceptable][] idle: [.....7] [ip4][..udp] [......127.0.0.1][35988] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] idle: [.....8] [ip4][..udp] [......127.0.0.1][36832] -> [......127.0.0.1][25826] [collectd][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/corba.pcap.out b/test/results/flow-info/default/corba.pcap.out index e3d830343..6a518cf84 100644 --- a/test/results/flow-info/default/corba.pcap.out +++ b/test/results/flow-info/default/corba.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.101.0.2][.8726] -> [.....10.102.0.2][..900] + new: [.....1] [ip4][..tcp] [.....10.101.0.2][.8726] -> [.....10.102.0.2][..900] detected: [.....1] [ip4][..tcp] [.....10.101.0.2][.8726] -> [.....10.102.0.2][..900] [Corba][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..tcp] [.....10.101.0.2][.8727] -> [.....10.102.0.2][.1049] + new: [.....2] [ip4][..tcp] [.....10.101.0.2][.8727] -> [.....10.102.0.2][.1049] detected: [.....2] [ip4][..tcp] [.....10.101.0.2][.8727] -> [.....10.102.0.2][.1049] [Corba][Unknown][RPC][Acceptable] - new: [.....3] [ip4][..tcp] [.....10.101.0.2][.8728] -> [.....10.102.0.2][61191] + new: [.....3] [ip4][..tcp] [.....10.101.0.2][.8728] -> [.....10.102.0.2][61191] detected: [.....3] [ip4][..tcp] [.....10.101.0.2][.8728] -> [.....10.102.0.2][61191] [Corba][Unknown][RPC][Acceptable] end: [.....1] [ip4][..tcp] [.....10.101.0.2][.8726] -> [.....10.102.0.2][..900] [Corba][Unknown][RPC][Acceptable] end: [.....2] [ip4][..tcp] [.....10.101.0.2][.8727] -> [.....10.102.0.2][.1049] [Corba][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/cpha.pcap.out b/test/results/flow-info/default/cpha.pcap.out index 02dd55f00..73db98c0b 100644 --- a/test/results/flow-info/default/cpha.pcap.out +++ b/test/results/flow-info/default/cpha.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [........0.0.0.0][.8116] -> [.....172.21.3.0][.8116] + new: [.....1] [ip4][..udp] [........0.0.0.0][.8116] -> [.....172.21.3.0][.8116] detected: [.....1] [ip4][..udp] [........0.0.0.0][.8116] -> [.....172.21.3.0][.8116] [CPHA][Unknown][Network][Fun] idle: [.....1] [ip4][..udp] [........0.0.0.0][.8116] -> [.....172.21.3.0][.8116] [CPHA][Unknown][Network][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/crawler_false_positive.pcapng.out b/test/results/flow-info/default/crawler_false_positive.pcapng.out index e4ea2b812..4421ebcb5 100644 --- a/test/results/flow-info/default/crawler_false_positive.pcapng.out +++ b/test/results/flow-info/default/crawler_false_positive.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.12.156][38291] -> [..93.184.220.29][...80] + new: [.....1] [ip4][..tcp] [.192.168.12.156][38291] -> [..93.184.220.29][...80] detected: [.....1] [ip4][..tcp] [.192.168.12.156][38291] -> [..93.184.220.29][...80] [HTTP][Edgecast][Web][Acceptable][] RISK: HTTP Susp User-Agent detection-update: [.....1] [ip4][..tcp] [.192.168.12.156][38291] -> [..93.184.220.29][...80] [HTTP.OCSP][Edgecast][Web][Safe][ocsp.digicert.com] diff --git a/test/results/flow-info/default/crynet.pcap.out b/test/results/flow-info/default/crynet.pcap.out index 38b5f0c40..fefdc72c9 100644 --- a/test/results/flow-info/default/crynet.pcap.out +++ b/test/results/flow-info/default/crynet.pcap.out @@ -1,34 +1,34 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][61837] -> [..78.159.118.97][25383] + new: [.....1] [ip4][..udp] [..192.168.2.100][61837] -> [..78.159.118.97][25383] detected: [.....1] [ip4][..udp] [..192.168.2.100][61837] -> [..78.159.118.97][25383] [CryNetwork][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][56333] -> [...37.58.56.245][20250] + new: [.....2] [ip4][..udp] [..192.168.2.100][56333] -> [...37.58.56.245][20250] detected: [.....2] [ip4][..udp] [..192.168.2.100][56333] -> [...37.58.56.245][20250] [CryNetwork][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][61837] -> [..78.159.118.97][25383] [CryNetwork][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.2.100][56970] -> [..84.16.230.222][28665] + new: [.....3] [ip4][..udp] [..192.168.2.100][56970] -> [..84.16.230.222][28665] detected: [.....3] [ip4][..udp] [..192.168.2.100][56970] -> [..84.16.230.222][28665] [CryNetwork][Unknown][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][56333] -> [...37.58.56.245][20250] [CryNetwork][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [..192.168.2.100][55645] -> [...78.159.98.94][28375] + new: [.....4] [ip4][..udp] [..192.168.2.100][55645] -> [...78.159.98.94][28375] detected: [.....4] [ip4][..udp] [..192.168.2.100][55645] -> [...78.159.98.94][28375] [CryNetwork][Unknown][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][56970] -> [..84.16.230.222][28665] [CryNetwork][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [..192.168.2.100][60751] -> [..84.16.248.143][30098] + new: [.....5] [ip4][..udp] [..192.168.2.100][60751] -> [..84.16.248.143][30098] detected: [.....5] [ip4][..udp] [..192.168.2.100][60751] -> [..84.16.248.143][30098] [CryNetwork][Unknown][Game][Fun] idle: [.....4] [ip4][..udp] [..192.168.2.100][55645] -> [...78.159.98.94][28375] [CryNetwork][Unknown][Game][Fun] - new: [.....6] [ip4][..udp] [..192.168.2.100][60224] -> [.78.159.106.139][28343] + new: [.....6] [ip4][..udp] [..192.168.2.100][60224] -> [.78.159.106.139][28343] detected: [.....6] [ip4][..udp] [..192.168.2.100][60224] -> [.78.159.106.139][28343] [CryNetwork][Unknown][Game][Fun] idle: [.....5] [ip4][..udp] [..192.168.2.100][60751] -> [..84.16.248.143][30098] [CryNetwork][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..udp] [..192.168.2.100][55460] -> [.78.159.118.143][21931] + new: [.....7] [ip4][..udp] [..192.168.2.100][55460] -> [.78.159.118.143][21931] detected: [.....7] [ip4][..udp] [..192.168.2.100][55460] -> [.78.159.118.143][21931] [CryNetwork][Unknown][Game][Fun] idle: [.....6] [ip4][..udp] [..192.168.2.100][60224] -> [.78.159.106.139][28343] [CryNetwork][Unknown][Game][Fun] idle: [.....7] [ip4][..udp] [..192.168.2.100][55460] -> [.78.159.118.143][21931] [CryNetwork][Unknown][Game][Fun] diff --git a/test/results/flow-info/default/custom_categories.pcapng.out b/test/results/flow-info/default/custom_categories.pcapng.out index a10d5e7be..cc3f6efb6 100644 --- a/test/results/flow-info/default/custom_categories.pcapng.out +++ b/test/results/flow-info/default/custom_categories.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [..........................2001:db8:1::1][64720] -> [........................2001:db8:200::1][20868] + new: [.....1] [ip6][..tcp] [..........................2001:db8:1::1][64720] -> [........................2001:db8:200::1][20868] detected: [.....1] [ip6][..tcp] [..........................2001:db8:1::1][64720] -> [........................2001:db8:200::1][20868] [SSH][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip6][..tcp] [..........................2001:db8:1::1][64720] -> [........................2001:db8:200::1][20868] [SSH][Unknown][RemoteAccess][Acceptable] @@ -20,7 +20,7 @@ [ENTROPIES...: 3.4,4.0,3.8,4.4,4.3,6.7,6.2,3.8,4.1,4.5,4.2,6.6,6.5,3.8,4.1,6.4,6.4,3.8,4.6,5.1,3.8,4.1,6.4,4.0,4.1,4.1,4.1,7.6,3.8,4.7,3.8,5.1] DAEMON-EVENT: [Processed: 62 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..tcp] [..172.26.219.44][58639] -> [..172.30.69.103][...22] + new: [.....2] [ip4][..tcp] [..172.26.219.44][58639] -> [..172.30.69.103][...22] detected: [.....2] [ip4][..tcp] [..172.26.219.44][58639] -> [..172.30.69.103][...22] [SSH][Unknown][RemoteAccess][Acceptable] RISK: SSH Obsolete Cli Vers/Cipher detection-update: [.....2] [ip4][..tcp] [..172.26.219.44][58639] -> [..172.30.69.103][...22] [SSH][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/custom_risk_mask.pcapng.out b/test/results/flow-info/default/custom_risk_mask.pcapng.out index 3c72ec460..ff4112f81 100644 --- a/test/results/flow-info/default/custom_risk_mask.pcapng.out +++ b/test/results/flow-info/default/custom_risk_mask.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [...............fe80::7c0:e74e:87c3:5d93][.6741] -> [..............................ff02::1:3][.5355] + new: [.....1] [ip6][..udp] [...............fe80::7c0:e74e:87c3:5d93][.6741] -> [..............................ff02::1:3][.5355] detected: [.....1] [ip6][..udp] [...............fe80::7c0:e74e:87c3:5d93][.6741] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [.....2] [ip6][..udp] [..............fe80::356b:e047:3695:f741][16765] -> [..............................ff02::1:3][.5355] + new: [.....2] [ip6][..udp] [..............fe80::356b:e047:3695:f741][16765] -> [..............................ff02::1:3][.5355] detected: [.....2] [ip6][..udp] [..............fe80::356b:e047:3695:f741][16765] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected idle: [.....1] [ip6][..udp] [...............fe80::7c0:e74e:87c3:5d93][.6741] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/custom_rules_ipv6.pcapng.out b/test/results/flow-info/default/custom_rules_ipv6.pcapng.out index bf6a69243..24767bdd3 100644 --- a/test/results/flow-info/default/custom_rules_ipv6.pcapng.out +++ b/test/results/flow-info/default/custom_rules_ipv6.pcapng.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [.........3ffe:507::1:200:86ff:fe05:80da][21554] -> [......................3ffe:501:4819::42][.5333] + new: [.....1] [ip6][..udp] [.........3ffe:507::1:200:86ff:fe05:80da][21554] -> [......................3ffe:501:4819::42][.5333] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][..100] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][.1991] + new: [.....2] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][..100] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][.1991] detected: [.....2] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][..100] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][.1991] [DTLS][Unknown][Web][Safe] - new: [.....3] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][36098] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][50621] + new: [.....3] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][36098] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][50621] detected: [.....3] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][36098] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][50621] [DTLS][Unknown][Web][Safe] not-detected: [.....1] [ip6][..udp] [.........3ffe:507::1:200:86ff:fe05:80da][21554] -> [......................3ffe:501:4819::42][.5333] [Unknown][Unknown][Unrated] - idle: [.....1] [ip6][..udp] [.........3ffe:507::1:200:86ff:fe05:80da][21554] -> [......................3ffe:501:4819::42][.5333] + idle: [.....1] [ip6][..udp] [.........3ffe:507::1:200:86ff:fe05:80da][21554] -> [......................3ffe:501:4819::42][.5333] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 1|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12718] -> [................................ff02::1][26993] - new: [.....5] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12717] -> [................................ff02::1][64315] + new: [.....4] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12718] -> [................................ff02::1][26993] + new: [.....5] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12717] -> [................................ff02::1][64315] idle: [.....2] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][..100] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][.1991] [DTLS][Unknown][Web][Safe] idle: [.....3] [ip6][..udp] [247f:855b:5e16:3caf:3f2c:4134:9592:661b][36098] -> [.21bc:b273:7f68:88d7:77a8:585:3990:927b][50621] [DTLS][Unknown][Web][Safe] not-detected: [.....4] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12718] -> [................................ff02::1][26993] [Unknown][Unknown][Unrated] - idle: [.....4] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12718] -> [................................ff02::1][26993] + idle: [.....4] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12718] -> [................................ff02::1][26993] not-detected: [.....5] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12717] -> [................................ff02::1][64315] [Unknown][Unknown][Unrated] - idle: [.....5] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12717] -> [................................ff02::1][64315] + idle: [.....5] [ip6][..udp] [..............fe80::76ac:b9ff:fe6c:c124][12717] -> [................................ff02::1][64315] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/custom_rules_same-ip_multiple_ports.pcapng.out b/test/results/flow-info/default/custom_rules_same-ip_multiple_ports.pcapng.out index 0892bc8fd..3057be65d 100644 --- a/test/results/flow-info/default/custom_rules_same-ip_multiple_ports.pcapng.out +++ b/test/results/flow-info/default/custom_rules_same-ip_multiple_ports.pcapng.out @@ -1,18 +1,18 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.245][56866] -> [........3.3.3.3][..443] - new: [.....2] [ip4][..tcp] [..192.168.1.245][59682] -> [........3.3.3.3][..444] + new: [.....1] [ip4][..tcp] [..192.168.1.245][56866] -> [........3.3.3.3][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.245][59682] -> [........3.3.3.3][..444] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..192.168.1.245][58288] -> [........3.3.3.3][..446] + new: [.....3] [ip4][..tcp] [..192.168.1.245][58288] -> [........3.3.3.3][..446] not-detected: [.....3] [ip4][..tcp] [..192.168.1.245][58288] -> [........3.3.3.3][..446] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....3] [ip4][..tcp] [..192.168.1.245][58288] -> [........3.3.3.3][..446] + idle: [.....3] [ip4][..tcp] [..192.168.1.245][58288] -> [........3.3.3.3][..446] guessed: [.....1] [ip4][..tcp] [..192.168.1.245][56866] -> [........3.3.3.3][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [..192.168.1.245][56866] -> [........3.3.3.3][..443] + idle: [.....1] [ip4][..tcp] [..192.168.1.245][56866] -> [........3.3.3.3][..443] not-detected: [.....2] [ip4][..tcp] [..192.168.1.245][59682] -> [........3.3.3.3][..444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....2] [ip4][..tcp] [..192.168.1.245][59682] -> [........3.3.3.3][..444] + idle: [.....2] [ip4][..tcp] [..192.168.1.245][59682] -> [........3.3.3.3][..444] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/dazn.pcapng.out b/test/results/flow-info/default/dazn.pcapng.out index f067af3f8..ecca8fa1f 100644 --- a/test/results/flow-info/default/dazn.pcapng.out +++ b/test/results/flow-info/default/dazn.pcapng.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.128][54020] -> [...52.84.223.58][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.128][54020] -> [...52.84.223.58][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.128][54020] -> [...52.84.223.58][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][www.dazn.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.128][54020] -> [...52.84.223.58][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][www.dazn.com] - new: [.....2] [ip4][..tcp] [..192.168.1.128][46036] -> [..13.226.244.27][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.128][46036] -> [..13.226.244.27][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.128][46036] -> [..13.226.244.27][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][user-profile.ar.indazn.com] detection-update: [.....2] [ip4][..tcp] [..192.168.1.128][46036] -> [..13.226.244.27][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][user-profile.ar.indazn.com] - new: [.....3] [ip4][..tcp] [..192.168.1.128][40882] -> [..13.226.244.30][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.128][40882] -> [..13.226.244.30][..443] detected: [.....3] [ip4][..tcp] [..192.168.1.128][40882] -> [..13.226.244.30][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][subscriptions-service.dazn-api.com] detection-update: [.....3] [ip4][..tcp] [..192.168.1.128][40882] -> [..13.226.244.30][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun][subscriptions-service.dazn-api.com] idle: [.....2] [ip4][..tcp] [..192.168.1.128][46036] -> [..13.226.244.27][..443] [TLS.Dazn][AmazonAWS][Streaming][Fun] diff --git a/test/results/flow-info/default/dcerpc.pcap.out b/test/results/flow-info/default/dcerpc.pcap.out index 42f948870..936114a3b 100644 --- a/test/results/flow-info/default/dcerpc.pcap.out +++ b/test/results/flow-info/default/dcerpc.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.1.11][49155] -> [...192.168.1.20][34964] + new: [.....1] [ip4][..udp] [...192.168.1.11][49155] -> [...192.168.1.20][34964] detected: [.....1] [ip4][..udp] [...192.168.1.11][49155] -> [...192.168.1.20][34964] [RPC][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.1.20][49161] -> [...192.168.1.11][49155] + new: [.....2] [ip4][..udp] [...192.168.1.20][49161] -> [...192.168.1.11][49155] detected: [.....2] [ip4][..udp] [...192.168.1.20][49161] -> [...192.168.1.11][49155] [RPC][Unknown][RPC][Acceptable] - new: [.....3] [ip4][..udp] [...192.168.1.20][49162] -> [...192.168.1.11][34964] + new: [.....3] [ip4][..udp] [...192.168.1.20][49162] -> [...192.168.1.11][34964] detected: [.....3] [ip4][..udp] [...192.168.1.20][49162] -> [...192.168.1.11][34964] [RPC][Unknown][RPC][Acceptable] - new: [.....4] [ip4][..udp] [...192.168.1.11][49154] -> [...192.168.1.20][49162] + new: [.....4] [ip4][..udp] [...192.168.1.11][49154] -> [...192.168.1.20][49162] detected: [.....4] [ip4][..udp] [...192.168.1.11][49154] -> [...192.168.1.20][49162] [RPC][Unknown][RPC][Acceptable] idle: [.....4] [ip4][..udp] [...192.168.1.11][49154] -> [...192.168.1.20][49162] [RPC][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..udp] [...192.168.1.20][49161] -> [...192.168.1.11][49155] [RPC][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/dhcp-fuzz.pcapng.out b/test/results/flow-info/default/dhcp-fuzz.pcapng.out index 58eff89e7..4d0560651 100644 --- a/test/results/flow-info/default/dhcp-fuzz.pcapng.out +++ b/test/results/flow-info/default/dhcp-fuzz.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [192.168.155.104][...68] -> [255.255.255.255][...67] + new: [.....1] [ip4][..udp] [192.168.155.104][...68] -> [255.255.255.255][...67] guessed: [.....1] [ip4][..udp] [192.168.155.104][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][] - idle: [.....1] [ip4][..udp] [192.168.155.104][...68] -> [255.255.255.255][...67] + idle: [.....1] [ip4][..udp] [192.168.155.104][...68] -> [255.255.255.255][...67] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/diameter.pcap.out b/test/results/flow-info/default/diameter.pcap.out index a84f3eb15..8802d1e57 100644 --- a/test/results/flow-info/default/diameter.pcap.out +++ b/test/results/flow-info/default/diameter.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.201.9.245][50957] -> [....10.201.9.11][.3868] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...10.201.9.245][50957] -> [....10.201.9.11][.3868] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...10.201.9.245][50957] -> [....10.201.9.11][.3868] [Diameter][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [...10.201.9.245][50957] -> [....10.201.9.11][.3868] [Diameter][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/discord.pcap.out b/test/results/flow-info/default/discord.pcap.out index 11f081945..cbedc9278 100644 --- a/test/results/flow-info/default/discord.pcap.out +++ b/test/results/flow-info/default/discord.pcap.out @@ -1,28 +1,28 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] + new: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] detected: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] [TLS.Discord][Cloudflare][Collaborative][Fun][discord.com] detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] [TLS.Discord][Cloudflare][Collaborative][Fun][discord.com] detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] [TLS.Discord][Cloudflare][Collaborative][Fun][discord.com] RISK: TLS Cert Expired DAEMON-EVENT: [Processed: 7 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.154][50004] + new: [.....2] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.154][50004] detected: [.....2] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.154][50004] [Discord][Discord][Collaborative][Fun] - new: [.....3] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.139][50004] + new: [.....3] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.139][50004] detected: [.....3] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.139][50004] [Discord][Discord][Collaborative][Fun] - new: [.....4] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.237.138][50004] + new: [.....4] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.237.138][50004] detected: [.....4] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.237.138][50004] [Discord][Discord][Collaborative][Fun] - new: [.....5] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.7][50004] + new: [.....5] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.7][50004] detected: [.....5] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.7][50004] [Discord][Discord][Collaborative][Fun] - new: [.....6] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.5][50004] + new: [.....6] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.5][50004] detected: [.....6] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.5][50004] [Discord][Discord][Collaborative][Fun] - new: [.....7] [ip4][..udp] [..192.168.2.100][56271] -> [...66.22.237.11][50004] + new: [.....7] [ip4][..udp] [..192.168.2.100][56271] -> [...66.22.237.11][50004] detected: [.....7] [ip4][..udp] [..192.168.2.100][56271] -> [...66.22.237.11][50004] [Discord][Discord][Collaborative][Fun] idle: [.....1] [ip4][..tcp] [......10.0.2.15][42834] -> [162.159.128.233][..443] [TLS.Discord][Cloudflare][Collaborative][Fun] RISK: TLS Cert Expired DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] + new: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] detected: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [.....7] [ip4][..udp] [..192.168.2.100][56271] -> [...66.22.237.11][50004] [Discord][Discord][Collaborative][Fun] idle: [.....6] [ip4][..udp] [..192.168.2.100][56271] -> [....66.22.241.5][50004] [Discord][Discord][Collaborative][Fun] @@ -30,25 +30,25 @@ idle: [.....4] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.237.138][50004] [Discord][Discord][Collaborative][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.139][50004] [Discord][Discord][Collaborative][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][56271] -> [..66.22.244.154][50004] [Discord][Discord][Collaborative][Fun] - new: [.....9] [ip4][..udp] [..192.168.2.100][64837] -> [.35.214.238.161][50001] + new: [.....9] [ip4][..udp] [..192.168.2.100][64837] -> [.35.214.238.161][50001] detected: [.....9] [ip4][..udp] [..192.168.2.100][64837] -> [.35.214.238.161][50001] [Discord][GoogleCloud][Collaborative][Fun] - new: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] + new: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] detected: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] + new: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] detected: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [.....9] [ip4][..udp] [..192.168.2.100][64837] -> [.35.214.238.161][50001] [Discord][GoogleCloud][Collaborative][Fun] - new: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] + new: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] detected: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] + new: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] detected: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [.....9] [ip4][..udp] [..192.168.2.100][64837] -> [.35.214.238.161][50001] [Discord][GoogleCloud][Collaborative][Fun] - new: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] + new: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] detected: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....10] [ip4][..udp] [..192.168.2.100][55085] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [.....8] [ip4][..udp] [..192.168.2.100][57955] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] @@ -56,30 +56,30 @@ update: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] + new: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] detected: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....11] [ip4][..udp] [..192.168.2.100][52283] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] + new: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] detected: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....13] [ip4][..udp] [..192.168.2.100][57956] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....12] [ip4][..udp] [..192.168.2.100][50199] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....17] [ip4][..udp] [..192.168.2.100][61392] -> [..66.22.196.173][50004] + new: [....17] [ip4][..udp] [..192.168.2.100][61392] -> [..66.22.196.173][50004] detected: [....17] [ip4][..udp] [..192.168.2.100][61392] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] + new: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] detected: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....14] [ip4][..udp] [..192.168.2.100][53459] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....17] [ip4][..udp] [..192.168.2.100][61392] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] + new: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] detected: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....15] [ip4][..udp] [..192.168.2.100][61435] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] @@ -87,84 +87,84 @@ update: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] DAEMON-EVENT: [Processed: 186 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 19|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 25] - new: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] + new: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] detected: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....17] [ip4][..udp] [..192.168.2.100][61392] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....16] [ip4][..udp] [..192.168.2.100][58322] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] + new: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] detected: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....18] [ip4][..udp] [..192.168.2.100][63362] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] + new: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] detected: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....19] [ip4][..udp] [..192.168.2.100][50335] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] + new: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] detected: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] + new: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] detected: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....20] [ip4][..udp] [..192.168.2.100][62379] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....21] [ip4][..udp] [..192.168.2.100][62844] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] + new: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] detected: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] + new: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] detected: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....22] [ip4][..udp] [..192.168.2.100][59891] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....23] [ip4][..udp] [..192.168.2.100][61985] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] + new: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] detected: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] + new: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] detected: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....25] [ip4][..udp] [..192.168.2.100][55432] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....24] [ip4][..udp] [..192.168.2.100][57764] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] + new: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] detected: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....26] [ip4][..udp] [..192.168.2.100][61060] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] DAEMON-EVENT: [Processed: 336 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 29|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 48] - new: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] + new: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] detected: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....27] [ip4][..udp] [..192.168.2.100][63893] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....31] [ip4][..udp] [..192.168.2.100][49648] -> [..66.22.196.173][50004] + new: [....31] [ip4][..udp] [..192.168.2.100][49648] -> [..66.22.196.173][50004] detected: [....31] [ip4][..udp] [..192.168.2.100][49648] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....32] [ip4][..udp] [..192.168.2.100][54950] -> [..66.22.196.173][50004] + new: [....32] [ip4][..udp] [..192.168.2.100][54950] -> [..66.22.196.173][50004] detected: [....32] [ip4][..udp] [..192.168.2.100][54950] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....28] [ip4][..udp] [..192.168.2.100][52323] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....29] [ip4][..udp] [..192.168.2.100][58753] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....31] [ip4][..udp] [..192.168.2.100][49648] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....33] [ip4][..udp] [..192.168.2.100][59240] -> [..66.22.196.173][50004] + new: [....33] [ip4][..udp] [..192.168.2.100][59240] -> [..66.22.196.173][50004] detected: [....33] [ip4][..udp] [..192.168.2.100][59240] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....30] [ip4][..udp] [..192.168.2.100][65053] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....32] [ip4][..udp] [..192.168.2.100][54950] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] update: [....31] [ip4][..udp] [..192.168.2.100][49648] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] - new: [....34] [ip4][..udp] [..192.168.2.100][62481] -> [..66.22.196.173][50004] + new: [....34] [ip4][..udp] [..192.168.2.100][62481] -> [..66.22.196.173][50004] detected: [....34] [ip4][..udp] [..192.168.2.100][62481] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....32] [ip4][..udp] [..192.168.2.100][54950] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] idle: [....33] [ip4][..udp] [..192.168.2.100][59240] -> [..66.22.196.173][50004] [Discord][Discord][Collaborative][Fun] diff --git a/test/results/flow-info/default/dnp3.pcap.out b/test/results/flow-info/default/dnp3.pcap.out index 3c88505cd..8b1077b27 100644 --- a/test/results/flow-info/default/dnp3.pcap.out +++ b/test/results/flow-info/default/dnp3.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.8][.2789] -> [.......10.0.0.3][20000] + new: [.....1] [ip4][..tcp] [.......10.0.0.8][.2789] -> [.......10.0.0.3][20000] detected: [.....1] [ip4][..tcp] [.......10.0.0.8][.2789] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....1] [ip4][..tcp] [.......10.0.0.8][.2789] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [ENTROPIES...: 4.3,4.3,4.3,4.7,4.7,4.7,4.1,4.1,4.1,4.9,4.9,4.9,4.1,4.1,4.1,4.8,4.8,4.8,5.1,5.1,5.1,4.1,4.1,4.1,4.8,4.8,4.8,4.1,4.1,4.1,4.9,4.9] DAEMON-EVENT: [Processed: 39 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [.......10.0.0.8][.2803] -> [.......10.0.0.3][20000] + new: [.....2] [ip4][..tcp] [.......10.0.0.8][.2803] -> [.......10.0.0.3][20000] detected: [.....2] [ip4][..tcp] [.......10.0.0.8][.2803] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....2] [ip4][..tcp] [.......10.0.0.8][.2803] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy @@ -29,7 +29,7 @@ [ENTROPIES...: 4.3,4.3,4.3,4.6,4.6,4.6,4.0,4.0,4.0,4.6,4.6,4.6,4.1,4.1,4.1,4.8,4.8,4.8,4.1,4.1,4.1,4.9,4.9,4.9,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1] DAEMON-EVENT: [Processed: 78 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [.......10.0.0.8][.2828] -> [.......10.0.0.3][20000] + new: [.....3] [ip4][..tcp] [.......10.0.0.8][.2828] -> [.......10.0.0.3][20000] detected: [.....3] [ip4][..tcp] [.......10.0.0.8][.2828] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] end: [.....2] [ip4][..tcp] [.......10.0.0.8][.2803] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....3] [ip4][..tcp] [.......10.0.0.8][.2828] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] @@ -44,7 +44,7 @@ [ENTROPIES...: 4.2,4.2,4.2,4.7,4.7,4.7,4.1,4.1,4.1,4.9,4.9,4.9,4.1,4.1,4.1,4.8,4.8,4.8,5.1,5.1,5.1,4.2,4.2,4.2,4.8,4.8,4.8,4.1,4.1,4.1,4.9,4.9] DAEMON-EVENT: [Processed: 216 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [.......10.0.0.9][.1080] -> [.......10.0.0.3][20000] + new: [.....4] [ip4][..tcp] [.......10.0.0.9][.1080] -> [.......10.0.0.3][20000] detected: [.....4] [ip4][..tcp] [.......10.0.0.9][.1080] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....4] [ip4][..tcp] [.......10.0.0.9][.1080] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy @@ -58,7 +58,7 @@ [ENTROPIES...: 4.2,4.2,4.2,4.7,4.7,4.7,4.2,4.2,4.2,4.9,4.9,4.9,4.7,4.7,4.7,4.8,4.8,4.8,4.2,4.2,4.2,4.9,4.9,4.9,4.2,4.2,4.2,4.9,4.9,4.9,4.7,4.7] DAEMON-EVENT: [Processed: 351 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [.......10.0.0.8][.1086] -> [.......10.0.0.3][20000] + new: [.....5] [ip4][..tcp] [.......10.0.0.8][.1086] -> [.......10.0.0.3][20000] detected: [.....5] [ip4][..tcp] [.......10.0.0.8][.1086] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....5] [ip4][..tcp] [.......10.0.0.8][.1086] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy @@ -72,12 +72,12 @@ [ENTROPIES...: 4.2,4.2,4.2,4.7,4.7,4.7,4.1,4.1,4.1,4.9,4.9,4.9,4.2,4.2,4.2,4.8,4.8,4.8,4.9,4.9,4.9,4.1,4.1,4.1,4.8,4.8,4.8,4.2,4.2,4.2,5.1,5.1] DAEMON-EVENT: [Processed: 444 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [.......10.0.0.8][.1159] -> [.......10.0.0.3][20000] + new: [.....6] [ip4][..tcp] [.......10.0.0.8][.1159] -> [.......10.0.0.3][20000] detected: [.....6] [ip4][..tcp] [.......10.0.0.8][.1159] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] idle: [.....1] [ip4][..tcp] [.......10.0.0.8][.2789] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] DAEMON-EVENT: [Processed: 471 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [.......10.0.0.8][.1184] -> [.......10.0.0.3][20000] + new: [.....7] [ip4][..tcp] [.......10.0.0.8][.1184] -> [.......10.0.0.3][20000] detected: [.....7] [ip4][..tcp] [.......10.0.0.8][.1184] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] idle: [.....3] [ip4][..tcp] [.......10.0.0.8][.2828] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....7] [ip4][..tcp] [.......10.0.0.8][.1184] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] @@ -92,7 +92,7 @@ [ENTROPIES...: 4.2,4.2,4.2,4.6,4.6,4.6,4.0,4.0,4.0,4.8,4.8,4.8,4.1,4.1,4.1,4.9,4.9,4.9,4.9,4.9,4.9,4.1,4.1,4.1,4.9,4.9,4.9,4.9,4.9,4.9,4.1,4.1] DAEMON-EVENT: [Processed: 504 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..tcp] [.......10.0.0.9][.1084] -> [.......10.0.0.3][20000] + new: [.....8] [ip4][..tcp] [.......10.0.0.9][.1084] -> [.......10.0.0.3][20000] detected: [.....8] [ip4][..tcp] [.......10.0.0.9][.1084] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] analyse: [.....8] [ip4][..tcp] [.......10.0.0.9][.1084] -> [.......10.0.0.3][20000] [DNP3][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/dns-exf.pcap.out b/test/results/flow-info/default/dns-exf.pcap.out index f8438a96b..e41b0d900 100644 --- a/test/results/flow-info/default/dns-exf.pcap.out +++ b/test/results/flow-info/default/dns-exf.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.225][45290] -> [..192.168.2.134][...53] + new: [.....1] [ip4][..udp] [..192.168.2.225][45290] -> [..192.168.2.134][...53] detected: [.....1] [ip4][..udp] [..192.168.2.225][45290] -> [..192.168.2.134][...53] [DNS][Unknown][Network][Acceptable][4sicn03_2qaa3rlc3qudhh0aavjycxwakjehelu5klueow0zjxulgage-.4s2fgaaaa__-.test.txt] RISK: Susp DNS Traffic, Non-Printable/Invalid Chars Detected detection-update: [.....1] [ip4][..udp] [..192.168.2.225][45290] -> [..192.168.2.134][...53] [DNS][Unknown][Network][Acceptable][4sicn03_2qaa3rlc3qudhh0aavjycxwakjehelu5klueow0zjxulgage-.4s2fgaaaa__-.test.txt] diff --git a/test/results/flow-info/default/dns-google-nsid.pcapng.out b/test/results/flow-info/default/dns-google-nsid.pcapng.out index 6b641a453..8e3f2f6e9 100644 --- a/test/results/flow-info/default/dns-google-nsid.pcapng.out +++ b/test/results/flow-info/default/dns-google-nsid.pcapng.out @@ -1,28 +1,28 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [...2001:b07:a3d:c112:b332:20d:89ab:105e][41624] -> [...................2001:4860:4860::8844][...53] + new: [.....1] [ip6][..udp] [...2001:b07:a3d:c112:b332:20d:89ab:105e][41624] -> [...................2001:4860:4860::8844][...53] detected: [.....1] [ip6][..udp] [...2001:b07:a3d:c112:b332:20d:89ab:105e][41624] -> [...................2001:4860:4860::8844][...53] [DNS][Google][Network][Acceptable][] detection-update: [.....1] [ip6][..udp] [...2001:b07:a3d:c112:b332:20d:89ab:105e][41624] -> [...................2001:4860:4860::8844][...53] [DNS][Google][Network][Acceptable][] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....2] [ip4][..udp] [...192.168.1.29][58580] -> [........8.8.4.4][...53] + new: [.....2] [ip4][..udp] [...192.168.1.29][58580] -> [........8.8.4.4][...53] detected: [.....2] [ip4][..udp] [...192.168.1.29][58580] -> [........8.8.4.4][...53] [DNS.ntop][Google][Network][Safe][www.ntop.org] detection-update: [.....2] [ip4][..udp] [...192.168.1.29][58580] -> [........8.8.4.4][...53] [DNS.ntop][Google][Network][Safe][www.ntop.org] - new: [.....3] [ip4][..udp] [...192.168.1.29][62500] -> [........8.8.4.4][...53] + new: [.....3] [ip4][..udp] [...192.168.1.29][62500] -> [........8.8.4.4][...53] detected: [.....3] [ip4][..udp] [...192.168.1.29][62500] -> [........8.8.4.4][...53] [DNS.Wikipedia][Google][Network][Safe][www.wikipedia.it] detection-update: [.....3] [ip4][..udp] [...192.168.1.29][62500] -> [........8.8.4.4][...53] [DNS.Wikipedia][Google][Network][Safe][www.wikipedia.it] - new: [.....4] [ip4][..udp] [...192.168.1.29][51166] -> [........8.8.4.4][...53] + new: [.....4] [ip4][..udp] [...192.168.1.29][51166] -> [........8.8.4.4][...53] detected: [.....4] [ip4][..udp] [...192.168.1.29][51166] -> [........8.8.4.4][...53] [DNS][Google][Network][Acceptable][www.wireshark.org] detection-update: [.....4] [ip4][..udp] [...192.168.1.29][51166] -> [........8.8.4.4][...53] [DNS][Google][Network][Acceptable][www.wireshark.org] idle: [.....1] [ip6][..udp] [...2001:b07:a3d:c112:b332:20d:89ab:105e][41624] -> [...................2001:4860:4860::8844][...53] [DNS][Google][Network][Acceptable] - new: [.....5] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][46618] -> [...................2001:4860:4860::8888][...53] + new: [.....5] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][46618] -> [...................2001:4860:4860::8888][...53] detected: [.....5] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][46618] -> [...................2001:4860:4860::8888][...53] [DNS.ntop][Google][Network][Safe][www.ntop.org] detection-update: [.....5] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][46618] -> [...................2001:4860:4860::8888][...53] [DNS.ntop][Google][Network][Safe][www.ntop.org] - new: [.....6] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][44924] -> [...................2001:4860:4860::8888][...53] + new: [.....6] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][44924] -> [...................2001:4860:4860::8888][...53] detected: [.....6] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][44924] -> [...................2001:4860:4860::8888][...53] [DNS.Wikipedia][Google][Network][Safe][www.wikipedia.it] detection-update: [.....6] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][44924] -> [...................2001:4860:4860::8888][...53] [DNS.Wikipedia][Google][Network][Safe][www.wikipedia.it] - new: [.....7] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][43660] -> [...................2001:4860:4860::8888][...53] + new: [.....7] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][43660] -> [...................2001:4860:4860::8888][...53] detected: [.....7] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][43660] -> [...................2001:4860:4860::8888][...53] [DNS][Google][Network][Acceptable][www.wireshark.org] detection-update: [.....7] [ip6][..udp] [...............2a03:b0c0:2:d0::360:4001][43660] -> [...................2001:4860:4860::8888][...53] [DNS][Google][Network][Acceptable][www.wireshark.org] idle: [.....4] [ip4][..udp] [...192.168.1.29][51166] -> [........8.8.4.4][...53] [DNS][Google][Network][Acceptable] diff --git a/test/results/flow-info/default/dns-invalid-chars.pcap.out b/test/results/flow-info/default/dns-invalid-chars.pcap.out index e18c06633..1814145af 100644 --- a/test/results/flow-info/default/dns-invalid-chars.pcap.out +++ b/test/results/flow-info/default/dns-invalid-chars.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][35980] -> [......127.0.0.1][...53] + new: [.....1] [ip4][..udp] [......127.0.0.1][35980] -> [......127.0.0.1][...53] detected: [.....1] [ip4][..udp] [......127.0.0.1][35980] -> [......127.0.0.1][...53] [DNS][Unknown][Network][Acceptable][www.allyourba???arebelongto.cn] RISK: Non-Printable/Invalid Chars Detected detection-update: [.....1] [ip4][..udp] [......127.0.0.1][35980] -> [......127.0.0.1][...53] [DNS][Unknown][Network][Acceptable][www.allyourbasesare???ongto.cn] diff --git a/test/results/flow-info/default/dns-tunnel-iodine.pcap.out b/test/results/flow-info/default/dns-tunnel-iodine.pcap.out index c772747c2..f72a03799 100644 --- a/test/results/flow-info/default/dns-tunnel-iodine.pcap.out +++ b/test/results/flow-info/default/dns-tunnel-iodine.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......10.0.2.30][44639] -> [......10.0.2.20][...53] + new: [.....1] [ip4][..udp] [......10.0.2.30][44639] -> [......10.0.2.20][...53] detected: [.....1] [ip4][..udp] [......10.0.2.30][44639] -> [......10.0.2.20][...53] [DNS][Unknown][Network][Acceptable][vaaaakardli.pirate.sea] detection-update: [.....1] [ip4][..udp] [......10.0.2.30][44639] -> [......10.0.2.20][...53] [DNS][Unknown][Network][Acceptable][vaaaakardli.pirate.sea] RISK: Susp DNS Traffic, Minor Issues diff --git a/test/results/flow-info/default/dns2tcp_tunnel.pcap.out b/test/results/flow-info/default/dns2tcp_tunnel.pcap.out index a6d3ee657..34487be18 100644 --- a/test/results/flow-info/default/dns2tcp_tunnel.pcap.out +++ b/test/results/flow-info/default/dns2tcp_tunnel.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] + new: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] detected: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....1] [ip4][..tcp] [.192.168.20.211][44404] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/default/dns_ambiguous_names.pcap.out b/test/results/flow-info/default/dns_ambiguous_names.pcap.out index 47814d283..c04b5ad58 100644 --- a/test/results/flow-info/default/dns_ambiguous_names.pcap.out +++ b/test/results/flow-info/default/dns_ambiguous_names.pcap.out @@ -1,36 +1,36 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....10.200.2.11][48375] -> [........8.8.8.8][...53] + new: [.....1] [ip4][..udp] [....10.200.2.11][48375] -> [........8.8.8.8][...53] detected: [.....1] [ip4][..udp] [....10.200.2.11][48375] -> [........8.8.8.8][...53] [DNS.ApplePush][Google][Network][Acceptable][41-courier.push.apple.com] detection-update: [.....1] [ip4][..udp] [....10.200.2.11][48375] -> [........8.8.8.8][...53] [DNS.ApplePush][Google][Network][Acceptable][41-courier.push.apple.com] - new: [.....2] [ip4][..udp] [....10.200.2.11][57290] -> [........8.8.8.8][...53] + new: [.....2] [ip4][..udp] [....10.200.2.11][57290] -> [........8.8.8.8][...53] detected: [.....2] [ip4][..udp] [....10.200.2.11][57290] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][teams.skype.com] detection-update: [.....2] [ip4][..udp] [....10.200.2.11][57290] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][teams.skype.com] - new: [.....3] [ip4][..udp] [....10.200.2.11][57051] -> [........8.8.8.8][...53] + new: [.....3] [ip4][..udp] [....10.200.2.11][57051] -> [........8.8.8.8][...53] detected: [.....3] [ip4][..udp] [....10.200.2.11][57051] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][api.teams.skype.com] detection-update: [.....3] [ip4][..udp] [....10.200.2.11][57051] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][api.teams.skype.com] - new: [.....4] [ip4][..udp] [....10.200.2.11][46134] -> [........8.8.8.8][...53] + new: [.....4] [ip4][..udp] [....10.200.2.11][46134] -> [........8.8.8.8][...53] detected: [.....4] [ip4][..udp] [....10.200.2.11][46134] -> [........8.8.8.8][...53] [DNS.GoogleServices][Google][Network][Acceptable][alt2-mtalk.google.com] detection-update: [.....4] [ip4][..udp] [....10.200.2.11][46134] -> [........8.8.8.8][...53] [DNS.GoogleServices][Google][Network][Acceptable][alt2-mtalk.google.com] - new: [.....5] [ip4][..udp] [....10.200.2.11][57632] -> [........8.8.8.8][...53] + new: [.....5] [ip4][..udp] [....10.200.2.11][57632] -> [........8.8.8.8][...53] detected: [.....5] [ip4][..udp] [....10.200.2.11][57632] -> [........8.8.8.8][...53] [DNS.PlayStore][Google][Network][Safe][android.clients.google.com] detection-update: [.....5] [ip4][..udp] [....10.200.2.11][57632] -> [........8.8.8.8][...53] [DNS.PlayStore][Google][Network][Safe][android.clients.google.com] - new: [.....6] [ip4][..udp] [....10.200.2.11][42790] -> [........8.8.8.8][...53] + new: [.....6] [ip4][..udp] [....10.200.2.11][42790] -> [........8.8.8.8][...53] detected: [.....6] [ip4][..udp] [....10.200.2.11][42790] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][_.teams.microsoft.com] RISK: Non-Printable/Invalid Chars Detected detection-update: [.....6] [ip4][..udp] [....10.200.2.11][42790] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe][_.teams.microsoft.com] RISK: Non-Printable/Invalid Chars Detected, Error Code - new: [.....7] [ip4][..udp] [....10.200.2.11][44198] -> [........8.8.8.8][...53] + new: [.....7] [ip4][..udp] [....10.200.2.11][44198] -> [........8.8.8.8][...53] detected: [.....7] [ip4][..udp] [....10.200.2.11][44198] -> [........8.8.8.8][...53] [DNS.Google][Google][Network][Acceptable][wide-youtube.l.google.com] detection-update: [.....7] [ip4][..udp] [....10.200.2.11][44198] -> [........8.8.8.8][...53] [DNS.Google][Google][Network][Acceptable][wide-youtube.l.google.com] - new: [.....8] [ip4][..udp] [....10.200.2.11][52541] -> [........8.8.8.8][...53] + new: [.....8] [ip4][..udp] [....10.200.2.11][52541] -> [........8.8.8.8][...53] detected: [.....8] [ip4][..udp] [....10.200.2.11][52541] -> [........8.8.8.8][...53] [DNS.AppleSiri][Google][Network][Acceptable][guzzoni.apple.com] detection-update: [.....8] [ip4][..udp] [....10.200.2.11][52541] -> [........8.8.8.8][...53] [DNS.AppleSiri][Google][Network][Acceptable][guzzoni.apple.com] - new: [.....9] [ip4][..udp] [....10.200.2.11][53951] -> [........8.8.8.8][...53] + new: [.....9] [ip4][..udp] [....10.200.2.11][53951] -> [........8.8.8.8][...53] detected: [.....9] [ip4][..udp] [....10.200.2.11][53951] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][short.weixin.qq.com] detection-update: [.....9] [ip4][..udp] [....10.200.2.11][53951] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][short.weixin.qq.com] - new: [....10] [ip4][..udp] [....10.200.2.11][44883] -> [........8.8.8.8][...53] + new: [....10] [ip4][..udp] [....10.200.2.11][44883] -> [........8.8.8.8][...53] detected: [....10] [ip4][..udp] [....10.200.2.11][44883] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][instagram.faae1-1.fna.fbcdn.net] detection-update: [....10] [ip4][..udp] [....10.200.2.11][44883] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][instagram.faae1-1.fna.fbcdn.net] idle: [.....2] [ip4][..udp] [....10.200.2.11][57290] -> [........8.8.8.8][...53] [DNS.Teams][Google][Network][Safe] diff --git a/test/results/flow-info/default/dns_doh.pcap.out b/test/results/flow-info/default/dns_doh.pcap.out index d933c7425..d9c07a1d7 100644 --- a/test/results/flow-info/default/dns_doh.pcap.out +++ b/test/results/flow-info/default/dns_doh.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....172.20.10.4][49877] -> [.104.16.248.249][..443] + new: [.....1] [ip4][..tcp] [....172.20.10.4][49877] -> [.104.16.248.249][..443] detected: [.....1] [ip4][..tcp] [....172.20.10.4][49877] -> [.104.16.248.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com] detection-update: [.....1] [ip4][..tcp] [....172.20.10.4][49877] -> [.104.16.248.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com] analyse: [.....1] [ip4][..tcp] [....172.20.10.4][49877] -> [.104.16.248.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable] diff --git a/test/results/flow-info/default/dns_dot.pcap.out b/test/results/flow-info/default/dns_dot.pcap.out index e32784bca..09b92c4a0 100644 --- a/test/results/flow-info/default/dns_dot.pcap.out +++ b/test/results/flow-info/default/dns_dot.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.185][58290] -> [........8.8.8.8][..853] + new: [.....1] [ip4][..tcp] [..192.168.1.185][58290] -> [........8.8.8.8][..853] detected: [.....1] [ip4][..tcp] [..192.168.1.185][58290] -> [........8.8.8.8][..853] [TLS][Google][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..tcp] [..192.168.1.185][58290] -> [........8.8.8.8][..853] [TLS.DoH_DoT][Google][Network][Acceptable][] diff --git a/test/results/flow-info/default/dns_exfiltration.pcap.out b/test/results/flow-info/default/dns_exfiltration.pcap.out index bb06f643b..5cad6ddb7 100644 --- a/test/results/flow-info/default/dns_exfiltration.pcap.out +++ b/test/results/flow-info/default/dns_exfiltration.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.220.56][56373] -> [192.168.203.167][...53] + new: [.....1] [ip4][..udp] [.192.168.220.56][56373] -> [192.168.203.167][...53] detected: [.....1] [ip4][..udp] [.192.168.220.56][56373] -> [192.168.203.167][...53] [DNS][Unknown][Network][Acceptable][e1aa8f8fdb1bbe8d5e04952141f7d4f82c7e3b06dcc8b87fad7a.19e4d098dc8c618f8d81cfeb02] RISK: Susp DGA Domain name detection-update: [.....1] [ip4][..udp] [.192.168.220.56][56373] -> [192.168.203.167][...53] [DNS][Unknown][Network][Acceptable][e1aa8f8fdb1bbe8d5e04952141f7d4f82c7e3b06dcc8b87fad7a.19e4d098dc8c618f8d81cfeb02] diff --git a/test/results/flow-info/default/dns_fragmented.pcap.out b/test/results/flow-info/default/dns_fragmented.pcap.out index 4dc28ea61..dac5c3f4a 100644 --- a/test/results/flow-info/default/dns_fragmented.pcap.out +++ b/test/results/flow-info/default/dns_fragmented.pcap.out @@ -1,51 +1,51 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..172.217.40.76][56680] -> [.193.24.227.238][...53] + new: [.....1] [ip4][..udp] [..172.217.40.76][56680] -> [.193.24.227.238][...53] detected: [.....1] [ip4][..udp] [..172.217.40.76][56680] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][weberlab.de] detection-update: [.....1] [ip4][..udp] [..172.217.40.76][56680] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [.....2] [ip6][..udp] [................2a00:1450:4013:c03::10a][46433] -> [..................2001:470:765b::a25:53][...53] + new: [.....2] [ip6][..udp] [................2a00:1450:4013:c03::10a][46433] -> [..................2001:470:765b::a25:53][...53] detected: [.....2] [ip6][..udp] [................2a00:1450:4013:c03::10a][46433] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][pa.weberlab.de] detection-update: [.....2] [ip6][..udp] [................2a00:1450:4013:c03::10a][46433] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][pa.weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv6/L4 payload detection failed [2/16] - new: [.....3] [ip6][..udp] [................2a00:1450:4013:c06::105][63369] -> [..................2001:470:765b::a25:53][...53] + new: [.....3] [ip6][..udp] [................2a00:1450:4013:c06::105][63369] -> [..................2001:470:765b::a25:53][...53] detected: [.....3] [ip6][..udp] [................2a00:1450:4013:c06::105][63369] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] detection-update: [.....3] [ip6][..udp] [................2a00:1450:4013:c06::105][63369] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv6/L4 payload detection failed [3/16] - new: [.....4] [ip4][..udp] [173.194.169.104][59464] -> [.193.24.227.238][...53] + new: [.....4] [ip4][..udp] [173.194.169.104][59464] -> [.193.24.227.238][...53] detected: [.....4] [ip4][..udp] [173.194.169.104][59464] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] detection-update: [.....4] [ip4][..udp] [173.194.169.104][59464] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [.....5] [ip6][..udp] [................2a00:1450:400c:c00::106][54430] -> [..................2001:470:765b::a25:53][...53] + new: [.....5] [ip6][..udp] [................2a00:1450:400c:c00::106][54430] -> [..................2001:470:765b::a25:53][...53] detected: [.....5] [ip6][..udp] [................2a00:1450:400c:c00::106][54430] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] detection-update: [.....5] [ip6][..udp] [................2a00:1450:400c:c00::106][54430] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] RISK: Large DNS Packet (512+ bytes) - new: [.....6] [ip4][..udp] [..74.125.47.136][59330] -> [.193.24.227.238][...53] + new: [.....6] [ip4][..udp] [..74.125.47.136][59330] -> [.193.24.227.238][...53] detected: [.....6] [ip4][..udp] [..74.125.47.136][59330] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][weberlab.de] detection-update: [.....6] [ip4][..udp] [..74.125.47.136][59330] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable][weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] - new: [.....7] [ip6][..udp] [................2a00:1450:4013:c05::10e][34944] -> [..................2001:470:765b::a25:53][...53] + new: [.....7] [ip6][..udp] [................2a00:1450:4013:c05::10e][34944] -> [..................2001:470:765b::a25:53][...53] detected: [.....7] [ip6][..udp] [................2a00:1450:4013:c05::10e][34944] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] detection-update: [.....7] [ip6][..udp] [................2a00:1450:4013:c05::10e][34944] -> [..................2001:470:765b::a25:53][...53] [DNS][Google][Network][Acceptable][fg2.weberlab.de] RISK: Large DNS Packet (512+ bytes) DAEMON-EVENT: [Processed: 14 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 7|updates: 0] - new: [.....8] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][47634] -> [..................2001:470:765b::a25:53][...53] + new: [.....8] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][47634] -> [..................2001:470:765b::a25:53][...53] detected: [.....8] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][47634] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] detection-update: [.....8] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][47634] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] - new: [.....9] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][33592] -> [..................2001:470:765b::a25:53][...53] + new: [.....9] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][33592] -> [..................2001:470:765b::a25:53][...53] detected: [.....9] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][33592] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] detection-update: [.....9] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][33592] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] - new: [....10] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46316] -> [..................2001:470:765b::a25:53][...53] + new: [....10] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46316] -> [..................2001:470:765b::a25:53][...53] detected: [....10] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46316] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] detection-update: [....10] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46316] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] - new: [....11] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46440] -> [..................2001:470:765b::a25:53][...53] + new: [....11] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46440] -> [..................2001:470:765b::a25:53][...53] detected: [....11] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46440] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] detection-update: [....11] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46440] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][fg2-mgmt.weberlab.de] idle: [.....1] [ip4][..udp] [..172.217.40.76][56680] -> [.193.24.227.238][...53] [DNS][Google][Network][Acceptable] @@ -64,45 +64,45 @@ RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message DAEMON-EVENT: [Processed: 22 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 11|updates: 0] - new: [....12] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][48758] -> [...................2606:4700:4700::1111][...53] + new: [....12] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][48758] -> [...................2606:4700:4700::1111][...53] detected: [....12] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][48758] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][sigok.verteiltesysteme.net] detection-update: [....12] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][48758] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][sigok.verteiltesysteme.net] - new: [....13] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][52814] -> [...................2606:4700:4700::1111][...53] + new: [....13] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][52814] -> [...................2606:4700:4700::1111][...53] detected: [....13] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][52814] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][sigfail.verteiltesysteme.net] detection-update: [....13] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][52814] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][sigfail.verteiltesysteme.net] RISK: Error Code - new: [....14] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][42344] -> [............................2620:fe::fe][...53] + new: [....14] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][42344] -> [............................2620:fe::fe][...53] detected: [....14] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][42344] -> [............................2620:fe::fe][...53] [DNS][Unknown][Network][Acceptable][formel1.de] detection-update: [....14] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][42344] -> [............................2620:fe::fe][...53] [DNS][Unknown][Network][Acceptable][formel1.de] idle: [.....8] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][47634] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable] idle: [.....9] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][33592] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable] idle: [....10] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46316] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable] idle: [....11] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46440] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable] - new: [....15] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46709] -> [............................2620:fe::fe][...53] + new: [....15] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46709] -> [............................2620:fe::fe][...53] detected: [....15] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46709] -> [............................2620:fe::fe][...53] [DNS][Unknown][Network][Acceptable][erfpop.de] detection-update: [....15] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][46709] -> [............................2620:fe::fe][...53] [DNS][Unknown][Network][Acceptable][erfpop.de] - new: [....16] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][55729] -> [..................2001:470:765b::a25:53][...53] + new: [....16] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][55729] -> [..................2001:470:765b::a25:53][...53] detected: [....16] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][55729] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] detection-update: [....16] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][55729] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] RISK: Unidirectional Traffic detection-update: [....16] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][55729] -> [..................2001:470:765b::a25:53][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv6/L4 payload detection failed [1/16] - new: [....17] [ip4][..udp] [....194.247.5.6][51791] -> [.193.24.227.238][...53] + new: [....17] [ip4][..udp] [....194.247.5.6][51791] -> [.193.24.227.238][...53] detected: [....17] [ip4][..udp] [....194.247.5.6][51791] -> [.193.24.227.238][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] detection-update: [....17] [ip4][..udp] [....194.247.5.6][51791] -> [.193.24.227.238][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] RISK: Large DNS Packet (512+ bytes), Fragmented DNS Message ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [....18] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][60550] -> [...................2606:4700:4700::1111][...53] + new: [....18] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][60550] -> [...................2606:4700:4700::1111][...53] detected: [....18] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][60550] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][ns2.weberdns.de] detection-update: [....18] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][60550] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][ns2.weberdns.de] - new: [....19] [ip6][..tcp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][57089] -> [.............2001:470:1f0b:16b0::a26:53][...53] + new: [....19] [ip6][..tcp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][57089] -> [.............2001:470:1f0b:16b0::a26:53][...53] detected: [....19] [ip6][..tcp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][57089] -> [.............2001:470:1f0b:16b0::a26:53][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] detection-update: [....19] [ip6][..tcp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][57089] -> [.............2001:470:1f0b:16b0::a26:53][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] - new: [....20] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][54590] -> [...................2606:4700:4700::1111][...53] + new: [....20] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][54590] -> [...................2606:4700:4700::1111][...53] detected: [....20] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][54590] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][ns2.weberdns.de] detection-update: [....20] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][54590] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable][ns2.weberdns.de] - new: [....21] [ip4][..tcp] [....194.247.5.6][39005] -> [...194.247.5.14][...53] + new: [....21] [ip4][..tcp] [....194.247.5.6][39005] -> [...194.247.5.14][...53] detected: [....21] [ip4][..tcp] [....194.247.5.6][39005] -> [...194.247.5.14][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] detection-update: [....21] [ip4][..tcp] [....194.247.5.6][39005] -> [...194.247.5.14][...53] [DNS][Unknown][Network][Acceptable][weberlab.de] idle: [....18] [ip6][..udp] [..2001:470:1f0b:16b0:20c:29ff:fe7c:a4cb][60550] -> [...................2606:4700:4700::1111][...53] [DNS][Cloudflare][Network][Acceptable] diff --git a/test/results/flow-info/default/dns_invert_query.pcapng.out b/test/results/flow-info/default/dns_invert_query.pcapng.out index 91025acdf..b2e700220 100644 --- a/test/results/flow-info/default/dns_invert_query.pcapng.out +++ b/test/results/flow-info/default/dns_invert_query.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [173.147.108.174][18427] -> [...244.187.95.1][...53] + new: [.....1] [ip4][..udp] [173.147.108.174][18427] -> [...244.187.95.1][...53] detected: [.....1] [ip4][..udp] [173.147.108.174][18427] -> [...244.187.95.1][...53] [DNS][Unknown][Network][Acceptable][216.58.202.4] idle: [.....1] [ip4][..udp] [173.147.108.174][18427] -> [...244.187.95.1][...53] [DNS][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/dns_long_domainname.pcap.out b/test/results/flow-info/default/dns_long_domainname.pcap.out index 910e48d00..20960db56 100644 --- a/test/results/flow-info/default/dns_long_domainname.pcap.out +++ b/test/results/flow-info/default/dns_long_domainname.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] + new: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] detected: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][gmr02c.16.0.fhkfhsdkfhsk.tunnel.example.com] detection-update: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][gmr02c.16.0.fhkfhsdkfhsk.tunnel.example.com] RISK: Error Code diff --git a/test/results/flow-info/default/dnscrypt-v1-and-resolver-pings.pcap.out b/test/results/flow-info/default/dnscrypt-v1-and-resolver-pings.pcap.out index 6669ed8b2..03efd6f33 100644 --- a/test/results/flow-info/default/dnscrypt-v1-and-resolver-pings.pcap.out +++ b/test/results/flow-info/default/dnscrypt-v1-and-resolver-pings.pcap.out @@ -1,170 +1,170 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.0.0.1][38388] -> [..149.56.228.45][..443] + new: [.....1] [ip4][..udp] [.......10.0.0.1][38388] -> [..149.56.228.45][..443] detected: [.....1] [ip4][..udp] [.......10.0.0.1][38388] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [.......10.0.0.1][45722] -> [..149.56.228.45][..443] + new: [.....2] [ip4][..udp] [.......10.0.0.1][45722] -> [..149.56.228.45][..443] detected: [.....2] [ip4][..udp] [.......10.0.0.1][45722] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [.....3] [ip4][..udp] [.......10.0.0.1][35495] -> [..149.56.228.45][..443] + new: [.....3] [ip4][..udp] [.......10.0.0.1][35495] -> [..149.56.228.45][..443] detected: [.....3] [ip4][..udp] [.......10.0.0.1][35495] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [.....4] [ip4][..udp] [.......10.0.0.1][33565] -> [..149.56.228.45][..443] + new: [.....4] [ip4][..udp] [.......10.0.0.1][33565] -> [..149.56.228.45][..443] detected: [.....4] [ip4][..udp] [.......10.0.0.1][33565] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [.......10.0.0.1][35228] -> [..149.56.228.45][..443] + new: [.....5] [ip4][..udp] [.......10.0.0.1][35228] -> [..149.56.228.45][..443] detected: [.....5] [ip4][..udp] [.......10.0.0.1][35228] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [.....6] [ip4][..udp] [.......10.0.0.1][60301] -> [..149.56.228.45][..443] + new: [.....6] [ip4][..udp] [.......10.0.0.1][60301] -> [..149.56.228.45][..443] detected: [.....6] [ip4][..udp] [.......10.0.0.1][60301] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..udp] [.......10.0.0.1][51004] -> [..62.210.180.71][.1053] + new: [.....7] [ip4][..udp] [.......10.0.0.1][51004] -> [..62.210.180.71][.1053] detected: [.....7] [ip4][..udp] [.......10.0.0.1][51004] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] - new: [.....8] [ip4][..udp] [.......10.0.0.1][52636] -> [..62.210.180.71][.1053] + new: [.....8] [ip4][..udp] [.......10.0.0.1][52636] -> [..62.210.180.71][.1053] detected: [.....8] [ip4][..udp] [.......10.0.0.1][52636] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [.......10.0.0.1][49518] -> [..62.210.180.71][.1053] + new: [.....9] [ip4][..udp] [.......10.0.0.1][49518] -> [..62.210.180.71][.1053] detected: [.....9] [ip4][..udp] [.......10.0.0.1][49518] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] - new: [....10] [ip4][..udp] [.......10.0.0.1][43748] -> [..62.210.180.71][.1053] + new: [....10] [ip4][..udp] [.......10.0.0.1][43748] -> [..62.210.180.71][.1053] detected: [....10] [ip4][..udp] [.......10.0.0.1][43748] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....11] [ip4][..udp] [.......10.0.0.1][57395] -> [..62.210.180.71][.1053] + new: [....11] [ip4][..udp] [.......10.0.0.1][57395] -> [..62.210.180.71][.1053] detected: [....11] [ip4][..udp] [.......10.0.0.1][57395] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [....12] [ip4][..udp] [.......10.0.0.1][53299] -> [..62.210.180.71][.1053] + new: [....12] [ip4][..udp] [.......10.0.0.1][53299] -> [..62.210.180.71][.1053] detected: [....12] [ip4][..udp] [.......10.0.0.1][53299] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [....13] [ip4][..udp] [.......10.0.0.1][53697] -> [.185.134.196.55][.8443] + new: [....13] [ip4][..udp] [.......10.0.0.1][53697] -> [.185.134.196.55][.8443] detected: [....13] [ip4][..udp] [.......10.0.0.1][53697] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....14] [ip4][..udp] [.......10.0.0.1][37413] -> [.185.134.196.55][.8443] + new: [....14] [ip4][..udp] [.......10.0.0.1][37413] -> [.185.134.196.55][.8443] detected: [....14] [ip4][..udp] [.......10.0.0.1][37413] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [....15] [ip4][..udp] [.......10.0.0.1][35005] -> [.185.134.196.55][.8443] + new: [....15] [ip4][..udp] [.......10.0.0.1][35005] -> [.185.134.196.55][.8443] detected: [....15] [ip4][..udp] [.......10.0.0.1][35005] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] - new: [....16] [ip4][..udp] [.......10.0.0.1][59405] -> [.185.134.196.55][.8443] + new: [....16] [ip4][..udp] [.......10.0.0.1][59405] -> [.185.134.196.55][.8443] detected: [....16] [ip4][..udp] [.......10.0.0.1][59405] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....17] [ip4][..udp] [.......10.0.0.1][50435] -> [.185.134.196.55][.8443] + new: [....17] [ip4][..udp] [.......10.0.0.1][50435] -> [.185.134.196.55][.8443] detected: [....17] [ip4][..udp] [.......10.0.0.1][50435] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....18] [ip4][..udp] [.......10.0.0.1][55123] -> [.185.134.196.55][.8443] + new: [....18] [ip4][..udp] [.......10.0.0.1][55123] -> [.185.134.196.55][.8443] detected: [....18] [ip4][..udp] [.......10.0.0.1][55123] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] - new: [....19] [ip4][..udp] [.......10.0.0.1][44712] -> [104.238.186.192][..443] + new: [....19] [ip4][..udp] [.......10.0.0.1][44712] -> [104.238.186.192][..443] detected: [....19] [ip4][..udp] [.......10.0.0.1][44712] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....20] [ip4][..udp] [.......10.0.0.1][56997] -> [104.238.186.192][..443] + new: [....20] [ip4][..udp] [.......10.0.0.1][56997] -> [104.238.186.192][..443] detected: [....20] [ip4][..udp] [.......10.0.0.1][56997] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [7/16] - new: [....21] [ip4][..udp] [.......10.0.0.1][39655] -> [104.238.186.192][..443] + new: [....21] [ip4][..udp] [.......10.0.0.1][39655] -> [104.238.186.192][..443] detected: [....21] [ip4][..udp] [.......10.0.0.1][39655] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....22] [ip4][..udp] [.......10.0.0.1][59261] -> [104.238.186.192][..443] + new: [....22] [ip4][..udp] [.......10.0.0.1][59261] -> [104.238.186.192][..443] detected: [....22] [ip4][..udp] [.......10.0.0.1][59261] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....23] [ip4][..udp] [.......10.0.0.1][59641] -> [104.238.186.192][..443] + new: [....23] [ip4][..udp] [.......10.0.0.1][59641] -> [104.238.186.192][..443] detected: [....23] [ip4][..udp] [.......10.0.0.1][59641] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....24] [ip4][..udp] [.......10.0.0.1][44491] -> [104.238.186.192][..443] + new: [....24] [ip4][..udp] [.......10.0.0.1][44491] -> [104.238.186.192][..443] detected: [....24] [ip4][..udp] [.......10.0.0.1][44491] -> [104.238.186.192][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [8/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [9/16] - new: [....25] [ip4][..udp] [.......10.0.0.1][32793] -> [.209.250.241.25][..443] + new: [....25] [ip4][..udp] [.......10.0.0.1][32793] -> [.209.250.241.25][..443] detected: [....25] [ip4][..udp] [.......10.0.0.1][32793] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....26] [ip4][..udp] [.......10.0.0.1][56035] -> [.209.250.241.25][..443] + new: [....26] [ip4][..udp] [.......10.0.0.1][56035] -> [.209.250.241.25][..443] detected: [....26] [ip4][..udp] [.......10.0.0.1][56035] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [10/16] - new: [....27] [ip4][..udp] [.......10.0.0.1][37123] -> [.209.250.241.25][..443] + new: [....27] [ip4][..udp] [.......10.0.0.1][37123] -> [.209.250.241.25][..443] detected: [....27] [ip4][..udp] [.......10.0.0.1][37123] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [11/16] - new: [....28] [ip4][..udp] [.......10.0.0.1][37950] -> [.209.250.241.25][..443] + new: [....28] [ip4][..udp] [.......10.0.0.1][37950] -> [.209.250.241.25][..443] detected: [....28] [ip4][..udp] [.......10.0.0.1][37950] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....29] [ip4][..udp] [.......10.0.0.1][34324] -> [.209.250.241.25][..443] + new: [....29] [ip4][..udp] [.......10.0.0.1][34324] -> [.209.250.241.25][..443] detected: [....29] [ip4][..udp] [.......10.0.0.1][34324] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....30] [ip4][..udp] [.......10.0.0.1][59367] -> [.209.250.241.25][..443] + new: [....30] [ip4][..udp] [.......10.0.0.1][59367] -> [.209.250.241.25][..443] detected: [....30] [ip4][..udp] [.......10.0.0.1][59367] -> [.209.250.241.25][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [12/16] - new: [....31] [ip4][..udp] [.......10.0.0.1][43609] -> [....41.79.69.13][..443] + new: [....31] [ip4][..udp] [.......10.0.0.1][43609] -> [....41.79.69.13][..443] detected: [....31] [ip4][..udp] [.......10.0.0.1][43609] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....32] [ip4][..udp] [.......10.0.0.1][46229] -> [....41.79.69.13][..443] + new: [....32] [ip4][..udp] [.......10.0.0.1][46229] -> [....41.79.69.13][..443] detected: [....32] [ip4][..udp] [.......10.0.0.1][46229] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [13/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [14/16] - new: [....33] [ip4][..udp] [.......10.0.0.1][56043] -> [....41.79.69.13][..443] + new: [....33] [ip4][..udp] [.......10.0.0.1][56043] -> [....41.79.69.13][..443] detected: [....33] [ip4][..udp] [.......10.0.0.1][56043] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....34] [ip4][..udp] [.......10.0.0.1][38136] -> [....41.79.69.13][..443] + new: [....34] [ip4][..udp] [.......10.0.0.1][38136] -> [....41.79.69.13][..443] detected: [....34] [ip4][..udp] [.......10.0.0.1][38136] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [15/16] - new: [....35] [ip4][..udp] [.......10.0.0.1][56177] -> [....41.79.69.13][..443] + new: [....35] [ip4][..udp] [.......10.0.0.1][56177] -> [....41.79.69.13][..443] detected: [....35] [ip4][..udp] [.......10.0.0.1][56177] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....36] [ip4][..udp] [.......10.0.0.1][43365] -> [....41.79.69.13][..443] + new: [....36] [ip4][..udp] [.......10.0.0.1][43365] -> [....41.79.69.13][..443] detected: [....36] [ip4][..udp] [.......10.0.0.1][43365] -> [....41.79.69.13][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....37] [ip4][..udp] [.......10.0.0.1][45767] -> [..51.15.122.250][..443] + new: [....37] [ip4][..udp] [.......10.0.0.1][45767] -> [..51.15.122.250][..443] detected: [....37] [ip4][..udp] [.......10.0.0.1][45767] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....38] [ip4][..udp] [.......10.0.0.1][38867] -> [..51.15.122.250][..443] + new: [....38] [ip4][..udp] [.......10.0.0.1][38867] -> [..51.15.122.250][..443] detected: [....38] [ip4][..udp] [.......10.0.0.1][38867] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [16/16] - new: [....39] [ip4][..udp] [.......10.0.0.1][59709] -> [..51.15.122.250][..443] + new: [....39] [ip4][..udp] [.......10.0.0.1][59709] -> [..51.15.122.250][..443] detected: [....39] [ip4][..udp] [.......10.0.0.1][59709] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....40] [ip4][..udp] [.......10.0.0.1][36668] -> [..51.15.122.250][..443] + new: [....40] [ip4][..udp] [.......10.0.0.1][36668] -> [..51.15.122.250][..443] detected: [....40] [ip4][..udp] [.......10.0.0.1][36668] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....41] [ip4][..udp] [.......10.0.0.1][39007] -> [..51.15.122.250][..443] + new: [....41] [ip4][..udp] [.......10.0.0.1][39007] -> [..51.15.122.250][..443] detected: [....41] [ip4][..udp] [.......10.0.0.1][39007] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....42] [ip4][..udp] [.......10.0.0.1][38362] -> [..51.15.122.250][..443] + new: [....42] [ip4][..udp] [.......10.0.0.1][38362] -> [..51.15.122.250][..443] detected: [....42] [ip4][..udp] [.......10.0.0.1][38362] -> [..51.15.122.250][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....43] [ip4][..udp] [.......10.0.0.1][59476] -> [.139.59.200.116][..443] + new: [....43] [ip4][..udp] [.......10.0.0.1][59476] -> [.139.59.200.116][..443] detected: [....43] [ip4][..udp] [.......10.0.0.1][59476] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....44] [ip4][..udp] [.......10.0.0.1][47341] -> [.139.59.200.116][..443] + new: [....44] [ip4][..udp] [.......10.0.0.1][47341] -> [.139.59.200.116][..443] detected: [....44] [ip4][..udp] [.......10.0.0.1][47341] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....45] [ip4][..udp] [.......10.0.0.1][50335] -> [.139.59.200.116][..443] + new: [....45] [ip4][..udp] [.......10.0.0.1][50335] -> [.139.59.200.116][..443] detected: [....45] [ip4][..udp] [.......10.0.0.1][50335] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....46] [ip4][..udp] [.......10.0.0.1][43633] -> [.139.59.200.116][..443] + new: [....46] [ip4][..udp] [.......10.0.0.1][43633] -> [.139.59.200.116][..443] detected: [....46] [ip4][..udp] [.......10.0.0.1][43633] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....47] [ip4][..udp] [.......10.0.0.1][37595] -> [.139.59.200.116][..443] + new: [....47] [ip4][..udp] [.......10.0.0.1][37595] -> [.139.59.200.116][..443] detected: [....47] [ip4][..udp] [.......10.0.0.1][37595] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....48] [ip4][..udp] [.......10.0.0.1][59194] -> [.139.59.200.116][..443] + new: [....48] [ip4][..udp] [.......10.0.0.1][59194] -> [.139.59.200.116][..443] detected: [....48] [ip4][..udp] [.......10.0.0.1][59194] -> [.139.59.200.116][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....49] [ip4][..udp] [.......10.0.0.1][47865] -> [...195.30.94.28][.8443] + new: [....49] [ip4][..udp] [.......10.0.0.1][47865] -> [...195.30.94.28][.8443] detected: [....49] [ip4][..udp] [.......10.0.0.1][47865] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....50] [ip4][..udp] [.......10.0.0.1][33369] -> [...195.30.94.28][.8443] + new: [....50] [ip4][..udp] [.......10.0.0.1][33369] -> [...195.30.94.28][.8443] detected: [....50] [ip4][..udp] [.......10.0.0.1][33369] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....51] [ip4][..udp] [.......10.0.0.1][34885] -> [...195.30.94.28][.8443] + new: [....51] [ip4][..udp] [.......10.0.0.1][34885] -> [...195.30.94.28][.8443] detected: [....51] [ip4][..udp] [.......10.0.0.1][34885] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....52] [ip4][..udp] [.......10.0.0.1][44093] -> [...195.30.94.28][.8443] + new: [....52] [ip4][..udp] [.......10.0.0.1][44093] -> [...195.30.94.28][.8443] detected: [....52] [ip4][..udp] [.......10.0.0.1][44093] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....53] [ip4][..udp] [.......10.0.0.1][53811] -> [...195.30.94.28][.8443] + new: [....53] [ip4][..udp] [.......10.0.0.1][53811] -> [...195.30.94.28][.8443] detected: [....53] [ip4][..udp] [.......10.0.0.1][53811] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....54] [ip4][..udp] [.......10.0.0.1][44282] -> [...195.30.94.28][.8443] + new: [....54] [ip4][..udp] [.......10.0.0.1][44282] -> [...195.30.94.28][.8443] detected: [....54] [ip4][..udp] [.......10.0.0.1][44282] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....55] [ip4][..udp] [.......10.0.0.1][32970] -> [..142.4.204.111][..443] + new: [....55] [ip4][..udp] [.......10.0.0.1][32970] -> [..142.4.204.111][..443] detected: [....55] [ip4][..udp] [.......10.0.0.1][32970] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....56] [ip4][..udp] [.......10.0.0.1][60962] -> [..142.4.204.111][..443] + new: [....56] [ip4][..udp] [.......10.0.0.1][60962] -> [..142.4.204.111][..443] detected: [....56] [ip4][..udp] [.......10.0.0.1][60962] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....57] [ip4][..udp] [.......10.0.0.1][33071] -> [..142.4.204.111][..443] + new: [....57] [ip4][..udp] [.......10.0.0.1][33071] -> [..142.4.204.111][..443] detected: [....57] [ip4][..udp] [.......10.0.0.1][33071] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....58] [ip4][..udp] [.......10.0.0.1][43505] -> [..142.4.204.111][..443] + new: [....58] [ip4][..udp] [.......10.0.0.1][43505] -> [..142.4.204.111][..443] detected: [....58] [ip4][..udp] [.......10.0.0.1][43505] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....59] [ip4][..udp] [.......10.0.0.1][52284] -> [..142.4.204.111][..443] + new: [....59] [ip4][..udp] [.......10.0.0.1][52284] -> [..142.4.204.111][..443] detected: [....59] [ip4][..udp] [.......10.0.0.1][52284] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....60] [ip4][..udp] [.......10.0.0.1][46856] -> [..142.4.204.111][..443] + new: [....60] [ip4][..udp] [.......10.0.0.1][46856] -> [..142.4.204.111][..443] detected: [....60] [ip4][..udp] [.......10.0.0.1][46856] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....61] [ip4][..udp] [.......10.0.0.1][50035] -> [.149.112.112.10][.8443] + new: [....61] [ip4][..udp] [.......10.0.0.1][50035] -> [.149.112.112.10][.8443] detected: [....61] [ip4][..udp] [.......10.0.0.1][50035] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....62] [ip4][..udp] [.......10.0.0.1][40009] -> [.149.112.112.10][.8443] + new: [....62] [ip4][..udp] [.......10.0.0.1][40009] -> [.149.112.112.10][.8443] detected: [....62] [ip4][..udp] [.......10.0.0.1][40009] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....63] [ip4][..udp] [.......10.0.0.1][56022] -> [.149.112.112.10][.8443] + new: [....63] [ip4][..udp] [.......10.0.0.1][56022] -> [.149.112.112.10][.8443] detected: [....63] [ip4][..udp] [.......10.0.0.1][56022] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....64] [ip4][..udp] [.......10.0.0.1][42570] -> [.149.112.112.10][.8443] + new: [....64] [ip4][..udp] [.......10.0.0.1][42570] -> [.149.112.112.10][.8443] detected: [....64] [ip4][..udp] [.......10.0.0.1][42570] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....65] [ip4][..udp] [.......10.0.0.1][57465] -> [.149.112.112.10][.8443] + new: [....65] [ip4][..udp] [.......10.0.0.1][57465] -> [.149.112.112.10][.8443] detected: [....65] [ip4][..udp] [.......10.0.0.1][57465] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....66] [ip4][..udp] [.......10.0.0.1][55482] -> [.149.112.112.10][.8443] + new: [....66] [ip4][..udp] [.......10.0.0.1][55482] -> [.149.112.112.10][.8443] detected: [....66] [ip4][..udp] [.......10.0.0.1][55482] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [....67] [ip4][..udp] [.......10.0.0.1][49512] -> [..172.104.93.80][.1443] + new: [....67] [ip4][..udp] [.......10.0.0.1][49512] -> [..172.104.93.80][.1443] detected: [....67] [ip4][..udp] [.......10.0.0.1][49512] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] - new: [....68] [ip4][..udp] [.......10.0.0.1][50913] -> [..172.104.93.80][.1443] + new: [....68] [ip4][..udp] [.......10.0.0.1][50913] -> [..172.104.93.80][.1443] detected: [....68] [ip4][..udp] [.......10.0.0.1][50913] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] - new: [....69] [ip4][..udp] [.......10.0.0.1][41800] -> [..172.104.93.80][.1443] + new: [....69] [ip4][..udp] [.......10.0.0.1][41800] -> [..172.104.93.80][.1443] detected: [....69] [ip4][..udp] [.......10.0.0.1][41800] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] - new: [....70] [ip4][..udp] [.......10.0.0.1][38283] -> [..172.104.93.80][.1443] + new: [....70] [ip4][..udp] [.......10.0.0.1][38283] -> [..172.104.93.80][.1443] detected: [....70] [ip4][..udp] [.......10.0.0.1][38283] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] - new: [....71] [ip4][..udp] [.......10.0.0.1][59489] -> [..172.104.93.80][.1443] + new: [....71] [ip4][..udp] [.......10.0.0.1][59489] -> [..172.104.93.80][.1443] detected: [....71] [ip4][..udp] [.......10.0.0.1][59489] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] - new: [....72] [ip4][..udp] [.......10.0.0.1][56902] -> [..172.104.93.80][.1443] + new: [....72] [ip4][..udp] [.......10.0.0.1][56902] -> [..172.104.93.80][.1443] detected: [....72] [ip4][..udp] [.......10.0.0.1][56902] -> [..172.104.93.80][.1443] [DNScrypt][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [.......10.0.0.1][38388] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] update: [.....5] [ip4][..udp] [.......10.0.0.1][35228] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] @@ -172,235 +172,235 @@ update: [.....3] [ip4][..udp] [.......10.0.0.1][35495] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [.......10.0.0.1][33565] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] update: [.....6] [ip4][..udp] [.......10.0.0.1][60301] -> [..149.56.228.45][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....73] [ip4][..udp] [.......10.0.0.1][38349] -> [205.185.116.116][..553] + new: [....73] [ip4][..udp] [.......10.0.0.1][38349] -> [205.185.116.116][..553] detected: [....73] [ip4][..udp] [.......10.0.0.1][38349] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....74] [ip4][..udp] [.......10.0.0.1][38879] -> [205.185.116.116][..553] + new: [....74] [ip4][..udp] [.......10.0.0.1][38879] -> [205.185.116.116][..553] detected: [....74] [ip4][..udp] [.......10.0.0.1][38879] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....75] [ip4][..udp] [.......10.0.0.1][43528] -> [205.185.116.116][..553] + new: [....75] [ip4][..udp] [.......10.0.0.1][43528] -> [205.185.116.116][..553] detected: [....75] [ip4][..udp] [.......10.0.0.1][43528] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....76] [ip4][..udp] [.......10.0.0.1][51770] -> [205.185.116.116][..553] + new: [....76] [ip4][..udp] [.......10.0.0.1][51770] -> [205.185.116.116][..553] detected: [....76] [ip4][..udp] [.......10.0.0.1][51770] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....77] [ip4][..udp] [.......10.0.0.1][38278] -> [205.185.116.116][..553] + new: [....77] [ip4][..udp] [.......10.0.0.1][38278] -> [205.185.116.116][..553] detected: [....77] [ip4][..udp] [.......10.0.0.1][38278] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....78] [ip4][..udp] [.......10.0.0.1][55822] -> [205.185.116.116][..553] + new: [....78] [ip4][..udp] [.......10.0.0.1][55822] -> [205.185.116.116][..553] detected: [....78] [ip4][..udp] [.......10.0.0.1][55822] -> [205.185.116.116][..553] [DNScrypt][Unknown][Network][Acceptable] - new: [....79] [ip4][..udp] [.......10.0.0.1][55834] -> [..52.65.235.129][..443] + new: [....79] [ip4][..udp] [.......10.0.0.1][55834] -> [..52.65.235.129][..443] detected: [....79] [ip4][..udp] [.......10.0.0.1][55834] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....80] [ip4][..udp] [.......10.0.0.1][46313] -> [..52.65.235.129][..443] + new: [....80] [ip4][..udp] [.......10.0.0.1][46313] -> [..52.65.235.129][..443] detected: [....80] [ip4][..udp] [.......10.0.0.1][46313] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....81] [ip4][..udp] [.......10.0.0.1][52911] -> [..52.65.235.129][..443] + new: [....81] [ip4][..udp] [.......10.0.0.1][52911] -> [..52.65.235.129][..443] detected: [....81] [ip4][..udp] [.......10.0.0.1][52911] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....82] [ip4][..udp] [.......10.0.0.1][47685] -> [..52.65.235.129][..443] + new: [....82] [ip4][..udp] [.......10.0.0.1][47685] -> [..52.65.235.129][..443] detected: [....82] [ip4][..udp] [.......10.0.0.1][47685] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....83] [ip4][..udp] [.......10.0.0.1][55979] -> [..52.65.235.129][..443] + new: [....83] [ip4][..udp] [.......10.0.0.1][55979] -> [..52.65.235.129][..443] detected: [....83] [ip4][..udp] [.......10.0.0.1][55979] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....84] [ip4][..udp] [.......10.0.0.1][55409] -> [..52.65.235.129][..443] + new: [....84] [ip4][..udp] [.......10.0.0.1][55409] -> [..52.65.235.129][..443] detected: [....84] [ip4][..udp] [.......10.0.0.1][55409] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] - new: [....85] [ip4][..udp] [.......10.0.0.1][38812] -> [....51.15.62.65][..443] + new: [....85] [ip4][..udp] [.......10.0.0.1][38812] -> [....51.15.62.65][..443] detected: [....85] [ip4][..udp] [.......10.0.0.1][38812] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....86] [ip4][..udp] [.......10.0.0.1][45993] -> [....51.15.62.65][..443] + new: [....86] [ip4][..udp] [.......10.0.0.1][45993] -> [....51.15.62.65][..443] detected: [....86] [ip4][..udp] [.......10.0.0.1][45993] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....87] [ip4][..udp] [.......10.0.0.1][56688] -> [....51.15.62.65][..443] + new: [....87] [ip4][..udp] [.......10.0.0.1][56688] -> [....51.15.62.65][..443] detected: [....87] [ip4][..udp] [.......10.0.0.1][56688] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....88] [ip4][..udp] [.......10.0.0.1][33521] -> [....51.15.62.65][..443] + new: [....88] [ip4][..udp] [.......10.0.0.1][33521] -> [....51.15.62.65][..443] detected: [....88] [ip4][..udp] [.......10.0.0.1][33521] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....89] [ip4][..udp] [.......10.0.0.1][43714] -> [....51.15.62.65][..443] + new: [....89] [ip4][..udp] [.......10.0.0.1][43714] -> [....51.15.62.65][..443] detected: [....89] [ip4][..udp] [.......10.0.0.1][43714] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....90] [ip4][..udp] [.......10.0.0.1][60735] -> [....51.15.62.65][..443] + new: [....90] [ip4][..udp] [.......10.0.0.1][60735] -> [....51.15.62.65][..443] detected: [....90] [ip4][..udp] [.......10.0.0.1][60735] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....91] [ip4][..udp] [.......10.0.0.1][41913] -> [..45.153.187.96][.4343] + new: [....91] [ip4][..udp] [.......10.0.0.1][41913] -> [..45.153.187.96][.4343] detected: [....91] [ip4][..udp] [.......10.0.0.1][41913] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....92] [ip4][..udp] [.......10.0.0.1][37890] -> [..45.153.187.96][.4343] + new: [....92] [ip4][..udp] [.......10.0.0.1][37890] -> [..45.153.187.96][.4343] detected: [....92] [ip4][..udp] [.......10.0.0.1][37890] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....93] [ip4][..udp] [.......10.0.0.1][45987] -> [..45.153.187.96][.4343] + new: [....93] [ip4][..udp] [.......10.0.0.1][45987] -> [..45.153.187.96][.4343] detected: [....93] [ip4][..udp] [.......10.0.0.1][45987] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....94] [ip4][..udp] [.......10.0.0.1][46063] -> [..45.153.187.96][.4343] + new: [....94] [ip4][..udp] [.......10.0.0.1][46063] -> [..45.153.187.96][.4343] detected: [....94] [ip4][..udp] [.......10.0.0.1][46063] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....95] [ip4][..udp] [.......10.0.0.1][43129] -> [..45.153.187.96][.4343] + new: [....95] [ip4][..udp] [.......10.0.0.1][43129] -> [..45.153.187.96][.4343] detected: [....95] [ip4][..udp] [.......10.0.0.1][43129] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....96] [ip4][..udp] [.......10.0.0.1][40451] -> [..45.153.187.96][.4343] + new: [....96] [ip4][..udp] [.......10.0.0.1][40451] -> [..45.153.187.96][.4343] detected: [....96] [ip4][..udp] [.......10.0.0.1][40451] -> [..45.153.187.96][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [....97] [ip4][..udp] [.......10.0.0.1][55896] -> [...66.85.30.115][..443] + new: [....97] [ip4][..udp] [.......10.0.0.1][55896] -> [...66.85.30.115][..443] detected: [....97] [ip4][..udp] [.......10.0.0.1][55896] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....98] [ip4][..udp] [.......10.0.0.1][48448] -> [...66.85.30.115][..443] + new: [....98] [ip4][..udp] [.......10.0.0.1][48448] -> [...66.85.30.115][..443] detected: [....98] [ip4][..udp] [.......10.0.0.1][48448] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [....99] [ip4][..udp] [.......10.0.0.1][40099] -> [...66.85.30.115][..443] + new: [....99] [ip4][..udp] [.......10.0.0.1][40099] -> [...66.85.30.115][..443] detected: [....99] [ip4][..udp] [.......10.0.0.1][40099] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...100] [ip4][..udp] [.......10.0.0.1][47432] -> [...66.85.30.115][..443] + new: [...100] [ip4][..udp] [.......10.0.0.1][47432] -> [...66.85.30.115][..443] detected: [...100] [ip4][..udp] [.......10.0.0.1][47432] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...101] [ip4][..udp] [.......10.0.0.1][54112] -> [...66.85.30.115][..443] + new: [...101] [ip4][..udp] [.......10.0.0.1][54112] -> [...66.85.30.115][..443] detected: [...101] [ip4][..udp] [.......10.0.0.1][54112] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...102] [ip4][..udp] [.......10.0.0.1][35634] -> [...66.85.30.115][..443] + new: [...102] [ip4][..udp] [.......10.0.0.1][35634] -> [...66.85.30.115][..443] detected: [...102] [ip4][..udp] [.......10.0.0.1][35634] -> [...66.85.30.115][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...103] [ip4][..udp] [.......10.0.0.1][46255] -> [..93.95.226.165][..443] + new: [...103] [ip4][..udp] [.......10.0.0.1][46255] -> [..93.95.226.165][..443] detected: [...103] [ip4][..udp] [.......10.0.0.1][46255] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...104] [ip4][..udp] [.......10.0.0.1][49186] -> [..93.95.226.165][..443] + new: [...104] [ip4][..udp] [.......10.0.0.1][49186] -> [..93.95.226.165][..443] detected: [...104] [ip4][..udp] [.......10.0.0.1][49186] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...105] [ip4][..udp] [.......10.0.0.1][58113] -> [..93.95.226.165][..443] + new: [...105] [ip4][..udp] [.......10.0.0.1][58113] -> [..93.95.226.165][..443] detected: [...105] [ip4][..udp] [.......10.0.0.1][58113] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...106] [ip4][..udp] [.......10.0.0.1][42156] -> [..93.95.226.165][..443] + new: [...106] [ip4][..udp] [.......10.0.0.1][42156] -> [..93.95.226.165][..443] detected: [...106] [ip4][..udp] [.......10.0.0.1][42156] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...107] [ip4][..udp] [.......10.0.0.1][58936] -> [..93.95.226.165][..443] + new: [...107] [ip4][..udp] [.......10.0.0.1][58936] -> [..93.95.226.165][..443] detected: [...107] [ip4][..udp] [.......10.0.0.1][58936] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...108] [ip4][..udp] [.......10.0.0.1][40595] -> [..93.95.226.165][..443] + new: [...108] [ip4][..udp] [.......10.0.0.1][40595] -> [..93.95.226.165][..443] detected: [...108] [ip4][..udp] [.......10.0.0.1][40595] -> [..93.95.226.165][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...109] [ip4][..udp] [.......10.0.0.1][37035] -> [..51.158.166.97][..443] + new: [...109] [ip4][..udp] [.......10.0.0.1][37035] -> [..51.158.166.97][..443] detected: [...109] [ip4][..udp] [.......10.0.0.1][37035] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...110] [ip4][..udp] [.......10.0.0.1][47257] -> [..51.158.166.97][..443] + new: [...110] [ip4][..udp] [.......10.0.0.1][47257] -> [..51.158.166.97][..443] detected: [...110] [ip4][..udp] [.......10.0.0.1][47257] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...111] [ip4][..udp] [.......10.0.0.1][46066] -> [..51.158.166.97][..443] + new: [...111] [ip4][..udp] [.......10.0.0.1][46066] -> [..51.158.166.97][..443] detected: [...111] [ip4][..udp] [.......10.0.0.1][46066] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...112] [ip4][..udp] [.......10.0.0.1][56494] -> [..51.158.166.97][..443] + new: [...112] [ip4][..udp] [.......10.0.0.1][56494] -> [..51.158.166.97][..443] detected: [...112] [ip4][..udp] [.......10.0.0.1][56494] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...113] [ip4][..udp] [.......10.0.0.1][60334] -> [..51.158.166.97][..443] + new: [...113] [ip4][..udp] [.......10.0.0.1][60334] -> [..51.158.166.97][..443] detected: [...113] [ip4][..udp] [.......10.0.0.1][60334] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...114] [ip4][..udp] [.......10.0.0.1][48065] -> [..51.158.166.97][..443] + new: [...114] [ip4][..udp] [.......10.0.0.1][48065] -> [..51.158.166.97][..443] detected: [...114] [ip4][..udp] [.......10.0.0.1][48065] -> [..51.158.166.97][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...115] [ip4][..udp] [.......10.0.0.1][41717] -> [.176.56.237.171][..443] + new: [...115] [ip4][..udp] [.......10.0.0.1][41717] -> [.176.56.237.171][..443] detected: [...115] [ip4][..udp] [.......10.0.0.1][41717] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...116] [ip4][..udp] [.......10.0.0.1][55046] -> [.176.56.237.171][..443] + new: [...116] [ip4][..udp] [.......10.0.0.1][55046] -> [.176.56.237.171][..443] detected: [...116] [ip4][..udp] [.......10.0.0.1][55046] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...117] [ip4][..udp] [.......10.0.0.1][51363] -> [.176.56.237.171][..443] + new: [...117] [ip4][..udp] [.......10.0.0.1][51363] -> [.176.56.237.171][..443] detected: [...117] [ip4][..udp] [.......10.0.0.1][51363] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...118] [ip4][..udp] [.......10.0.0.1][36676] -> [.176.56.237.171][..443] + new: [...118] [ip4][..udp] [.......10.0.0.1][36676] -> [.176.56.237.171][..443] detected: [...118] [ip4][..udp] [.......10.0.0.1][36676] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...119] [ip4][..udp] [.......10.0.0.1][49008] -> [.176.56.237.171][..443] + new: [...119] [ip4][..udp] [.......10.0.0.1][49008] -> [.176.56.237.171][..443] detected: [...119] [ip4][..udp] [.......10.0.0.1][49008] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...120] [ip4][..udp] [.......10.0.0.1][48325] -> [.176.56.237.171][..443] + new: [...120] [ip4][..udp] [.......10.0.0.1][48325] -> [.176.56.237.171][..443] detected: [...120] [ip4][..udp] [.......10.0.0.1][48325] -> [.176.56.237.171][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...121] [ip4][..udp] [.......10.0.0.1][60091] -> [178.216.201.222][.2053] + new: [...121] [ip4][..udp] [.......10.0.0.1][60091] -> [178.216.201.222][.2053] detected: [...121] [ip4][..udp] [.......10.0.0.1][60091] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...122] [ip4][..udp] [.......10.0.0.1][52356] -> [178.216.201.222][.2053] + new: [...122] [ip4][..udp] [.......10.0.0.1][52356] -> [178.216.201.222][.2053] detected: [...122] [ip4][..udp] [.......10.0.0.1][52356] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...123] [ip4][..udp] [.......10.0.0.1][53117] -> [178.216.201.222][.2053] + new: [...123] [ip4][..udp] [.......10.0.0.1][53117] -> [178.216.201.222][.2053] detected: [...123] [ip4][..udp] [.......10.0.0.1][53117] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...124] [ip4][..udp] [.......10.0.0.1][52221] -> [178.216.201.222][.2053] + new: [...124] [ip4][..udp] [.......10.0.0.1][52221] -> [178.216.201.222][.2053] detected: [...124] [ip4][..udp] [.......10.0.0.1][52221] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...125] [ip4][..udp] [.......10.0.0.1][38594] -> [178.216.201.222][.2053] + new: [...125] [ip4][..udp] [.......10.0.0.1][38594] -> [178.216.201.222][.2053] detected: [...125] [ip4][..udp] [.......10.0.0.1][38594] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...126] [ip4][..udp] [.......10.0.0.1][58740] -> [178.216.201.222][.2053] + new: [...126] [ip4][..udp] [.......10.0.0.1][58740] -> [178.216.201.222][.2053] detected: [...126] [ip4][..udp] [.......10.0.0.1][58740] -> [178.216.201.222][.2053] [DNScrypt][Unknown][Network][Acceptable] - new: [...127] [ip4][..udp] [.......10.0.0.1][43224] -> [...45.76.113.31][..443] + new: [...127] [ip4][..udp] [.......10.0.0.1][43224] -> [...45.76.113.31][..443] detected: [...127] [ip4][..udp] [.......10.0.0.1][43224] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...128] [ip4][..udp] [.......10.0.0.1][55267] -> [...45.76.113.31][..443] + new: [...128] [ip4][..udp] [.......10.0.0.1][55267] -> [...45.76.113.31][..443] detected: [...128] [ip4][..udp] [.......10.0.0.1][55267] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...129] [ip4][..udp] [.......10.0.0.1][51589] -> [...45.76.113.31][..443] + new: [...129] [ip4][..udp] [.......10.0.0.1][51589] -> [...45.76.113.31][..443] detected: [...129] [ip4][..udp] [.......10.0.0.1][51589] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...130] [ip4][..udp] [.......10.0.0.1][43776] -> [...45.76.113.31][..443] + new: [...130] [ip4][..udp] [.......10.0.0.1][43776] -> [...45.76.113.31][..443] detected: [...130] [ip4][..udp] [.......10.0.0.1][43776] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...131] [ip4][..udp] [.......10.0.0.1][59707] -> [...45.76.113.31][..443] + new: [...131] [ip4][..udp] [.......10.0.0.1][59707] -> [...45.76.113.31][..443] detected: [...131] [ip4][..udp] [.......10.0.0.1][59707] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...132] [ip4][..udp] [.......10.0.0.1][52069] -> [...45.76.113.31][..443] + new: [...132] [ip4][..udp] [.......10.0.0.1][52069] -> [...45.76.113.31][..443] detected: [...132] [ip4][..udp] [.......10.0.0.1][52069] -> [...45.76.113.31][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...133] [ip4][..udp] [.......10.0.0.1][53876] -> [..151.80.222.79][..443] + new: [...133] [ip4][..udp] [.......10.0.0.1][53876] -> [..151.80.222.79][..443] detected: [...133] [ip4][..udp] [.......10.0.0.1][53876] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...134] [ip4][..udp] [.......10.0.0.1][45497] -> [..151.80.222.79][..443] + new: [...134] [ip4][..udp] [.......10.0.0.1][45497] -> [..151.80.222.79][..443] detected: [...134] [ip4][..udp] [.......10.0.0.1][45497] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...135] [ip4][..udp] [.......10.0.0.1][47729] -> [..151.80.222.79][..443] + new: [...135] [ip4][..udp] [.......10.0.0.1][47729] -> [..151.80.222.79][..443] detected: [...135] [ip4][..udp] [.......10.0.0.1][47729] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...136] [ip4][..udp] [.......10.0.0.1][52040] -> [..151.80.222.79][..443] + new: [...136] [ip4][..udp] [.......10.0.0.1][52040] -> [..151.80.222.79][..443] detected: [...136] [ip4][..udp] [.......10.0.0.1][52040] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...137] [ip4][..udp] [.......10.0.0.1][57636] -> [..151.80.222.79][..443] + new: [...137] [ip4][..udp] [.......10.0.0.1][57636] -> [..151.80.222.79][..443] detected: [...137] [ip4][..udp] [.......10.0.0.1][57636] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...138] [ip4][..udp] [.......10.0.0.1][38511] -> [..151.80.222.79][..443] + new: [...138] [ip4][..udp] [.......10.0.0.1][38511] -> [..151.80.222.79][..443] detected: [...138] [ip4][..udp] [.......10.0.0.1][38511] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...139] [ip4][..udp] [.......10.0.0.1][59011] -> [...142.4.205.47][..443] + new: [...139] [ip4][..udp] [.......10.0.0.1][59011] -> [...142.4.205.47][..443] detected: [...139] [ip4][..udp] [.......10.0.0.1][59011] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...140] [ip4][..udp] [.......10.0.0.1][50387] -> [...142.4.205.47][..443] + new: [...140] [ip4][..udp] [.......10.0.0.1][50387] -> [...142.4.205.47][..443] detected: [...140] [ip4][..udp] [.......10.0.0.1][50387] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...141] [ip4][..udp] [.......10.0.0.1][40138] -> [...142.4.205.47][..443] + new: [...141] [ip4][..udp] [.......10.0.0.1][40138] -> [...142.4.205.47][..443] detected: [...141] [ip4][..udp] [.......10.0.0.1][40138] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...142] [ip4][..udp] [.......10.0.0.1][51935] -> [...142.4.205.47][..443] + new: [...142] [ip4][..udp] [.......10.0.0.1][51935] -> [...142.4.205.47][..443] detected: [...142] [ip4][..udp] [.......10.0.0.1][51935] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...143] [ip4][..udp] [.......10.0.0.1][54096] -> [...142.4.205.47][..443] + new: [...143] [ip4][..udp] [.......10.0.0.1][54096] -> [...142.4.205.47][..443] detected: [...143] [ip4][..udp] [.......10.0.0.1][54096] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...144] [ip4][..udp] [.......10.0.0.1][35903] -> [...142.4.205.47][..443] + new: [...144] [ip4][..udp] [.......10.0.0.1][35903] -> [...142.4.205.47][..443] detected: [...144] [ip4][..udp] [.......10.0.0.1][35903] -> [...142.4.205.47][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...145] [ip4][..udp] [.......10.0.0.1][37328] -> [193.191.187.107][..443] + new: [...145] [ip4][..udp] [.......10.0.0.1][37328] -> [193.191.187.107][..443] detected: [...145] [ip4][..udp] [.......10.0.0.1][37328] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...146] [ip4][..udp] [.......10.0.0.1][35885] -> [193.191.187.107][..443] + new: [...146] [ip4][..udp] [.......10.0.0.1][35885] -> [193.191.187.107][..443] detected: [...146] [ip4][..udp] [.......10.0.0.1][35885] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...147] [ip4][..udp] [.......10.0.0.1][33279] -> [193.191.187.107][..443] + new: [...147] [ip4][..udp] [.......10.0.0.1][33279] -> [193.191.187.107][..443] detected: [...147] [ip4][..udp] [.......10.0.0.1][33279] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...148] [ip4][..udp] [.......10.0.0.1][54215] -> [193.191.187.107][..443] + new: [...148] [ip4][..udp] [.......10.0.0.1][54215] -> [193.191.187.107][..443] detected: [...148] [ip4][..udp] [.......10.0.0.1][54215] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...149] [ip4][..udp] [.......10.0.0.1][49040] -> [193.191.187.107][..443] + new: [...149] [ip4][..udp] [.......10.0.0.1][49040] -> [193.191.187.107][..443] detected: [...149] [ip4][..udp] [.......10.0.0.1][49040] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...150] [ip4][..udp] [.......10.0.0.1][49115] -> [193.191.187.107][..443] + new: [...150] [ip4][..udp] [.......10.0.0.1][49115] -> [193.191.187.107][..443] detected: [...150] [ip4][..udp] [.......10.0.0.1][49115] -> [193.191.187.107][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...151] [ip4][..udp] [.......10.0.0.1][45375] -> [..51.15.124.208][.4343] + new: [...151] [ip4][..udp] [.......10.0.0.1][45375] -> [..51.15.124.208][.4343] detected: [...151] [ip4][..udp] [.......10.0.0.1][45375] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...152] [ip4][..udp] [.......10.0.0.1][49975] -> [..51.15.124.208][.4343] + new: [...152] [ip4][..udp] [.......10.0.0.1][49975] -> [..51.15.124.208][.4343] detected: [...152] [ip4][..udp] [.......10.0.0.1][49975] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...153] [ip4][..udp] [.......10.0.0.1][38310] -> [..51.15.124.208][.4343] + new: [...153] [ip4][..udp] [.......10.0.0.1][38310] -> [..51.15.124.208][.4343] detected: [...153] [ip4][..udp] [.......10.0.0.1][38310] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...154] [ip4][..udp] [.......10.0.0.1][55768] -> [..51.15.124.208][.4343] + new: [...154] [ip4][..udp] [.......10.0.0.1][55768] -> [..51.15.124.208][.4343] detected: [...154] [ip4][..udp] [.......10.0.0.1][55768] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...155] [ip4][..udp] [.......10.0.0.1][39910] -> [..51.15.124.208][.4343] + new: [...155] [ip4][..udp] [.......10.0.0.1][39910] -> [..51.15.124.208][.4343] detected: [...155] [ip4][..udp] [.......10.0.0.1][39910] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [...156] [ip4][..udp] [.......10.0.0.1][53887] -> [..51.15.124.208][.4343] + new: [...156] [ip4][..udp] [.......10.0.0.1][53887] -> [..51.15.124.208][.4343] detected: [...156] [ip4][..udp] [.......10.0.0.1][53887] -> [..51.15.124.208][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...157] [ip4][..udp] [.......10.0.0.1][36930] -> [167.114.220.125][..443] + new: [...157] [ip4][..udp] [.......10.0.0.1][36930] -> [167.114.220.125][..443] detected: [...157] [ip4][..udp] [.......10.0.0.1][36930] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...158] [ip4][..udp] [.......10.0.0.1][38508] -> [167.114.220.125][..443] + new: [...158] [ip4][..udp] [.......10.0.0.1][38508] -> [167.114.220.125][..443] detected: [...158] [ip4][..udp] [.......10.0.0.1][38508] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [...159] [ip4][..udp] [.......10.0.0.1][39816] -> [167.114.220.125][..443] + new: [...159] [ip4][..udp] [.......10.0.0.1][39816] -> [167.114.220.125][..443] detected: [...159] [ip4][..udp] [.......10.0.0.1][39816] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...160] [ip4][..udp] [.......10.0.0.1][45613] -> [167.114.220.125][..443] + new: [...160] [ip4][..udp] [.......10.0.0.1][45613] -> [167.114.220.125][..443] detected: [...160] [ip4][..udp] [.......10.0.0.1][45613] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] - new: [...161] [ip4][..udp] [.......10.0.0.1][59589] -> [167.114.220.125][..443] + new: [...161] [ip4][..udp] [.......10.0.0.1][59589] -> [167.114.220.125][..443] detected: [...161] [ip4][..udp] [.......10.0.0.1][59589] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] - new: [...162] [ip4][..udp] [.......10.0.0.1][45747] -> [167.114.220.125][..443] + new: [...162] [ip4][..udp] [.......10.0.0.1][45747] -> [167.114.220.125][..443] detected: [...162] [ip4][..udp] [.......10.0.0.1][45747] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...163] [ip4][..udp] [.......10.0.0.1][35734] -> [..5.189.170.196][..465] + new: [...163] [ip4][..udp] [.......10.0.0.1][35734] -> [..5.189.170.196][..465] detected: [...163] [ip4][..udp] [.......10.0.0.1][35734] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] - new: [...164] [ip4][..udp] [.......10.0.0.1][44496] -> [..5.189.170.196][..465] + new: [...164] [ip4][..udp] [.......10.0.0.1][44496] -> [..5.189.170.196][..465] detected: [...164] [ip4][..udp] [.......10.0.0.1][44496] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] - new: [...165] [ip4][..udp] [.......10.0.0.1][58104] -> [..5.189.170.196][..465] + new: [...165] [ip4][..udp] [.......10.0.0.1][58104] -> [..5.189.170.196][..465] detected: [...165] [ip4][..udp] [.......10.0.0.1][58104] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [7/16] - new: [...166] [ip4][..udp] [.......10.0.0.1][40748] -> [..5.189.170.196][..465] + new: [...166] [ip4][..udp] [.......10.0.0.1][40748] -> [..5.189.170.196][..465] detected: [...166] [ip4][..udp] [.......10.0.0.1][40748] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] - new: [...167] [ip4][..udp] [.......10.0.0.1][58650] -> [..5.189.170.196][..465] + new: [...167] [ip4][..udp] [.......10.0.0.1][58650] -> [..5.189.170.196][..465] detected: [...167] [ip4][..udp] [.......10.0.0.1][58650] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] - new: [...168] [ip4][..udp] [.......10.0.0.1][59749] -> [..5.189.170.196][..465] + new: [...168] [ip4][..udp] [.......10.0.0.1][59749] -> [..5.189.170.196][..465] detected: [...168] [ip4][..udp] [.......10.0.0.1][59749] -> [..5.189.170.196][..465] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [8/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [9/16] - new: [...169] [ip4][..udp] [.......10.0.0.1][38709] -> [.185.253.154.66][.4343] + new: [...169] [ip4][..udp] [.......10.0.0.1][38709] -> [.185.253.154.66][.4343] detected: [...169] [ip4][..udp] [.......10.0.0.1][38709] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...170] [ip4][..udp] [.......10.0.0.1][44469] -> [.185.253.154.66][.4343] + new: [...170] [ip4][..udp] [.......10.0.0.1][44469] -> [.185.253.154.66][.4343] detected: [...170] [ip4][..udp] [.......10.0.0.1][44469] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...171] [ip4][..udp] [.......10.0.0.1][45815] -> [.185.253.154.66][.4343] + new: [...171] [ip4][..udp] [.......10.0.0.1][45815] -> [.185.253.154.66][.4343] detected: [...171] [ip4][..udp] [.......10.0.0.1][45815] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...172] [ip4][..udp] [.......10.0.0.1][43540] -> [.185.253.154.66][.4343] + new: [...172] [ip4][..udp] [.......10.0.0.1][43540] -> [.185.253.154.66][.4343] detected: [...172] [ip4][..udp] [.......10.0.0.1][43540] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] - new: [...173] [ip4][..udp] [.......10.0.0.1][48159] -> [.185.253.154.66][.4343] + new: [...173] [ip4][..udp] [.......10.0.0.1][48159] -> [.185.253.154.66][.4343] detected: [...173] [ip4][..udp] [.......10.0.0.1][48159] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...174] [ip4][..udp] [.......10.0.0.1][38482] -> [.185.253.154.66][.4343] + new: [...174] [ip4][..udp] [.......10.0.0.1][38482] -> [.185.253.154.66][.4343] detected: [...174] [ip4][..udp] [.......10.0.0.1][38482] -> [.185.253.154.66][.4343] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [...175] [ip4][..udp] [.......10.0.0.1][51647] -> [..142.4.204.111][..443] + new: [...175] [ip4][..udp] [.......10.0.0.1][51647] -> [..142.4.204.111][..443] detected: [...175] [ip4][..udp] [.......10.0.0.1][51647] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...176] [ip4][..udp] [.......10.0.0.1][59224] -> [..142.4.204.111][..443] + new: [...176] [ip4][..udp] [.......10.0.0.1][59224] -> [..142.4.204.111][..443] detected: [...176] [ip4][..udp] [.......10.0.0.1][59224] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...177] [ip4][..udp] [.......10.0.0.1][41895] -> [..142.4.204.111][..443] + new: [...177] [ip4][..udp] [.......10.0.0.1][41895] -> [..142.4.204.111][..443] detected: [...177] [ip4][..udp] [.......10.0.0.1][41895] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [...178] [ip4][..udp] [.......10.0.0.1][46363] -> [..142.4.204.111][..443] + new: [...178] [ip4][..udp] [.......10.0.0.1][46363] -> [..142.4.204.111][..443] detected: [...178] [ip4][..udp] [.......10.0.0.1][46363] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...179] [ip4][..udp] [.......10.0.0.1][57180] -> [..142.4.204.111][..443] + new: [...179] [ip4][..udp] [.......10.0.0.1][57180] -> [..142.4.204.111][..443] detected: [...179] [ip4][..udp] [.......10.0.0.1][57180] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] - new: [...180] [ip4][..udp] [.......10.0.0.1][47621] -> [..142.4.204.111][..443] + new: [...180] [ip4][..udp] [.......10.0.0.1][47621] -> [..142.4.204.111][..443] detected: [...180] [ip4][..udp] [.......10.0.0.1][47621] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] update: [....10] [ip4][..udp] [.......10.0.0.1][43748] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] @@ -409,33 +409,33 @@ update: [....11] [ip4][..udp] [.......10.0.0.1][57395] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [.......10.0.0.1][53299] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [.......10.0.0.1][49518] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] - new: [...181] [ip4][..udp] [.......10.0.0.1][38371] -> [.212.47.228.136][..443] + new: [...181] [ip4][..udp] [.......10.0.0.1][38371] -> [.212.47.228.136][..443] detected: [...181] [ip4][..udp] [.......10.0.0.1][38371] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...182] [ip4][..udp] [.......10.0.0.1][34228] -> [.212.47.228.136][..443] + new: [...182] [ip4][..udp] [.......10.0.0.1][34228] -> [.212.47.228.136][..443] detected: [...182] [ip4][..udp] [.......10.0.0.1][34228] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...183] [ip4][..udp] [.......10.0.0.1][52056] -> [.212.47.228.136][..443] + new: [...183] [ip4][..udp] [.......10.0.0.1][52056] -> [.212.47.228.136][..443] detected: [...183] [ip4][..udp] [.......10.0.0.1][52056] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...184] [ip4][..udp] [.......10.0.0.1][40775] -> [.212.47.228.136][..443] + new: [...184] [ip4][..udp] [.......10.0.0.1][40775] -> [.212.47.228.136][..443] detected: [...184] [ip4][..udp] [.......10.0.0.1][40775] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...185] [ip4][..udp] [.......10.0.0.1][56335] -> [.212.47.228.136][..443] + new: [...185] [ip4][..udp] [.......10.0.0.1][56335] -> [.212.47.228.136][..443] detected: [...185] [ip4][..udp] [.......10.0.0.1][56335] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...186] [ip4][..udp] [.......10.0.0.1][60885] -> [.212.47.228.136][..443] + new: [...186] [ip4][..udp] [.......10.0.0.1][60885] -> [.212.47.228.136][..443] detected: [...186] [ip4][..udp] [.......10.0.0.1][60885] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [...187] [ip4][..udp] [.......10.0.0.1][58948] -> [....85.5.93.230][.8443] + new: [...187] [ip4][..udp] [.......10.0.0.1][58948] -> [....85.5.93.230][.8443] detected: [...187] [ip4][..udp] [.......10.0.0.1][58948] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...188] [ip4][..udp] [.......10.0.0.1][50403] -> [....85.5.93.230][.8443] + new: [...188] [ip4][..udp] [.......10.0.0.1][50403] -> [....85.5.93.230][.8443] detected: [...188] [ip4][..udp] [.......10.0.0.1][50403] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...189] [ip4][..udp] [.......10.0.0.1][46646] -> [....85.5.93.230][.8443] + new: [...189] [ip4][..udp] [.......10.0.0.1][46646] -> [....85.5.93.230][.8443] detected: [...189] [ip4][..udp] [.......10.0.0.1][46646] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...190] [ip4][..udp] [.......10.0.0.1][57090] -> [....85.5.93.230][.8443] + new: [...190] [ip4][..udp] [.......10.0.0.1][57090] -> [....85.5.93.230][.8443] detected: [...190] [ip4][..udp] [.......10.0.0.1][57090] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [...191] [ip4][..udp] [.......10.0.0.1][51826] -> [....85.5.93.230][.8443] + new: [...191] [ip4][..udp] [.......10.0.0.1][51826] -> [....85.5.93.230][.8443] detected: [...191] [ip4][..udp] [.......10.0.0.1][51826] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...192] [ip4][..udp] [.......10.0.0.1][39259] -> [....85.5.93.230][.8443] + new: [...192] [ip4][..udp] [.......10.0.0.1][39259] -> [....85.5.93.230][.8443] detected: [...192] [ip4][..udp] [.......10.0.0.1][39259] -> [....85.5.93.230][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] @@ -583,93 +583,93 @@ update: [....16] [ip4][..udp] [.......10.0.0.1][59405] -> [.185.134.196.55][.8443] [DNScrypt][Unknown][Network][Acceptable] update: [....80] [ip4][..udp] [.......10.0.0.1][46313] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] update: [....64] [ip4][..udp] [.......10.0.0.1][42570] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...193] [ip4][..udp] [.......10.0.0.1][50601] -> [..139.99.222.72][.8443] + new: [...193] [ip4][..udp] [.......10.0.0.1][50601] -> [..139.99.222.72][.8443] detected: [...193] [ip4][..udp] [.......10.0.0.1][50601] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...194] [ip4][..udp] [.......10.0.0.1][40374] -> [..139.99.222.72][.8443] + new: [...194] [ip4][..udp] [.......10.0.0.1][40374] -> [..139.99.222.72][.8443] detected: [...194] [ip4][..udp] [.......10.0.0.1][40374] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...195] [ip4][..udp] [.......10.0.0.1][51509] -> [..139.99.222.72][.8443] + new: [...195] [ip4][..udp] [.......10.0.0.1][51509] -> [..139.99.222.72][.8443] detected: [...195] [ip4][..udp] [.......10.0.0.1][51509] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...196] [ip4][..udp] [.......10.0.0.1][45682] -> [..139.99.222.72][.8443] + new: [...196] [ip4][..udp] [.......10.0.0.1][45682] -> [..139.99.222.72][.8443] detected: [...196] [ip4][..udp] [.......10.0.0.1][45682] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...197] [ip4][..udp] [.......10.0.0.1][59400] -> [..139.99.222.72][.8443] + new: [...197] [ip4][..udp] [.......10.0.0.1][59400] -> [..139.99.222.72][.8443] detected: [...197] [ip4][..udp] [.......10.0.0.1][59400] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...198] [ip4][..udp] [.......10.0.0.1][49796] -> [..139.99.222.72][.8443] + new: [...198] [ip4][..udp] [.......10.0.0.1][49796] -> [..139.99.222.72][.8443] detected: [...198] [ip4][..udp] [.......10.0.0.1][49796] -> [..139.99.222.72][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [...199] [ip4][..udp] [.......10.0.0.1][48300] -> [.144.91.106.227][..443] + new: [...199] [ip4][..udp] [.......10.0.0.1][48300] -> [.144.91.106.227][..443] detected: [...199] [ip4][..udp] [.......10.0.0.1][48300] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...200] [ip4][..udp] [.......10.0.0.1][41108] -> [.144.91.106.227][..443] + new: [...200] [ip4][..udp] [.......10.0.0.1][41108] -> [.144.91.106.227][..443] detected: [...200] [ip4][..udp] [.......10.0.0.1][41108] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [...201] [ip4][..udp] [.......10.0.0.1][48237] -> [.144.91.106.227][..443] + new: [...201] [ip4][..udp] [.......10.0.0.1][48237] -> [.144.91.106.227][..443] detected: [...201] [ip4][..udp] [.......10.0.0.1][48237] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] - new: [...202] [ip4][..udp] [.......10.0.0.1][54305] -> [.144.91.106.227][..443] + new: [...202] [ip4][..udp] [.......10.0.0.1][54305] -> [.144.91.106.227][..443] detected: [...202] [ip4][..udp] [.......10.0.0.1][54305] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...203] [ip4][..udp] [.......10.0.0.1][55469] -> [.144.91.106.227][..443] + new: [...203] [ip4][..udp] [.......10.0.0.1][55469] -> [.144.91.106.227][..443] detected: [...203] [ip4][..udp] [.......10.0.0.1][55469] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...204] [ip4][..udp] [.......10.0.0.1][54204] -> [.144.91.106.227][..443] + new: [...204] [ip4][..udp] [.......10.0.0.1][54204] -> [.144.91.106.227][..443] detected: [...204] [ip4][..udp] [.......10.0.0.1][54204] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] - new: [...205] [ip4][..udp] [.......10.0.0.1][33293] -> [..46.227.200.55][.8443] + new: [...205] [ip4][..udp] [.......10.0.0.1][33293] -> [..46.227.200.55][.8443] detected: [...205] [ip4][..udp] [.......10.0.0.1][33293] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...206] [ip4][..udp] [.......10.0.0.1][38242] -> [..46.227.200.55][.8443] + new: [...206] [ip4][..udp] [.......10.0.0.1][38242] -> [..46.227.200.55][.8443] detected: [...206] [ip4][..udp] [.......10.0.0.1][38242] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...207] [ip4][..udp] [.......10.0.0.1][33246] -> [..46.227.200.55][.8443] + new: [...207] [ip4][..udp] [.......10.0.0.1][33246] -> [..46.227.200.55][.8443] detected: [...207] [ip4][..udp] [.......10.0.0.1][33246] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [7/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [8/16] - new: [...208] [ip4][..udp] [.......10.0.0.1][50277] -> [..46.227.200.55][.8443] + new: [...208] [ip4][..udp] [.......10.0.0.1][50277] -> [..46.227.200.55][.8443] detected: [...208] [ip4][..udp] [.......10.0.0.1][50277] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...209] [ip4][..udp] [.......10.0.0.1][44161] -> [..46.227.200.55][.8443] + new: [...209] [ip4][..udp] [.......10.0.0.1][44161] -> [..46.227.200.55][.8443] detected: [...209] [ip4][..udp] [.......10.0.0.1][44161] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [9/16] - new: [...210] [ip4][..udp] [.......10.0.0.1][49177] -> [..46.227.200.55][.8443] + new: [...210] [ip4][..udp] [.......10.0.0.1][49177] -> [..46.227.200.55][.8443] detected: [...210] [ip4][..udp] [.......10.0.0.1][49177] -> [..46.227.200.55][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...211] [ip4][..udp] [.......10.0.0.1][54375] -> [..107.170.57.34][..443] + new: [...211] [ip4][..udp] [.......10.0.0.1][54375] -> [..107.170.57.34][..443] detected: [...211] [ip4][..udp] [.......10.0.0.1][54375] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...212] [ip4][..udp] [.......10.0.0.1][55185] -> [..107.170.57.34][..443] + new: [...212] [ip4][..udp] [.......10.0.0.1][55185] -> [..107.170.57.34][..443] detected: [...212] [ip4][..udp] [.......10.0.0.1][55185] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [10/16] - new: [...213] [ip4][..udp] [.......10.0.0.1][36335] -> [..107.170.57.34][..443] + new: [...213] [ip4][..udp] [.......10.0.0.1][36335] -> [..107.170.57.34][..443] detected: [...213] [ip4][..udp] [.......10.0.0.1][36335] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...214] [ip4][..udp] [.......10.0.0.1][37287] -> [..107.170.57.34][..443] + new: [...214] [ip4][..udp] [.......10.0.0.1][37287] -> [..107.170.57.34][..443] detected: [...214] [ip4][..udp] [.......10.0.0.1][37287] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...215] [ip4][..udp] [.......10.0.0.1][33143] -> [..107.170.57.34][..443] + new: [...215] [ip4][..udp] [.......10.0.0.1][33143] -> [..107.170.57.34][..443] detected: [...215] [ip4][..udp] [.......10.0.0.1][33143] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...216] [ip4][..udp] [.......10.0.0.1][42141] -> [..107.170.57.34][..443] + new: [...216] [ip4][..udp] [.......10.0.0.1][42141] -> [..107.170.57.34][..443] detected: [...216] [ip4][..udp] [.......10.0.0.1][42141] -> [..107.170.57.34][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [11/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [12/16] - new: [...217] [ip4][..udp] [.......10.0.0.1][56988] -> [185.193.127.244][..443] + new: [...217] [ip4][..udp] [.......10.0.0.1][56988] -> [185.193.127.244][..443] detected: [...217] [ip4][..udp] [.......10.0.0.1][56988] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...218] [ip4][..udp] [.......10.0.0.1][50062] -> [185.193.127.244][..443] + new: [...218] [ip4][..udp] [.......10.0.0.1][50062] -> [185.193.127.244][..443] detected: [...218] [ip4][..udp] [.......10.0.0.1][50062] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...219] [ip4][..udp] [.......10.0.0.1][59354] -> [185.193.127.244][..443] + new: [...219] [ip4][..udp] [.......10.0.0.1][59354] -> [185.193.127.244][..443] detected: [...219] [ip4][..udp] [.......10.0.0.1][59354] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...220] [ip4][..udp] [.......10.0.0.1][54920] -> [185.193.127.244][..443] + new: [...220] [ip4][..udp] [.......10.0.0.1][54920] -> [185.193.127.244][..443] detected: [...220] [ip4][..udp] [.......10.0.0.1][54920] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [13/16] - new: [...221] [ip4][..udp] [.......10.0.0.1][46314] -> [185.193.127.244][..443] + new: [...221] [ip4][..udp] [.......10.0.0.1][46314] -> [185.193.127.244][..443] detected: [...221] [ip4][..udp] [.......10.0.0.1][46314] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...222] [ip4][..udp] [.......10.0.0.1][47971] -> [185.193.127.244][..443] + new: [...222] [ip4][..udp] [.......10.0.0.1][47971] -> [185.193.127.244][..443] detected: [...222] [ip4][..udp] [.......10.0.0.1][47971] -> [185.193.127.244][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [14/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [15/16] - new: [...223] [ip4][..udp] [.......10.0.0.1][49568] -> [...77.66.84.233][..443] + new: [...223] [ip4][..udp] [.......10.0.0.1][49568] -> [...77.66.84.233][..443] detected: [...223] [ip4][..udp] [.......10.0.0.1][49568] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...224] [ip4][..udp] [.......10.0.0.1][46140] -> [...77.66.84.233][..443] + new: [...224] [ip4][..udp] [.......10.0.0.1][46140] -> [...77.66.84.233][..443] detected: [...224] [ip4][..udp] [.......10.0.0.1][46140] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...225] [ip4][..udp] [.......10.0.0.1][40209] -> [...77.66.84.233][..443] + new: [...225] [ip4][..udp] [.......10.0.0.1][40209] -> [...77.66.84.233][..443] detected: [...225] [ip4][..udp] [.......10.0.0.1][40209] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...226] [ip4][..udp] [.......10.0.0.1][49732] -> [...77.66.84.233][..443] + new: [...226] [ip4][..udp] [.......10.0.0.1][49732] -> [...77.66.84.233][..443] detected: [...226] [ip4][..udp] [.......10.0.0.1][49732] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [16/16] - new: [...227] [ip4][..udp] [.......10.0.0.1][50757] -> [...77.66.84.233][..443] + new: [...227] [ip4][..udp] [.......10.0.0.1][50757] -> [...77.66.84.233][..443] detected: [...227] [ip4][..udp] [.......10.0.0.1][50757] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...228] [ip4][..udp] [.......10.0.0.1][57109] -> [...77.66.84.233][..443] + new: [...228] [ip4][..udp] [.......10.0.0.1][57109] -> [...77.66.84.233][..443] detected: [...228] [ip4][..udp] [.......10.0.0.1][57109] -> [...77.66.84.233][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...159] [ip4][..udp] [.......10.0.0.1][39816] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...175] [ip4][..udp] [.......10.0.0.1][51647] -> [..142.4.204.111][..443] [DNScrypt][Unknown][Network][Acceptable] @@ -707,27 +707,27 @@ update: [...160] [ip4][..udp] [.......10.0.0.1][45613] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...162] [ip4][..udp] [.......10.0.0.1][45747] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [.......10.0.0.1][49518] -> [..62.210.180.71][.1053] [DNScrypt][Unknown][Network][Acceptable] - new: [...229] [ip4][..udp] [.......10.0.0.1][59587] -> [..23.111.74.205][..443] + new: [...229] [ip4][..udp] [.......10.0.0.1][59587] -> [..23.111.74.205][..443] detected: [...229] [ip4][..udp] [.......10.0.0.1][59587] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...230] [ip4][..udp] [.......10.0.0.1][60852] -> [..23.111.74.205][..443] + new: [...230] [ip4][..udp] [.......10.0.0.1][60852] -> [..23.111.74.205][..443] detected: [...230] [ip4][..udp] [.......10.0.0.1][60852] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...231] [ip4][..udp] [.......10.0.0.1][44793] -> [..23.111.74.205][..443] + new: [...231] [ip4][..udp] [.......10.0.0.1][44793] -> [..23.111.74.205][..443] detected: [...231] [ip4][..udp] [.......10.0.0.1][44793] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...232] [ip4][..udp] [.......10.0.0.1][53045] -> [..23.111.74.205][..443] + new: [...232] [ip4][..udp] [.......10.0.0.1][53045] -> [..23.111.74.205][..443] detected: [...232] [ip4][..udp] [.......10.0.0.1][53045] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...233] [ip4][..udp] [.......10.0.0.1][34024] -> [..23.111.74.205][..443] + new: [...233] [ip4][..udp] [.......10.0.0.1][34024] -> [..23.111.74.205][..443] detected: [...233] [ip4][..udp] [.......10.0.0.1][34024] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...234] [ip4][..udp] [.......10.0.0.1][60113] -> [..23.111.74.205][..443] + new: [...234] [ip4][..udp] [.......10.0.0.1][60113] -> [..23.111.74.205][..443] detected: [...234] [ip4][..udp] [.......10.0.0.1][60113] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...235] [ip4][..udp] [.......10.0.0.1][47545] -> [..151.80.222.79][..443] + new: [...235] [ip4][..udp] [.......10.0.0.1][47545] -> [..151.80.222.79][..443] detected: [...235] [ip4][..udp] [.......10.0.0.1][47545] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...236] [ip4][..udp] [.......10.0.0.1][38660] -> [.144.91.106.227][..443] + new: [...236] [ip4][..udp] [.......10.0.0.1][38660] -> [.144.91.106.227][..443] detected: [...236] [ip4][..udp] [.......10.0.0.1][38660] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...237] [ip4][..udp] [.......10.0.0.1][60393] -> [.144.91.106.227][..443] + new: [...237] [ip4][..udp] [.......10.0.0.1][60393] -> [.144.91.106.227][..443] detected: [...237] [ip4][..udp] [.......10.0.0.1][60393] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...238] [ip4][..udp] [.......10.0.0.1][50443] -> [.144.91.106.227][..443] + new: [...238] [ip4][..udp] [.......10.0.0.1][50443] -> [.144.91.106.227][..443] detected: [...238] [ip4][..udp] [.......10.0.0.1][50443] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...239] [ip4][..udp] [.......10.0.0.1][37711] -> [.144.91.106.227][..443] + new: [...239] [ip4][..udp] [.......10.0.0.1][37711] -> [.144.91.106.227][..443] detected: [...239] [ip4][..udp] [.......10.0.0.1][37711] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] idle: [...159] [ip4][..udp] [.......10.0.0.1][39816] -> [167.114.220.125][..443] [DNScrypt][Unknown][Network][Acceptable] idle: [....51] [ip4][..udp] [.......10.0.0.1][34885] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] @@ -963,17 +963,17 @@ idle: [...231] [ip4][..udp] [.......10.0.0.1][44793] -> [..23.111.74.205][..443] [DNScrypt][Unknown][Network][Acceptable] idle: [....80] [ip4][..udp] [.......10.0.0.1][46313] -> [..52.65.235.129][..443] [DNScrypt][AmazonAWS][Network][Acceptable] idle: [....64] [ip4][..udp] [.......10.0.0.1][42570] -> [.149.112.112.10][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...240] [ip4][..udp] [.......10.0.0.1][40958] -> [...195.30.94.28][.8443] + new: [...240] [ip4][..udp] [.......10.0.0.1][40958] -> [...195.30.94.28][.8443] detected: [...240] [ip4][..udp] [.......10.0.0.1][40958] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] update: [...235] [ip4][..udp] [.......10.0.0.1][47545] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...236] [ip4][..udp] [.......10.0.0.1][38660] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...241] [ip4][..udp] [.......10.0.0.1][59812] -> [...195.30.94.28][.8443] + new: [...241] [ip4][..udp] [.......10.0.0.1][59812] -> [...195.30.94.28][.8443] detected: [...241] [ip4][..udp] [.......10.0.0.1][59812] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...242] [ip4][..udp] [.......10.0.0.1][45234] -> [....51.15.62.65][..443] + new: [...242] [ip4][..udp] [.......10.0.0.1][45234] -> [....51.15.62.65][..443] detected: [...242] [ip4][..udp] [.......10.0.0.1][45234] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...243] [ip4][..udp] [.......10.0.0.1][36746] -> [....51.15.62.65][..443] + new: [...243] [ip4][..udp] [.......10.0.0.1][36746] -> [....51.15.62.65][..443] detected: [...243] [ip4][..udp] [.......10.0.0.1][36746] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] - new: [...244] [ip4][..udp] [.......10.0.0.1][33089] -> [....51.15.62.65][..443] + new: [...244] [ip4][..udp] [.......10.0.0.1][33089] -> [....51.15.62.65][..443] detected: [...244] [ip4][..udp] [.......10.0.0.1][33089] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...239] [ip4][..udp] [.......10.0.0.1][37711] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...237] [ip4][..udp] [.......10.0.0.1][60393] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] @@ -981,7 +981,7 @@ update: [...235] [ip4][..udp] [.......10.0.0.1][47545] -> [..151.80.222.79][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...236] [ip4][..udp] [.......10.0.0.1][38660] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] update: [...240] [ip4][..udp] [.......10.0.0.1][40958] -> [...195.30.94.28][.8443] [DNScrypt][Unknown][Network][Acceptable] - new: [...245] [ip4][..udp] [.......10.0.0.1][40675] -> [....51.15.62.65][..443] + new: [...245] [ip4][..udp] [.......10.0.0.1][40675] -> [....51.15.62.65][..443] detected: [...245] [ip4][..udp] [.......10.0.0.1][40675] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] idle: [...243] [ip4][..udp] [.......10.0.0.1][36746] -> [....51.15.62.65][..443] [DNScrypt][Unknown][Network][Acceptable] idle: [...239] [ip4][..udp] [.......10.0.0.1][37711] -> [.144.91.106.227][..443] [DNScrypt][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/dnscrypt-v2-doh.pcap.out b/test/results/flow-info/default/dnscrypt-v2-doh.pcap.out index 425f418dc..22b4da7b3 100644 --- a/test/results/flow-info/default/dnscrypt-v2-doh.pcap.out +++ b/test/results/flow-info/default/dnscrypt-v2-doh.pcap.out @@ -1,115 +1,115 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.1][53674] -> [..139.99.222.72][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.......10.0.0.1][53674] -> [..139.99.222.72][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.......10.0.0.1][53674] -> [..139.99.222.72][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh-2.seby.io] detection-update: [.....1] [ip4][..tcp] [.......10.0.0.1][53674] -> [..139.99.222.72][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh-2.seby.io] - new: [.....2] [ip4][..tcp] [.......10.0.0.1][53676] -> [..139.99.222.72][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.......10.0.0.1][53676] -> [..139.99.222.72][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [.......10.0.0.1][53676] -> [..139.99.222.72][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh-2.seby.io] detection-update: [.....2] [ip4][..tcp] [.......10.0.0.1][53676] -> [..139.99.222.72][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh-2.seby.io] - new: [.....3] [ip4][..tcp] [.......10.0.0.1][50614] -> [..185.95.218.42][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [.......10.0.0.1][50614] -> [..185.95.218.42][..443] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [.......10.0.0.1][50614] -> [..185.95.218.42][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.digitale-gesellschaft.ch] detection-update: [.....3] [ip4][..tcp] [.......10.0.0.1][50614] -> [..185.95.218.42][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.digitale-gesellschaft.ch] - new: [.....4] [ip4][..tcp] [.......10.0.0.1][55962] -> [..51.158.147.50][..443] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [.......10.0.0.1][55962] -> [..51.158.147.50][..443] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [.......10.0.0.1][55962] -> [..51.158.147.50][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][resolver-eu.lelux.fi] detection-update: [.....4] [ip4][..tcp] [.......10.0.0.1][55962] -> [..51.158.147.50][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][resolver-eu.lelux.fi] - new: [.....5] [ip4][..tcp] [.......10.0.0.1][59404] -> [.185.253.154.66][..443] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [.......10.0.0.1][59404] -> [.185.253.154.66][..443] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [.......10.0.0.1][59404] -> [.185.253.154.66][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnses.alekberg.net] detection-update: [.....5] [ip4][..tcp] [.......10.0.0.1][59404] -> [.185.253.154.66][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnses.alekberg.net] - new: [.....6] [ip4][..tcp] [.......10.0.0.1][40938] -> [..172.104.93.80][..443] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [.......10.0.0.1][40938] -> [..172.104.93.80][..443] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [.......10.0.0.1][40938] -> [..172.104.93.80][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jp.tiar.app] detection-update: [.....6] [ip4][..tcp] [.......10.0.0.1][40938] -> [..172.104.93.80][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jp.tiar.app] - new: [.....7] [ip4][..tcp] [.......10.0.0.1][37530] -> [167.114.220.125][..453] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [.......10.0.0.1][37530] -> [167.114.220.125][..453] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [.......10.0.0.1][37530] -> [167.114.220.125][..453] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns1.dnscrypt.ca] RISK: Known Proto on Non Std Port detection-update: [.....7] [ip4][..tcp] [.......10.0.0.1][37530] -> [167.114.220.125][..453] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns1.dnscrypt.ca] RISK: Known Proto on Non Std Port - new: [.....8] [ip4][..tcp] [.......10.0.0.1][38186] -> [...185.43.135.1][..443] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [.......10.0.0.1][38186] -> [...185.43.135.1][..443] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [.......10.0.0.1][38186] -> [...185.43.135.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][odvr.nic.cz] detection-update: [.....8] [ip4][..tcp] [.......10.0.0.1][38186] -> [...185.43.135.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][odvr.nic.cz] RISK: TLS Cert Expired - new: [.....9] [ip4][..tcp] [.......10.0.0.1][51770] -> [.......9.9.9.10][..443] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [.......10.0.0.1][51770] -> [.......9.9.9.10][..443] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [.......10.0.0.1][51770] -> [.......9.9.9.10][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns10.quad9.net] detection-update: [.....9] [ip4][..tcp] [.......10.0.0.1][51770] -> [.......9.9.9.10][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns10.quad9.net] - new: [....10] [ip4][..tcp] [.......10.0.0.1][55322] -> [.185.134.196.55][..443] [MIDSTREAM] + new: [....10] [ip4][..tcp] [.......10.0.0.1][55322] -> [.185.134.196.55][..443] [MIDSTREAM] detected: [....10] [ip4][..tcp] [.......10.0.0.1][55322] -> [.185.134.196.55][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rdns.faelix.net] detection-update: [....10] [ip4][..tcp] [.......10.0.0.1][55322] -> [.185.134.196.55][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rdns.faelix.net] - new: [....11] [ip4][..tcp] [.......10.0.0.1][52386] -> [..51.15.124.208][..443] [MIDSTREAM] + new: [....11] [ip4][..tcp] [.......10.0.0.1][52386] -> [..51.15.124.208][..443] [MIDSTREAM] detected: [....11] [ip4][..tcp] [.......10.0.0.1][52386] -> [..51.15.124.208][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnsnl.alekberg.net] detection-update: [....11] [ip4][..tcp] [.......10.0.0.1][52386] -> [..51.15.124.208][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnsnl.alekberg.net] - new: [....12] [ip4][..tcp] [.......10.0.0.1][41720] -> [116.203.179.248][..443] [MIDSTREAM] + new: [....12] [ip4][..tcp] [.......10.0.0.1][41720] -> [116.203.179.248][..443] [MIDSTREAM] detected: [....12] [ip4][..tcp] [.......10.0.0.1][41720] -> [116.203.179.248][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rumpelsepp.org] detection-update: [....12] [ip4][..tcp] [.......10.0.0.1][41720] -> [116.203.179.248][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rumpelsepp.org] - new: [....13] [ip4][..tcp] [.......10.0.0.1][60026] -> [...195.30.94.28][..443] [MIDSTREAM] + new: [....13] [ip4][..tcp] [.......10.0.0.1][60026] -> [...195.30.94.28][..443] [MIDSTREAM] detected: [....13] [ip4][..tcp] [.......10.0.0.1][60026] -> [...195.30.94.28][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.ffmuc.net] detection-update: [....13] [ip4][..tcp] [.......10.0.0.1][60026] -> [...195.30.94.28][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.ffmuc.net] - new: [....14] [ip4][..tcp] [.......10.0.0.1][46658] -> [185.233.106.232][..443] [MIDSTREAM] + new: [....14] [ip4][..tcp] [.......10.0.0.1][46658] -> [185.233.106.232][..443] [MIDSTREAM] detected: [....14] [ip4][..tcp] [.......10.0.0.1][46658] -> [185.233.106.232][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.dnshome.de] detection-update: [....14] [ip4][..tcp] [.......10.0.0.1][46658] -> [185.233.106.232][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.dnshome.de] - new: [....15] [ip4][..tcp] [.......10.0.0.1][36012] -> [..149.56.228.45][..453] [MIDSTREAM] + new: [....15] [ip4][..tcp] [.......10.0.0.1][36012] -> [..149.56.228.45][..453] [MIDSTREAM] detected: [....15] [ip4][..tcp] [.......10.0.0.1][36012] -> [..149.56.228.45][..453] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns2.dnscrypt.ca] RISK: Known Proto on Non Std Port detection-update: [....15] [ip4][..tcp] [.......10.0.0.1][36012] -> [..149.56.228.45][..453] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns2.dnscrypt.ca] RISK: Known Proto on Non Std Port - new: [....16] [ip4][..tcp] [.......10.0.0.1][38018] -> [..45.153.187.96][..443] [MIDSTREAM] + new: [....16] [ip4][..tcp] [.......10.0.0.1][38018] -> [..45.153.187.96][..443] [MIDSTREAM] detected: [....16] [ip4][..tcp] [.......10.0.0.1][38018] -> [..45.153.187.96][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnsse.alekberg.net] detection-update: [....16] [ip4][..tcp] [.......10.0.0.1][38018] -> [..45.153.187.96][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dnsse.alekberg.net] - new: [....17] [ip4][..tcp] [.......10.0.0.1][44640] -> [...185.235.81.1][..443] [MIDSTREAM] + new: [....17] [ip4][..tcp] [.......10.0.0.1][44640] -> [...185.235.81.1][..443] [MIDSTREAM] detected: [....17] [ip4][..tcp] [.......10.0.0.1][44640] -> [...185.235.81.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.dnslify.com] detection-update: [....17] [ip4][..tcp] [.......10.0.0.1][44640] -> [...185.235.81.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.dnslify.com] - new: [....18] [ip4][..tcp] [.......10.0.0.1][43106] -> [.116.202.176.26][..443] [MIDSTREAM] + new: [....18] [ip4][..tcp] [.......10.0.0.1][43106] -> [.116.202.176.26][..443] [MIDSTREAM] detected: [....18] [ip4][..tcp] [.......10.0.0.1][43106] -> [.116.202.176.26][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.libredns.gr] detection-update: [....18] [ip4][..tcp] [.......10.0.0.1][43106] -> [.116.202.176.26][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.libredns.gr] - new: [....19] [ip4][..tcp] [.......10.0.0.1][59026] -> [....85.5.93.230][..443] [MIDSTREAM] + new: [....19] [ip4][..tcp] [.......10.0.0.1][59026] -> [....85.5.93.230][..443] [MIDSTREAM] detected: [....19] [ip4][..tcp] [.......10.0.0.1][59026] -> [....85.5.93.230][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][ibksturm.synology.me] detection-update: [....19] [ip4][..tcp] [.......10.0.0.1][59026] -> [....85.5.93.230][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][ibksturm.synology.me] - new: [....20] [ip4][..tcp] [.......10.0.0.1][33724] -> [...104.28.28.34][..443] [MIDSTREAM] + new: [....20] [ip4][..tcp] [.......10.0.0.1][33724] -> [...104.28.28.34][..443] [MIDSTREAM] detected: [....20] [ip4][..tcp] [.......10.0.0.1][33724] -> [...104.28.28.34][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jp.tiarap.org] detection-update: [....20] [ip4][..tcp] [.......10.0.0.1][33724] -> [...104.28.28.34][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jp.tiarap.org] - new: [....21] [ip4][..tcp] [.......10.0.0.1][53802] -> [........1.0.0.1][..443] [MIDSTREAM] + new: [....21] [ip4][..tcp] [.......10.0.0.1][53802] -> [........1.0.0.1][..443] [MIDSTREAM] detected: [....21] [ip4][..tcp] [.......10.0.0.1][53802] -> [........1.0.0.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.cloudflare.com] detection-update: [....21] [ip4][..tcp] [.......10.0.0.1][53802] -> [........1.0.0.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.cloudflare.com] - new: [....22] [ip4][..tcp] [.......10.0.0.1][33338] -> [.....45.90.28.0][..443] [MIDSTREAM] + new: [....22] [ip4][..tcp] [.......10.0.0.1][33338] -> [.....45.90.28.0][..443] [MIDSTREAM] detected: [....22] [ip4][..tcp] [.......10.0.0.1][33338] -> [.....45.90.28.0][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.nextdns.io] detection-update: [....22] [ip4][..tcp] [.......10.0.0.1][33338] -> [.....45.90.28.0][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.nextdns.io] - new: [....23] [ip4][..tcp] [.......10.0.0.1][52176] -> [136.144.215.158][..443] [MIDSTREAM] + new: [....23] [ip4][..tcp] [.......10.0.0.1][52176] -> [136.144.215.158][..443] [MIDSTREAM] detected: [....23] [ip4][..tcp] [.......10.0.0.1][52176] -> [136.144.215.158][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.powerdns.org] detection-update: [....23] [ip4][..tcp] [.......10.0.0.1][52176] -> [136.144.215.158][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.powerdns.org] - new: [....24] [ip4][..tcp] [.......10.0.0.1][39214] -> [...104.28.0.106][..443] [MIDSTREAM] + new: [....24] [ip4][..tcp] [.......10.0.0.1][39214] -> [...104.28.0.106][..443] [MIDSTREAM] detected: [....24] [ip4][..tcp] [.......10.0.0.1][39214] -> [...104.28.0.106][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.crypto.sx] detection-update: [....24] [ip4][..tcp] [.......10.0.0.1][39214] -> [...104.28.0.106][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.crypto.sx] - new: [....25] [ip4][..tcp] [.......10.0.0.1][52028] -> [...45.76.113.31][.8443] [MIDSTREAM] + new: [....25] [ip4][..tcp] [.......10.0.0.1][52028] -> [...45.76.113.31][.8443] [MIDSTREAM] detected: [....25] [ip4][..tcp] [.......10.0.0.1][52028] -> [...45.76.113.31][.8443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.seby.io] RISK: Known Proto on Non Std Port detection-update: [....25] [ip4][..tcp] [.......10.0.0.1][52028] -> [...45.76.113.31][.8443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.seby.io] RISK: Known Proto on Non Std Port - new: [....26] [ip4][..tcp] [.......10.0.0.1][34036] -> [..217.169.20.23][..443] [MIDSTREAM] + new: [....26] [ip4][..tcp] [.......10.0.0.1][34036] -> [..217.169.20.23][..443] [MIDSTREAM] detected: [....26] [ip4][..tcp] [.......10.0.0.1][34036] -> [..217.169.20.23][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.aa.net.uk] detection-update: [....26] [ip4][..tcp] [.......10.0.0.1][34036] -> [..217.169.20.23][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns.aa.net.uk] - new: [....27] [ip4][..tcp] [.......10.0.0.1][43718] -> [..146.255.56.98][..443] [MIDSTREAM] + new: [....27] [ip4][..tcp] [.......10.0.0.1][43718] -> [..146.255.56.98][..443] [MIDSTREAM] detected: [....27] [ip4][..tcp] [.......10.0.0.1][43718] -> [..146.255.56.98][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.appliedprivacy.net] detection-update: [....27] [ip4][..tcp] [.......10.0.0.1][43718] -> [..146.255.56.98][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.appliedprivacy.net] - new: [....28] [ip4][..tcp] [.......10.0.0.1][54164] -> [...193.70.85.11][..443] [MIDSTREAM] + new: [....28] [ip4][..tcp] [.......10.0.0.1][54164] -> [...193.70.85.11][..443] [MIDSTREAM] detected: [....28] [ip4][..tcp] [.......10.0.0.1][54164] -> [...193.70.85.11][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.bortzmeyer.fr] detection-update: [....28] [ip4][..tcp] [.......10.0.0.1][54164] -> [...193.70.85.11][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.bortzmeyer.fr] - new: [....29] [ip4][..tcp] [.......10.0.0.1][35714] -> [.209.250.241.25][..443] [MIDSTREAM] + new: [....29] [ip4][..tcp] [.......10.0.0.1][35714] -> [.209.250.241.25][..443] [MIDSTREAM] detected: [....29] [ip4][..tcp] [.......10.0.0.1][35714] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] detection-update: [....29] [ip4][..tcp] [.......10.0.0.1][35714] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] detection-update: [....29] [ip4][..tcp] [.......10.0.0.1][35714] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] RISK: TLS Cert Expired - new: [....30] [ip4][..tcp] [.......10.0.0.1][43888] -> [.95.216.229.153][..443] [MIDSTREAM] + new: [....30] [ip4][..tcp] [.......10.0.0.1][43888] -> [.95.216.229.153][..443] [MIDSTREAM] detected: [....30] [ip4][..tcp] [.......10.0.0.1][43888] -> [.95.216.229.153][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][fi.doh.dns.snopyta.org] detection-update: [....30] [ip4][..tcp] [.......10.0.0.1][43888] -> [.95.216.229.153][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][fi.doh.dns.snopyta.org] - new: [....31] [ip4][..tcp] [.......10.0.0.1][57058] -> [..46.227.200.54][..443] [MIDSTREAM] + new: [....31] [ip4][..tcp] [.......10.0.0.1][57058] -> [..46.227.200.54][..443] [MIDSTREAM] detected: [....31] [ip4][..tcp] [.......10.0.0.1][57058] -> [..46.227.200.54][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rdns.faelix.net] detection-update: [....31] [ip4][..tcp] [.......10.0.0.1][57058] -> [..46.227.200.54][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][rdns.faelix.net] - new: [....32] [ip4][..tcp] [.......10.0.0.1][51846] -> [.......9.9.9.10][..443] [MIDSTREAM] + new: [....32] [ip4][..tcp] [.......10.0.0.1][51846] -> [.......9.9.9.10][..443] [MIDSTREAM] detected: [....32] [ip4][..tcp] [.......10.0.0.1][51846] -> [.......9.9.9.10][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns10.quad9.net] detection-update: [....32] [ip4][..tcp] [.......10.0.0.1][51846] -> [.......9.9.9.10][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][dns10.quad9.net] - new: [....33] [ip4][..tcp] [.......10.0.0.1][44704] -> [...185.235.81.1][..443] [MIDSTREAM] + new: [....33] [ip4][..tcp] [.......10.0.0.1][44704] -> [...185.235.81.1][..443] [MIDSTREAM] detected: [....33] [ip4][..tcp] [.......10.0.0.1][44704] -> [...185.235.81.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.dnslify.com] detection-update: [....33] [ip4][..tcp] [.......10.0.0.1][44704] -> [...185.235.81.1][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][doh.dnslify.com] - new: [....34] [ip4][..tcp] [.......10.0.0.1][35742] -> [.209.250.241.25][..443] [MIDSTREAM] + new: [....34] [ip4][..tcp] [.......10.0.0.1][35742] -> [.209.250.241.25][..443] [MIDSTREAM] detected: [....34] [ip4][..tcp] [.......10.0.0.1][35742] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] detection-update: [....34] [ip4][..tcp] [.......10.0.0.1][35742] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] detection-update: [....34] [ip4][..tcp] [.......10.0.0.1][35742] -> [.209.250.241.25][..443] [TLS.DoH_DoT][Unknown][Network][Acceptable][jarjar.meganerd.nl] diff --git a/test/results/flow-info/default/dnscrypt-v2.pcap.out b/test/results/flow-info/default/dnscrypt-v2.pcap.out index 928e5e146..82ef63a0c 100644 --- a/test/results/flow-info/default/dnscrypt-v2.pcap.out +++ b/test/results/flow-info/default/dnscrypt-v2.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][38650] -> [......127.0.0.2][.5353] + new: [.....1] [ip4][..udp] [......127.0.0.1][38650] -> [......127.0.0.2][.5353] detected: [.....1] [ip4][..udp] [......127.0.0.1][38650] -> [......127.0.0.2][.5353] [DNScrypt][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [......127.0.0.1][42883] -> [......127.0.0.2][.5353] + new: [.....2] [ip4][..udp] [......127.0.0.1][42883] -> [......127.0.0.2][.5353] detected: [.....2] [ip4][..udp] [......127.0.0.1][42883] -> [......127.0.0.2][.5353] [DNScrypt][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [......127.0.0.1][50893] -> [......127.0.0.2][.5353] + new: [.....3] [ip4][..udp] [......127.0.0.1][50893] -> [......127.0.0.2][.5353] detected: [.....3] [ip4][..udp] [......127.0.0.1][50893] -> [......127.0.0.2][.5353] [DNScrypt][Unknown][Network][Acceptable] idle: [.....3] [ip4][..udp] [......127.0.0.1][50893] -> [......127.0.0.2][.5353] [DNScrypt][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [......127.0.0.1][38650] -> [......127.0.0.2][.5353] [DNScrypt][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/dnscrypt_skype_false_positive.pcapng.out b/test/results/flow-info/default/dnscrypt_skype_false_positive.pcapng.out index 6c011b6e5..730f60ca8 100644 --- a/test/results/flow-info/default/dnscrypt_skype_false_positive.pcapng.out +++ b/test/results/flow-info/default/dnscrypt_skype_false_positive.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][46858] -> [.212.47.228.136][..443] + new: [.....1] [ip4][..udp] [..192.168.2.100][46858] -> [.212.47.228.136][..443] detected: [.....1] [ip4][..udp] [..192.168.2.100][46858] -> [.212.47.228.136][..443] [DNScrypt][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] diff --git a/test/results/flow-info/default/doh.pcapng.out b/test/results/flow-info/default/doh.pcapng.out index 09ea6804f..696f20101 100644 --- a/test/results/flow-info/default/doh.pcapng.out +++ b/test/results/flow-info/default/doh.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/default/doq.pcapng.out b/test/results/flow-info/default/doq.pcapng.out index eeeb8d2f2..0317b5c8e 100644 --- a/test/results/flow-info/default/doq.pcapng.out +++ b/test/results/flow-info/default/doq.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....................................::1][47826] -> [....................................::1][..784] + new: [.....1] [ip6][..udp] [....................................::1][47826] -> [....................................::1][..784] detected: [.....1] [ip6][..udp] [....................................::1][47826] -> [....................................::1][..784] [QUIC.DoH_DoT][Unknown][Network][Acceptable][] RISK: Missing SNI TLS Extn - new: [.....2] [ip6][icmp6] [....................................::1] -> [....................................::1] + new: [.....2] [ip6][icmp6] [....................................::1] -> [....................................::1] detected: [.....2] [ip6][icmp6] [....................................::1] -> [....................................::1] [ICMPV6][Unknown][Network][Acceptable] idle: [.....2] [ip6][icmp6] [....................................::1] -> [....................................::1] [ICMPV6][Unknown][Network][Acceptable] idle: [.....1] [ip6][..udp] [....................................::1][47826] -> [....................................::1][..784] [QUIC.DoH_DoT][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/doq_adguard.pcapng.out b/test/results/flow-info/default/doq_adguard.pcapng.out index 98eba0ec2..80b392467 100644 --- a/test/results/flow-info/default/doq_adguard.pcapng.out +++ b/test/results/flow-info/default/doq_adguard.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.169][41070] -> [...94.140.14.14][..784] + new: [.....1] [ip4][..udp] [.192.168.12.169][41070] -> [...94.140.14.14][..784] detected: [.....1] [ip4][..udp] [.192.168.12.169][41070] -> [...94.140.14.14][..784] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.adguard.com] analyse: [.....1] [ip4][..udp] [.192.168.12.169][41070] -> [...94.140.14.14][..784] [QUIC.DoH_DoT][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/dos_win98_smb_netbeui.pcap.out b/test/results/flow-info/default/dos_win98_smb_netbeui.pcap.out index d8b433147..953c2fbb1 100644 --- a/test/results/flow-info/default/dos_win98_smb_netbeui.pcap.out +++ b/test/results/flow-info/default/dos_win98_smb_netbeui.pcap.out @@ -9,17 +9,17 @@ ERROR-EVENT: Unknown packet type [6/16] ERROR-EVENT: Unknown packet type [7/16] ERROR-EVENT: Unknown packet type [8/16] - new: [.....1] [ip4][..udp] [192.168.239.129][..137] -> [..192.168.239.2][..137] + new: [.....1] [ip4][..udp] [192.168.239.129][..137] -> [..192.168.239.2][..137] detected: [.....1] [ip4][..udp] [192.168.239.129][..137] -> [..192.168.239.2][..137] [NetBIOS][Unknown][System][Acceptable][mdjr98] - new: [.....2] [ip4][.icmp] [192.168.239.129] -> [......224.0.0.2] + new: [.....2] [ip4][.icmp] [192.168.239.129] -> [......224.0.0.2] detected: [.....2] [ip4][.icmp] [192.168.239.129] -> [......224.0.0.2] [ICMP][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [9/16] ERROR-EVENT: Unknown packet type [10/16] ERROR-EVENT: Unknown packet type [11/16] - new: [.....3] [ip4][..udp] [192.168.239.129][..137] -> [192.168.239.255][..137] + new: [.....3] [ip4][..udp] [192.168.239.129][..137] -> [192.168.239.255][..137] detected: [.....3] [ip4][..udp] [192.168.239.129][..137] -> [192.168.239.255][..137] [NetBIOS][Unknown][System][Acceptable][mdjr98] ERROR-EVENT: Unknown packet type [12/16] - new: [.....4] [ip4][..udp] [192.168.239.129][..138] -> [192.168.239.255][..138] + new: [.....4] [ip4][..udp] [192.168.239.129][..138] -> [192.168.239.255][..138] detected: [.....4] [ip4][..udp] [192.168.239.129][..138] -> [192.168.239.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][mdjr98] RISK: Unsafe Protocol ERROR-EVENT: Unknown packet type [13/16] diff --git a/test/results/flow-info/default/drda_db2.pcap.out b/test/results/flow-info/default/drda_db2.pcap.out index 38c80585c..79d5dd5b9 100644 --- a/test/results/flow-info/default/drda_db2.pcap.out +++ b/test/results/flow-info/default/drda_db2.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.106.1][.4847] -> [192.168.106.128][50000] + new: [.....1] [ip4][..tcp] [..192.168.106.1][.4847] -> [192.168.106.128][50000] detected: [.....1] [ip4][..tcp] [..192.168.106.1][.4847] -> [192.168.106.128][50000] [DRDA][Unknown][Database][Acceptable] analyse: [.....1] [ip4][..tcp] [..192.168.106.1][.4847] -> [192.168.106.128][50000] [DRDA][Unknown][Database][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/dropbox.pcap.out b/test/results/flow-info/default/dropbox.pcap.out index bc9f5036a..b2a7ff2b3 100644 --- a/test/results/flow-info/default/dropbox.pcap.out +++ b/test/results/flow-info/default/dropbox.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] + new: [.....1] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] detected: [.....1] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] + new: [.....2] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] detected: [.....2] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [.....1] [ip4][..udp] [...192.168.56.1][50311] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [IATS(ms)....: 1.8,103.9,104.0,109.0,108.5,105.4,105.9,113.8,113.7,106.8,107.1,109.4,109.0,108.9,116.0,117.8,112.3,110.6,110.8,109.9,107.9,108.0,108.0,113.1,114.0,110.8,110.4,107.4,111.2,109.5,105.1] [PKTLENS.....: 124,47,123,46,122,45,129,52,125,48,122,45,124,47,124,47,126,49,123,46,124,47,123,46,123,46,123,46,129,52,122,45] [ENTROPIES...: 5.5,5.0,5.5,5.1,5.5,5.0,5.7,5.2,5.6,5.1,5.5,5.0,5.6,5.0,5.5,5.0,5.6,5.1,5.5,5.0,5.5,5.0,5.5,5.0,5.5,5.1,5.5,5.1,5.7,5.3,5.6,5.0] - new: [.....3] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] + new: [.....3] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] detected: [.....3] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [.....2] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -27,7 +27,7 @@ [IATS(ms)....: 2.4,112.9,114.3,107.8,108.1,108.0,108.0,109.5,111.4,119.1,118.3,117.0,117.0,127.7,125.1,114.0,113.0,120.2,120.9,111.5,111.3,105.6,107.8,113.8,112.0,122.6,125.5,113.0,110.0,123.5,125.7] [PKTLENS.....: 123,46,127,50,126,49,128,51,123,46,125,48,126,49,125,48,123,46,124,47,128,51,126,49,123,46,123,46,123,46,127,50] [ENTROPIES...: 5.5,5.0,5.6,5.1,5.6,5.0,5.7,5.2,5.5,5.0,5.5,5.0,5.6,5.1,5.6,5.1,5.5,5.1,5.6,5.1,5.6,5.1,5.5,4.9,5.5,5.1,5.5,5.0,5.5,5.1,5.7,5.2] - new: [.....4] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] + new: [.....4] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] detected: [.....4] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [.....3] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -51,16 +51,16 @@ [ENTROPIES...: 5.6,5.1,5.6,5.1,5.5,5.1,5.5,5.1,5.6,5.1,5.5,5.1,5.5,5.0,5.6,5.2,5.6,5.1,5.7,5.3,5.6,5.1,5.6,5.1,5.5,5.1,5.6,5.2,5.5,5.0,5.6,5.2] DAEMON-EVENT: [Processed: 800 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [..192.168.1.105][55407] -> [..192.168.1.254][...53] + new: [.....5] [ip4][..udp] [..192.168.1.105][55407] -> [..192.168.1.254][...53] detected: [.....5] [ip4][..udp] [..192.168.1.105][55407] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][client.dropbox.com] detection-update: [.....5] [ip4][..udp] [..192.168.1.105][55407] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][client.dropbox.com] RISK: Unidirectional Traffic detection-update: [.....5] [ip4][..udp] [..192.168.1.105][55407] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][client.dropbox.com] - new: [.....6] [ip4][..udp] [..192.168.1.105][49112] -> [..192.168.1.254][...53] + new: [.....6] [ip4][..udp] [..192.168.1.105][49112] -> [..192.168.1.254][...53] detected: [.....6] [ip4][..udp] [..192.168.1.105][49112] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][client-cf.dropbox.com] detection-update: [.....6] [ip4][..udp] [..192.168.1.105][49112] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][client-cf.dropbox.com] RISK: Unidirectional Traffic - new: [.....7] [ip4][..udp] [..192.168.1.105][50789] -> [..192.168.1.254][...53] + new: [.....7] [ip4][..udp] [..192.168.1.105][50789] -> [..192.168.1.254][...53] detected: [.....7] [ip4][..udp] [..192.168.1.105][50789] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][d.dropbox.com] detection-update: [.....7] [ip4][..udp] [..192.168.1.105][50789] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][d.dropbox.com] RISK: Unidirectional Traffic @@ -70,27 +70,27 @@ idle: [.....3] [ip4][..udp] [...192.168.56.1][50312] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [.....2] [ip4][..udp] [...192.168.56.1][50318] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [.....4] [ip4][..udp] [...192.168.56.1][50319] -> [.192.168.56.101][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] + new: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] detected: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][log.getdropbox.com] detection-update: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][log.getdropbox.com] RISK: Unidirectional Traffic detection-update: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][log.getdropbox.com] RISK: Unidirectional Traffic detection-update: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][log.getdropbox.com] - new: [.....9] [ip4][..udp] [..192.168.1.105][17500] -> [255.255.255.255][17500] + new: [.....9] [ip4][..udp] [..192.168.1.105][17500] -> [255.255.255.255][17500] detected: [.....9] [ip4][..udp] [..192.168.1.105][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....10] [ip4][..udp] [..192.168.1.105][17500] -> [..192.168.1.255][17500] + new: [....10] [ip4][..udp] [..192.168.1.105][17500] -> [..192.168.1.255][17500] detected: [....10] [ip4][..udp] [..192.168.1.105][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....11] [ip4][..udp] [..192.168.1.105][33189] -> [..192.168.1.254][...53] + new: [....11] [ip4][..udp] [..192.168.1.105][33189] -> [..192.168.1.254][...53] detected: [....11] [ip4][..udp] [..192.168.1.105][33189] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][notify.dropbox.com] detection-update: [....11] [ip4][..udp] [..192.168.1.105][33189] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][notify.dropbox.com] RISK: Unidirectional Traffic detection-update: [....11] [ip4][..udp] [..192.168.1.105][33189] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable][notify.dropbox.com] DAEMON-EVENT: [Processed: 836 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 11|updates: 0] - new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] + new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] detected: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....13] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] + new: [....13] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] detected: [....13] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [.....7] [ip4][..udp] [..192.168.1.105][50789] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable] idle: [.....9] [ip4][..udp] [..192.168.1.105][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] @@ -101,9 +101,9 @@ idle: [.....8] [ip4][..udp] [..192.168.1.105][36173] -> [..192.168.1.254][...53] [DNS.Dropbox][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [....13] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....14] [ip4][..udp] [...192.168.1.64][17500] -> [255.255.255.255][17500] + new: [....14] [ip4][..udp] [...192.168.1.64][17500] -> [255.255.255.255][17500] detected: [....14] [ip4][..udp] [...192.168.1.64][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....15] [ip4][..udp] [...192.168.1.64][17500] -> [..192.168.1.255][17500] + new: [....15] [ip4][..udp] [...192.168.1.64][17500] -> [..192.168.1.255][17500] detected: [....15] [ip4][..udp] [...192.168.1.64][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [....13] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] diff --git a/test/results/flow-info/default/dtls.pcap.out b/test/results/flow-info/default/dtls.pcap.out index bd8f3d093..400cb06a0 100644 --- a/test/results/flow-info/default/dtls.pcap.out +++ b/test/results/flow-info/default/dtls.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.13.203][40739] -> [..192.168.13.57][56515] + new: [.....1] [ip4][..udp] [.192.168.13.203][40739] -> [..192.168.13.57][56515] detected: [.....1] [ip4][..udp] [.192.168.13.203][40739] -> [..192.168.13.57][56515] [DTLS][Unknown][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..udp] [.192.168.13.203][40739] -> [..192.168.13.57][56515] [DTLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/dtls2.pcap.out b/test/results/flow-info/default/dtls2.pcap.out index 2cb907eeb..3f36e919f 100644 --- a/test/results/flow-info/default/dtls2.pcap.out +++ b/test/results/flow-info/default/dtls2.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..61.68.110.153][53045] -> [..212.32.214.39][61457] + new: [.....1] [ip4][..udp] [..61.68.110.153][53045] -> [..212.32.214.39][61457] detected: [.....1] [ip4][..udp] [..61.68.110.153][53045] -> [..212.32.214.39][61457] [DTLS][Unknown][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..udp] [..61.68.110.153][53045] -> [..212.32.214.39][61457] [DTLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/dtls_certificate.pcapng.out b/test/results/flow-info/default/dtls_certificate.pcapng.out index 452724a3f..80f6f97aa 100644 --- a/test/results/flow-info/default/dtls_certificate.pcapng.out +++ b/test/results/flow-info/default/dtls_certificate.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..191.62.60.190][..443] -> [.163.205.15.180][38876] + new: [.....1] [ip4][..udp] [..191.62.60.190][..443] -> [.163.205.15.180][38876] detected: [.....1] [ip4][..udp] [..191.62.60.190][..443] -> [.163.205.15.180][38876] [DTLS.WindowsUpdate][Unknown][SoftwareUpdate][Safe] RISK: TLS Cert Expired idle: [.....1] [ip4][..udp] [..191.62.60.190][..443] -> [.163.205.15.180][38876] [DTLS.WindowsUpdate][Unknown][SoftwareUpdate][Safe] diff --git a/test/results/flow-info/default/dtls_certificate_fragments.pcap.out b/test/results/flow-info/default/dtls_certificate_fragments.pcap.out index 59bb48bd4..c296c1698 100644 --- a/test/results/flow-info/default/dtls_certificate_fragments.pcap.out +++ b/test/results/flow-info/default/dtls_certificate_fragments.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.10.186.198.149][39347] -> [..35.210.59.134][44443] + new: [.....1] [ip4][..udp] [.10.186.198.149][39347] -> [..35.210.59.134][44443] detected: [.....1] [ip4][..udp] [.10.186.198.149][39347] -> [..35.210.59.134][44443] [DTLS][GoogleCloud][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..udp] [.10.186.198.149][39347] -> [..35.210.59.134][44443] [DTLS][GoogleCloud][Web][Safe] @@ -10,7 +10,7 @@ RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, TLS Cert About To Expire DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..udp] [...192.168.1.26][43594] -> [.104.153.87.149][50001] + new: [.....2] [ip4][..udp] [...192.168.1.26][43594] -> [.104.153.87.149][50001] detected: [.....2] [ip4][..udp] [...192.168.1.26][43594] -> [.104.153.87.149][50001] [DTLS][Discord][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....2] [ip4][..udp] [...192.168.1.26][43594] -> [.104.153.87.149][50001] [DTLS][Discord][Web][Safe] diff --git a/test/results/flow-info/default/dtls_mid_sessions.pcapng.out b/test/results/flow-info/default/dtls_mid_sessions.pcapng.out index dd24e8233..f9a673c38 100644 --- a/test/results/flow-info/default/dtls_mid_sessions.pcapng.out +++ b/test/results/flow-info/default/dtls_mid_sessions.pcapng.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..53.214.238.65][53558] -> [199.186.151.155][..443] + new: [.....1] [ip4][..udp] [..53.214.238.65][53558] -> [199.186.151.155][..443] detected: [.....1] [ip4][..udp] [..53.214.238.65][53558] -> [199.186.151.155][..443] [DTLS][Unknown][Web][Safe] - new: [.....2] [ip4][..udp] [.135.215.56.198][..443] -> [..124.73.140.89][61189] + new: [.....2] [ip4][..udp] [.135.215.56.198][..443] -> [..124.73.140.89][61189] detected: [.....2] [ip4][..udp] [.135.215.56.198][..443] -> [..124.73.140.89][61189] [DTLS][Unknown][Web][Safe] - new: [.....3] [ip4][..udp] [170.151.105.215][..443] -> [121.152.255.238][.8460] + new: [.....3] [ip4][..udp] [170.151.105.215][..443] -> [121.152.255.238][.8460] detected: [.....3] [ip4][..udp] [170.151.105.215][..443] -> [121.152.255.238][.8460] [DTLS][Unknown][Web][Safe] - new: [.....4] [ip4][..udp] [170.151.105.215][..443] -> [.72.102.179.218][62811] + new: [.....4] [ip4][..udp] [170.151.105.215][..443] -> [.72.102.179.218][62811] detected: [.....4] [ip4][..udp] [170.151.105.215][..443] -> [.72.102.179.218][62811] [DTLS][Unknown][Web][Safe] idle: [.....2] [ip4][..udp] [.135.215.56.198][..443] -> [..124.73.140.89][61189] [DTLS][Unknown][Web][Safe] idle: [.....3] [ip4][..udp] [170.151.105.215][..443] -> [121.152.255.238][.8460] [DTLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/dtls_old_version.pcapng.out b/test/results/flow-info/default/dtls_old_version.pcapng.out index 628bece61..26349b553 100644 --- a/test/results/flow-info/default/dtls_old_version.pcapng.out +++ b/test/results/flow-info/default/dtls_old_version.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...37.188.4.115][56453] -> [....70.66.6.128][..443] + new: [.....1] [ip4][..udp] [...37.188.4.115][56453] -> [....70.66.6.128][..443] detected: [.....1] [ip4][..udp] [...37.188.4.115][56453] -> [....70.66.6.128][..443] [DTLS][Unknown][Web][Safe] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....1] [ip4][..udp] [...37.188.4.115][56453] -> [....70.66.6.128][..443] [DTLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/dtls_session_id_and_coockie_both.pcap.out b/test/results/flow-info/default/dtls_session_id_and_coockie_both.pcap.out index c46812398..e0a6a2227 100644 --- a/test/results/flow-info/default/dtls_session_id_and_coockie_both.pcap.out +++ b/test/results/flow-info/default/dtls_session_id_and_coockie_both.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [185.196.113.239][50257] -> [223.116.105.247][44443] + new: [.....1] [ip4][..udp] [185.196.113.239][50257] -> [223.116.105.247][44443] detected: [.....1] [ip4][..udp] [185.196.113.239][50257] -> [223.116.105.247][44443] [DTLS][Unknown][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..udp] [185.196.113.239][50257] -> [223.116.105.247][44443] [DTLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/edonkey.pcap.out b/test/results/flow-info/default/edonkey.pcap.out index 9f10c5a72..62a6477ae 100644 --- a/test/results/flow-info/default/edonkey.pcap.out +++ b/test/results/flow-info/default/edonkey.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.201.15.177.227][.1754] -> [135.192.214.240][.7551] + new: [.....1] [ip4][..tcp] [.201.15.177.227][.1754] -> [135.192.214.240][.7551] detected: [.....1] [ip4][..tcp] [.201.15.177.227][.1754] -> [135.192.214.240][.7551] [eDonkey][Unknown][Download][Unsafe] RISK: Unsafe Protocol end: [.....1] [ip4][..tcp] [.201.15.177.227][.1754] -> [135.192.214.240][.7551] [eDonkey][Unknown][Download][Unsafe] diff --git a/test/results/flow-info/default/elasticsearch.pcap.out b/test/results/flow-info/default/elasticsearch.pcap.out index de330a283..73a98d771 100644 --- a/test/results/flow-info/default/elasticsearch.pcap.out +++ b/test/results/flow-info/default/elasticsearch.pcap.out @@ -1,22 +1,22 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..172.16.17.102][40282] -> [..172.16.16.107][.9300] + new: [.....1] [ip4][..tcp] [..172.16.17.102][40282] -> [..172.16.16.107][.9300] detected: [.....1] [ip4][..tcp] [..172.16.17.102][40282] -> [..172.16.16.107][.9300] [Elasticsearch][Unknown][System][Acceptable] - new: [.....2] [ip4][..tcp] [..172.16.17.102][48038] -> [..172.16.16.106][.9300] + new: [.....2] [ip4][..tcp] [..172.16.17.102][48038] -> [..172.16.16.106][.9300] detected: [.....2] [ip4][..tcp] [..172.16.17.102][48038] -> [..172.16.16.106][.9300] [Elasticsearch][Unknown][System][Acceptable] - new: [.....3] [ip4][..tcp] [..172.16.16.107][33288] -> [..172.16.17.102][.9300] - new: [.....4] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40342] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..172.16.16.107][33288] -> [..172.16.17.102][.9300] + new: [.....4] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40342] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40342] [Elasticsearch][Unknown][System][Acceptable] detected: [.....3] [ip4][..tcp] [..172.16.16.107][33288] -> [..172.16.17.102][.9300] [Elasticsearch][Unknown][System][Acceptable] - new: [.....5] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40298] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40298] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..172.16.16.107][.9300] -> [..172.16.17.102][40298] [Elasticsearch][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 37 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] end: [.....1] [ip4][..tcp] [..172.16.17.102][40282] -> [..172.16.16.107][.9300] [Elasticsearch][Unknown][System][Acceptable] - new: [.....6] [ip4][..tcp] [..172.16.17.102][48028] -> [..172.16.16.106][.9300] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..172.16.17.102][48028] -> [..172.16.16.106][.9300] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..172.16.17.102][48028] -> [..172.16.16.106][.9300] [Elasticsearch][Unknown][System][Acceptable] - new: [.....7] [ip4][..tcp] [..172.16.17.102][47980] -> [..172.16.16.106][.9300] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..172.16.17.102][47980] -> [..172.16.16.106][.9300] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [..172.16.17.102][47980] -> [..172.16.16.106][.9300] [Elasticsearch][Unknown][System][Acceptable] idle: [.....7] [ip4][..tcp] [..172.16.17.102][47980] -> [..172.16.16.106][.9300] [Elasticsearch][Unknown][System][Acceptable] idle: [.....6] [ip4][..tcp] [..172.16.17.102][48028] -> [..172.16.16.106][.9300] [Elasticsearch][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/emotet.pcap.out b/test/results/flow-info/default/emotet.pcap.out index 286ba1ff8..b49c3201a 100644 --- a/test/results/flow-info/default/emotet.pcap.out +++ b/test/results/flow-info/default/emotet.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....10.2.25.102][57309] -> [..193.252.22.84][..587] + new: [.....1] [ip4][..tcp] [....10.2.25.102][57309] -> [..193.252.22.84][..587] detected: [.....1] [ip4][..tcp] [....10.2.25.102][57309] -> [..193.252.22.84][..587] [SMTP][Unknown][Email][Acceptable][opmta1mto02nd1] analyse: [.....1] [ip4][..tcp] [....10.2.25.102][57309] -> [..193.252.22.84][..587] [SMTP][Unknown][Email][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [ENTROPIES...: 4.6,5.0,5.0,5.5,5.4,4.8,5.7,5.4,4.8,5.5,5.7,4.8,5.0,4.7,5.3,5.4,4.8,4.9,4.8,5.3,5.6,4.8,5.4,5.6,4.8,5.5,5.1,4.8,5.1,5.3,4.8,5.6] DAEMON-EVENT: [Processed: 626 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [....10.3.29.101][56309] -> [.104.161.127.22][...80] + new: [.....2] [ip4][..tcp] [....10.3.29.101][56309] -> [.104.161.127.22][...80] detected: [.....2] [ip4][..tcp] [....10.3.29.101][56309] -> [.104.161.127.22][...80] [HTTP][Unknown][Web][Acceptable][fkl.co.ke] analyse: [.....2] [ip4][..tcp] [....10.3.29.101][56309] -> [.104.161.127.22][...80] [HTTP][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy @@ -30,7 +30,7 @@ end: [.....1] [ip4][..tcp] [....10.2.25.102][57309] -> [..193.252.22.84][..587] [SMTP][Unknown][Email][Acceptable] DAEMON-EVENT: [Processed: 834 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [....10.4.20.102][54319] -> [107.161.178.210][...80] + new: [.....3] [ip4][..tcp] [....10.4.20.102][54319] -> [107.161.178.210][...80] detected: [.....3] [ip4][..tcp] [....10.4.20.102][54319] -> [107.161.178.210][...80] [HTTP][Unknown][Web][Acceptable][gandhitoday.org] detection-update: [.....3] [ip4][..tcp] [....10.4.20.102][54319] -> [107.161.178.210][...80] [HTTP][Unknown][Download][Acceptable][gandhitoday.org] RISK: Binary App Transfer @@ -47,7 +47,7 @@ end: [.....2] [ip4][..tcp] [....10.3.29.101][56309] -> [.104.161.127.22][...80] [HTTP][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 1663 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....4] [ip4][..tcp] [....10.4.25.101][49797] -> [..77.105.36.156][...80] + new: [.....4] [ip4][..tcp] [....10.4.25.101][49797] -> [..77.105.36.156][...80] detected: [.....4] [ip4][..tcp] [....10.4.25.101][49797] -> [..77.105.36.156][...80] [HTTP][Unknown][Web][Acceptable][filmmogzivota.rs] RISK: HTTP Susp User-Agent detection-update: [.....4] [ip4][..tcp] [....10.4.25.101][49797] -> [..77.105.36.156][...80] [HTTP][Unknown][Download][Acceptable][filmmogzivota.rs] @@ -64,7 +64,7 @@ [ENTROPIES...: 4.7,4.8,4.5,5.7,4.4,5.6,4.0,5.1,4.5,5.1,5.0,5.3,5.5,4.5,5.1,5.2,5.5,4.5,5.2,5.1,5.3,4.5,5.4,5.1,5.1,4.4,5.2,5.4,5.4,4.9,4.5,4.4] end: [.....3] [ip4][..tcp] [....10.4.20.102][54319] -> [107.161.178.210][...80] [HTTP][Unknown][Download][Acceptable] RISK: Binary App Transfer - new: [.....5] [ip4][..tcp] [....10.4.25.101][49803] -> [138.197.147.101][..443] + new: [.....5] [ip4][..tcp] [....10.4.25.101][49803] -> [138.197.147.101][..443] detected: [.....5] [ip4][..tcp] [....10.4.25.101][49803] -> [138.197.147.101][..443] [TLS][Unknown][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....5] [ip4][..tcp] [....10.4.25.101][49803] -> [138.197.147.101][..443] [TLS][Unknown][Web][Safe][] @@ -81,7 +81,7 @@ [ENTROPIES...: 4.7,4.9,4.5,5.4,4.6,7.5,4.6,5.9,7.1,4.5,7.5,4.5,7.9,7.9,7.9,4.5,4.5,7.9,7.9,5.0,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.1,5.1,5.1,7.8,7.9] detection-update: [.....5] [ip4][..tcp] [....10.4.25.101][49803] -> [138.197.147.101][..443] [TLS][Unknown][Web][Safe][] RISK: Self-signed Cert, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn - new: [.....6] [ip4][..tcp] [....10.4.25.101][49804] -> [138.197.147.101][..443] + new: [.....6] [ip4][..tcp] [....10.4.25.101][49804] -> [138.197.147.101][..443] detected: [.....6] [ip4][..tcp] [....10.4.25.101][49804] -> [138.197.147.101][..443] [TLS][Unknown][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....6] [ip4][..tcp] [....10.4.25.101][49804] -> [138.197.147.101][..443] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/default/encrypted_sni.pcap.out b/test/results/flow-info/default/encrypted_sni.pcap.out index d3195577c..645f6b8c2 100644 --- a/test/results/flow-info/default/encrypted_sni.pcap.out +++ b/test/results/flow-info/default/encrypted_sni.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [TLS][Cloudflare][Web][Safe][] - new: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [TLS][Cloudflare][Web][Safe][] - new: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [TLS][Cloudflare][Web][Safe][] idle: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [TLS][Cloudflare][Web][Safe] idle: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [TLS][Cloudflare][Web][Safe] diff --git a/test/results/flow-info/default/epicgames.pcapng.out b/test/results/flow-info/default/epicgames.pcapng.out index fe57187b3..fa4d74425 100644 --- a/test/results/flow-info/default/epicgames.pcapng.out +++ b/test/results/flow-info/default/epicgames.pcapng.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.156][49693] -> [..18.157.15.184][15011] - new: [.....2] [ip4][..udp] [.192.168.12.156][47446] -> [..18.157.15.184][15011] + new: [.....1] [ip4][..udp] [.192.168.12.156][49693] -> [..18.157.15.184][15011] + new: [.....2] [ip4][..udp] [.192.168.12.156][47446] -> [..18.157.15.184][15011] detected: [.....2] [ip4][..udp] [.192.168.12.156][47446] -> [..18.157.15.184][15011] [EpicGames][AmazonAWS][Game][Fun] detected: [.....1] [ip4][..udp] [.192.168.12.156][49693] -> [..18.157.15.184][15011] [EpicGames][AmazonAWS][Game][Fun] - new: [.....3] [ip4][..udp] [.192.168.12.156][39322] -> [..18.157.15.184][.9011] + new: [.....3] [ip4][..udp] [.192.168.12.156][39322] -> [..18.157.15.184][.9011] detected: [.....3] [ip4][..udp] [.192.168.12.156][39322] -> [..18.157.15.184][.9011] [EpicGames][AmazonAWS][Game][Fun] - new: [.....4] [ip4][..udp] [.192.168.12.156][37989] -> [..18.157.15.184][15011] + new: [.....4] [ip4][..udp] [.192.168.12.156][37989] -> [..18.157.15.184][15011] detected: [.....4] [ip4][..udp] [.192.168.12.156][37989] -> [..18.157.15.184][15011] [EpicGames][AmazonAWS][Game][Fun] idle: [.....2] [ip4][..udp] [.192.168.12.156][47446] -> [..18.157.15.184][15011] [EpicGames][AmazonAWS][Game][Fun] idle: [.....1] [ip4][..udp] [.192.168.12.156][49693] -> [..18.157.15.184][15011] [EpicGames][AmazonAWS][Game][Fun] diff --git a/test/results/flow-info/default/esp.pcapng.out b/test/results/flow-info/default/esp.pcapng.out index a614afcbd..72aec2203 100644 --- a/test/results/flow-info/default/esp.pcapng.out +++ b/test/results/flow-info/default/esp.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] + new: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] detected: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] [IPSec][Unknown][VPN][Safe] - new: [.....2] [ip4][...50] [.......10.2.3.2] -> [.......10.3.4.4] + new: [.....2] [ip4][...50] [.......10.2.3.2] -> [.......10.3.4.4] detected: [.....2] [ip4][...50] [.......10.2.3.2] -> [.......10.3.4.4] [IPSec][Unknown][VPN][Safe] idle: [.....1] [ip4][..udp] [.......10.2.3.2][..500] -> [.......10.3.4.4][..500] [IPSec][Unknown][VPN][Safe] idle: [.....2] [ip4][...50] [.......10.2.3.2] -> [.......10.3.4.4] [IPSec][Unknown][VPN][Safe] diff --git a/test/results/flow-info/default/ethereum.pcap.out b/test/results/flow-info/default/ethereum.pcap.out index 51780413d..9195c369f 100644 --- a/test/results/flow-info/default/ethereum.pcap.out +++ b/test/results/flow-info/default/ethereum.pcap.out @@ -1,45 +1,45 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...87.14.222.25][56693] -> [..192.168.1.184][30303] + new: [.....1] [ip4][..udp] [...87.14.222.25][56693] -> [..192.168.1.184][30303] detected: [.....1] [ip4][..udp] [...87.14.222.25][56693] -> [..192.168.1.184][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [.....2] [ip4][..udp] [...60.191.32.71][30303] -> [..192.168.1.184][30303] + new: [.....2] [ip4][..udp] [...60.191.32.71][30303] -> [..192.168.1.184][30303] detected: [.....2] [ip4][..udp] [...60.191.32.71][30303] -> [..192.168.1.184][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [.....3] [ip4][..udp] [...3.112.138.57][25516] -> [..192.168.1.184][30303] + new: [.....3] [ip4][..udp] [...3.112.138.57][25516] -> [..192.168.1.184][30303] detected: [.....3] [ip4][..udp] [...3.112.138.57][25516] -> [..192.168.1.184][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] - new: [.....4] [ip4][..udp] [..192.168.1.184][30303] -> [....3.209.45.79][30303] + new: [.....4] [ip4][..udp] [..192.168.1.184][30303] -> [....3.209.45.79][30303] detected: [.....4] [ip4][..udp] [..192.168.1.184][30303] -> [....3.209.45.79][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] - new: [.....5] [ip4][..udp] [..192.168.1.184][30303] -> [.52.231.165.108][30303] + new: [.....5] [ip4][..udp] [..192.168.1.184][30303] -> [.52.231.165.108][30303] detected: [.....5] [ip4][..udp] [..192.168.1.184][30303] -> [.52.231.165.108][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] - new: [.....6] [ip4][..udp] [..192.168.1.184][30303] -> [..18.138.108.67][30303] + new: [.....6] [ip4][..udp] [..192.168.1.184][30303] -> [..18.138.108.67][30303] detected: [.....6] [ip4][..udp] [..192.168.1.184][30303] -> [..18.138.108.67][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] - new: [.....7] [ip4][..udp] [..192.168.1.184][30303] -> [...34.97.172.22][30303] + new: [.....7] [ip4][..udp] [..192.168.1.184][30303] -> [...34.97.172.22][30303] detected: [.....7] [ip4][..udp] [..192.168.1.184][30303] -> [...34.97.172.22][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] - new: [.....8] [ip4][..udp] [..192.168.1.184][30303] -> [...66.42.82.246][30303] + new: [.....8] [ip4][..udp] [..192.168.1.184][30303] -> [...66.42.82.246][30303] detected: [.....8] [ip4][..udp] [..192.168.1.184][30303] -> [...66.42.82.246][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [.....9] [ip4][..tcp] [..192.168.1.184][56612] -> [...66.42.82.246][30303] - new: [....10] [ip4][..tcp] [..192.168.1.184][56610] -> [..165.22.107.33][30303] - new: [....11] [ip4][..tcp] [..192.168.1.184][56611] -> [..104.42.217.25][30303] - new: [....12] [ip4][..tcp] [..192.168.1.184][56613] -> [.162.243.160.83][30303] - new: [....13] [ip4][..tcp] [..192.168.1.184][56615] -> [.35.158.244.151][30303] - new: [....14] [ip4][..tcp] [..192.168.1.184][56617] -> [...34.97.172.22][30303] - new: [....15] [ip4][..tcp] [..192.168.1.184][56618] -> [.52.231.165.108][30303] - new: [....16] [ip4][..tcp] [..192.168.1.184][56620] -> [191.234.162.198][30303] - new: [....17] [ip4][..tcp] [..192.168.1.184][56621] -> [..52.187.207.27][30303] - new: [....18] [ip4][..tcp] [..192.168.1.184][56622] -> [..18.138.108.67][30303] - new: [....19] [ip4][..tcp] [..192.168.1.184][56623] -> [...18.138.81.28][30303] - new: [....20] [ip4][..tcp] [..192.168.1.184][56624] -> [....89.38.99.34][30303] - new: [....21] [ip4][..tcp] [..192.168.1.184][56625] -> [.....5.1.83.226][30303] - new: [....22] [ip4][..tcp] [..192.168.1.184][56626] -> [178.128.195.220][30303] - new: [....23] [ip4][..tcp] [..192.168.1.184][56627] -> [..34.255.23.113][30303] - new: [....24] [ip4][..tcp] [..192.168.1.184][56628] -> [....3.209.45.79][30303] + new: [.....9] [ip4][..tcp] [..192.168.1.184][56612] -> [...66.42.82.246][30303] + new: [....10] [ip4][..tcp] [..192.168.1.184][56610] -> [..165.22.107.33][30303] + new: [....11] [ip4][..tcp] [..192.168.1.184][56611] -> [..104.42.217.25][30303] + new: [....12] [ip4][..tcp] [..192.168.1.184][56613] -> [.162.243.160.83][30303] + new: [....13] [ip4][..tcp] [..192.168.1.184][56615] -> [.35.158.244.151][30303] + new: [....14] [ip4][..tcp] [..192.168.1.184][56617] -> [...34.97.172.22][30303] + new: [....15] [ip4][..tcp] [..192.168.1.184][56618] -> [.52.231.165.108][30303] + new: [....16] [ip4][..tcp] [..192.168.1.184][56620] -> [191.234.162.198][30303] + new: [....17] [ip4][..tcp] [..192.168.1.184][56621] -> [..52.187.207.27][30303] + new: [....18] [ip4][..tcp] [..192.168.1.184][56622] -> [..18.138.108.67][30303] + new: [....19] [ip4][..tcp] [..192.168.1.184][56623] -> [...18.138.81.28][30303] + new: [....20] [ip4][..tcp] [..192.168.1.184][56624] -> [....89.38.99.34][30303] + new: [....21] [ip4][..tcp] [..192.168.1.184][56625] -> [.....5.1.83.226][30303] + new: [....22] [ip4][..tcp] [..192.168.1.184][56626] -> [178.128.195.220][30303] + new: [....23] [ip4][..tcp] [..192.168.1.184][56627] -> [..34.255.23.113][30303] + new: [....24] [ip4][..tcp] [..192.168.1.184][56628] -> [....3.209.45.79][30303] detected: [....13] [ip4][..tcp] [..192.168.1.184][56615] -> [.35.158.244.151][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] detected: [....22] [ip4][..tcp] [..192.168.1.184][56626] -> [178.128.195.220][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....20] [ip4][..tcp] [..192.168.1.184][56624] -> [....89.38.99.34][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....23] [ip4][..tcp] [..192.168.1.184][56627] -> [..34.255.23.113][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] - new: [....25] [ip4][..tcp] [..192.168.1.184][56629] -> [....51.38.60.79][30303] + new: [....25] [ip4][..tcp] [..192.168.1.184][56629] -> [....51.38.60.79][30303] detected: [....12] [ip4][..tcp] [..192.168.1.184][56613] -> [.162.243.160.83][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....26] [ip4][..udp] [..192.168.1.184][30303] -> [...128.0.51.140][30303] + new: [....26] [ip4][..udp] [..192.168.1.184][30303] -> [...128.0.51.140][30303] detected: [....26] [ip4][..udp] [..192.168.1.184][30303] -> [...128.0.51.140][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] analyse: [....13] [ip4][..tcp] [..192.168.1.184][56615] -> [.35.158.244.151][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -51,7 +51,7 @@ [IATS(ms)....: 42.9,43.0,2.2,63.5,0.8,0.0,62.1,0.0,0.4,0.3,0.4,0.4,0.1,0.0,0.1,0.0,0.1,0.2,0.3,0.0,0.1,0.0,0.0,0.1,0.0,0.1,0.0,0.0,0.0,27.6,0.0] [PKTLENS.....: 64,60,52,547,52,500,84,52,52,53,52,54,52,65,68,52,52,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46] [ENTROPIES...: 4.5,5.3,5.0,7.6,5.2,7.6,5.9,5.1,5.1,5.3,5.1,5.3,5.1,5.5,5.7,5.1,5.1,5.2,5.1,5.8,5.2,6.7,5.2,5.5,5.9,5.2,5.2,5.5,5.5,5.1,3.7,3.7] - new: [....27] [ip4][..tcp] [..192.168.1.184][56630] -> [..40.67.144.128][30303] + new: [....27] [ip4][..tcp] [..192.168.1.184][56630] -> [..40.67.144.128][30303] detected: [....24] [ip4][..tcp] [..192.168.1.184][56628] -> [....3.209.45.79][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] analyse: [....22] [ip4][..tcp] [..192.168.1.184][56626] -> [178.128.195.220][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -65,10 +65,10 @@ [ENTROPIES...: 4.4,5.4,5.1,7.7,5.2,7.5,6.0,5.2,6.9,5.3,5.1,5.0,5.0,5.0,5.5,5.0,5.0,5.9,5.0,6.8,5.2,5.4,5.9,5.0,6.0,5.4,5.4,5.2,5.2,5.2,7.3,5.2] detected: [.....9] [ip4][..tcp] [..192.168.1.184][56612] -> [...66.42.82.246][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....25] [ip4][..tcp] [..192.168.1.184][56629] -> [....51.38.60.79][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....28] [ip4][..tcp] [..192.168.1.184][56632] -> [...51.38.81.180][30303] - new: [....29] [ip4][..udp] [..192.168.1.184][30303] -> [..54.36.160.211][30303] + new: [....28] [ip4][..tcp] [..192.168.1.184][56632] -> [...51.38.81.180][30303] + new: [....29] [ip4][..udp] [..192.168.1.184][30303] -> [..54.36.160.211][30303] detected: [....29] [ip4][..udp] [..192.168.1.184][30303] -> [..54.36.160.211][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....30] [ip4][..tcp] [..192.168.1.184][56633] -> [.82.145.220.249][30303] + new: [....30] [ip4][..tcp] [..192.168.1.184][56633] -> [.82.145.220.249][30303] detected: [....11] [ip4][..tcp] [..192.168.1.184][56611] -> [..104.42.217.25][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] analyse: [....23] [ip4][..tcp] [..192.168.1.184][56627] -> [..34.255.23.113][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -80,10 +80,10 @@ [IATS(ms)....: 70.0,70.2,1.4,62.1,2.1,0.0,0.0,0.0,0.0,0.0,62.7,0.0,0.0,0.0,0.0,0.0,0.1,0.1,0.6,0.0,0.1,0.0,0.0,0.1,0.0,0.1,0.0,0.1,0.0,63.7,0.0] [PKTLENS.....: 64,60,52,564,52,454,84,53,54,65,68,52,52,52,52,52,52,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46] [ENTROPIES...: 4.4,5.3,5.0,7.6,5.2,7.6,5.9,5.3,5.3,5.5,5.6,5.1,5.0,5.0,5.0,5.1,5.1,5.3,5.1,6.0,5.2,6.7,5.2,5.5,5.8,5.1,5.2,5.5,5.6,5.1,3.6,3.6] - new: [....31] [ip4][..udp] [..192.168.1.184][30303] -> [..111.229.0.180][20182] + new: [....31] [ip4][..udp] [..192.168.1.184][30303] -> [..111.229.0.180][20182] detected: [....31] [ip4][..udp] [..192.168.1.184][30303] -> [..111.229.0.180][20182] [ETHEREUM][Tencent][Crypto_Currency][Acceptable] detected: [....28] [ip4][..tcp] [..192.168.1.184][56632] -> [...51.38.81.180][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....32] [ip4][..udp] [..192.168.1.184][30303] -> [...209.97.143.1][50000] + new: [....32] [ip4][..udp] [..192.168.1.184][30303] -> [...209.97.143.1][50000] detected: [....32] [ip4][..udp] [..192.168.1.184][30303] -> [...209.97.143.1][50000] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....15] [ip4][..tcp] [..192.168.1.184][56618] -> [.52.231.165.108][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] analyse: [....25] [ip4][..tcp] [..192.168.1.184][56629] -> [....51.38.60.79][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -99,9 +99,9 @@ detected: [....16] [ip4][..tcp] [..192.168.1.184][56620] -> [191.234.162.198][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] detected: [....30] [ip4][..tcp] [..192.168.1.184][56633] -> [.82.145.220.249][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....27] [ip4][..tcp] [..192.168.1.184][56630] -> [..40.67.144.128][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] - new: [....33] [ip4][..tcp] [..192.168.1.184][56634] -> [..159.203.84.31][30303] + new: [....33] [ip4][..tcp] [..192.168.1.184][56634] -> [..159.203.84.31][30303] detected: [....18] [ip4][..tcp] [..192.168.1.184][56622] -> [..18.138.108.67][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] - new: [....34] [ip4][..tcp] [..192.168.1.184][56635] -> [.162.228.29.160][30303] + new: [....34] [ip4][..tcp] [..192.168.1.184][56635] -> [.162.228.29.160][30303] detected: [....19] [ip4][..tcp] [..192.168.1.184][56623] -> [...18.138.81.28][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] detected: [....14] [ip4][..tcp] [..192.168.1.184][56617] -> [...34.97.172.22][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] detected: [....10] [ip4][..tcp] [..192.168.1.184][56610] -> [..165.22.107.33][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -126,11 +126,11 @@ [IATS(ms)....: 74.2,74.3,1.2,77.3,76.1,0.7,0.0,0.6,0.0,0.2,0.0,0.1,0.0,0.1,0.1,0.0,0.1,0.0,0.0,0.0,52.0,0.0,0.2,0.0,0.0,0.0,0.1,0.0,0.0,0.0,0.1] [PKTLENS.....: 64,60,52,494,474,52,84,84,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46,46,46,46,46,46,46,46,46,46] [ENTROPIES...: 4.4,5.4,5.1,7.6,7.5,5.1,5.9,6.0,5.1,5.1,6.0,5.2,6.8,5.3,5.6,5.7,5.0,5.2,5.5,5.6,5.1,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7] - new: [....35] [ip4][..tcp] [..192.168.1.184][56637] -> [.35.233.197.131][30303] - new: [....36] [ip4][..tcp] [..192.168.1.184][56638] -> [209.250.240.205][30303] - new: [....37] [ip4][..udp] [..192.168.1.184][30303] -> [.35.180.246.169][30301] + new: [....35] [ip4][..tcp] [..192.168.1.184][56637] -> [.35.233.197.131][30303] + new: [....36] [ip4][..tcp] [..192.168.1.184][56638] -> [209.250.240.205][30303] + new: [....37] [ip4][..udp] [..192.168.1.184][30303] -> [.35.180.246.169][30301] detected: [....37] [ip4][..udp] [..192.168.1.184][30303] -> [.35.180.246.169][30301] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] - new: [....38] [ip4][..tcp] [..192.168.1.184][56639] -> [.18.219.167.159][30303] + new: [....38] [ip4][..tcp] [..192.168.1.184][56639] -> [.18.219.167.159][30303] detected: [....33] [ip4][..tcp] [..192.168.1.184][56634] -> [..159.203.84.31][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] analyse: [....24] [ip4][..tcp] [..192.168.1.184][56628] -> [....3.209.45.79][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -144,9 +144,9 @@ [ENTROPIES...: 4.4,5.3,5.0,7.5,5.1,7.6,4.9,6.0,5.2,5.0,5.0,5.3,5.6,5.6,5.0,5.0,4.9,5.1,5.0,5.9,5.1,6.8,5.2,5.5,5.9,5.1,5.1,5.5,5.5,5.0,5.1,3.7] detected: [....36] [ip4][..tcp] [..192.168.1.184][56638] -> [209.250.240.205][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....34] [ip4][..tcp] [..192.168.1.184][56635] -> [.162.228.29.160][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....39] [ip4][..tcp] [..192.168.1.184][56641] -> [.144.91.120.135][30303] - new: [....40] [ip4][..tcp] [..192.168.1.184][56642] -> [..178.62.10.218][30303] - new: [....41] [ip4][..tcp] [..192.168.1.184][56643] -> [..178.62.29.183][30303] + new: [....39] [ip4][..tcp] [..192.168.1.184][56641] -> [.144.91.120.135][30303] + new: [....40] [ip4][..tcp] [..192.168.1.184][56642] -> [..178.62.10.218][30303] + new: [....41] [ip4][..tcp] [..192.168.1.184][56643] -> [..178.62.29.183][30303] analyse: [....36] [ip4][..tcp] [..192.168.1.184][56638] -> [209.250.240.205][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.043| 0.007| 0.014| 203.606| 2.800] @@ -157,7 +157,7 @@ [IATS(ms)....: 32.6,32.7,1.1,41.2,3.0,43.1,1.1,0.0,0.1,0.0,0.0,2.2,0.0,0.0,1.1,0.0,0.0,0.1,0.1,0.4,0.0,0.0,0.0,0.1,33.8,0.0,0.0,0.0,33.3,0.0,0.1] [PKTLENS.....: 64,60,52,467,52,546,52,84,53,176,55,68,84,53,195,52,52,52,68,52,84,53,100,67,68,64,64,64,64,212,164,52] [ENTROPIES...: 4.5,5.4,5.1,7.6,5.2,7.6,5.0,5.9,5.0,6.7,5.2,5.5,6.1,5.2,6.8,5.0,5.1,5.1,5.6,5.1,5.9,5.2,6.1,5.6,5.5,5.1,5.1,5.2,5.1,6.9,6.7,5.2] - new: [....42] [ip4][..tcp] [..192.168.1.184][56644] -> [..13.230.108.42][30303] + new: [....42] [ip4][..tcp] [..192.168.1.184][56644] -> [..13.230.108.42][30303] detected: [....39] [ip4][..tcp] [..192.168.1.184][56641] -> [.144.91.120.135][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] analyse: [....27] [ip4][..tcp] [..192.168.1.184][56630] -> [..40.67.144.128][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -169,13 +169,13 @@ [IATS(ms)....: 158.1,158.1,1.9,112.7,1.0,0.0,111.8,0.0,0.1,0.0,0.1,0.0,0.9,0.0,0.1,0.0,0.0,0.1,0.0,0.1,0.0,0.0,0.0,111.1,0.0,0.8,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 64,60,52,483,52,475,84,52,52,68,68,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46,46,46,46,46,46,46] [ENTROPIES...: 4.5,5.3,5.1,7.6,5.2,7.5,5.9,5.1,5.2,5.7,5.6,5.1,5.2,5.8,5.1,6.7,5.1,5.4,5.8,5.1,5.1,5.4,5.5,5.0,3.6,3.6,3.6,3.6,3.6,3.6,3.6,3.6] - new: [....43] [ip4][..tcp] [..192.168.1.184][56645] -> [.185.219.133.62][30303] + new: [....43] [ip4][..tcp] [..192.168.1.184][56645] -> [.185.219.133.62][30303] detected: [....38] [ip4][..tcp] [..192.168.1.184][56639] -> [.18.219.167.159][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] detected: [....40] [ip4][..tcp] [..192.168.1.184][56642] -> [..178.62.10.218][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....41] [ip4][..tcp] [..192.168.1.184][56643] -> [..178.62.29.183][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....44] [ip4][..tcp] [..192.168.1.184][56646] -> [..172.105.94.62][30303] + new: [....44] [ip4][..tcp] [..192.168.1.184][56646] -> [..172.105.94.62][30303] detected: [....43] [ip4][..tcp] [..192.168.1.184][56645] -> [.185.219.133.62][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....45] [ip4][..tcp] [..192.168.1.184][56647] -> [.182.162.161.61][30303] + new: [....45] [ip4][..tcp] [..192.168.1.184][56647] -> [.182.162.161.61][30303] analyse: [....11] [ip4][..tcp] [..192.168.1.184][56611] -> [..104.42.217.25][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.202| 0.031| 0.071| 5088.628| 2.400] @@ -197,8 +197,8 @@ [IATS(ms)....: 107.6,107.7,1.5,109.0,1.8,109.4,0.7,0.0,0.1,0.0,0.1,1.0,0.2,0.1,0.1,0.1,0.1,0.1,0.0,0.1,0.0,0.1,0.1,0.0,0.0,0.1,0.0,0.0,0.0,107.1,0.0] [PKTLENS.....: 64,60,52,623,52,565,52,84,53,176,55,68,84,52,53,52,54,52,65,68,52,52,84,52,53,52,54,65,68,52,46,46] [ENTROPIES...: 4.5,5.4,5.1,7.7,5.2,7.7,5.2,5.9,5.2,6.9,5.2,5.6,5.9,5.1,5.2,5.1,5.3,5.1,5.6,5.7,5.1,5.1,5.8,5.2,5.2,5.1,5.1,5.3,5.6,5.1,4.0,4.0] - new: [....46] [ip4][..tcp] [..192.168.1.184][56650] -> [.35.228.250.140][30303] - new: [....47] [ip4][..tcp] [..192.168.1.184][56651] -> [..138.201.12.87][30303] + new: [....46] [ip4][..tcp] [..192.168.1.184][56650] -> [.35.228.250.140][30303] + new: [....47] [ip4][..tcp] [..192.168.1.184][56651] -> [..138.201.12.87][30303] analyse: [....41] [ip4][..tcp] [..192.168.1.184][56643] -> [..178.62.29.183][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.049| 0.009| 0.018| 316.609| 2.700] @@ -209,10 +209,10 @@ [IATS(ms)....: 44.4,44.5,1.1,47.4,2.6,0.0,48.9,0.0,0.1,0.1,0.1,0.0,0.1,0.0,0.1,0.1,0.6,0.0,0.1,0.0,0.1,0.4,0.0,0.0,0.0,0.1,43.3,0.5,42.7,0.2,0.0] [PKTLENS.....: 64,60,52,521,52,370,84,52,52,53,52,177,54,52,52,68,52,84,53,176,55,68,84,53,100,67,68,52,84,52,53,56] [ENTROPIES...: 4.5,5.4,5.1,7.6,5.1,7.5,5.9,5.0,5.0,5.2,5.1,6.7,5.3,5.0,5.0,5.7,5.1,5.9,5.2,6.7,5.2,5.5,5.8,5.1,6.1,5.5,5.6,5.1,5.9,5.0,5.2,5.4] - new: [....48] [ip4][..tcp] [..192.168.1.184][56652] -> [..176.9.136.209][30303] + new: [....48] [ip4][..tcp] [..192.168.1.184][56652] -> [..176.9.136.209][30303] detected: [....47] [ip4][..tcp] [..192.168.1.184][56651] -> [..138.201.12.87][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....49] [ip4][..tcp] [..192.168.1.184][56654] -> [..85.214.108.52][30303] - new: [....50] [ip4][..udp] [..192.168.1.184][30303] -> [.18.219.167.159][30303] + new: [....49] [ip4][..tcp] [..192.168.1.184][56654] -> [..85.214.108.52][30303] + new: [....50] [ip4][..udp] [..192.168.1.184][30303] -> [.18.219.167.159][30303] detected: [....50] [ip4][..udp] [..192.168.1.184][30303] -> [.18.219.167.159][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] analyse: [....43] [ip4][..tcp] [..192.168.1.184][56645] -> [.185.219.133.62][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy @@ -224,7 +224,7 @@ [IATS(ms)....: 47.2,47.4,1.6,49.5,3.7,51.6,0.8,0.0,1.0,0.1,0.0,0.0,0.0,0.1,0.1,0.1,0.1,0.1,0.1,0.1,0.1,0.4,0.0,0.0,0.0,0.1,45.6,1.1,0.0,46.3,0.1] [PKTLENS.....: 64,60,52,462,52,434,52,84,53,84,176,52,55,68,53,52,208,52,55,52,68,52,84,53,100,67,68,52,52,84,52,53] [ENTROPIES...: 4.5,5.3,5.1,7.5,5.2,7.4,5.0,5.8,5.1,5.9,6.7,5.1,5.2,5.4,5.2,5.1,6.9,5.1,5.3,5.1,5.4,5.1,5.6,5.1,6.0,5.4,5.5,5.2,5.2,5.8,5.1,5.2] - new: [....51] [ip4][..tcp] [..192.168.1.184][56655] -> [.202.112.28.106][30303] + new: [....51] [ip4][..tcp] [..192.168.1.184][56655] -> [.202.112.28.106][30303] detected: [....48] [ip4][..tcp] [..192.168.1.184][56652] -> [..176.9.136.209][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....46] [ip4][..tcp] [..192.168.1.184][56650] -> [.35.228.250.140][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] analyse: [....15] [ip4][..tcp] [..192.168.1.184][56618] -> [.52.231.165.108][30303] [ETHEREUM][Azure][Crypto_Currency][Acceptable] @@ -248,8 +248,8 @@ [PKTLENS.....: 64,60,52,564,52,511,84,53,52,52,52,54,65,52,52,68,52,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46] [ENTROPIES...: 4.4,5.3,4.9,7.6,5.2,7.5,6.0,5.2,5.1,5.1,5.1,5.2,5.6,5.1,5.1,5.6,5.2,5.1,5.1,5.9,5.0,6.7,5.1,5.4,5.8,5.0,5.0,5.4,5.5,5.0,3.7,3.7] detected: [....49] [ip4][..tcp] [..192.168.1.184][56654] -> [..85.214.108.52][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....52] [ip4][..tcp] [..192.168.1.184][56657] -> [.138.75.171.190][30303] - new: [....53] [ip4][..tcp] [..192.168.1.184][56658] -> [.157.230.152.87][30303] + new: [....52] [ip4][..tcp] [..192.168.1.184][56657] -> [.138.75.171.190][30303] + new: [....53] [ip4][..tcp] [..192.168.1.184][56658] -> [.157.230.152.87][30303] analyse: [....47] [ip4][..tcp] [..192.168.1.184][56651] -> [..138.201.12.87][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.037| 0.006| 0.012| 148.778| 2.600] @@ -280,10 +280,10 @@ [IATS(ms)....: 32.8,32.8,1.3,33.9,2.4,35.0,0.3,0.2,0.1,0.0,0.1,0.0,0.4,0.0,0.1,0.0,0.1,0.0,0.0,0.1,0.0,0.0,0.0,32.6,0.0,0.1,0.1,0.1,0.0,0.0,0.1] [PKTLENS.....: 64,60,52,583,52,480,52,84,52,68,68,52,52,84,53,176,55,68,84,53,54,65,68,52,46,46,46,46,46,46,46,46] [ENTROPIES...: 4.5,5.4,5.1,7.6,5.3,7.5,5.1,5.9,5.1,5.7,5.7,5.1,5.1,5.9,5.2,6.8,5.2,5.7,5.9,5.2,5.2,5.5,5.6,5.2,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7] - new: [....54] [ip4][..tcp] [..192.168.1.184][56660] -> [...51.161.23.12][30303] - new: [....55] [ip4][..tcp] [..192.168.1.184][56661] -> [....52.9.128.68][30303] - new: [....56] [ip4][..tcp] [..192.168.1.184][56662] -> [..35.229.232.19][30303] - new: [....57] [ip4][..tcp] [..192.168.1.184][56663] -> [124.217.235.180][30303] + new: [....54] [ip4][..tcp] [..192.168.1.184][56660] -> [...51.161.23.12][30303] + new: [....55] [ip4][..tcp] [..192.168.1.184][56661] -> [....52.9.128.68][30303] + new: [....56] [ip4][..tcp] [..192.168.1.184][56662] -> [..35.229.232.19][30303] + new: [....57] [ip4][..tcp] [..192.168.1.184][56663] -> [124.217.235.180][30303] analyse: [....34] [ip4][..tcp] [..192.168.1.184][56635] -> [.162.228.29.160][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.159| 0.026| 0.057| 3248.179| 2.500] @@ -334,7 +334,7 @@ [IATS(ms)....: 308.0,308.1,2.1,260.3,1.6,259.8,0.5,0.5,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.0,0.1,0.0,0.0,0.0,0.0,0.0,2.3,1.9,254.5,0.0] [PKTLENS.....: 64,60,52,523,52,474,52,84,52,53,54,52,52,65,68,52,52,84,53,176,55,68,84,53,54,65,68,52,52,52,52,46] [ENTROPIES...: 4.5,5.4,5.1,7.6,5.2,7.5,5.1,5.9,5.0,5.2,5.2,5.0,5.0,5.6,5.6,5.0,5.0,5.8,5.0,6.7,5.2,5.4,5.9,5.1,5.1,5.5,5.5,5.0,5.2,5.1,5.2,3.8] - new: [....58] [ip4][..udp] [183.129.242.164][.1024] -> [..192.168.1.184][30303] + new: [....58] [ip4][..udp] [183.129.242.164][.1024] -> [..192.168.1.184][30303] detected: [....58] [ip4][..udp] [183.129.242.164][.1024] -> [..192.168.1.184][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....54] [ip4][..tcp] [..192.168.1.184][56660] -> [...51.161.23.12][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....53] [ip4][..tcp] [..192.168.1.184][56658] -> [.157.230.152.87][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -349,7 +349,7 @@ [PKTLENS.....: 64,60,52,626,52,448,52,84,53,52,52,84,53,54,65,176,52,55,52,68,68,52,84,53,54,65,68,52,52,52,46,46] [ENTROPIES...: 4.5,5.4,5.0,7.6,5.0,7.5,5.1,5.8,5.1,5.0,5.0,5.8,5.0,5.1,5.5,6.7,5.0,5.2,5.0,5.4,5.5,5.0,5.9,5.0,5.1,5.4,5.6,5.1,5.2,5.1,3.7,3.7] detected: [....55] [ip4][..tcp] [..192.168.1.184][56661] -> [....52.9.128.68][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] - new: [....59] [ip4][..udp] [..192.168.1.184][30303] -> [.202.112.28.106][30303] + new: [....59] [ip4][..udp] [..192.168.1.184][30303] -> [.202.112.28.106][30303] detected: [....59] [ip4][..udp] [..192.168.1.184][30303] -> [.202.112.28.106][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....45] [ip4][..tcp] [..192.168.1.184][56647] -> [.182.162.161.61][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....52] [ip4][..tcp] [..192.168.1.184][56657] -> [.138.75.171.190][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -363,10 +363,10 @@ [IATS(ms)....: 354.5,354.6,1.5,316.9,1.3,316.7,0.2,0.1,0.1,0.1,0.1,0.1,0.1,0.0,0.1,0.0,0.1,0.1,0.3,0.0,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,313.9,0.3] [PKTLENS.....: 64,60,52,577,52,503,52,84,52,53,52,54,52,65,68,52,52,52,52,84,53,176,55,68,84,53,54,65,68,52,52,46] [ENTROPIES...: 4.5,5.4,5.1,7.6,5.2,7.6,5.1,5.9,5.1,5.3,5.1,5.3,5.1,5.5,5.7,5.0,5.1,5.1,5.0,5.7,5.0,6.9,5.1,5.4,5.8,5.0,5.0,5.4,5.4,5.0,5.1,3.7] - new: [....60] [ip4][..udp] [..192.168.1.184][30303] -> [..106.12.39.168][30333] + new: [....60] [ip4][..udp] [..192.168.1.184][30303] -> [..106.12.39.168][30333] detected: [....60] [ip4][..udp] [..192.168.1.184][30303] -> [..106.12.39.168][30333] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....61] [ip4][..tcp] [..192.168.1.184][56670] -> [..167.86.122.50][30303] - new: [....62] [ip4][..tcp] [..192.168.1.184][56671] -> [..86.107.243.62][30303] + new: [....61] [ip4][..tcp] [..192.168.1.184][56670] -> [..167.86.122.50][30303] + new: [....62] [ip4][..tcp] [..192.168.1.184][56671] -> [..86.107.243.62][30303] detected: [....56] [ip4][..tcp] [..192.168.1.184][56662] -> [..35.229.232.19][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] detected: [....51] [ip4][..tcp] [..192.168.1.184][56655] -> [.202.112.28.106][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....62] [ip4][..tcp] [..192.168.1.184][56671] -> [..86.107.243.62][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -382,8 +382,8 @@ [IATS(ms)....: 139.3,139.4,1.7,141.7,7.2,147.3,0.8,0.0,0.1,0.0,0.1,6.7,5.8,0.3,0.2,0.7,0.0,0.0,0.8,0.0,0.0,0.4,0.0,0.0,0.0,0.0,130.0,0.2,0.8,130.5,0.3] [PKTLENS.....: 64,60,52,625,52,473,52,84,53,176,55,68,84,52,53,52,202,61,68,52,52,52,84,53,100,67,68,52,52,84,52,53] [ENTROPIES...: 4.5,5.3,5.0,7.7,5.1,7.6,5.1,5.8,5.1,6.7,5.2,5.6,5.9,5.1,5.3,5.1,6.9,5.5,5.7,5.1,5.1,5.0,5.8,5.0,6.1,5.5,5.5,5.1,5.1,6.0,5.0,5.2] - new: [....63] [ip4][..tcp] [..192.168.1.184][56672] -> [139.162.255.210][30303] - new: [....64] [ip4][..tcp] [..192.168.1.184][56673] -> [..78.47.147.155][30303] + new: [....63] [ip4][..tcp] [..192.168.1.184][56672] -> [139.162.255.210][30303] + new: [....64] [ip4][..tcp] [..192.168.1.184][56673] -> [..78.47.147.155][30303] analyse: [....62] [ip4][..tcp] [..192.168.1.184][56671] -> [..86.107.243.62][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.039| 0.010| 0.016| 256.751| 3.100] @@ -394,9 +394,9 @@ [IATS(ms)....: 39.1,39.2,1.5,38.4,0.4,37.3,0.8,0.0,0.0,0.0,0.1,39.2,38.3,0.3,0.3,0.6,0.0,0.0,0.0,0.1,30.7,30.6,0.3,0.2,0.0,0.0,0.0,0.0,0.1,0.0,0.1] [PKTLENS.....: 64,60,52,592,52,416,52,84,53,176,55,68,292,52,52,52,84,53,100,67,68,260,52,52,84,53,55,64,68,84,53,56] [ENTROPIES...: 4.5,5.3,5.1,7.7,5.2,7.5,5.1,5.8,5.1,6.7,5.2,5.6,7.3,5.0,5.1,5.2,5.8,5.1,6.1,5.5,5.6,7.1,5.0,5.2,5.7,5.2,5.2,5.4,5.6,5.9,5.2,5.3] - new: [....65] [ip4][..tcp] [..192.168.1.184][56674] -> [...94.68.55.162][30303] + new: [....65] [ip4][..tcp] [..192.168.1.184][56674] -> [...94.68.55.162][30303] detected: [....63] [ip4][..tcp] [..192.168.1.184][56672] -> [139.162.255.210][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....66] [ip4][..tcp] [..192.168.1.184][56675] -> [..35.235.37.216][30303] + new: [....66] [ip4][..tcp] [..192.168.1.184][56675] -> [..35.235.37.216][30303] detected: [....64] [ip4][..tcp] [..192.168.1.184][56673] -> [..78.47.147.155][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....66] [ip4][..tcp] [..192.168.1.184][56675] -> [..35.235.37.216][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] analyse: [....53] [ip4][..tcp] [..192.168.1.184][56658] -> [.157.230.152.87][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -410,7 +410,7 @@ [PKTLENS.....: 64,60,52,635,52,443,52,84,52,53,52,213,66,52,52,68,52,84,53,176,55,68,84,53,111,56,68,52,52,84,53,52] [ENTROPIES...: 4.5,5.3,5.0,7.7,5.2,7.4,5.1,5.9,5.1,5.3,5.1,7.0,5.6,5.1,5.1,5.6,5.0,5.8,5.1,6.8,5.1,5.4,5.8,5.1,6.2,5.1,5.4,5.1,5.2,5.9,5.3,5.0] detected: [....65] [ip4][..tcp] [..192.168.1.184][56674] -> [...94.68.55.162][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....67] [ip4][..tcp] [..192.168.1.184][56678] -> [..13.251.14.199][30303] + new: [....67] [ip4][..tcp] [..192.168.1.184][56678] -> [..13.251.14.199][30303] analyse: [....63] [ip4][..tcp] [..192.168.1.184][56672] -> [139.162.255.210][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.042| 0.007| 0.015| 228.263| 2.600] @@ -421,7 +421,7 @@ [IATS(ms)....: 41.4,41.5,1.3,42.4,1.0,42.1,0.2,0.2,0.4,0.4,0.4,0.4,0.2,0.0,0.1,0.0,0.1,0.1,0.0,0.1,0.0,0.0,0.0,39.1,1.4,0.0,0.1,0.1,0.0,0.1,0.1] [PKTLENS.....: 64,60,52,438,52,408,52,84,52,68,52,68,52,84,53,176,55,68,84,53,54,65,68,52,52,46,46,46,46,46,46,46] [ENTROPIES...: 4.5,5.4,5.1,7.5,5.1,7.5,5.0,5.9,5.0,5.7,5.0,5.6,5.0,5.7,5.1,6.8,5.2,5.4,5.8,5.1,5.1,5.4,5.5,5.1,5.2,3.7,3.7,3.7,3.7,3.7,3.7,3.7] - new: [....68] [ip4][..tcp] [..192.168.1.184][56679] -> [..35.228.158.52][30303] + new: [....68] [ip4][..tcp] [..192.168.1.184][56679] -> [..35.228.158.52][30303] analyse: [....55] [ip4][..tcp] [..192.168.1.184][56661] -> [....52.9.128.68][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.194| 0.037| 0.074| 5538.541| 2.700] @@ -432,10 +432,10 @@ [IATS(ms)....: 179.2,179.3,1.5,193.5,0.4,0.0,192.3,0.0,0.2,0.2,0.7,0.0,0.1,0.0,0.1,2.8,2.1,0.4,0.0,0.0,0.0,0.1,193.8,0.2,0.8,194.1,0.1,0.1,1.1,0.0,1.2] [PKTLENS.....: 64,60,52,524,52,480,84,52,52,184,52,84,53,176,55,68,80,52,84,53,100,67,68,52,52,84,52,133,52,83,52,52] [ENTROPIES...: 4.5,5.3,5.0,7.6,4.9,7.5,5.8,4.9,4.9,6.8,4.9,5.8,5.1,6.7,5.1,5.3,5.8,4.9,5.8,5.1,6.2,5.3,5.4,5.0,5.0,5.9,5.0,6.5,5.0,5.9,5.2,5.0] - new: [....69] [ip4][..tcp] [..192.168.1.184][56680] -> [...138.59.17.58][30303] - new: [....70] [ip4][..tcp] [..192.168.1.184][56681] -> [207.180.206.216][30303] + new: [....69] [ip4][..tcp] [..192.168.1.184][56680] -> [...138.59.17.58][30303] + new: [....70] [ip4][..tcp] [..192.168.1.184][56681] -> [207.180.206.216][30303] detected: [....68] [ip4][..tcp] [..192.168.1.184][56679] -> [..35.228.158.52][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] - new: [....71] [ip4][..udp] [..192.168.1.184][30303] -> [..167.86.122.50][30303] + new: [....71] [ip4][..udp] [..192.168.1.184][30303] -> [..167.86.122.50][30303] detected: [....71] [ip4][..udp] [..192.168.1.184][30303] -> [..167.86.122.50][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....70] [ip4][..tcp] [..192.168.1.184][56681] -> [207.180.206.216][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] analyse: [....65] [ip4][..tcp] [..192.168.1.184][56674] -> [...94.68.55.162][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -448,7 +448,7 @@ [IATS(ms)....: 71.3,71.4,1.3,75.1,1.0,0.0,74.8,0.0,0.1,0.1,0.5,0.5,0.2,0.0,0.1,0.0,0.1,0.3,0.0,0.0,0.0,0.1,69.6,0.8,0.0,69.7,0.7,0.0,0.7,0.0,0.1] [PKTLENS.....: 64,60,52,599,52,556,84,52,52,195,52,69,52,84,53,176,55,68,84,53,100,67,68,52,52,84,52,134,82,52,52,52] [ENTROPIES...: 4.4,5.3,5.0,7.6,5.2,7.6,5.8,5.0,5.0,6.9,5.0,5.5,5.0,5.7,5.1,6.8,5.1,5.5,5.9,5.2,6.1,5.6,5.5,5.2,5.2,5.8,5.0,6.4,5.9,5.0,5.0,5.1] - new: [....72] [ip4][..tcp] [..192.168.1.184][56684] -> [...51.83.237.44][30303] + new: [....72] [ip4][..tcp] [..192.168.1.184][56684] -> [...51.83.237.44][30303] analyse: [....52] [ip4][..tcp] [..192.168.1.184][56657] -> [.138.75.171.190][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.263| 0.042| 0.096| 9182.918| 2.400] @@ -459,11 +459,11 @@ [IATS(ms)....: 259.7,259.8,1.3,261.4,3.0,263.1,0.5,0.4,0.3,0.2,0.2,0.0,0.1,0.0,0.0,0.1,0.0,0.1,0.0,0.0,0.0,260.1,0.0,0.0,0.1,0.1,0.0,0.7,0.0,0.0,0.0] [PKTLENS.....: 64,60,52,591,52,511,52,84,52,84,52,84,53,176,55,68,84,53,54,65,68,52,46,46,46,46,46,46,46,46,46,46] [ENTROPIES...: 4.5,5.3,5.0,7.6,5.2,7.5,4.9,5.8,4.9,5.8,4.9,5.8,5.1,6.7,5.1,5.5,5.8,5.0,5.1,5.5,5.4,5.0,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7,3.7] - new: [....73] [ip4][..tcp] [..192.168.1.184][56685] -> [...88.99.93.219][30303] + new: [....73] [ip4][..tcp] [..192.168.1.184][56685] -> [...88.99.93.219][30303] detected: [....72] [ip4][..tcp] [..192.168.1.184][56684] -> [...51.83.237.44][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....69] [ip4][..tcp] [..192.168.1.184][56680] -> [...138.59.17.58][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] detected: [....73] [ip4][..tcp] [..192.168.1.184][56685] -> [...88.99.93.219][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] - new: [....74] [ip4][..tcp] [..192.168.1.184][56686] -> [.206.189.107.35][30303] + new: [....74] [ip4][..tcp] [..192.168.1.184][56686] -> [.206.189.107.35][30303] detected: [....67] [ip4][..tcp] [..192.168.1.184][56678] -> [..13.251.14.199][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] detected: [....74] [ip4][..tcp] [..192.168.1.184][56686] -> [.206.189.107.35][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] analyse: [....64] [ip4][..tcp] [..192.168.1.184][56673] -> [..78.47.147.155][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -493,7 +493,7 @@ end: [....13] [ip4][..tcp] [..192.168.1.184][56615] -> [.35.158.244.151][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] guessed: [....42] [ip4][..tcp] [..192.168.1.184][56644] -> [..13.230.108.42][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] RISK: Unidirectional Traffic - idle: [....42] [ip4][..tcp] [..192.168.1.184][56644] -> [..13.230.108.42][30303] + idle: [....42] [ip4][..tcp] [..192.168.1.184][56644] -> [..13.230.108.42][30303] end: [....25] [ip4][..tcp] [..192.168.1.184][56629] -> [....51.38.60.79][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] end: [....28] [ip4][..tcp] [..192.168.1.184][56632] -> [...51.38.81.180][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] end: [....20] [ip4][..tcp] [..192.168.1.184][56624] -> [....89.38.99.34][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] @@ -518,12 +518,12 @@ idle: [....51] [ip4][..tcp] [..192.168.1.184][56655] -> [.202.112.28.106][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] guessed: [....21] [ip4][..tcp] [..192.168.1.184][56625] -> [.....5.1.83.226][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] RISK: Unidirectional Traffic - idle: [....21] [ip4][..tcp] [..192.168.1.184][56625] -> [.....5.1.83.226][30303] + idle: [....21] [ip4][..tcp] [..192.168.1.184][56625] -> [.....5.1.83.226][30303] end: [....24] [ip4][..tcp] [..192.168.1.184][56628] -> [....3.209.45.79][30303] [ETHEREUM][ETHEREUM][Crypto_Currency][Acceptable] end: [....14] [ip4][..tcp] [..192.168.1.184][56617] -> [...34.97.172.22][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] guessed: [....35] [ip4][..tcp] [..192.168.1.184][56637] -> [.35.233.197.131][30303] [ETHEREUM][GoogleCloud][Crypto_Currency][Acceptable] RISK: Unidirectional Traffic - idle: [....35] [ip4][..tcp] [..192.168.1.184][56637] -> [.35.233.197.131][30303] + idle: [....35] [ip4][..tcp] [..192.168.1.184][56637] -> [.35.233.197.131][30303] end: [....54] [ip4][..tcp] [..192.168.1.184][56660] -> [...51.161.23.12][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] end: [....55] [ip4][..tcp] [..192.168.1.184][56661] -> [....52.9.128.68][30303] [ETHEREUM][AmazonAWS][Crypto_Currency][Acceptable] end: [....30] [ip4][..tcp] [..192.168.1.184][56633] -> [.82.145.220.249][30303] [ETHEREUM][Unknown][Crypto_Currency][Acceptable] diff --git a/test/results/flow-info/default/ethernetIP.pcap.out b/test/results/flow-info/default/ethernetIP.pcap.out index bbe57c8cb..b3618b1ea 100644 --- a/test/results/flow-info/default/ethernetIP.pcap.out +++ b/test/results/flow-info/default/ethernetIP.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....141.81.0.10][50275] -> [....141.81.0.83][44818] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....141.81.0.10][50275] -> [....141.81.0.83][44818] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [....141.81.0.10][50275] -> [....141.81.0.83][44818] [EthernetIP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..tcp] [....141.81.0.63][44818] -> [....141.81.0.10][52593] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [....141.81.0.63][44818] -> [....141.81.0.10][52593] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [....141.81.0.63][44818] -> [....141.81.0.10][52593] [EthernetIP][Unknown][Network][Acceptable] - new: [.....3] [ip4][..tcp] [....141.81.0.10][52594] -> [....141.81.0.43][44818] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [....141.81.0.10][52594] -> [....141.81.0.43][44818] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [....141.81.0.10][52594] -> [....141.81.0.43][44818] [EthernetIP][Unknown][Network][Acceptable] - new: [.....4] [ip4][..tcp] [....141.81.0.10][62717] -> [....141.81.0.23][44818] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....141.81.0.10][62717] -> [....141.81.0.23][44818] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [....141.81.0.10][62717] -> [....141.81.0.23][44818] [EthernetIP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [....141.81.0.10][50275] -> [....141.81.0.83][44818] [EthernetIP][Unknown][Network][Acceptable] idle: [.....4] [ip4][..tcp] [....141.81.0.10][62717] -> [....141.81.0.23][44818] [EthernetIP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/exe_download.pcap.out b/test/results/flow-info/default/exe_download.pcap.out index 4b7dfbc3d..aa96b3850 100644 --- a/test/results/flow-info/default/exe_download.pcap.out +++ b/test/results/flow-info/default/exe_download.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] + new: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] detected: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Unknown][Web][Acceptable][144.91.69.195] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Unknown][Download][Acceptable][144.91.69.195] diff --git a/test/results/flow-info/default/exe_download_as_png.pcap.out b/test/results/flow-info/default/exe_download_as_png.pcap.out index 7dde9ff64..8912cc4e7 100644 --- a/test/results/flow-info/default/exe_download_as_png.pcap.out +++ b/test/results/flow-info/default/exe_download_as_png.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....10.9.25.101][49197] -> [..185.98.87.185][...80] + new: [.....1] [ip4][..tcp] [....10.9.25.101][49197] -> [..185.98.87.185][...80] detected: [.....1] [ip4][..tcp] [....10.9.25.101][49197] -> [..185.98.87.185][...80] [HTTP][Unknown][Web][Acceptable][185.98.87.185] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....1] [ip4][..tcp] [....10.9.25.101][49197] -> [..185.98.87.185][...80] [HTTP][Unknown][Web][Acceptable][185.98.87.185] diff --git a/test/results/flow-info/default/facebook.pcap.out b/test/results/flow-info/default/facebook.pcap.out index 64d7fdf98..040f3f7b7 100644 --- a/test/results/flow-info/default/facebook.pcap.out +++ b/test/results/flow-info/default/facebook.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.43.18][52066] -> [..66.220.156.68][..443] + new: [.....1] [ip4][..tcp] [..192.168.43.18][52066] -> [..66.220.156.68][..443] detected: [.....1] [ip4][..tcp] [..192.168.43.18][52066] -> [..66.220.156.68][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][facebook.com] detection-update: [.....1] [ip4][..tcp] [..192.168.43.18][52066] -> [..66.220.156.68][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][facebook.com] detection-update: [.....1] [ip4][..tcp] [..192.168.43.18][52066] -> [..66.220.156.68][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][facebook.com] - new: [.....2] [ip4][..tcp] [..192.168.43.18][44614] -> [....31.13.86.36][..443] + new: [.....2] [ip4][..tcp] [..192.168.43.18][44614] -> [....31.13.86.36][..443] detected: [.....2] [ip4][..tcp] [..192.168.43.18][44614] -> [....31.13.86.36][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] detection-update: [.....2] [ip4][..tcp] [..192.168.43.18][44614] -> [....31.13.86.36][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] analyse: [.....2] [ip4][..tcp] [..192.168.43.18][44614] -> [....31.13.86.36][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] diff --git a/test/results/flow-info/default/fastcgi.pcap.out b/test/results/flow-info/default/fastcgi.pcap.out index fe0696146..91b788320 100644 --- a/test/results/flow-info/default/fastcgi.pcap.out +++ b/test/results/flow-info/default/fastcgi.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.9][38254] -> [......10.0.0.11][.9000] + new: [.....1] [ip4][..tcp] [.......10.0.0.9][38254] -> [......10.0.0.11][.9000] detected: [.....1] [ip4][..tcp] [.......10.0.0.9][38254] -> [......10.0.0.11][.9000] [FastCGI][Unknown][Network][Safe] analyse: [.....1] [ip4][..tcp] [.......10.0.0.9][38254] -> [......10.0.0.11][.9000] [FastCGI][Unknown][Network][Safe] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/firefox.pcap.out b/test/results/flow-info/default/firefox.pcap.out index 7b63fcdb5..09ac1659b 100644 --- a/test/results/flow-info/default/firefox.pcap.out +++ b/test/results/flow-info/default/firefox.pcap.out @@ -1,18 +1,18 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][51577] -> [...146.48.58.18][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][51577] -> [...146.48.58.18][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][51577] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][51577] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] - new: [.....2] [ip4][..tcp] [..192.168.1.178][51583] -> [...146.48.58.18][..443] - new: [.....3] [ip4][..tcp] [..192.168.1.178][51588] -> [...146.48.58.18][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.178][51583] -> [...146.48.58.18][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.178][51588] -> [...146.48.58.18][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.178][51583] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detected: [.....3] [ip4][..tcp] [..192.168.1.178][51588] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....2] [ip4][..tcp] [..192.168.1.178][51583] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....3] [ip4][..tcp] [..192.168.1.178][51588] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] - new: [.....4] [ip4][..tcp] [..192.168.1.178][51599] -> [...146.48.58.18][..443] - new: [.....5] [ip4][..tcp] [..192.168.1.178][51600] -> [...146.48.58.18][..443] - new: [.....6] [ip4][..tcp] [..192.168.1.178][51601] -> [...146.48.58.18][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.178][51599] -> [...146.48.58.18][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.178][51600] -> [...146.48.58.18][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.178][51601] -> [...146.48.58.18][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.178][51600] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detected: [.....4] [ip4][..tcp] [..192.168.1.178][51599] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detected: [.....6] [ip4][..tcp] [..192.168.1.178][51601] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] diff --git a/test/results/flow-info/default/fix.pcap.out b/test/results/flow-info/default/fix.pcap.out index 1644b6a8f..7432f806e 100644 --- a/test/results/flow-info/default/fix.pcap.out +++ b/test/results/flow-info/default/fix.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][43594] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][43594] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][43594] [FIX][Unknown][RPC][Safe] - new: [.....2] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47968] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47968] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47968] [FIX][Unknown][RPC][Safe] - new: [.....3] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45578] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45578] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45578] [FIX][Unknown][RPC][Safe] - new: [.....4] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47952] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47952] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47952] [FIX][Unknown][RPC][Safe] - new: [.....5] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45584] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45584] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45584] [FIX][Unknown][RPC][Safe] - new: [.....6] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47962] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47962] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47962] [FIX][Unknown][RPC][Safe] analyse: [.....3] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45578] [FIX][Unknown][RPC][Safe] min| max| avg| stddev| variance| entropy @@ -23,9 +23,9 @@ [IATS(ms)....: 0.2,0.2,52.4,3.6,94.0,87.6,49.4,50.7,50.7,52.8,52.9,49.7,49.6,49.7,49.7,49.5,49.4,49.8,49.8,50.0,50.0,49.9,49.9,49.6,49.6,49.8,49.8,50.2,50.2,314.9,315.0] [PKTLENS.....: 79,46,126,155,40,46,497,46,216,46,219,46,129,46,96,46,171,46,98,46,67,46,92,46,67,46,75,46,94,46,67,46] [ENTROPIES...: 5.2,4.4,6.4,5.1,4.8,4.5,5.2,4.4,5.0,4.5,5.2,4.4,5.1,4.5,5.1,4.5,5.1,4.4,5.1,4.3,5.1,4.5,5.0,4.4,5.1,4.4,5.2,4.5,4.9,4.5,5.1,4.4] - new: [.....7] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38652] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38652] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38652] [FIX][Unknown][RPC][Safe] - new: [.....8] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40918] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40918] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40918] [FIX][Unknown][RPC][Safe] analyse: [.....2] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][47968] [FIX][Unknown][RPC][Safe] min| max| avg| stddev| variance| entropy @@ -37,7 +37,7 @@ [IATS(ms)....: 0.1,100.1,0.1,100.2,0.1,100.0,0.1,100.1,0.0,99.9,100.0,100.2,100.2,100.8,100.8,300.2,0.0,300.2,0.0,0.2,17.9,82.4,142.0,200.5,158.5,100.0,99.9,0.4,0.4,200.2,200.3] [PKTLENS.....: 82,52,87,78,52,52,87,86,52,52,78,52,121,52,77,52,91,121,52,52,139,52,91,52,87,52,87,52,76,52,84,52] [ENTROPIES...: 5.4,5.2,5.4,5.4,5.1,5.2,5.4,5.4,5.1,5.2,5.3,5.1,5.6,5.2,5.5,5.2,5.4,5.2,5.1,5.1,6.5,5.1,5.5,5.2,5.5,5.2,5.2,5.2,5.2,5.2,5.4,5.1] - new: [.....9] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38646] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38646] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][38646] [FIX][Unknown][RPC][Safe] analyse: [.....1] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][43594] [FIX][Unknown][RPC][Safe] min| max| avg| stddev| variance| entropy @@ -49,11 +49,11 @@ [IATS(ms)....: 0.2,0.3,0.3,250.6,0.1,250.6,0.0,0.2,18.2,232.1,291.3,250.1,209.0,250.7,250.7,250.6,250.6,250.7,250.7,250.7,250.7,250.6,0.0,250.7,0.0,251.5,251.5,249.7,249.8,250.3,250.3] [PKTLENS.....: 138,52,77,52,91,138,52,52,137,52,155,52,155,52,172,52,155,52,155,52,104,52,240,99,52,52,121,52,189,52,104,52] [ENTROPIES...: 5.5,5.2,5.3,5.1,5.4,5.4,5.2,5.1,6.4,5.1,5.4,5.2,5.5,5.2,5.6,5.2,5.4,5.2,5.5,5.2,5.4,5.2,5.6,5.6,5.2,5.2,5.5,5.2,5.4,5.2,5.5,5.2] - new: [....10] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][39094] [MIDSTREAM] + new: [....10] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][39094] [MIDSTREAM] detected: [....10] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][39094] [FIX][Unknown][RPC][Safe] - new: [....11] [ip4][..tcp] [..217.192.86.32][.4000] -> [...192.168.0.20][53330] [MIDSTREAM] + new: [....11] [ip4][..tcp] [..217.192.86.32][.4000] -> [...192.168.0.20][53330] [MIDSTREAM] detected: [....11] [ip4][..tcp] [..217.192.86.32][.4000] -> [...192.168.0.20][53330] [FIX][Unknown][RPC][Safe] - new: [....12] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40928] [MIDSTREAM] + new: [....12] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40928] [MIDSTREAM] detected: [....12] [ip4][..tcp] [.....8.17.22.31][.4000] -> [...192.168.0.20][40928] [FIX][Unknown][RPC][Safe] analyse: [.....5] [ip4][..tcp] [..208.245.107.3][.4000] -> [...192.168.0.20][45584] [FIX][Unknown][RPC][Safe] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/fix2.pcap.out b/test/results/flow-info/default/fix2.pcap.out index dca353080..b80097c53 100644 --- a/test/results/flow-info/default/fix2.pcap.out +++ b/test/results/flow-info/default/fix2.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.101.0.2][34962] -> [.....10.102.0.2][.1024] - new: [.....2] [ip4][..tcp] [.....10.101.0.2][34963] -> [.....10.102.0.9][.1024] + new: [.....1] [ip4][..tcp] [.....10.101.0.2][34962] -> [.....10.102.0.2][.1024] + new: [.....2] [ip4][..tcp] [.....10.101.0.2][34963] -> [.....10.102.0.9][.1024] detected: [.....1] [ip4][..tcp] [.....10.101.0.2][34962] -> [.....10.102.0.2][.1024] [FIX][Unknown][RPC][Safe] detected: [.....2] [ip4][..tcp] [.....10.101.0.2][34963] -> [.....10.102.0.9][.1024] [FIX][Unknown][RPC][Safe] analyse: [.....1] [ip4][..tcp] [.....10.101.0.2][34962] -> [.....10.102.0.2][.1024] [FIX][Unknown][RPC][Safe] diff --git a/test/results/flow-info/default/forticlient.pcap.out b/test/results/flow-info/default/forticlient.pcap.out index 0a96f439f..2071c9d09 100644 --- a/test/results/flow-info/default/forticlient.pcap.out +++ b/test/results/flow-info/default/forticlient.pcap.out @@ -1,35 +1,35 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][61805] -> [....82.81.46.13][10443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][61805] -> [....82.81.46.13][10443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][61805] -> [....82.81.46.13][10443] [TLS][Unknown][Web][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][61805] -> [....82.81.46.13][10443] [TLS][Unknown][Web][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][61805] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [.....2] [ip4][..tcp] [..192.168.1.178][61806] -> [....82.81.46.13][10443] + new: [.....2] [ip4][..tcp] [..192.168.1.178][61806] -> [....82.81.46.13][10443] detected: [.....2] [ip4][..tcp] [..192.168.1.178][61806] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....2] [ip4][..tcp] [..192.168.1.178][61806] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....2] [ip4][..tcp] [..192.168.1.178][61806] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [.....3] [ip4][..tcp] [..192.168.1.178][61811] -> [....82.81.46.13][10443] + new: [.....3] [ip4][..tcp] [..192.168.1.178][61811] -> [....82.81.46.13][10443] detected: [.....3] [ip4][..tcp] [..192.168.1.178][61811] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [..192.168.1.178][61811] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [..192.168.1.178][61811] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [.....4] [ip4][..tcp] [..192.168.1.178][61812] -> [....82.81.46.13][10443] + new: [.....4] [ip4][..tcp] [..192.168.1.178][61812] -> [....82.81.46.13][10443] detected: [.....4] [ip4][..tcp] [..192.168.1.178][61812] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....4] [ip4][..tcp] [..192.168.1.178][61812] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....4] [ip4][..tcp] [..192.168.1.178][61812] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [.....5] [ip4][..tcp] [..192.168.1.178][61820] -> [....82.81.46.13][10443] + new: [.....5] [ip4][..tcp] [..192.168.1.178][61820] -> [....82.81.46.13][10443] detected: [.....5] [ip4][..tcp] [..192.168.1.178][61820] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....5] [ip4][..tcp] [..192.168.1.178][61820] -> [....82.81.46.13][10443] [TLS.FortiClient][Unknown][VPN][Safe][82.81.46.13] diff --git a/test/results/flow-info/default/ftp-start-tls.pcap.out b/test/results/flow-info/default/ftp-start-tls.pcap.out index 99ec9172c..b732fc9fc 100644 --- a/test/results/flow-info/default/ftp-start-tls.pcap.out +++ b/test/results/flow-info/default/ftp-start-tls.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.238.26.36][62092] -> [...10.220.50.76][...21] + new: [.....1] [ip4][..tcp] [...10.238.26.36][62092] -> [...10.220.50.76][...21] detected: [.....1] [ip4][..tcp] [...10.238.26.36][62092] -> [...10.220.50.76][...21] [FTPS][Unknown][Download][Unsafe] RISK: Unsafe Protocol detection-update: [.....1] [ip4][..tcp] [...10.238.26.36][62092] -> [...10.220.50.76][...21] [FTPS][Unknown][Download][Unsafe] diff --git a/test/results/flow-info/default/ftp.pcap.out b/test/results/flow-info/default/ftp.pcap.out index 6e18aa82b..c60f23980 100644 --- a/test/results/flow-info/default/ftp.pcap.out +++ b/test/results/flow-info/default/ftp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.212][50694] -> [...90.130.70.73][...21] + new: [.....1] [ip4][..tcp] [..192.168.1.212][50694] -> [...90.130.70.73][...21] detected: [.....1] [ip4][..tcp] [..192.168.1.212][50694] -> [...90.130.70.73][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials analyse: [.....1] [ip4][..tcp] [..192.168.1.212][50694] -> [...90.130.70.73][...21] [FTP_CONTROL][Unknown][Download][Unsafe] @@ -14,11 +14,11 @@ [IATS(ms)....: 27.4,27.5,29.0,29.0,0.5,27.7,0.3,27.4,0.2,69.1,21.2,90.0,0.3,27.1,0.0,26.8,0.1,27.0,0.1,26.9,0.0,0.3,27.5,27.3,0.1,0.0,0.7,27.1,26.5,0.1,26.8] [PKTLENS.....: 64,60,52,72,52,68,52,86,52,65,52,75,52,57,52,86,52,58,67,117,52,52,63,96,52,293,52,82,74,52,57,86] [ENTROPIES...: 4.2,5.3,4.9,5.6,4.9,5.4,5.2,5.7,4.9,5.2,5.1,5.7,4.9,5.0,5.0,5.6,4.8,5.0,5.5,5.3,4.9,4.9,5.2,5.7,4.9,5.0,4.9,5.6,5.6,4.9,5.1,5.7] - new: [.....2] [ip4][..tcp] [..192.168.1.212][50695] -> [...90.130.70.73][25685] + new: [.....2] [ip4][..tcp] [..192.168.1.212][50695] -> [...90.130.70.73][25685] detected: [.....2] [ip4][..tcp] [..192.168.1.212][50695] -> [...90.130.70.73][25685] [FTP_DATA][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] - analyse: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] + new: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] + analyse: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.030| 0.006| 0.011| 123.407| 3.100] [PKTLEN......: 52.000| 1492.000| 818.000| 717.500| 514855.000| 4.300] @@ -29,7 +29,7 @@ [PKTLENS.....: 64,60,52,1492,64,1492,52,1492,52,1492,1492,52,1492,52,1492,1492,1492,52,52,1492,1492,52,1492,52,1492,1492,52,52,1492,52,1492,1492] [ENTROPIES...: 4.3,5.3,4.9,0.4,5.0,0.4,5.0,0.4,4.8,0.4,0.4,4.9,0.4,4.8,0.4,0.4,0.4,4.9,4.8,0.4,0.4,4.9,0.4,4.8,0.4,0.4,5.2,5.0,0.4,4.8,0.4,0.4] not-detected: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] [Unknown][Unknown][Unrated] - end: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] + end: [.....3] [ip4][..tcp] [..192.168.1.212][50696] -> [...90.130.70.73][24523] end: [.....1] [ip4][..tcp] [..192.168.1.212][50694] -> [...90.130.70.73][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials end: [.....2] [ip4][..tcp] [..192.168.1.212][50695] -> [...90.130.70.73][25685] [FTP_DATA][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/ftp_failed.pcap.out b/test/results/flow-info/default/ftp_failed.pcap.out index 43b78d438..12f4bc8da 100644 --- a/test/results/flow-info/default/ftp_failed.pcap.out +++ b/test/results/flow-info/default/ftp_failed.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [.............2a00:d40:1:3:192:12:193:11][44724] -> [.......................2a00:800:1010::1][...21] + new: [.....1] [ip6][..tcp] [.............2a00:d40:1:3:192:12:193:11][44724] -> [.......................2a00:800:1010::1][...21] detected: [.....1] [ip6][..tcp] [.............2a00:d40:1:3:192:12:193:11][44724] -> [.......................2a00:800:1010::1][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials end: [.....1] [ip6][..tcp] [.............2a00:d40:1:3:192:12:193:11][44724] -> [.......................2a00:800:1010::1][...21] [FTP_CONTROL][Unknown][Download][Unsafe] diff --git a/test/results/flow-info/default/fuzz-2006-06-26-2594.pcap.out b/test/results/flow-info/default/fuzz-2006-06-26-2594.pcap.out index 42d53ae26..11d285897 100644 --- a/test/results/flow-info/default/fuzz-2006-06-26-2594.pcap.out +++ b/test/results/flow-info/default/fuzz-2006-06-26-2594.pcap.out @@ -1,33 +1,33 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] + new: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] detected: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] - new: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] - new: [.....3] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][...53] + new: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] + new: [.....3] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] - new: [.....4] [ip4][..udp] [....192.168.1.2][.2712] -> [...192.37.115.0][...53] + new: [.....4] [ip4][..udp] [....192.168.1.2][.2712] -> [...192.37.115.0][...53] detected: [.....4] [ip4][..udp] [....192.168.1.2][.2712] -> [...192.37.115.0][...53] [DNS][Unknown][Network][Acceptable][sip.cybercrty.dk] - new: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] - new: [.....6] [ip4][..udp] [....192.168.1.3][...53] -> [....192.168.1.2][.2712] + new: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] + new: [.....6] [ip4][..udp] [....192.168.1.3][...53] -> [....192.168.1.2][.2712] detected: [.....6] [ip4][..udp] [....192.168.1.3][...53] -> [....192.168.1.2][.2712] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] - new: [.....7] [ip4][..udp] [....192.168.1.2][.2713] -> [....192.168.1.1][...53] + new: [.....7] [ip4][..udp] [....192.168.1.2][.2713] -> [....192.168.1.1][...53] detected: [.....7] [ip4][..udp] [....192.168.1.2][.2713] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] - new: [.....8] [ip4][..udp] [..192.168.1.110][.2713] -> [....192.168.1.1][...53] + new: [.....8] [ip4][..udp] [..192.168.1.110][.2713] -> [....192.168.1.1][...53] detected: [.....8] [ip4][..udp] [..192.168.1.110][.2713] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet ERROR-EVENT: Unknown packet type [1/16] - new: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] + new: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] detection-update: [.....7] [ip4][..udp] [....192.168.1.2][.2713] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] + new: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] detected: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....11] [ip4][..udp] [...192.168.1.52][.5060] -> [..212.242.33.35][.5060] + new: [....11] [ip4][..udp] [...192.168.1.52][.5060] -> [..212.242.33.35][.5060] detected: [....11] [ip4][..udp] [...192.168.1.52][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] + new: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] detected: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] + new: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] detected: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic @@ -35,20 +35,20 @@ detection-update: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyber?ity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] + new: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] detected: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] + new: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] ERROR-EVENT: Unknown packet type [3/16] - new: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] + new: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] detected: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] + new: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] detected: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][] RISK: Unsafe Protocol update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] - new: [....18] [ip4][..tcp] [....192.168.1.2][.2717] -> [..147.137.21.94][..445] - new: [....19] [ip4][..tcp] [....192.168.1.2][.2718] -> [..147.137.21.94][..139] - new: [....20] [ip4][..tcp] [...192.168.1.71][.2718] -> [.147.137.21.122][..139] + update: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] + new: [....18] [ip4][..tcp] [....192.168.1.2][.2717] -> [..147.137.21.94][..445] + new: [....19] [ip4][..tcp] [....192.168.1.2][.2718] -> [..147.137.21.94][..139] + new: [....20] [ip4][..tcp] [...192.168.1.71][.2718] -> [.147.137.21.122][..139] update: [.....4] [ip4][..udp] [....192.168.1.2][.2712] -> [...192.37.115.0][...53] [DNS][Unknown][Network][Acceptable] update: [....11] [ip4][..udp] [...192.168.1.52][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -61,49 +61,49 @@ update: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] - update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] - new: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] + update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] + update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] + new: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] detected: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][ftp.ecite?e.com] RISK: Non-Printable/Invalid Chars Detected - new: [....22] [ip4][..udp] [....192.168.1.2][.2719] -> [....192.168.1.1][...53] + new: [....22] [ip4][..udp] [....192.168.1.2][.2719] -> [....192.168.1.1][...53] detected: [....22] [ip4][..udp] [....192.168.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][ftp.ecitele.com] detection-update: [....22] [ip4][..udp] [....192.168.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [....23] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.234.1.253][...21] + new: [....23] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.234.1.253][...21] ERROR-EVENT: Unknown L3 protocol [1/16] - new: [....24] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.169.1.2][.2720] [MIDSTREAM] - new: [....25] [ip4][..tcp] [....192.168.1.2][.2679] -> [..147.234.1.253][...21] [MIDSTREAM] + new: [....24] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.169.1.2][.2720] [MIDSTREAM] + new: [....25] [ip4][..tcp] [....192.168.1.2][.2679] -> [..147.234.1.253][...21] [MIDSTREAM] ERROR-EVENT: Unknown L3 protocol [2/16] - new: [....26] [ip4][..tcp] [..147.234.1.253][...21] -> [......192.2.1.2][.2720] [MIDSTREAM] - new: [....27] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.1.66][.2720] [MIDSTREAM] - new: [....28] [ip4][..tcp] [..147.234.1.253][..120] -> [....192.168.1.2][.2720] [MIDSTREAM] - new: [....29] [ip4][..tcp] [..147.234.1.170][43690] -> [170.170.170.170][43690] - new: [....30] [ip4][..tcp] [..147.234.1.249][.2069] -> [....192.168.1.2][.2720] [MIDSTREAM] - new: [....31] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2208] [MIDSTREAM] - new: [....32] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2732] [MIDSTREAM] + new: [....26] [ip4][..tcp] [..147.234.1.253][...21] -> [......192.2.1.2][.2720] [MIDSTREAM] + new: [....27] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.1.66][.2720] [MIDSTREAM] + new: [....28] [ip4][..tcp] [..147.234.1.253][..120] -> [....192.168.1.2][.2720] [MIDSTREAM] + new: [....29] [ip4][..tcp] [..147.234.1.170][43690] -> [170.170.170.170][43690] + new: [....30] [ip4][..tcp] [..147.234.1.249][.2069] -> [....192.168.1.2][.2720] [MIDSTREAM] + new: [....31] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2208] [MIDSTREAM] + new: [....32] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2732] [MIDSTREAM] detected: [....32] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2732] [Protobuf][Unknown][Network][Safe] - new: [....33] [ip4][..tcp] [..147.234.1.253][.1045] -> [....192.168.1.2][.2720] [MIDSTREAM] - new: [....34] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.65.2][.2720] [MIDSTREAM] + new: [....33] [ip4][..tcp] [..147.234.1.253][.1045] -> [....192.168.1.2][.2720] [MIDSTREAM] + new: [....34] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.65.2][.2720] [MIDSTREAM] ERROR-EVENT: Unknown L3 protocol [3/16] - new: [....35] [ip4][..tcp] [..147.234.1.253][...21] -> [.....84.168.1.2][.2720] [MIDSTREAM] - new: [....36] [ip4][..tcp] [....192.112.1.2][.2720] -> [..147.234.1.253][...21] [MIDSTREAM] - new: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [....38] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.117.1.253][...21] [MIDSTREAM] - new: [....39] [ip4][..tcp] [....192.168.1.6][.2721] -> [..147.234.1.253][58999] + new: [....35] [ip4][..tcp] [..147.234.1.253][...21] -> [.....84.168.1.2][.2720] [MIDSTREAM] + new: [....36] [ip4][..tcp] [....192.112.1.2][.2720] -> [..147.234.1.253][...21] [MIDSTREAM] + new: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [....38] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.117.1.253][...21] [MIDSTREAM] + new: [....39] [ip4][..tcp] [....192.168.1.6][.2721] -> [..147.234.1.253][58999] ERROR-EVENT: Unknown packet type [4/16] - new: [....40] [ip4][..tcp] [...37.115.0.253][58999] -> [....192.168.1.2][.2721] + new: [....40] [ip4][..tcp] [...37.115.0.253][58999] -> [....192.168.1.2][.2721] ERROR-EVENT: TCP packet smaller than expected [5/16] - new: [....41] [ip4][..tcp] [....192.168.1.2][.2721] -> [..147.234.1.253][58999] [MIDSTREAM] - new: [....42] [ip4][..tcp] [..147.234.1.253][58999] -> [....192.232.1.2][.2721] [MIDSTREAM] - new: [....43] [ip4][..tcp] [.....37.115.0.2][.2639] -> [..147.234.1.253][...21] [MIDSTREAM] + new: [....41] [ip4][..tcp] [....192.168.1.2][.2721] -> [..147.234.1.253][58999] [MIDSTREAM] + new: [....42] [ip4][..tcp] [..147.234.1.253][58999] -> [....192.232.1.2][.2721] [MIDSTREAM] + new: [....43] [ip4][..tcp] [.....37.115.0.2][.2639] -> [..147.234.1.253][...21] [MIDSTREAM] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] update: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] - new: [....44] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.136.1.1][...53] + update: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] + new: [....44] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.136.1.1][...53] detected: [....44] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.136.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] + new: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] detected: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic @@ -112,7 +112,7 @@ update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol - update: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] + update: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] update: [....11] [ip4][..udp] [...192.168.1.52][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....3] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -124,20 +124,20 @@ update: [....10] [ip4][..udp] [....192.168.1.2][.2714] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....13] [ip4][..udp] [....192.168.1.2][.2715] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] - update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] + update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] + update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] detection-update: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] RISK: Unidirectional Traffic - new: [....46] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2723] + new: [....46] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2723] detected: [....46] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2723] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-adds.arpa] - new: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] - new: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] + new: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] + new: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] detected: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp._s?.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected detection-update: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] - new: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] + new: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] + new: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] detected: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] [DNS][Unknown][Network][Acceptable][_zip._udp.sip.cybercity.dk] update: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -145,18 +145,18 @@ RISK: Malformed Packet update: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - update: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] - new: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] + update: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] + new: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] detected: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] + new: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] detected: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] idle: [.....4] [ip4][..udp] [....192.168.1.2][.2712] -> [...192.37.115.0][...53] [DNS][Unknown][Network][Acceptable] guessed: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][] - idle: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] + idle: [.....2] [ip4][..udp] [....217.168.1.2][..137] -> [..192.168.1.255][..137] idle: [.....3] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] + update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol @@ -177,9 +177,9 @@ update: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] - update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] - update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] + update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] + update: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] + update: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] idle: [....17] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.251][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol idle: [....16] [ip4][..udp] [..208.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -195,20 +195,20 @@ idle: [....14] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] not-detected: [....41] [ip4][..tcp] [....192.168.1.2][.2721] -> [..147.234.1.253][58999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - end: [....41] [ip4][..tcp] [....192.168.1.2][.2721] -> [..147.234.1.253][58999] + end: [....41] [ip4][..tcp] [....192.168.1.2][.2721] -> [..147.234.1.253][58999] guessed: [....23] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.234.1.253][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol - end: [....23] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.234.1.253][...21] + end: [....23] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.234.1.253][...21] not-detected: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] + idle: [.....9] [ip4][..udp] [....192.168.1.2][.2597] -> [....192.168.1.1][29440] not-detected: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] + idle: [.....5] [ip4][..udp] [....192.168.1.2][.2712] -> [....192.168.1.1][49973] not-detected: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] - update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] + idle: [....15] [ip4][..udp] [....192.168.1.1][.9587] -> [....192.168.1.2][..156] + update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....22] [ip4][..udp] [....192.168.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -222,13 +222,13 @@ update: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] [DNS][Unknown][Network][Acceptable] update: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] [DNS][Unknown][Network][Acceptable] - update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] + update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] update: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] + new: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] detected: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_dom] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] + new: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] detected: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] detection-update: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] @@ -237,7 +237,7 @@ RISK: Malformed Packet idle: [....21] [ip4][..udp] [....192.114.1.2][.2719] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] + update: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....44] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.136.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -249,49 +249,49 @@ update: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] [DNS][Unknown][Network][Acceptable] update: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] [DNS][Unknown][Network][Acceptable] - update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] - new: [....56] [ip4][..udp] [....192.168.1.2][.2733] -> [..192.168.115.1][...53] + update: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] + new: [....56] [ip4][..udp] [....192.168.1.2][.2733] -> [..192.168.115.1][...53] detected: [....56] [ip4][..udp] [....192.168.1.2][.2733] -> [..192.168.115.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arqa] - new: [....57] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] + new: [....57] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] detected: [....57] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] - new: [....59] [ip4][..udp] [....192.168.1.2][.2734] -> [....192.168.1.1][...53] + new: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] + new: [....59] [ip4][..udp] [....192.168.1.2][.2734] -> [....192.168.1.1][...53] detected: [....59] [ip4][..udp] [....192.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....60] [ip4][..udp] [....172.168.1.2][.2734] -> [....192.168.1.1][...53] + new: [....60] [ip4][..udp] [....172.168.1.2][.2734] -> [....192.168.1.1][...53] detected: [....60] [ip4][..udp] [....172.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Azure][Network][Acceptable][_sip._udp.sip.cybercity.dk] idle: [....44] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.136.1.1][...53] [DNS][Unknown][Network][Acceptable] detection-update: [....59] [ip4][..udp] [....192.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyberxity.dk] RISK: Unidirectional Traffic detection-update: [....59] [ip4][..udp] [....192.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] + new: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] detected: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-adds.arpa] - new: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] + new: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] detected: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] not-detected: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] + idle: [....47] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][.9587] idle: [....45] [ip4][..udp] [....192.168.1.2][.2722] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [....46] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2723] [DNS][Unknown][Network][Acceptable] guessed: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] [NetBIOS][Unknown][System][Acceptable][] - idle: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] + idle: [....49] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][25481] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] + new: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] idle: [....50] [ip4][..udp] [....192.168.1.2][.2724] -> [...192.168.17.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....48] [ip4][..udp] [....192.168.1.2][.2724] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] + new: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] detected: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] + new: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] detected: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.dybercity.dk] ERROR-EVENT: Unknown packet type [1/16] - new: [....66] [ip4][..udp] [....192.168.1.2][.2736] -> [...192.168.1.17][...53] + new: [....66] [ip4][..udp] [....192.168.1.2][.2736] -> [...192.168.1.17][...53] detected: [....66] [ip4][..udp] [....192.168.1.2][.2736] -> [...192.168.1.17][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic @@ -299,10 +299,10 @@ RISK: Malformed Packet, Unidirectional Traffic idle: [....51] [ip4][..udp] [....192.168.1.2][.2725] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....52] [ip4][..udp] [...192.168.1.46][...53] -> [....192.168.1.2][.2726] [DNS][Unknown][Network][Acceptable] - update: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] + update: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] + update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....60] [ip4][..udp] [....172.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Azure][Network][Acceptable] update: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -313,23 +313,23 @@ RISK: Unidirectional Traffic update: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] [DNS][Unknown][Network][Acceptable] - new: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] + new: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] detected: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] + new: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] detected: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [....69] [ip4][..udp] [....192.168.1.2][.2738] -> [...192.168.84.1][...53] + new: [....69] [ip4][..udp] [....192.168.1.2][.2738] -> [...192.168.84.1][...53] detected: [....69] [ip4][..udp] [....192.168.1.2][.2738] -> [...192.168.84.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercitu.dk] - new: [....70] [ip4][..udp] [....192.168.1.2][.2738] -> [....192.168.1.1][...53] + new: [....70] [ip4][..udp] [....192.168.1.2][.2738] -> [....192.168.1.1][...53] detected: [....70] [ip4][..udp] [....192.168.1.2][.2738] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....70] [ip4][..udp] [....192.168.1.2][.2738] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] + new: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] detected: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] + new: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] detected: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] + new: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] detected: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyberci_s] RISK: Non-Printable/Invalid Chars Detected detection-update: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] @@ -337,27 +337,27 @@ ERROR-EVENT: Unknown packet type [1/16] detection-update: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] - new: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] + new: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] + new: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] detected: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] + new: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] detected: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] update: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic update: [....66] [ip4][..udp] [....192.168.1.2][.2736] -> [...192.168.1.17][...53] [DNS][Unknown][Network][Acceptable] - new: [....77] [ip4][..udp] [....192.168.1.2][.2742] -> [....192.168.1.1][...53] + new: [....77] [ip4][..udp] [....192.168.1.2][.2742] -> [....192.168.1.1][...53] detected: [....77] [ip4][..udp] [....192.168.1.2][.2742] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] + new: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] detection-update: [....77] [ip4][..udp] [....192.168.1.2][.2742] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic detection-update: [....77] [ip4][..udp] [....192.168.1.2][.2742] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - update: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] + update: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] update: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] + update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....60] [ip4][..udp] [....172.168.1.2][.2734] -> [....192.168.1.1][...53] [DNS][Azure][Network][Acceptable] update: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -373,41 +373,41 @@ RISK: Unidirectional Traffic update: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] [DNS][Unknown][Network][Acceptable] - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] ERROR-EVENT: Unknown packet type [1/16] - new: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] + new: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] detected: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] + update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] update: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] + new: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] detected: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] + new: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] detected: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] not-detected: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] + idle: [....55] [ip4][..udp] [....192.168.1.2][43690] -> [192.170.170.170][43690] idle: [....53] [ip4][..udp] [..192.168.1.202][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....54] [ip4][..udp] [....192.168.1.2][.2732] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] + update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] update: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic update: [....66] [ip4][..udp] [....192.168.1.2][.2736] -> [...192.168.1.17][...53] [DNS][Unknown][Network][Acceptable] update: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] [DNS][Unknown][Network][Acceptable] - new: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] - new: [....83] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2745] + new: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] + new: [....83] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2745] detected: [....83] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2745] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....84] [ip4][..udp] [....192.168.1.2][.2746] -> [....192.168.1.1][...53] + new: [....84] [ip4][..udp] [....192.168.1.2][.2746] -> [....192.168.1.1][...53] detected: [....84] [ip4][..udp] [....192.168.1.2][.2746] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] - new: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] - new: [....86] [ip4][..udp] [...192.168.1.34][.2746] -> [....192.168.1.1][...53] + new: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] + new: [....86] [ip4][..udp] [...192.168.1.34][.2746] -> [....192.168.1.1][...53] detected: [....86] [ip4][..udp] [...192.168.1.34][.2746] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp._s?p.brvjula.net] RISK: Non-Printable/Invalid Chars Detected detection-update: [....84] [ip4][..udp] [....192.168.1.2][.2746] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] @@ -419,7 +419,7 @@ RISK: Unidirectional Traffic update: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] + update: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -430,16 +430,16 @@ RISK: Unidirectional Traffic update: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] [DNS][Unknown][Network][Acceptable] - update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] - new: [....87] [ip4][..udp] [....192.168.1.2][.2747] -> [.....67.168.1.1][...53] + update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] + new: [....87] [ip4][..udp] [....192.168.1.2][.2747] -> [.....67.168.1.1][...53] detected: [....87] [ip4][..udp] [....192.168.1.2][.2747] -> [.....67.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....88] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2747] + new: [....88] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2747] detected: [....88] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2747] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [....89] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.4932] + new: [....89] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.4932] detected: [....89] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.4932] [SIP][Unknown][VoIP][Acceptable] - new: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] + new: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] detected: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] + new: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] detection-update: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic detected: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -449,31 +449,31 @@ detection-update: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic guessed: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] [NetBIOS][Unknown][System][Acceptable][] - idle: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] + idle: [....63] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..169] idle: [....61] [ip4][..udp] [....200.168.1.2][.2735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....62] [ip4][..udp] [....253.168.1.1][...53] -> [....192.168.1.2][.2735] [DNS][Unknown][Network][Acceptable] update: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - new: [....92] [ip4][..udp] [....192.168.1.2][.2749] -> [....192.168.1.1][...53] + new: [....92] [ip4][..udp] [....192.168.1.2][.2749] -> [....192.168.1.1][...53] detected: [....92] [ip4][..udp] [....192.168.1.2][.2749] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [....93] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] + new: [....93] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] detected: [....93] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] ERROR-EVENT: Unknown packet type [1/16] - new: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] + new: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] detected: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] detection-update: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] RISK: Unidirectional Traffic - new: [....95] [ip4][..udp] [....192.168.1.2][10942] -> [....192.168.1.1][...53] + new: [....95] [ip4][..udp] [....192.168.1.2][10942] -> [....192.168.1.1][...53] detected: [....95] [ip4][..udp] [....192.168.1.2][10942] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] detection-update: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.voip.brujula.net] RISK: Malformed Packet, Unidirectional Traffic detection-update: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.vo_s] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] + update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] update: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....64] [ip4][..udp] [....192.168.1.2][.2736] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic @@ -482,27 +482,27 @@ update: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] [DNS][Unknown][Network][Acceptable] update: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [....96] [ip4][..udp] [...192.168.1.18][.2751] -> [....192.168.1.1][...53] + new: [....96] [ip4][..udp] [...192.168.1.18][.2751] -> [....192.168.1.1][...53] detected: [....96] [ip4][..udp] [...192.168.1.18][.2751] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [....97] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2751] + new: [....97] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2751] detected: [....97] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2751] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [....98] [ip4][..udp] [....192.168.1.2][.2752] -> [....192.168.1.1][...53] + new: [....98] [ip4][..udp] [....192.168.1.2][.2752] -> [....192.168.1.1][...53] detected: [....98] [ip4][..udp] [....192.168.1.2][.2752] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [....98] [ip4][..udp] [....192.168.1.2][.2752] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] + new: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] detected: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] + new: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] detected: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] [SIP][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port - new: [...101] [ip4][..udp] [....192.168.1.2][.2752] -> [....102.168.1.1][...53] + new: [...101] [ip4][..udp] [....192.168.1.2][.2752] -> [....102.168.1.1][...53] detected: [...101] [ip4][..udp] [....192.168.1.2][.2752] -> [....102.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] + new: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] detected: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] + update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] update: [....68] [ip4][..udp] [....192.168.1.2][20932] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -518,13 +518,13 @@ RISK: Unidirectional Traffic update: [....86] [ip4][..udp] [...192.168.1.34][.2746] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] - new: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] + update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] + new: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] detected: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [...104] [ip4][..udp] [....192.168.1.2][.2753] -> [....192.168.1.1][...53] + new: [...104] [ip4][..udp] [....192.168.1.2][.2753] -> [....192.168.1.1][...53] detected: [...104] [ip4][..udp] [....192.168.1.2][.2753] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.tn-addr.arpa] detection-update: [...104] [ip4][..udp] [....192.168.1.2][.2753] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.527.in-addr.arpa] - new: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] + new: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] update: [....87] [ip4][..udp] [....192.168.1.2][.2747] -> [.....67.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....88] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2747] [DNS][Unknown][Network][Acceptable] update: [....90] [ip4][..udp] [....192.168.1.2][.2748] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -533,8 +533,8 @@ update: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic ERROR-EVENT: Unknown packet type [1/16] - new: [...106] [ip4][..udp] [....192.168.1.2][.2754] -> [....192.168.1.1][...53] - new: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] + new: [...106] [ip4][..udp] [....192.168.1.2][.2754] -> [....192.168.1.1][...53] + new: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] detected: [...106] [ip4][..udp] [....192.168.1.2][.2754] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyberciwy.dk] RISK: Unidirectional Traffic idle: [....65] [ip4][..udp] [....192.168.1.2][.2684] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -551,7 +551,7 @@ update: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....95] [ip4][..udp] [....192.168.1.2][10942] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - new: [...108] [ip4][..udp] [.....14.168.1.2][.2754] -> [....192.168.1.1][...53] + new: [...108] [ip4][..udp] [.....14.168.1.2][.2754] -> [....192.168.1.1][...53] detected: [...108] [ip4][..udp] [.....14.168.1.2][.2754] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...106] [ip4][..udp] [....192.168.1.2][.2754] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic @@ -559,12 +559,12 @@ idle: [....67] [ip4][..udp] [....192.168.1.2][.2737] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....69] [ip4][..udp] [....192.168.1.2][.2738] -> [...192.168.84.1][...53] [DNS][Unknown][Network][Acceptable] update: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] + update: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] update: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] [DNS][Unknown][Network][Acceptable] update: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] + new: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] detected: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] detection-update: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] idle: [....71] [ip4][..udp] [....192.168.1.2][.2716] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -578,21 +578,21 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 241 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 63 / 109|skipped: 0|!detected: 6|guessed: 4|detection-updates: 34|updates: 178] - new: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] + new: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] detected: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_?ip._udp.sip.cybercit?.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic detection-update: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic guessed: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] [NetBIOS][Unknown][System][Acceptable][] - idle: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] + idle: [....74] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][.8329] idle: [....72] [ip4][..udp] [....192.168.1.2][.2739] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....73] [ip4][..udp] [....192.168.1.2][.2740] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] + update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] update: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] + update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] [SIP][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port @@ -614,10 +614,10 @@ update: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic update: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] update: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] - new: [...111] [ip4][..udp] [....192.168.1.2][.2757] -> [....192.168.1.1][...53] + update: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] + new: [...111] [ip4][..udp] [....192.168.1.2][.2757] -> [....192.168.1.1][...53] detected: [...111] [ip4][..udp] [....192.168.1.2][.2757] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.v.0.127.in-addr.arpa] detection-update: [...111] [ip4][..udp] [....192.168.1.2][.2757] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected @@ -633,7 +633,7 @@ [ENTROPIES...: 4.3,4.2,4.2,4.3,4.2,4.2,4.2,4.3,4.3,4.3,4.3,4.3,4.3,4.2,4.2,4.2,4.3,4.2,4.2,4.3,4.2,4.2,4.2,4.3,4.2,4.2,4.3,4.3,4.3,4.3,4.2,3.2] idle: [....76] [ip4][..udp] [..192.168.130.1][...53] -> [....192.168.1.2][.2741] [DNS][Unknown][Network][Acceptable] idle: [....75] [ip4][..udp] [....192.168.1.2][.2741] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] + update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] update: [....93] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] [DNS][Unknown][Network][Acceptable] update: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....92] [ip4][..udp] [....192.168.1.2][.2749] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -643,13 +643,13 @@ update: [....95] [ip4][..udp] [....192.168.1.2][10942] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...106] [ip4][..udp] [....192.168.1.2][.2754] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] + new: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] detected: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] + new: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] detected: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._tdp.sip.cybercity.dk] - new: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] - new: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] + new: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] + new: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] detected: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.gybercity.dk] RISK: Unidirectional Traffic @@ -657,7 +657,7 @@ RISK: Unidirectional Traffic not-detected: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] + idle: [....78] [ip4][..udp] [....192.168.1.2][.2730] -> [....192.168.1.1][43690] update: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...108] [ip4][..udp] [.....14.168.1.2][.2754] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -669,16 +669,16 @@ update: [....98] [ip4][..udp] [....192.168.1.2][.2752] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - new: [...116] [ip4][..udp] [....192.168.1.2][.2759] -> [....192.168.1.1][...53] + new: [...116] [ip4][..udp] [....192.168.1.2][.2759] -> [....192.168.1.1][...53] detected: [...116] [ip4][..udp] [....192.168.1.2][.2759] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.sn-addr.arpa] - new: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + new: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] idle: [....79] [ip4][..udp] [....192.168.1.2][.2743] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] + update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] update: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] - new: [...119] [ip4][..udp] [....192.168.1.2][.2760] -> [....192.168.1.1][...53] + new: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] + new: [...119] [ip4][..udp] [....192.168.1.2][.2760] -> [....192.168.1.1][...53] detected: [...119] [ip4][..udp] [....192.168.1.2][.2760] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip.eudp.sip.cybercity.dk] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] @@ -688,10 +688,10 @@ idle: [....81] [ip4][..udp] [....192.168.1.2][...88] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....80] [ip4][..udp] [....192.168.1.2][.2744] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] + update: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] update: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] + update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] [SIP][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port @@ -722,9 +722,9 @@ RISK: Unidirectional Traffic update: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] + new: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] detected: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] + new: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] detected: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Unidirectional Traffic @@ -734,25 +734,25 @@ ERROR-EVENT: Unknown L3 protocol [2/16] not-detected: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] + idle: [....82] [ip4][..udp] [..192.168.1.170][43690] -> [170.170.170.170][43690] idle: [....83] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2745] [DNS][Unknown][Network][Acceptable] idle: [....86] [ip4][..udp] [...192.168.1.34][.2746] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] + update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] update: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [3/16] - new: [...122] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2763] + new: [...122] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2763] detected: [...122] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2763] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] RISK: Malformed Packet ERROR-EVENT: Unknown packet type [4/16] - new: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] + new: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] detected: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] ERROR-EVENT: Unknown packet type [5/16] detection-update: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - new: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] + new: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] detection-update: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.s?p.cibercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic detection-update: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] @@ -777,19 +777,19 @@ update: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [...116] [ip4][..udp] [....192.168.1.2][.2759] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - new: [...125] [ip4][..udp] [..192.168.1.110][.2765] -> [....192.168.1.1][...53] + new: [...125] [ip4][..udp] [..192.168.1.110][.2765] -> [....192.168.1.1][...53] detected: [...125] [ip4][..udp] [..192.168.1.110][.2765] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...126] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2765] + new: [...126] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2765] detected: [...126] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2765] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...127] [ip4][..udp] [..192.168.1.172][.2766] -> [....192.168.1.1][...53] + new: [...127] [ip4][..udp] [..192.168.1.172][.2766] -> [....192.168.1.1][...53] detected: [...127] [ip4][..udp] [..192.168.1.172][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] + new: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] detected: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybe0city.dk] RISK: Unidirectional Traffic ERROR-EVENT: Unknown packet type [1/16] - new: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] + new: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] detected: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] idle: [....93] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2733] [DNS][Unknown][Network][Acceptable] idle: [....92] [ip4][..udp] [....192.168.1.2][.2749] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -798,9 +798,9 @@ idle: [....94] [ip4][..udp] [....192.168.1.2][.2750] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] + update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] + update: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...100] [ip4][..udp] [....192.168.1.2][.4901] -> [..200.68.120.81][29440] [SIP][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port @@ -817,15 +817,15 @@ RISK: Unidirectional Traffic update: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] + new: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] detected: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] + new: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] detected: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] + new: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] detected: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] + new: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] detection-update: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Unidirectional Traffic idle: [....99] [ip4][..udp] [....192.168.1.2][.4292] -> [..200.68.37.115][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -842,33 +842,33 @@ idle: [...102] [ip4][..udp] [.....192.98.1.2][.2752] -> [.....25.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] + update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] update: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic update: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] - new: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] + update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] + new: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] detected: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] + new: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] guessed: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] + idle: [...105] [ip4][..udp] [.....192.86.1.2][.5060] -> [..200.68.120.99][.5060] idle: [...104] [ip4][..udp] [....192.168.1.2][.2753] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...103] [ip4][..udp] [....192.169.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] + update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] update: [...122] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2763] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Error Code, Unidirectional Traffic ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] - new: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] - new: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] + new: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] + new: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] detected: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - new: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] + new: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] detected: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_doma] ERROR-EVENT: Unknown packet type [4/16] detection-update: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] @@ -878,7 +878,7 @@ RISK: Unidirectional Traffic idle: [....91] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] + update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -898,38 +898,38 @@ update: [...127] [ip4][..udp] [..192.168.1.172][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [...139] [ip4][..udp] [...192.168.1.57][.2771] -> [....192.168.1.1][...53] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [...139] [ip4][..udp] [...192.168.1.57][.2771] -> [....192.168.1.1][...53] detected: [...139] [ip4][..udp] [...192.168.1.57][.2771] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] - new: [...140] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2771] + new: [...140] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2771] detected: [...140] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2771] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...141] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] + new: [...141] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] detected: [...141] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][d002465] RISK: Unsafe Protocol idle: [...109] [ip4][..udp] [....192.168.1.2][.2755] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] + update: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] update: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic - new: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] + new: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] detected: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected detection-update: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic detection-update: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] + new: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] detected: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic idle: [...110] [ip4][..udp] [....192.168.1.2][.2756] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] - update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] + update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] + update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] update: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] + update: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] update: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic @@ -940,8 +940,8 @@ update: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] - new: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] + update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] + new: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] detected: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.il-addr.arpa] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] idle: [...112] [ip4][..udp] [....192.168.1.2][.2640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -949,10 +949,10 @@ idle: [...111] [ip4][..udp] [....192.168.1.2][.2757] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected idle: [...113] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] update: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] - update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] + update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] + update: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -969,20 +969,20 @@ RISK: Unidirectional Traffic update: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic - new: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] + new: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] detected: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet detection-update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Unidirectional Traffic detection-update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...146] [ip4][..udp] [....192.168.9.2][.2774] -> [....192.168.1.1][...53] + new: [...146] [ip4][..udp] [....192.168.9.2][.2774] -> [....192.168.1.1][...53] detected: [...146] [ip4][..udp] [....192.168.9.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic guessed: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Unidirectional Traffic - idle: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] + idle: [...114] [ip4][..udp] [.192.168.37.115][.2758] -> [....128.168.1.1][...53] idle: [...115] [ip4][..udp] [....192.168.1.2][.2758] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [...141] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -992,7 +992,7 @@ RISK: Malformed Packet, Unidirectional Traffic update: [...139] [ip4][..udp] [...192.168.1.57][.2771] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...140] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2771] [DNS][Unknown][Network][Acceptable] - new: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] + new: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] detected: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-aqd?.arpa] RISK: Non-Printable/Invalid Chars Detected detection-update: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] @@ -1000,7 +1000,7 @@ idle: [...116] [ip4][..udp] [....192.168.1.2][.2759] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...142] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...148] [ip4][..udp] [....192.168.1.2][.2776] -> [....192.168.1.1][...53] + new: [...148] [ip4][..udp] [....192.168.1.2][.2776] -> [....192.168.1.1][...53] detected: [...148] [ip4][..udp] [....192.168.1.2][.2776] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...148] [ip4][..udp] [....192.168.1.2][.2776] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic @@ -1009,11 +1009,11 @@ RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic guessed: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Unidirectional Traffic - idle: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] + idle: [...118] [ip4][..udp] [.....192.22.1.2][.2760] -> [....192.168.1.1][...53] idle: [...119] [ip4][..udp] [....192.168.1.2][.2760] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] - update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] + update: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] + update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] update: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic @@ -1025,14 +1025,14 @@ update: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] - new: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] - new: [...150] [ip4][..udp] [...192.168.33.2][.2782] -> [....192.168.1.1][...53] + update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] + new: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] + new: [...150] [ip4][..udp] [...192.168.33.2][.2782] -> [....192.168.1.1][...53] detected: [...150] [ip4][..udp] [...192.168.33.2][.2782] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...151] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2782] + new: [...151] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2782] detected: [...151] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2782] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] + new: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] ERROR-EVENT: Unknown packet type [1/16] idle: [...120] [ip4][..udp] [....192.168.1.2][.2761] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...121] [ip4][..udp] [....192.168.1.2][.2762] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1051,18 +1051,18 @@ RISK: Malformed Packet, Unidirectional Traffic update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] + new: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] detected: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic ERROR-EVENT: Unknown packet type [1/16] - new: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] + new: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] detected: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Unidirectional Traffic not-detected: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] + idle: [...124] [ip4][..udp] [....192.168.1.2][43690] -> [170.170.170.170][43690] idle: [...122] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2763] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet idle: [...123] [ip4][..udp] [....192.168.1.2][.2764] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1079,10 +1079,10 @@ update: [...146] [ip4][..udp] [....192.168.9.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [...155] [ip4][..udp] [....192.168.1.2][.2784] -> [....192.168.1.1][...53] + new: [...155] [ip4][..udp] [....192.168.1.2][.2784] -> [....192.168.1.1][...53] detected: [...155] [ip4][..udp] [....192.168.1.2][.2784] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...156] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.5.2][.2784] + new: [...156] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.5.2][.2784] detected: [...156] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.5.2][.2784] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.aspa] ERROR-EVENT: Unknown packet type [1/16] idle: [...129] [ip4][..udp] [....192.168.1.2][14798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1092,29 +1092,29 @@ idle: [...128] [ip4][..udp] [....192.168.1.2][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...127] [ip4][..udp] [..192.168.1.172][.2766] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] + update: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] update: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...148] [ip4][..udp] [....192.168.1.2][.2776] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] - update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] - new: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] - new: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] + update: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] + update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] + new: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] + new: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] detected: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] - new: [...160] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] + new: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] + new: [...160] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] detected: [...160] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybevcity.dk] not-detected: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] + idle: [....58] [ip4][..120] [....192.168.1.2] -> [..212.242.33.35] idle: [...130] [ip4][..udp] [....192.168.1.2][.2767] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] + update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] update: [...137] [ip4][..udp] [....192.168.1.2][.2770] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1122,14 +1122,14 @@ update: [...150] [ip4][..udp] [...192.168.33.2][.2782] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...151] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2782] [DNS][Unknown][Network][Acceptable] - new: [...161] [ip4][..udp] [....192.168.1.2][.2786] -> [....192.168.1.3][...53] + new: [...161] [ip4][..udp] [....192.168.1.2][.2786] -> [....192.168.1.3][...53] detected: [...161] [ip4][..udp] [....192.168.1.2][.2786] -> [....192.168.1.3][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-ad?r.arpa] RISK: Non-Printable/Invalid Chars Detected ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] - new: [...163] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.3.1][...53] + new: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] + new: [...163] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.3.1][...53] detected: [...163] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.3.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] + new: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] detected: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected detection-update: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] @@ -1140,22 +1140,22 @@ RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic not-detected: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] + idle: [...133] [ip4][..udp] [.....94.168.1.2][.2768] -> [....192.168.1.1][....4] idle: [...132] [ip4][..udp] [....192.168.1.2][35536] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...131] [ip4][..udp] [....192.168.1.2][.2768] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic idle: [...134] [ip4][..udp] [....192.168.1.2][.2769] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] not-detected: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] - update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] + idle: [...135] [ip4][..udp] [....192.168.1.1][..117] -> [....192.168.1.2][.2769] + update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] update: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [...165] [ip4][..udp] [....192.168.1.2][.2788] -> [....192.168.1.1][...53] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [...165] [ip4][..udp] [....192.168.1.2][.2788] -> [....192.168.1.1][...53] detected: [...165] [ip4][..udp] [....192.168.1.2][.2788] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] + new: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] analyse: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.026| 279.042| 51.474| 59.389| 3527099352.613| 4.200] @@ -1168,7 +1168,7 @@ [ENTROPIES...: 5.8,5.8,5.8,5.8,5.8,1.5,3.4,2.9,5.8,4.1,5.8,3.2,4.1,4.1,4.1,4.1,4.1,4.1,4.1,4.1,5.8,5.8,5.7,4.1,1.5,5.8,4.6,4.1,4.0,4.1,3.3,2.3] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...167] [ip4][..udp] [....192.168.1.2][.2789] -> [....192.168.1.1][...53] + new: [...167] [ip4][..udp] [....192.168.1.2][.2789] -> [....192.168.1.1][...53] detected: [...167] [ip4][..udp] [....192.168.1.2][.2789] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...167] [ip4][..udp] [....192.168.1.2][.2789] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Unidirectional Traffic @@ -1188,20 +1188,20 @@ update: [...155] [ip4][..udp] [....192.168.1.2][.2784] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...156] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.5.2][.2784] [DNS][Unknown][Network][Acceptable] - new: [...168] [ip4][..udp] [....192.168.1.2][.2790] -> [....192.168.1.1][...53] + new: [...168] [ip4][..udp] [....192.168.1.2][.2790] -> [....192.168.1.1][...53] detected: [...168] [ip4][..udp] [....192.168.1.2][.2790] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] + new: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] detected: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [...170] [ip4][..udp] [...192.168.79.2][.2791] -> [....192.168.1.1][...53] + new: [...170] [ip4][..udp] [...192.168.79.2][.2791] -> [....192.168.1.1][...53] detected: [...170] [ip4][..udp] [...192.168.79.2][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...171] [ip4][..udp] [...192.168.1.53][.2791] -> [....192.168.1.1][...53] + new: [...171] [ip4][..udp] [...192.168.1.53][.2791] -> [....192.168.1.1][...53] detected: [...171] [ip4][..udp] [...192.168.1.53][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] + new: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] detected: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] - new: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] - new: [...174] [ip4][..udp] [....192.168.1.2][.2791] -> [....192.168.1.1][...53] + new: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + new: [...174] [ip4][..udp] [....192.168.1.2][.2791] -> [....192.168.1.1][...53] detected: [...174] [ip4][..udp] [....192.168.1.2][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] idle: [...138] [ip4][..udp] [....192.168.1.2][..137] -> [..120.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [...141] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -1212,7 +1212,7 @@ idle: [...139] [ip4][..udp] [...192.168.1.57][.2771] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] + update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] update: [...143] [ip4][..udp] [....192.168.1.2][.2772] -> [....192.184.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...144] [ip4][..udp] [....192.168.1.2][.2773] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1224,19 +1224,19 @@ update: [...151] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2782] [DNS][Unknown][Network][Acceptable] update: [...160] [ip4][..udp] [....192.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] - new: [...175] [ip4][..udp] [....192.168.1.2][.2791] -> [...192.168.67.1][...53] + update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] + new: [...175] [ip4][..udp] [....192.168.1.2][.2791] -> [...192.168.67.1][...53] detected: [...175] [ip4][..udp] [....192.168.1.2][.2791] -> [...192.168.67.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] + new: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] detected: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] + new: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] detected: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-a?dr.arpa] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] - update: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] - update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] + update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + update: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] + update: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] update: [...161] [ip4][..udp] [....192.168.1.2][.2786] -> [....192.168.1.3][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...163] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.3.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1249,9 +1249,9 @@ idle: [...146] [ip4][..udp] [....192.168.9.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] + update: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] update: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic @@ -1277,14 +1277,14 @@ update: [...174] [ip4][..udp] [....192.168.1.2][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...171] [ip4][..udp] [...192.168.1.53][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] - new: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] + update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] + new: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] detected: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] - new: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] + new: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] detected: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][5ci_dombin] guessed: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] + idle: [...152] [ip4][..udp] [....192.168.1.6][.5060] -> [..212.242.33.35][.5060] idle: [...145] [ip4][..udp] [....192.168.1.2][.2774] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic idle: [...147] [ip4][..udp] [....192.168.1.2][.2775] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1295,10 +1295,10 @@ idle: [...150] [ip4][..udp] [...192.168.33.2][.2782] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] - update: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] + update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] + update: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -1326,15 +1326,15 @@ update: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] - update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] + update: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] + update: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] not-detected: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] + idle: [...162] [ip4][..udp] [..212.242.33.35][.9587] -> [....192.168.1.2][..196] not-detected: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] + idle: [....85] [ip4][..240] [....192.168.1.2] -> [....192.168.1.1] idle: [...154] [ip4][..udp] [......0.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...153] [ip4][..udp] [....192.168.1.2][.2783] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic @@ -1347,15 +1347,15 @@ idle: [...163] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.3.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...158] [ip4][..udp] [....200.168.1.2][.2785] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] guessed: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] [NetBIOS][Unknown][System][Acceptable][] - idle: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] + idle: [...159] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][35721] update: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] - update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] - update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] + update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] + update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] + update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + update: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] update: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1372,17 +1372,17 @@ update: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [...180] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..138] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [...180] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..138] detected: [...180] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][lab111] RISK: Unsafe Protocol - new: [...181] [ip4][..udp] [.192.184.189.41][..137] -> [..192.168.1.255][..137] + new: [...181] [ip4][..udp] [.192.184.189.41][..137] -> [..192.168.1.255][..137] detected: [...181] [ip4][..udp] [.192.184.189.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workg] - new: [...182] [ip4][..udp] [...192.168.1.41][..137] -> [..192.168.1.255][..137] + new: [...182] [ip4][..udp] [...192.168.1.41][..137] -> [..192.168.1.255][..137] detected: [...182] [ip4][..udp] [...192.168.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] - new: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] + new: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] detected: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] - new: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] + new: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] detected: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] idle: [...164] [ip4][..udp] [....192.168.1.2][.2787] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1390,19 +1390,19 @@ idle: [...165] [ip4][..udp] [....192.168.1.2][.2788] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...167] [ip4][..udp] [....192.168.1.2][.2789] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic - update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] - new: [...185] [ip4][..udp] [...192.168.1.41][..137] -> [.192.168.37.115][..137] + update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + new: [...185] [ip4][..udp] [...192.168.1.41][..137] -> [.192.168.37.115][..137] detected: [...185] [ip4][..udp] [...192.168.1.41][..137] -> [.192.168.37.115][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] idle: [...169] [ip4][..udp] [..212.242.33.35][.5060] -> [...192.37.115.0][.5060] [SIP][Unknown][VoIP][Acceptable] idle: [...168] [ip4][..udp] [....192.168.1.2][.2790] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...171] [ip4][..udp] [...192.168.1.53][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...170] [ip4][..udp] [...192.168.79.2][.2791] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - new: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] - new: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] + new: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] + new: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] detected: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] not-detected: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + idle: [...173] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] idle: [...172] [ip4][..udp] [....192.168.1.2][..137] -> [..192.194.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [...175] [ip4][..udp] [....192.168.1.2][.2791] -> [...192.168.67.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected @@ -1414,16 +1414,16 @@ update: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] + new: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] detected: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] [DHCP][Unknown][Network][Acceptable][d002465] - new: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] + new: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] idle: [....12] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] idle: [...176] [ip4][..udp] [....192.168.1.2][.2792] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...177] [ip4][..udp] [....192.168.1.1][...53] -> [....240.168.1.2][.2792] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected not-detected: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] + idle: [...107] [ip4][..118] [....192.168.1.2] -> [..200.68.120.81] update: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...181] [ip4][..udp] [.192.184.189.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -1435,21 +1435,21 @@ update: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] [NetBIOS][Unknown][System][Acceptable] update: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] + update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] DAEMON-EVENT: [Processed: 409 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 40 / 189|skipped: 0|!detected: 16|guessed: 10|detection-updates: 65|updates: 489] - new: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] + new: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] detected: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][re-.sippstar.com] detection-update: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][reg.sip?star.com] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] detection-update: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][reg.sippstar.com] RISK: Non-Printable/Invalid Chars Detected - new: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] + new: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] detected: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] idle: [...178] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.112][..137] [NetBIOS][Unknown][System][Acceptable] idle: [...179] [ip4][..udp] [....192.136.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] + update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] update: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] [DHCP][Unknown][Network][Acceptable] update: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -1458,10 +1458,10 @@ update: [...182] [ip4][..udp] [...192.168.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...180] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol - update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] - new: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] + update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] + new: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] detected: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] - new: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] + new: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] detected: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] detection-update: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] RISK: Unidirectional Traffic @@ -1470,49 +1470,49 @@ ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] detection-update: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] detection-update: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] - new: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] + new: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] detected: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.ak] detection-update: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] + new: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] detection-update: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] - new: [...196] [ip4][..udp] [....192.168.1.2][.2796] -> [..192.168.1.129][...53] + update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] + new: [...196] [ip4][..udp] [....192.168.1.2][.2796] -> [..192.168.1.129][...53] detected: [...196] [ip4][..udp] [....192.168.1.2][.2796] -> [..192.168.1.129][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...197] [ip4][..udp] [....192.168.1.2][.2797] -> [....192.168.1.1][...53] + new: [...197] [ip4][..udp] [....192.168.1.2][.2797] -> [....192.168.1.1][...53] detected: [...197] [ip4][..udp] [....192.168.1.2][.2797] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arp_] RISK: Non-Printable/Invalid Chars Detected detection-update: [...197] [ip4][..udp] [....192.168.1.2][.2797] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] RISK: Non-Printable/Invalid Chars Detected - new: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] + new: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] detected: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...199] [ip4][..udp] [....192.168.1.2][.2798] -> [....192.168.1.1][...53] + new: [...199] [ip4][..udp] [....192.168.1.2][.2798] -> [....192.168.1.1][...53] detected: [...199] [ip4][..udp] [....192.168.1.2][.2798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] - update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] - update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] + update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] + update: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] detection-update: [...199] [ip4][..udp] [....192.168.1.2][.2798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic ERROR-EVENT: Unknown packet type [2/16] - new: [...200] [ip4][..udp] [....192.168.1.2][.2799] -> [....192.168.1.1][...53] + new: [...200] [ip4][..udp] [....192.168.1.2][.2799] -> [....192.168.1.1][...53] detected: [...200] [ip4][..udp] [....192.168.1.2][.2799] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] + new: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] detected: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] + new: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] detected: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_s?p._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected detection-update: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] + new: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] ERROR-EVENT: Unknown packet type [1/16] - update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] update: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] [DHCP][Unknown][Network][Acceptable] update: [...183] [ip4][..udp] [...192.168.1.41][..137] -> [..107.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...184] [ip4][..udp] [.....115.0.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -1521,24 +1521,24 @@ update: [...182] [ip4][..udp] [...192.168.1.41][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...180] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol - update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] + update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] update: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] [DNS][Unknown][Network][Acceptable] - new: [...204] [ip4][..udp] [....192.168.1.2][.2801] -> [....192.168.1.1][...53] + new: [...204] [ip4][..udp] [....192.168.1.2][.2801] -> [....192.168.1.1][...53] detected: [...204] [ip4][..udp] [....192.168.1.2][.2801] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...204] [ip4][..udp] [....192.168.1.2][.2801] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] - new: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] + new: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] + new: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] detected: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] + new: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] detected: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] + new: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] detected: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyhercity.dk] detection-update: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic - update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] + update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1547,11 +1547,11 @@ RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [...196] [ip4][..udp] [....192.168.1.2][.2796] -> [..192.168.1.129][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet - update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] - new: [...209] [ip4][..udp] [....192.168.1.2][.2803] -> [....192.168.1.1][...53] + update: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] + new: [...209] [ip4][..udp] [....192.168.1.2][.2803] -> [....192.168.1.1][...53] detected: [...209] [ip4][..udp] [....192.168.1.2][.2803] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...209] [ip4][..udp] [....192.168.1.2][.2803] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...210] [ip4][..udp] [....192.168.1.2][.2804] -> [....192.168.1.1][...53] + new: [...210] [ip4][..udp] [....192.168.1.2][.2804] -> [....192.168.1.1][...53] detected: [...210] [ip4][..udp] [....192.168.1.2][.2804] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] ERROR-EVENT: Unknown L3 protocol [1/16] detection-update: [...210] [ip4][..udp] [....192.168.1.2][.2804] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyberc?ty.dk] @@ -1571,10 +1571,10 @@ ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] idle: [...185] [ip4][..udp] [...192.168.1.41][..137] -> [.192.168.37.115][..137] [NetBIOS][Unknown][System][Acceptable] - new: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] - new: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] + new: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] + new: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] detected: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] + new: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] detected: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sim._udp.sip.c_ber_itm.dk] RISK: Non-Printable/Invalid Chars Detected detection-update: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.c4bercity.dk] @@ -1589,10 +1589,10 @@ idle: [...187] [ip4][..udp] [....192.168.1.2][..137] -> [..200.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] not-detected: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] + idle: [...186] [ip4][..udp] [....192.168.1.2][43690] -> [192.168.170.170][43690] update: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] [DHCP][Unknown][Network][Acceptable] - update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] - update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] + update: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] + update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] update: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1601,16 +1601,16 @@ update: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic ERROR-EVENT: Unknown packet type [1/16] - new: [...214] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2807] + new: [...214] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2807] detected: [...214] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2807] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected - new: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] - new: [...216] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][...53] + new: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] + new: [...216] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][...53] detected: [...216] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...216] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic update: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] + update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1624,28 +1624,28 @@ update: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic ERROR-EVENT: Unknown packet type [2/16] - new: [...217] [ip4][..udp] [....192.168.1.2][19192] -> [....192.168.1.1][...53] + new: [...217] [ip4][..udp] [....192.168.1.2][19192] -> [....192.168.1.1][...53] detected: [...217] [ip4][..udp] [....192.168.1.2][19192] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] + new: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] detected: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] - new: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] + new: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] + new: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] detected: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] + new: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] detected: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udq.sip.mybercity.dk] detection-update: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic detection-update: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.nybercity.dk] RISK: Unidirectional Traffic - new: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] + new: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] not-detected: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] + idle: [...136] [ip4][..127] [....192.168.1.2] -> [....192.168.1.1] idle: [...188] [ip4][..udp] [....192.168.1.2][...68] -> [....192.168.1.1][...67] [DHCP][Unknown][Network][Acceptable] guessed: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] [NetBIOS][Unknown][System][Acceptable][] - idle: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] + idle: [...189] [ip4][..udp] [...192.168.1.41][..138] -> [..192.168.1.255][..394] update: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...197] [ip4][..udp] [....192.168.1.2][.2797] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected @@ -1654,16 +1654,16 @@ update: [...209] [ip4][..udp] [....192.168.1.2][.2803] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...210] [ip4][..udp] [....192.168.1.2][.2804] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...223] [ip4][..udp] [....192.168.1.2][.2811] -> [....192.168.1.1][...53] + new: [...223] [ip4][..udp] [....192.168.1.2][.2811] -> [....192.168.1.1][...53] detected: [...223] [ip4][..udp] [....192.168.1.2][.2811] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...224] [ip4][..udp] [..192.168.233.1][...53] -> [....192.168.1.2][.2811] + new: [...224] [ip4][..udp] [..192.168.233.1][...53] -> [....192.168.1.2][.2811] detected: [...224] [ip4][..udp] [..192.168.233.1][...53] -> [....192.168.1.2][.2811] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] - new: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] - update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] - update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] + new: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] + update: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] + update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] update: [...190] [ip4][..udp] [....192.168.1.2][.2793] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1671,11 +1671,11 @@ update: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] [DNS][Unknown][Network][Acceptable] update: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] + update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] update: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] [DNS][Unknown][Network][Acceptable] update: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...226] [ip4][..udp] [....192.168.1.2][.2812] -> [....192.168.1.1][...53] + new: [...226] [ip4][..udp] [....192.168.1.2][.2812] -> [....192.168.1.1][...53] detected: [...226] [ip4][..udp] [....192.168.1.2][.2812] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyaercity.dk] detection-update: [...226] [ip4][..udp] [....192.168.1.2][.2812] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic @@ -1684,14 +1684,14 @@ RISK: Non-Printable/Invalid Chars Detected idle: [...191] [ip4][..udp] [....192.168.1.2][.2794] -> [..192.168.108.1][...53] [DNS][Unknown][Network][Acceptable] update: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] - update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] - update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] + update: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] + update: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] + update: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] + update: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] update: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] + update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] update: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1717,66 +1717,66 @@ update: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] - update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] + update: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] update: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet - new: [...227] [ip4][..udp] [....192.168.1.2][.2813] -> [....192.168.1.1][...53] + new: [...227] [ip4][..udp] [....192.168.1.2][.2813] -> [....192.168.1.1][...53] detected: [...227] [ip4][..udp] [....192.168.1.2][.2813] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127?in-ad_r?arpa???] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [...228] [ip4][..udp] [....192.168.1.2][.2814] -> [....192.168.1.1][...53] + new: [...228] [ip4][..udp] [....192.168.1.2][.2814] -> [....192.168.1.1][...53] detected: [...228] [ip4][..udp] [....192.168.1.2][.2814] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] ERROR-EVENT: Unknown packet type [4/16] ERROR-EVENT: Unknown packet type [5/16] - new: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] + new: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] detected: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] [NetBIOS][Unknown][System][Acceptable][] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [6/16] detection-update: [...228] [ip4][..udp] [....192.168.1.2][.2814] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sib._udp.sip.cybercity.dk] RISK: Malformed Packet, Unidirectional Traffic not-detected: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] + idle: [...195] [ip4][..udp] [192.168.170.170][43690] -> [170.170.170.170][43690] idle: [...193] [ip4][..udp] [....192.168.1.2][.2794] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...192] [ip4][..udp] [....192.168.1.2][.2795] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...196] [ip4][..udp] [....192.168.1.2][.2796] -> [..192.168.1.129][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet idle: [...194] [ip4][..udp] [....192.168.1.2][.2796] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] - update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] + update: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + update: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] update: [...200] [ip4][..udp] [....192.168.1.2][.2799] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] [DNS][Unknown][Network][Acceptable] update: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] + update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] update: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] [DNS][Unknown][Network][Acceptable] update: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic update: [...223] [ip4][..udp] [....192.168.1.2][.2811] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...224] [ip4][..udp] [..192.168.233.1][...53] -> [....192.168.1.2][.2811] [DNS][Unknown][Network][Acceptable] - update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] - new: [...230] [ip4][..udp] [....192.168.1.2][.2815] -> [....192.168.1.1][...53] + update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] + new: [...230] [ip4][..udp] [....192.168.1.2][.2815] -> [....192.168.1.1][...53] detected: [...230] [ip4][..udp] [....192.168.1.2][.2815] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Error Code ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] + new: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] detected: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][?sip._udp.shp.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected - new: [...232] [ip4][..udp] [....192.168.1.2][.5060] -> [.212.242.33.201][.5060] + new: [...232] [ip4][..udp] [....192.168.1.2][.5060] -> [.212.242.33.201][.5060] detected: [...232] [ip4][..udp] [....192.168.1.2][.5060] -> [.212.242.33.201][.5060] [SIP][Unknown][VoIP][Acceptable] detection-update: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udq.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] - new: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] - new: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] + new: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] + new: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] + new: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] detected: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] - new: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] - new: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] + new: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] + new: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] ERROR-EVENT: Unknown packet type [2/16] detection-update: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic @@ -1785,14 +1785,14 @@ RISK: Non-Printable/Invalid Chars Detected idle: [...199] [ip4][..udp] [....192.168.1.2][.2798] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] - new: [...238] [ip4][..udp] [....192.168.1.2][.2822] -> [....192.168.1.1][...53] + update: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] + new: [...238] [ip4][..udp] [....192.168.1.2][.2822] -> [....192.168.1.1][...53] detected: [...238] [ip4][..udp] [....192.168.1.2][.2822] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.1?7.in-addr.arpa] RISK: Non-Printable/Invalid Chars Detected - new: [...239] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.234.33.35][.5060] + new: [...239] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.234.33.35][.5060] detected: [...239] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.234.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] + new: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] detected: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic @@ -1802,10 +1802,10 @@ detection-update: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic not-detected: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] [Unknown][Unknown][Unrated] - idle: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] + idle: [...149] [ip4][....0] [....192.168.1.2] -> [..192.168.1.255] not-detected: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] + idle: [...203] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...21] idle: [...201] [ip4][..udp] [....192.168.1.1][...53] -> [..192.168.119.2][.2799] [DNS][Unknown][Network][Acceptable] idle: [...200] [ip4][..udp] [....192.168.1.2][.2799] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...202] [ip4][..udp] [....192.168.1.2][.2800] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1813,9 +1813,9 @@ update: [...208] [ip4][..udp] [....192.168.1.2][18162] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] + update: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] update: [...206] [ip4][..udp] [....192.168.1.2][.2568] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] - update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] + update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] update: [...204] [ip4][..udp] [....192.168.1.2][.2801] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected update: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1833,14 +1833,14 @@ RISK: Unidirectional Traffic update: [...226] [ip4][..udp] [....192.168.1.2][.2812] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] + update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] update: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet - new: [...241] [ip4][..udp] [....192.168.1.2][.2824] -> [....192.168.1.1][...53] + new: [...241] [ip4][..udp] [....192.168.1.2][.2824] -> [....192.168.1.1][...53] detected: [...241] [ip4][..udp] [....192.168.1.2][.2824] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...241] [ip4][..udp] [....192.168.1.2][.2824] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...242] [ip4][..udp] [....192.168.1.2][.2825] -> [....192.168.1.1][...53] + new: [...242] [ip4][..udp] [....192.168.1.2][.2825] -> [....192.168.1.1][...53] detected: [...242] [ip4][..udp] [....192.168.1.2][.2825] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...242] [ip4][..udp] [....192.168.1.2][.2825] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Unidirectional Traffic @@ -1854,7 +1854,7 @@ RISK: Malformed Packet, Non-Printable/Invalid Chars Detected idle: [...207] [ip4][..udp] [....192.168.1.2][.2802] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] + update: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] update: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] [DNS][Unknown][Network][Acceptable] update: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic @@ -1866,11 +1866,11 @@ update: [...228] [ip4][..udp] [....192.168.1.2][.2814] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Unidirectional Traffic update: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] - new: [...243] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] + update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] + new: [...243] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] detected: [...243] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][d00] RISK: Unsafe Protocol - new: [...244] [ip4][..udp] [....192.168.1.2][.2826] -> [....192.168.1.1][...53] + new: [...244] [ip4][..udp] [....192.168.1.2][.2826] -> [....192.168.1.1][...53] detected: [...244] [ip4][..udp] [....192.168.1.2][.2826] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.?.0.127.in-addr.arpa] RISK: Non-Printable/Invalid Chars Detected detection-update: [...244] [ip4][..udp] [....192.168.1.2][.2826] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] @@ -1883,47 +1883,47 @@ RISK: Malformed Packet, Error Code update: [...231] [ip4][..udp] [....192.168.1.2][.2816] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] - update: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] + update: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] + update: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] update: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] - update: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] - update: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] - new: [...245] [ip4][..udp] [....192.168.1.2][.2827] -> [..192.168.1.114][...53] + update: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] + update: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] + new: [...245] [ip4][..udp] [....192.168.1.2][.2827] -> [..192.168.1.114][...53] detected: [...245] [ip4][..udp] [....192.168.1.2][.2827] -> [..192.168.1.114][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] - new: [...246] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.168.1.1][...53] + new: [...246] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.168.1.1][...53] detected: [...246] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercimy.v?] RISK: Non-Printable/Invalid Chars Detected ERROR-EVENT: Unknown packet type [1/16] - new: [...247] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.170.1.1][...53] + new: [...247] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.170.1.1][...53] detected: [...247] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.170.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cyberc?ty.dk] RISK: Non-Printable/Invalid Chars Detected ERROR-EVENT: Unknown L3 protocol [2/16] not-detected: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] + idle: [...157] [ip4][...19] [....192.168.1.2] -> [....192.168.1.1] not-detected: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] [Unknown][Unknown][Unrated] - idle: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] + idle: [...117] [ip4][...37] [....192.168.1.1] -> [....192.168.1.2] not-detected: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] + idle: [...211] [ip4][..udp] [....192.168.1.2][.2805] -> [....192.168.1.1][...51] idle: [...212] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2805] [DNS][Unknown][Network][Acceptable] update: [...239] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.234.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [...238] [ip4][..udp] [....192.168.1.2][.2822] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...240] [ip4][..udp] [....192.168.1.2][.2823] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic - new: [...248] [ip4][..udp] [....192.168.1.2][.2828] -> [....192.168.1.1][...53] + new: [...248] [ip4][..udp] [....192.168.1.2][.2828] -> [....192.168.1.1][...53] detected: [...248] [ip4][..udp] [....192.168.1.2][.2828] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] - new: [...249] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2572] + new: [...249] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2572] detected: [...249] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2572] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...250] [ip4][..udp] [....192.168.1.2][...11] -> [..192.168.1.255][..137] + new: [...250] [ip4][..udp] [....192.168.1.2][...11] -> [..192.168.1.255][..137] detected: [...250] [ip4][..udp] [....192.168.1.2][...11] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] - new: [...251] [ip4][..udp] [.....62.168.1.2][..137] -> [..192.168.1.255][..137] + new: [...251] [ip4][..udp] [.....62.168.1.2][..137] -> [..192.168.1.255][..137] detected: [...251] [ip4][..udp] [.....62.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][eci_domain] not-detected: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] + idle: [...215] [ip4][..udp] [....192.168.1.2][.2808] -> [....192.168.1.1][38709] idle: [...213] [ip4][..udp] [....192.168.1.2][.2806] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected, Unidirectional Traffic idle: [...214] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2807] [DNS][Unknown][Network][Acceptable] @@ -1932,7 +1932,7 @@ RISK: Unidirectional Traffic update: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] - update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] + update: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] update: [...217] [ip4][..udp] [....192.168.1.2][19192] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -1942,33 +1942,33 @@ update: [...241] [ip4][..udp] [....192.168.1.2][.2824] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [...242] [ip4][..udp] [....192.168.1.2][.2825] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet, Non-Printable/Invalid Chars Detected, Unidirectional Traffic - update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] + update: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] update: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet - new: [...252] [ip4][..udp] [....192.168.1.2][.2829] -> [....192.168.1.1][...53] + new: [...252] [ip4][..udp] [....192.168.1.2][.2829] -> [....192.168.1.1][...53] detected: [...252] [ip4][..udp] [....192.168.1.2][.2829] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] detection-update: [...252] [ip4][..udp] [....192.168.1.2][.2829] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] RISK: Unidirectional Traffic ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...253] [ip4][..udp] [...192.168.54.2][.2829] -> [....192.168.1.1][...53] + new: [...253] [ip4][..udp] [...192.168.54.2][.2829] -> [....192.168.1.1][...53] detected: [...253] [ip4][..udp] [...192.168.54.2][.2829] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet - new: [...254] [ip4][..udp] [....192.168.1.2][.2830] -> [....192.168.1.1][...53] + new: [...254] [ip4][..udp] [....192.168.1.2][.2830] -> [....192.168.1.1][...53] detected: [...254] [ip4][..udp] [....192.168.1.2][.2830] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] detection-update: [...254] [ip4][..udp] [....192.168.1.2][.2830] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] RISK: Unidirectional Traffic - new: [...255] [ip4][..udp] [....116.168.1.2][.2829] -> [....192.168.1.1][...53] + new: [...255] [ip4][..udp] [....116.168.1.2][.2829] -> [....192.168.1.1][...53] detected: [...255] [ip4][..udp] [....116.168.1.2][.2829] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] not-detected: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] + idle: [...166] [ip4][....0] [....192.168.1.1] -> [....192.168.1.2] idle: [...217] [ip4][..udp] [....192.168.1.2][19192] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...218] [ip4][..udp] [....192.168.1.2][.2809] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...221] [ip4][..udp] [....192.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] + idle: [...219] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][17860] idle: [...220] [ip4][..udp] [....192.170.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet update: [...243] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -1988,42 +1988,42 @@ update: [...244] [ip4][..udp] [....192.168.1.2][.2826] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] [NetBIOS][Unknown][System][Acceptable] - update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] - update: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] - update: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] + update: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] + update: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] + update: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] update: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] - update: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] - update: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] + update: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] + update: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] detection-update: [...254] [ip4][..udp] [....192.168.1.2][.2830] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][sip.cybercity.dk] - new: [...256] [ip4][..udp] [....192.168.1.2][.2831] -> [....192.168.1.1][...53] + new: [...256] [ip4][..udp] [....192.168.1.2][.2831] -> [....192.168.1.1][...53] detected: [...256] [ip4][..udp] [....192.168.1.2][.2831] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] detection-update: [...256] [ip4][..udp] [....192.168.1.2][.2831] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][1.0.0.127.in-addr.arpa] guessed: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][] RISK: Malformed Packet, Unidirectional Traffic - idle: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] + idle: [...222] [ip4][..udp] [....128.168.1.2][.2810] -> [....192.168.1.1][...53] update: [...245] [ip4][..udp] [....192.168.1.2][.2827] -> [..192.168.1.114][...53] [DNS][Unknown][Network][Acceptable] update: [...246] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [...257] [ip4][..udp] [....192.168.1.2][.2832] -> [....192.168.1.1][...53] + new: [...257] [ip4][..udp] [....192.168.1.2][.2832] -> [....192.168.1.1][...53] detected: [...257] [ip4][..udp] [....192.168.1.2][.2832] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][_sip._udp.sip.cybercity.dk] guessed: [....26] [ip4][..tcp] [..147.234.1.253][...21] -> [......192.2.1.2][.2720] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....26] [ip4][..tcp] [..147.234.1.253][...21] -> [......192.2.1.2][.2720] + idle: [....26] [ip4][..tcp] [..147.234.1.253][...21] -> [......192.2.1.2][.2720] guessed: [....43] [ip4][..tcp] [.....37.115.0.2][.2639] -> [..147.234.1.253][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....43] [ip4][..tcp] [.....37.115.0.2][.2639] -> [..147.234.1.253][...21] + idle: [....43] [ip4][..tcp] [.....37.115.0.2][.2639] -> [..147.234.1.253][...21] guessed: [....38] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.117.1.253][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....38] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.117.1.253][...21] + idle: [....38] [ip4][..tcp] [....192.168.1.2][.2720] -> [..147.117.1.253][...21] not-detected: [....33] [ip4][..tcp] [..147.234.1.253][.1045] -> [....192.168.1.2][.2720] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....33] [ip4][..tcp] [..147.234.1.253][.1045] -> [....192.168.1.2][.2720] + idle: [....33] [ip4][..tcp] [..147.234.1.253][.1045] -> [....192.168.1.2][.2720] idle: [...251] [ip4][..udp] [.....62.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [...250] [ip4][..udp] [....192.168.1.2][...11] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] not-detected: [....29] [ip4][..tcp] [..147.234.1.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....29] [ip4][..tcp] [..147.234.1.170][43690] -> [170.170.170.170][43690] + idle: [....29] [ip4][..tcp] [..147.234.1.170][43690] -> [170.170.170.170][43690] idle: [.....1] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [...243] [ip4][..udp] [....192.168.1.2][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol @@ -2032,18 +2032,18 @@ idle: [...198] [ip4][..udp] [..212.242.33.35][.5060] -> [....192.168.1.2][.5060] [SIP][Unknown][VoIP][Acceptable] not-detected: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] + idle: [...205] [ip4][....0] [....192.168.1.2] -> [..212.242.33.35] idle: [...249] [ip4][..udp] [....192.168.1.1][...53] -> [....192.168.1.2][.2572] [DNS][Unknown][Network][Acceptable] RISK: Malformed Packet guessed: [....31] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2208] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....31] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2208] + idle: [....31] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2208] not-detected: [....42] [ip4][..tcp] [..147.234.1.253][58999] -> [....192.232.1.2][.2721] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....42] [ip4][..tcp] [..147.234.1.253][58999] -> [....192.232.1.2][.2721] + idle: [....42] [ip4][..tcp] [..147.234.1.253][58999] -> [....192.232.1.2][.2721] not-detected: [....39] [ip4][..tcp] [....192.168.1.6][.2721] -> [..147.234.1.253][58999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....39] [ip4][..tcp] [....192.168.1.6][.2721] -> [..147.234.1.253][58999] + idle: [....39] [ip4][..tcp] [....192.168.1.6][.2721] -> [..147.234.1.253][58999] idle: [...255] [ip4][..udp] [....116.168.1.2][.2829] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [...224] [ip4][..udp] [..192.168.233.1][...53] -> [....192.168.1.2][.2811] [DNS][Unknown][Network][Acceptable] idle: [...223] [ip4][..udp] [....192.168.1.2][.2811] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -2080,60 +2080,60 @@ idle: [...257] [ip4][..udp] [....192.168.1.2][.2832] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] not-detected: [....40] [ip4][..tcp] [...37.115.0.253][58999] -> [....192.168.1.2][.2721] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....40] [ip4][..tcp] [...37.115.0.253][58999] -> [....192.168.1.2][.2721] + idle: [....40] [ip4][..tcp] [...37.115.0.253][58999] -> [....192.168.1.2][.2721] idle: [...229] [ip4][..udp] [....192.168.1.2][29440] -> [...192.168.1.37][..137] [NetBIOS][Unknown][System][Acceptable] guessed: [....20] [ip4][..tcp] [...192.168.1.71][.2718] -> [.147.137.21.122][..139] [NetBIOS][Unknown][System][Acceptable][] RISK: Unidirectional Traffic - idle: [....20] [ip4][..tcp] [...192.168.1.71][.2718] -> [.147.137.21.122][..139] + idle: [....20] [ip4][..tcp] [...192.168.1.71][.2718] -> [.147.137.21.122][..139] guessed: [....19] [ip4][..tcp] [....192.168.1.2][.2718] -> [..147.137.21.94][..139] [NetBIOS][Unknown][System][Acceptable][] RISK: Unidirectional Traffic - idle: [....19] [ip4][..tcp] [....192.168.1.2][.2718] -> [..147.137.21.94][..139] + idle: [....19] [ip4][..tcp] [....192.168.1.2][.2718] -> [..147.137.21.94][..139] guessed: [....35] [ip4][..tcp] [..147.234.1.253][...21] -> [.....84.168.1.2][.2720] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....35] [ip4][..tcp] [..147.234.1.253][...21] -> [.....84.168.1.2][.2720] + idle: [....35] [ip4][..tcp] [..147.234.1.253][...21] -> [.....84.168.1.2][.2720] guessed: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] [NetBIOS][Unknown][System][Acceptable][] - idle: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] + idle: [...225] [ip4][..udp] [....192.168.1.2][..137] -> [..192.168.1.255][..905] guessed: [....25] [ip4][..tcp] [....192.168.1.2][.2679] -> [..147.234.1.253][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials, Unidirectional Traffic - idle: [....25] [ip4][..tcp] [....192.168.1.2][.2679] -> [..147.234.1.253][...21] + idle: [....25] [ip4][..tcp] [....192.168.1.2][.2679] -> [..147.234.1.253][...21] not-detected: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + idle: [....37] [ip4][..170] [170.170.170.170] -> [170.170.170.170] guessed: [....36] [ip4][..tcp] [....192.112.1.2][.2720] -> [..147.234.1.253][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....36] [ip4][..tcp] [....192.112.1.2][.2720] -> [..147.234.1.253][...21] + idle: [....36] [ip4][..tcp] [....192.112.1.2][.2720] -> [..147.234.1.253][...21] not-detected: [....30] [ip4][..tcp] [..147.234.1.249][.2069] -> [....192.168.1.2][.2720] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....30] [ip4][..tcp] [..147.234.1.249][.2069] -> [....192.168.1.2][.2720] + idle: [....30] [ip4][..tcp] [..147.234.1.249][.2069] -> [....192.168.1.2][.2720] guessed: [....27] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.1.66][.2720] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....27] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.1.66][.2720] + idle: [....27] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.1.66][.2720] guessed: [....34] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.65.2][.2720] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....34] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.65.2][.2720] + idle: [....34] [ip4][..tcp] [..147.234.1.253][...21] -> [...192.168.65.2][.2720] idle: [....32] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.168.1.2][.2732] [Protobuf][Unknown][Network][Safe] not-detected: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] + idle: [...237] [ip4][..udp] [.....81.168.1.2][30000] -> [..212.242.33.36][40392] not-detected: [....28] [ip4][..tcp] [..147.234.1.253][..120] -> [....192.168.1.2][.2720] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....28] [ip4][..tcp] [..147.234.1.253][..120] -> [....192.168.1.2][.2720] + idle: [....28] [ip4][..tcp] [..147.234.1.253][..120] -> [....192.168.1.2][.2720] idle: [...235] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] not-detected: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] + idle: [...233] [ip4][..udp] [....192.168.1.3][30000] -> [..212.242.33.36][40392] not-detected: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] + idle: [...236] [ip4][..udp] [....192.168.1.2][30000] -> [..214.242.33.36][40392] guessed: [....18] [ip4][..tcp] [....192.168.1.2][.2717] -> [..147.137.21.94][..445] [SMBv23][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [....18] [ip4][..tcp] [....192.168.1.2][.2717] -> [..147.137.21.94][..445] + idle: [....18] [ip4][..tcp] [....192.168.1.2][.2717] -> [..147.137.21.94][..445] idle: [...247] [ip4][..udp] [....192.168.1.2][.2827] -> [....192.170.1.1][...53] [DNS][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected not-detected: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] + idle: [...234] [ip4][..udp] [....192.168.1.2][30000] -> [....37.115.0.36][40392] guessed: [....24] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.169.1.2][.2720] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....24] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.169.1.2][.2720] + idle: [....24] [ip4][..tcp] [..147.234.1.253][...21] -> [....192.169.1.2][.2720] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/fuzz-2006-09-29-28586.pcap.out b/test/results/flow-info/default/fuzz-2006-09-29-28586.pcap.out index 3b2dc4118..8cd895007 100644 --- a/test/results/flow-info/default/fuzz-2006-09-29-28586.pcap.out +++ b/test/results/flow-info/default/fuzz-2006-09-29-28586.pcap.out @@ -2,137 +2,137 @@ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] ERROR-EVENT: Unknown packet type [1/16] - new: [.....1] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2600] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2600] [MIDSTREAM] ERROR-EVENT: Unknown packet type [2/16] - new: [.....2] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2601] + new: [.....2] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2601] detected: [.....2] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2601] [HTTP][Unknown][Web][Acceptable][] - new: [.....3] [ip4][..tcp] [....172.20.3.13][...81] -> [.....172.20.3.5][.2601] [MIDSTREAM] - new: [.....4] [ip4][..tcp] [......0.20.3.13][...80] -> [.....172.20.3.5][.2601] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [....172.20.3.13][...81] -> [.....172.20.3.5][.2601] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [......0.20.3.13][...80] -> [.....172.20.3.5][.2601] [MIDSTREAM] ERROR-EVENT: Unknown packet type [3/16] - new: [.....5] [ip4][..tcp] [....172.20.3.13][53132] -> [.....172.20.3.5][...80] - new: [.....6] [ip4][..tcp] [.....172.20.3.1][...80] -> [....172.20.3.13][53132] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [....172.20.3.13][53132] -> [.....172.20.3.5][...80] + new: [.....6] [ip4][..tcp] [.....172.20.3.1][...80] -> [....172.20.3.13][53132] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [.....172.20.3.1][...80] -> [....172.20.3.13][53132] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [.....7] [ip4][..tcp] [.....172.20.3.5][...80] -> [....172.57.3.13][53132] [MIDSTREAM] - new: [.....8] [ip4][..tcp] [......172.6.3.5][...80] -> [....172.20.3.13][53132] [MIDSTREAM] - new: [.....9] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.21.3.13][...80] + new: [.....7] [ip4][..tcp] [.....172.20.3.5][...80] -> [....172.57.3.13][53132] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [......172.6.3.5][...80] -> [....172.20.3.13][53132] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.21.3.13][...80] ERROR-EVENT: Unknown packet type [4/16] - new: [....10] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [....11] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.20.3.13][...80] [MIDSTREAM] + new: [....10] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [....11] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.20.3.13][...80] [MIDSTREAM] detected: [....11] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.13] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....12] [ip4][..tcp] [....172.20.3.88][...80] -> [....172.20.3.82][.2601] [MIDSTREAM] - new: [....13] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.13][...80] - new: [....14] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.77][...80] [MIDSTREAM] - new: [....15] [ip4][..tcp] [.....172.20.3.5][.2603] -> [.....72.20.3.13][...80] [MIDSTREAM] - new: [....16] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.82.5][.2603] [MIDSTREAM] - new: [....17] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....68.37.115.0][...80] [MIDSTREAM] - new: [....18] [ip4][..tcp] [.....172.20.3.5][.2604] -> [....172.20.3.13][...80] + new: [....12] [ip4][..tcp] [....172.20.3.88][...80] -> [....172.20.3.82][.2601] [MIDSTREAM] + new: [....13] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.13][...80] + new: [....14] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.77][...80] [MIDSTREAM] + new: [....15] [ip4][..tcp] [.....172.20.3.5][.2603] -> [.....72.20.3.13][...80] [MIDSTREAM] + new: [....16] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.82.5][.2603] [MIDSTREAM] + new: [....17] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....68.37.115.0][...80] [MIDSTREAM] + new: [....18] [ip4][..tcp] [.....172.20.3.5][.2604] -> [....172.20.3.13][...80] detected: [....18] [ip4][..tcp] [.....172.20.3.5][.2604] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.13] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI ERROR-EVENT: Unknown packet type [1/16] - new: [....19] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.68.5][.2604] [MIDSTREAM] - new: [....20] [ip4][..tcp] [.....172.20.3.5][.2605] -> [....172.20.3.13][...80] + new: [....19] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.68.5][.2604] [MIDSTREAM] + new: [....20] [ip4][..tcp] [.....172.20.3.5][.2605] -> [....172.20.3.13][...80] detected: [....20] [ip4][..tcp] [.....172.20.3.5][.2605] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.13] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....21] [ip4][..tcp] [......51.20.3.5][.2605] -> [....172.20.3.13][...80] [MIDSTREAM] - new: [....22] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.76.5][65069] [MIDSTREAM] - new: [....23] [ip4][..tcp] [....172.20.3.13][...80] -> [......44.20.3.5][.2605] [MIDSTREAM] + new: [....21] [ip4][..tcp] [......51.20.3.5][.2605] -> [....172.20.3.13][...80] [MIDSTREAM] + new: [....22] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.76.5][65069] [MIDSTREAM] + new: [....23] [ip4][..tcp] [....172.20.3.13][...80] -> [......44.20.3.5][.2605] [MIDSTREAM] detected: [....23] [ip4][..tcp] [....172.20.3.13][...80] -> [......44.20.3.5][.2605] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent ERROR-EVENT: Unknown L3 protocol [2/16] - new: [....24] [ip4][..tcp] [170.170.170.170][43690] -> [170.170.170.170][43690] - new: [....25] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2639] [MIDSTREAM] - new: [....26] [ip4][..tcp] [....172.52.3.13][...80] -> [.....172.20.3.5][.2093] [MIDSTREAM] - new: [....27] [ip4][..tcp] [.....172.20.3.5][.2606] -> [....172.20.3.13][...80] + new: [....24] [ip4][..tcp] [170.170.170.170][43690] -> [170.170.170.170][43690] + new: [....25] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2639] [MIDSTREAM] + new: [....26] [ip4][..tcp] [....172.52.3.13][...80] -> [.....172.20.3.5][.2093] [MIDSTREAM] + new: [....27] [ip4][..tcp] [.....172.20.3.5][.2606] -> [....172.20.3.13][...80] detected: [....27] [ip4][..tcp] [.....172.20.3.5][.2606] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.13] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI ERROR-EVENT: Unknown L3 protocol [1/16] - new: [....28] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.72.5][.2606] [MIDSTREAM] + new: [....28] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.72.5][.2606] [MIDSTREAM] detected: [....28] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.72.5][.2606] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [....29] [ip4][..tcp] [.....172.20.3.5][.2607] -> [....172.20.3.13][...80] - new: [....30] [ip4][..tcp] [.....172.20.3.5][.9587] -> [....172.20.3.13][...80] [MIDSTREAM] + new: [....29] [ip4][..tcp] [.....172.20.3.5][.2607] -> [....172.20.3.13][...80] + new: [....30] [ip4][..tcp] [.....172.20.3.5][.9587] -> [....172.20.3.13][...80] [MIDSTREAM] detected: [....30] [ip4][..tcp] [.....172.20.3.5][.9587] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [....31] [ip4][..tcp] [....172.20.2.13][...80] -> [.....172.20.3.5][.2607] [MIDSTREAM] + new: [....31] [ip4][..tcp] [....172.20.2.13][...80] -> [.....172.20.3.5][.2607] [MIDSTREAM] detected: [....31] [ip4][..tcp] [....172.20.2.13][...80] -> [.....172.20.3.5][.2607] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [....32] [ip4][..tcp] [....172.20.3.13][53193] -> [.....172.20.3.5][...80] - new: [....33] [ip4][..tcp] [.....172.20.3.5][...80] -> [...172.20.35.13][53136] - new: [....34] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.20.3.5][...80] [MIDSTREAM] + new: [....32] [ip4][..tcp] [....172.20.3.13][53193] -> [.....172.20.3.5][...80] + new: [....33] [ip4][..tcp] [.....172.20.3.5][...80] -> [...172.20.35.13][53136] + new: [....34] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.20.3.5][...80] [MIDSTREAM] detected: [....34] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.5] RISK: Unidirectional Traffic - new: [....35] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.70.3.5][...80] [MIDSTREAM] + new: [....35] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.70.3.5][...80] [MIDSTREAM] detection-update: [....34] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable][172.20.3.5] - new: [....36] [ip4][..tcp] [...172.20.67.13][53136] -> [.....172.20.3.5][...80] [MIDSTREAM] + new: [....36] [ip4][..tcp] [...172.20.67.13][53136] -> [.....172.20.3.5][...80] [MIDSTREAM] ERROR-EVENT: Unknown packet type [2/16] - new: [....37] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2608] + new: [....37] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2608] detected: [....37] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2608] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [....38] [ip4][..tcp] [....172.20.3.13][...80] -> [...172.20.148.5][.2608] [MIDSTREAM] - new: [....39] [ip4][..115] [....172.20.3.13] -> [.....172.20.3.5] + new: [....38] [ip4][..tcp] [....172.20.3.13][...80] -> [...172.20.148.5][.2608] [MIDSTREAM] + new: [....39] [ip4][..115] [....172.20.3.13] -> [.....172.20.3.5] idle: [.....6] [ip4][..tcp] [.....172.20.3.1][...80] -> [....172.20.3.13][53132] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent guessed: [.....5] [ip4][..tcp] [....172.20.3.13][53132] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....5] [ip4][..tcp] [....172.20.3.13][53132] -> [.....172.20.3.5][...80] + end: [.....5] [ip4][..tcp] [....172.20.3.13][53132] -> [.....172.20.3.5][...80] guessed: [....36] [ip4][..tcp] [...172.20.67.13][53136] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....36] [ip4][..tcp] [...172.20.67.13][53136] -> [.....172.20.3.5][...80] + idle: [....36] [ip4][..tcp] [...172.20.67.13][53136] -> [.....172.20.3.5][...80] end: [....34] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable] guessed: [....33] [ip4][..tcp] [.....172.20.3.5][...80] -> [...172.20.35.13][53136] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....33] [ip4][..tcp] [.....172.20.3.5][...80] -> [...172.20.35.13][53136] + idle: [....33] [ip4][..tcp] [.....172.20.3.5][...80] -> [...172.20.35.13][53136] guessed: [....32] [ip4][..tcp] [....172.20.3.13][53193] -> [.....172.20.3.5][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....32] [ip4][..tcp] [....172.20.3.13][53193] -> [.....172.20.3.5][...80] + idle: [....32] [ip4][..tcp] [....172.20.3.13][53193] -> [.....172.20.3.5][...80] not-detected: [....39] [ip4][..115] [....172.20.3.13] -> [.....172.20.3.5] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....39] [ip4][..115] [....172.20.3.13] -> [.....172.20.3.5] + idle: [....39] [ip4][..115] [....172.20.3.13] -> [.....172.20.3.5] guessed: [....26] [ip4][..tcp] [....172.52.3.13][...80] -> [.....172.20.3.5][.2093] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....26] [ip4][..tcp] [....172.52.3.13][...80] -> [.....172.20.3.5][.2093] + end: [....26] [ip4][..tcp] [....172.52.3.13][...80] -> [.....172.20.3.5][.2093] not-detected: [....24] [ip4][..tcp] [170.170.170.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] - idle: [....24] [ip4][..tcp] [170.170.170.170][43690] -> [170.170.170.170][43690] + idle: [....24] [ip4][..tcp] [170.170.170.170][43690] -> [170.170.170.170][43690] guessed: [.....4] [ip4][..tcp] [......0.20.3.13][...80] -> [.....172.20.3.5][.2601] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....4] [ip4][..tcp] [......0.20.3.13][...80] -> [.....172.20.3.5][.2601] + idle: [.....4] [ip4][..tcp] [......0.20.3.13][...80] -> [.....172.20.3.5][.2601] guessed: [.....8] [ip4][..tcp] [......172.6.3.5][...80] -> [....172.20.3.13][53132] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....8] [ip4][..tcp] [......172.6.3.5][...80] -> [....172.20.3.13][53132] + idle: [.....8] [ip4][..tcp] [......172.6.3.5][...80] -> [....172.20.3.13][53132] guessed: [....35] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.70.3.5][...80] [HTTP][Cloudflare][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....35] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.70.3.5][...80] + idle: [....35] [ip4][..tcp] [....172.20.3.13][53136] -> [.....172.70.3.5][...80] idle: [....23] [ip4][..tcp] [....172.20.3.13][...80] -> [......44.20.3.5][.2605] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent guessed: [....21] [ip4][..tcp] [......51.20.3.5][.2605] -> [....172.20.3.13][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....21] [ip4][..tcp] [......51.20.3.5][.2605] -> [....172.20.3.13][...80] + idle: [....21] [ip4][..tcp] [......51.20.3.5][.2605] -> [....172.20.3.13][...80] guessed: [....15] [ip4][..tcp] [.....172.20.3.5][.2603] -> [.....72.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....15] [ip4][..tcp] [.....172.20.3.5][.2603] -> [.....72.20.3.13][...80] + end: [....15] [ip4][..tcp] [.....172.20.3.5][.2603] -> [.....72.20.3.13][...80] guessed: [.....1] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2600] [HTTP][Unknown][Web][Acceptable][] - end: [.....1] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2600] + end: [.....1] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2600] guessed: [....12] [ip4][..tcp] [....172.20.3.88][...80] -> [....172.20.3.82][.2601] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....12] [ip4][..tcp] [....172.20.3.88][...80] -> [....172.20.3.82][.2601] + idle: [....12] [ip4][..tcp] [....172.20.3.88][...80] -> [....172.20.3.82][.2601] end: [.....2] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2601] [HTTP][Unknown][Web][Acceptable] end: [....11] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI not-detected: [.....3] [ip4][..tcp] [....172.20.3.13][...81] -> [.....172.20.3.5][.2601] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....3] [ip4][..tcp] [....172.20.3.13][...81] -> [.....172.20.3.5][.2601] + idle: [.....3] [ip4][..tcp] [....172.20.3.13][...81] -> [.....172.20.3.5][.2601] guessed: [....16] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.82.5][.2603] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....16] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.82.5][.2603] + idle: [....16] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.82.5][.2603] guessed: [....14] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.77][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....14] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.77][...80] + idle: [....14] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.77][...80] guessed: [....13] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....13] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.13][...80] + end: [....13] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....172.20.3.13][...80] guessed: [....19] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.68.5][.2604] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic, TCP Connection Issues - end: [....19] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.68.5][.2604] + end: [....19] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.68.5][.2604] end: [....18] [ip4][..tcp] [.....172.20.3.5][.2604] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI end: [....20] [ip4][..tcp] [.....172.20.3.5][.2605] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable] @@ -144,29 +144,29 @@ idle: [....31] [ip4][..tcp] [....172.20.2.13][...80] -> [.....172.20.3.5][.2607] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent guessed: [....29] [ip4][..tcp] [.....172.20.3.5][.2607] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [....29] [ip4][..tcp] [.....172.20.3.5][.2607] -> [....172.20.3.13][...80] + idle: [....29] [ip4][..tcp] [.....172.20.3.5][.2607] -> [....172.20.3.13][...80] guessed: [....38] [ip4][..tcp] [....172.20.3.13][...80] -> [...172.20.148.5][.2608] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....38] [ip4][..tcp] [....172.20.3.13][...80] -> [...172.20.148.5][.2608] + idle: [....38] [ip4][..tcp] [....172.20.3.13][...80] -> [...172.20.148.5][.2608] idle: [....37] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2608] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent guessed: [....25] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2639] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....25] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2639] + idle: [....25] [ip4][..tcp] [....172.20.3.13][...80] -> [.....172.20.3.5][.2639] guessed: [....17] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....68.37.115.0][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [....17] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....68.37.115.0][...80] + idle: [....17] [ip4][..tcp] [.....172.20.3.5][.2603] -> [....68.37.115.0][...80] guessed: [.....9] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.21.3.13][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....9] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.21.3.13][...80] + idle: [.....9] [ip4][..tcp] [.....172.20.3.5][.2602] -> [....172.21.3.13][...80] not-detected: [....10] [ip4][..170] [170.170.170.170] -> [170.170.170.170] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....10] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + idle: [....10] [ip4][..170] [170.170.170.170] -> [170.170.170.170] guessed: [.....7] [ip4][..tcp] [.....172.20.3.5][...80] -> [....172.57.3.13][53132] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....7] [ip4][..tcp] [.....172.20.3.5][...80] -> [....172.57.3.13][53132] + idle: [.....7] [ip4][..tcp] [.....172.20.3.5][...80] -> [....172.57.3.13][53132] idle: [....30] [ip4][..tcp] [.....172.20.3.5][.9587] -> [....172.20.3.13][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent guessed: [....22] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.76.5][65069] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....22] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.76.5][65069] + idle: [....22] [ip4][..tcp] [....172.20.3.13][...80] -> [....172.20.76.5][65069] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/fuzz-2020-02-16-11740.pcap.out b/test/results/flow-info/default/fuzz-2020-02-16-11740.pcap.out index 2916c3684..c1aa79d0e 100644 --- a/test/results/flow-info/default/fuzz-2020-02-16-11740.pcap.out +++ b/test/results/flow-info/default/fuzz-2020-02-16-11740.pcap.out @@ -1,72 +1,72 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....10.12.64.30][29200] -> [..108.226.25.53][.1812] + new: [.....1] [ip4][..udp] [....10.12.64.30][29200] -> [..108.226.25.53][.1812] detected: [.....1] [ip4][..udp] [....10.12.64.30][29200] -> [..108.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.102.64.30][29200] + new: [.....2] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.102.64.30][29200] detected: [.....2] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.102.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] + new: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] detected: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] - new: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] + new: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] idle: [.....2] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.102.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [....10.12.64.30][29200] -> [..108.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] + new: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] detected: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] + update: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] ERROR-EVENT: Unknown L3 protocol [4/16] - new: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] + new: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] - new: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] + new: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] + new: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] detected: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] + new: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] detected: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] - update: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] - update: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] - new: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] + update: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] + update: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] + new: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] not-detected: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] + idle: [.....4] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1796] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] [Radius][Unknown][Network][Acceptable] - update: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] - update: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] + update: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] + update: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] not-detected: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] + idle: [.....6] [ip4][..udp] [..198.226.25.53][30764] -> [....10.12.64.30][12344] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] - update: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] + update: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] update: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] [Radius][Unknown][Network][Acceptable] - update: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] - new: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] - new: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] + update: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] + new: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + new: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] detected: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] idle: [.....8] [ip4][..udp] [.....10.4.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] + idle: [....10] [ip4][..udp] [..198.226.25.53][..309] -> [....10.12.64.30][12339] idle: [.....9] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29270] [Radius][Unknown][Network][Acceptable] not-detected: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] + idle: [.....7] [ip4][..udp] [198.226.170.170][43690] -> [170.170.170.170][43690] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [.....5] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [2/16] @@ -83,118 +83,118 @@ [PKTLENS.....: 683,243,225,304,225,731,165,683,165,683,192,731,683,731,683,192,165,683,731,165,683,192,731,225,711,731,711,304,731,225,711,731] [ENTROPIES...: 6.0,2.8,6.3,6.9,6.4,5.6,6.0,6.1,6.0,0.9,6.1,6.0,6.1,2.9,4.1,6.1,6.0,6.0,6.1,6.0,5.0,6.1,6.1,6.4,6.0,6.1,5.5,6.8,6.1,6.5,5.8,4.2] ERROR-EVENT: Unknown L3 protocol [1/16] - new: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] + new: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] ERROR-EVENT: Unknown packet type [1/16] update: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] [Radius][Unknown][Network][Acceptable] - update: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] - new: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] + update: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + new: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] detected: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] + new: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] detected: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] + new: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] detected: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] - new: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] - new: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] + new: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] + new: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] - update: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] + update: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] update: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] [Radius][Unknown][Network][Acceptable] - update: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + update: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] ERROR-EVENT: Unknown packet type [1/16] - new: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] - new: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] + new: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] + new: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] detected: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] - new: [....21] [ip4][..udp] [..198.157.25.53][.1812] -> [....10.12.64.30][29200] + new: [....21] [ip4][..udp] [..198.157.25.53][.1812] -> [....10.12.64.30][29200] detected: [....21] [ip4][..udp] [..198.157.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] not-detected: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] + idle: [....13] [ip4][..udp] [..198.162.25.53][.1810] -> [....10.12.64.30][29200] idle: [....12] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29264] [Radius][Unknown][Network][Acceptable] not-detected: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] + idle: [....11] [ip4][..udp] [170.170.170.170][43690] -> [170.170.170.170][43690] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] - update: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] + update: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] update: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] + new: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] detected: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] - new: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] + new: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] + new: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] detected: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] - new: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] + new: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] + new: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] detected: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] + new: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] detected: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] [Radius][Unknown][Network][Acceptable] idle: [....15] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.77.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....14] [ip4][..udp] [..198.226.25.53][.1812] -> [....74.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] - update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] + update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] + update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] DAEMON-EVENT: [Processed: 104 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 13 / 27|skipped: 0|!detected: 6|guessed: 0|detection-updates: 0|updates: 39] - new: [....28] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.28.64.30][29200] + new: [....28] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.28.64.30][29200] detected: [....28] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.28.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] - update: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] + update: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] update: [....21] [ip4][..udp] [..198.157.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [....29] [ip4][..udp] [....10.12.64.30][29200] -> [..198.224.25.53][.1812] + new: [....29] [ip4][..udp] [....10.12.64.30][29200] -> [..198.224.25.53][.1812] detected: [....29] [ip4][..udp] [....10.12.64.30][29200] -> [..198.224.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] + update: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] update: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] - new: [....30] [ip4][..udp] [..198.226.25.53][.1812] -> [.....10.12.37.0][29200] + new: [....30] [ip4][..udp] [..198.226.25.53][.1812] -> [.....10.12.37.0][29200] detected: [....30] [ip4][..udp] [..198.226.25.53][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown L3 protocol [2/16] - new: [....31] [ip4][..udp] [...10.12.64.110][29200] -> [..198.226.25.53][.1812] + new: [....31] [ip4][..udp] [...10.12.64.110][29200] -> [..198.226.25.53][.1812] detected: [....31] [ip4][..udp] [...10.12.64.110][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....32] [ip4][..udp] [...72.226.25.53][.1812] -> [....10.12.64.30][29200] + new: [....32] [ip4][..udp] [...72.226.25.53][.1812] -> [....10.12.64.30][29200] detected: [....32] [ip4][..udp] [...72.226.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] guessed: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] [Radius][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] + idle: [....19] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.120.30][29200] idle: [....20] [ip4][..udp] [....10.12.64.30][29200] -> [..206.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....21] [ip4][..udp] [..198.157.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] update: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....28] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.28.64.30][29200] [Radius][Unknown][Network][Acceptable] - update: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] + update: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] update: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....29] [ip4][..udp] [....10.12.64.30][29200] -> [..198.224.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] - new: [....33] [ip4][..udp] [....10.12.64.30][29200] -> [...198.226.37.0][.1812] + new: [....33] [ip4][..udp] [....10.12.64.30][29200] -> [...198.226.37.0][.1812] detected: [....33] [ip4][..udp] [....10.12.64.30][29200] -> [...198.226.37.0][.1812] [Radius][Unknown][Network][Acceptable] idle: [....28] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.28.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....24] [ip4][..udp] [..198.226.82.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....16] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] + idle: [....25] [ip4][..udp] [..198.226.25.53][.1895] -> [....10.12.64.30][29200] idle: [....26] [ip4][..udp] [....10.12.64.30][30224] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....22] [ip4][..udp] [..198.230.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....27] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.56.64.30][.9472] [Radius][Unknown][Network][Acceptable] @@ -202,11 +202,11 @@ update: [....30] [ip4][..udp] [..198.226.25.53][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] update: [....31] [ip4][..udp] [...10.12.64.110][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....29] [ip4][..udp] [....10.12.64.30][29200] -> [..198.224.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] - update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] + update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] + update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] update: [....32] [ip4][..udp] [...72.226.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] - new: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] + update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] + new: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] detected: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] [VRRP][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] idle: [....31] [ip4][..udp] [...10.12.64.110][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] @@ -215,65 +215,65 @@ idle: [....32] [ip4][..udp] [...72.226.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....33] [ip4][..udp] [....10.12.64.30][29200] -> [...198.226.37.0][.1812] [Radius][Unknown][Network][Acceptable] - update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] - update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] - update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] - new: [....35] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] + update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] + update: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] + update: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] + new: [....35] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] detected: [....35] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] - new: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] + new: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] detected: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] + new: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] detected: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] - new: [....38] [ip4][..udp] [..198.226.25.62][.1812] -> [....10.12.64.30][29295] + new: [....38] [ip4][..udp] [..198.226.25.62][.1812] -> [....10.12.64.30][29295] detected: [....38] [ip4][..udp] [..198.226.25.62][.1812] -> [....10.12.64.30][29295] [Radius][Unknown][Network][Acceptable] - new: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] + new: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] detected: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] idle: [....33] [ip4][..udp] [....10.12.64.30][29200] -> [...198.226.37.0][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] ERROR-EVENT: Unknown L3 protocol [1/16] - new: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] + new: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] detected: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] [Radius][Unknown][Network][Acceptable] - new: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] - new: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] + new: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] + new: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] ERROR-EVENT: Unknown packet type [2/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] - new: [....45] [ip4][..udp] [..198.234.25.53][.1812] -> [....10.12.64.30][29200] + new: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] + new: [....45] [ip4][..udp] [..198.234.25.53][.1812] -> [....10.12.64.30][29200] detected: [....45] [ip4][..udp] [..198.234.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] not-detected: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] + idle: [....17] [ip4][...88] [..198.226.25.53] -> [....10.12.64.30] not-detected: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] + idle: [....18] [ip4][..254] [....10.12.64.30] -> [..198.226.25.53] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] update: [....35] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] update: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] [Radius][Unknown][Network][Acceptable] update: [....38] [ip4][..udp] [..198.226.25.62][.1812] -> [....10.12.64.30][29295] [Radius][Unknown][Network][Acceptable] update: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] - update: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] + update: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] + update: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] update: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....46] [ip4][..udp] [....10.76.64.30][29200] -> [..198.226.25.53][.1812] + new: [....46] [ip4][..udp] [....10.76.64.30][29200] -> [..198.226.25.53][.1812] detected: [....46] [ip4][..udp] [....10.76.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] - new: [....48] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.112.30][29200] + new: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] + new: [....48] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.112.30][29200] detected: [....48] [ip4][..udp] [..198.226.25.53][.1812] -> [...10.12.112.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....49] [ip4][..udp] [.....10.84.37.0][29200] -> [..198.226.25.53][.1812] + new: [....49] [ip4][..udp] [.....10.84.37.0][29200] -> [..198.226.25.53][.1812] detected: [....49] [ip4][..udp] [.....10.84.37.0][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] ERROR-EVENT: Unknown L3 protocol [2/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] ERROR-EVENT: Unknown L3 protocol [4/16] ERROR-EVENT: Unknown L3 protocol [1/16] - new: [....50] [ip4][..udp] [....10.12.64.37][29200] -> [....0.226.25.53][.1812] + new: [....50] [ip4][..udp] [....10.12.64.37][29200] -> [....0.226.25.53][.1812] detected: [....50] [ip4][..udp] [....10.12.64.37][29200] -> [....0.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....51] [ip4][..udp] [....10.12.64.30][29200] -> [...198.48.25.53][.1812] + new: [....51] [ip4][..udp] [....10.12.64.30][29200] -> [...198.48.25.53][.1812] detected: [....51] [ip4][..udp] [....10.12.64.30][29200] -> [...198.48.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....52] [ip4][..udp] [...198.52.25.53][.1812] -> [....10.12.64.30][29200] + new: [....52] [ip4][..udp] [...198.52.25.53][.1812] -> [....10.12.64.30][29200] detected: [....52] [ip4][..udp] [...198.52.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] @@ -285,20 +285,20 @@ update: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] [Radius][Unknown][Network][Acceptable] update: [....38] [ip4][..udp] [..198.226.25.62][.1812] -> [....10.12.64.30][29295] [Radius][Unknown][Network][Acceptable] update: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] - update: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] - update: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] + update: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] + update: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] + update: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] update: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] + update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] update: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] [VRRP][Unknown][Network][Acceptable] - new: [....53] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29200] + new: [....53] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29200] detected: [....53] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown L3 protocol [2/16] idle: [....37] [ip4][..udp] [..198.226.25.62][.1812] -> [.....10.12.37.0][29200] [Radius][Unknown][Network][Acceptable] idle: [....36] [ip4][..udp] [.....37.0.25.62][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....54] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29204] + new: [....54] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29204] detected: [....54] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29204] [Radius][Unknown][Network][Acceptable] idle: [....41] [ip4][..udp] [..198.226.25.53][.1812] -> [..10.12.172.158][29200] [Radius][Unknown][Network][Acceptable] idle: [....35] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] @@ -306,10 +306,10 @@ idle: [....39] [ip4][..udp] [....10.12.64.30][29304] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] guessed: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] [Radius][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] + idle: [....42] [ip4][..udp] [....10.12.64.30][29200] -> [..198.119.25.53][.1812] not-detected: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] + idle: [....23] [ip4][...85] [..198.226.25.62] -> [....10.12.64.30] DAEMON-EVENT: [Processed: 200 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 15 / 54|skipped: 0|!detected: 10|guessed: 2|detection-updates: 0|updates: 98] ERROR-EVENT: Unknown packet type [1/16] @@ -320,27 +320,27 @@ idle: [....49] [ip4][..udp] [.....10.84.37.0][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] + idle: [....43] [ip4][..udp] [..198.226.25.53][.1965] -> [....10.12.64.30][29200] not-detected: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] + idle: [....47] [ip4][..udp] [..198.226.25.53][43690] -> [..10.12.170.170][43690] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....53] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....54] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29204] [Radius][Unknown][Network][Acceptable] update: [....52] [ip4][..udp] [...198.52.25.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] update: [....51] [ip4][..udp] [....10.12.64.30][29200] -> [...198.48.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] + update: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] update: [....50] [ip4][..udp] [....10.12.64.37][29200] -> [....0.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] [VRRP][Unknown][Network][Acceptable] - new: [....55] [ip4][..udp] [..198.226.25.53][.1812] -> [....65.12.64.30][29200] + new: [....55] [ip4][..udp] [..198.226.25.53][.1812] -> [....65.12.64.30][29200] detected: [....55] [ip4][..udp] [..198.226.25.53][.1812] -> [....65.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....56] [ip4][..udp] [....10.12.69.30][29200] -> [..198.226.25.53][.1813] + new: [....56] [ip4][..udp] [....10.12.69.30][29200] -> [..198.226.25.53][.1813] detected: [....56] [ip4][..udp] [....10.12.69.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] idle: [....50] [ip4][..udp] [....10.12.64.37][29200] -> [....0.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] + new: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] detected: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] + new: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] idle: [....56] [ip4][..udp] [....10.12.69.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] idle: [....53] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....54] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29204] [Radius][Unknown][Network][Acceptable] @@ -349,37 +349,37 @@ idle: [....51] [ip4][..udp] [....10.12.64.30][29200] -> [...198.48.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....34] [ip4][..112] [....10.12.64.30] -> [..198.226.25.53] [VRRP][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - update: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] - new: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] + update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + update: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] + new: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] detected: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] + new: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] detected: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....61] [ip4][..udp] [.....10.6.64.30][29200] -> [..198.226.25.53][.1812] + new: [....61] [ip4][..udp] [.....10.6.64.30][29200] -> [..198.226.25.53][.1812] detected: [....61] [ip4][..udp] [.....10.6.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....62] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.82.64.30][29200] + new: [....62] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.82.64.30][29200] detected: [....62] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.82.64.30][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....63] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.80.53][.1812] + new: [....63] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.80.53][.1812] detected: [....63] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.80.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] + new: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] + update: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] update: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....65] [ip4][..udp] [.....198.7.9.53][.1812] -> [....10.12.64.30][29200] + new: [....65] [ip4][..udp] [.....198.7.9.53][.1812] -> [....10.12.64.30][29200] detected: [....65] [ip4][..udp] [.....198.7.9.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....66] [ip4][..udp] [....10.12.64.30][29232] -> [..198.226.25.53][.1812] + new: [....66] [ip4][..udp] [....10.12.64.30][29232] -> [..198.226.25.53][.1812] detected: [....66] [ip4][..udp] [....10.12.64.30][29232] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown L3 protocol [2/16] - new: [....67] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.81.64.30][29200] + new: [....67] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.81.64.30][29200] detected: [....67] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.81.64.30][29200] [Radius][Unknown][Network][Acceptable] - new: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] + new: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] ERROR-EVENT: Unknown packet type [4/16] update: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] @@ -388,30 +388,30 @@ ERROR-EVENT: nDPI IPv4/L4 payload detection failed [5/16] ERROR-EVENT: Unknown L3 protocol [6/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....69] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.73][29200] + new: [....69] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.73][29200] detected: [....69] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.73][29200] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [3/16] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [4/16] - new: [....70] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29208] + new: [....70] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29208] detected: [....70] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29208] [Radius][Unknown][Network][Acceptable] - new: [....71] [ip4][..udp] [....10.12.64.30][29289] -> [..198.226.25.53][.1812] + new: [....71] [ip4][..udp] [....10.12.64.30][29289] -> [..198.226.25.53][.1812] detected: [....71] [ip4][..udp] [....10.12.64.30][29289] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: Unknown packet type [5/16] update: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] + update: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] update: [....63] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.80.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] + update: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] update: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....72] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.21][.1812] + new: [....72] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.21][.1812] detected: [....72] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.21][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] + idle: [....44] [ip4][....0] [....10.12.64.30] -> [..198.226.25.53] update: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] update: [....66] [ip4][..udp] [....10.12.64.30][29232] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - update: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] + update: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] update: [....61] [ip4][..udp] [.....10.6.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] update: [....65] [ip4][..udp] [.....198.7.9.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....67] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.81.64.30][29200] [Radius][Unknown][Network][Acceptable] @@ -421,45 +421,45 @@ idle: [....63] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.80.53][.1812] [Radius][Unknown][Network][Acceptable] guessed: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] [Radius][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] + idle: [....58] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.66][29200] idle: [....57] [ip4][..udp] [....10.12.82.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....72] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.21][.1812] [Radius][Unknown][Network][Acceptable] idle: [.....3] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] + idle: [....64] [ip4][..udp] [..198.226.25.53][.3860] -> [....14.12.64.30][29200] idle: [....70] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][29208] [Radius][Unknown][Network][Acceptable] idle: [....66] [ip4][..udp] [....10.12.64.30][29232] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....59] [ip4][..udp] [....88.12.80.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....71] [ip4][..udp] [....10.12.64.30][29289] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] not-detected: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] + idle: [....68] [ip4][..udp] [..198.226.25.53][43028] -> [....10.12.64.30][29200] idle: [....61] [ip4][..udp] [.....10.6.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] idle: [....67] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.81.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....65] [ip4][..udp] [.....198.7.9.53][.1812] -> [....10.12.64.30][29200] [Radius][Unknown][Network][Acceptable] idle: [....62] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.82.64.30][29200] [Radius][Unknown][Network][Acceptable] update: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] - update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] - new: [....73] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] + update: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + new: [....73] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] detected: [....73] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] - new: [....74] [ip4][..udp] [..198.226.25.53][.1814] -> [....10.12.64.30][29200] + new: [....74] [ip4][..udp] [..198.226.25.53][.1814] -> [....10.12.64.30][29200] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [1/16] - new: [....75] [ip4][..udp] [....57.12.64.30][29200] -> [..198.226.25.53][28948] - new: [....76] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][22544] + new: [....75] [ip4][..udp] [....57.12.64.30][29200] -> [..198.226.25.53][28948] + new: [....76] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][22544] detected: [....76] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][22544] [Radius][Unknown][Network][Acceptable] ERROR-EVENT: nDPI IPv4/L4 payload detection failed [2/16] DAEMON-EVENT: [Processed: 285 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 76|skipped: 0|!detected: 15|guessed: 3|detection-updates: 0|updates: 132] - new: [....77] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] + new: [....77] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] detected: [....77] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] - new: [....78] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][21008] + new: [....78] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][21008] detected: [....78] [ip4][..udp] [..198.226.25.53][.1813] -> [....10.12.64.30][21008] [Radius][Unknown][Network][Acceptable] not-detected: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] + idle: [....40] [ip4][..170] [170.170.170.170] -> [170.170.170.170] update: [....60] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.62][.1812] [Radius][Unknown][Network][Acceptable] - new: [....79] [ip4][...37] [..198.226.25.53] -> [....10.12.64.30] + new: [....79] [ip4][...37] [..198.226.25.53] -> [....10.12.64.30] ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] idle: [....73] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1812] [Radius][Unknown][Network][Acceptable] @@ -468,12 +468,12 @@ idle: [....77] [ip4][..udp] [....10.12.64.30][29200] -> [..198.226.25.53][.1813] [Radius][Unknown][Network][Acceptable] not-detected: [....74] [ip4][..udp] [..198.226.25.53][.1814] -> [....10.12.64.30][29200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....74] [ip4][..udp] [..198.226.25.53][.1814] -> [....10.12.64.30][29200] + idle: [....74] [ip4][..udp] [..198.226.25.53][.1814] -> [....10.12.64.30][29200] not-detected: [....75] [ip4][..udp] [....57.12.64.30][29200] -> [..198.226.25.53][28948] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....75] [ip4][..udp] [....57.12.64.30][29200] -> [..198.226.25.53][28948] + idle: [....75] [ip4][..udp] [....57.12.64.30][29200] -> [..198.226.25.53][28948] idle: [....76] [ip4][..udp] [..198.226.25.53][.1812] -> [....10.12.64.30][22544] [Radius][Unknown][Network][Acceptable] not-detected: [....79] [ip4][...37] [..198.226.25.53] -> [....10.12.64.30] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....79] [ip4][...37] [..198.226.25.53] -> [....10.12.64.30] + idle: [....79] [ip4][...37] [..198.226.25.53] -> [....10.12.64.30] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/geforcenow.pcapng.out b/test/results/flow-info/default/geforcenow.pcapng.out index 35c30b554..583894ab5 100644 --- a/test/results/flow-info/default/geforcenow.pcapng.out +++ b/test/results/flow-info/default/geforcenow.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.245][57490] -> [..80.84.167.206][49100] + new: [.....1] [ip4][..tcp] [..192.168.1.245][57490] -> [..80.84.167.206][49100] detected: [.....1] [ip4][..tcp] [..192.168.1.245][57490] -> [..80.84.167.206][49100] [TLS.GeForceNow][Nvidia][Game][Fun][80-84-167-206.cloudmatchbeta.nvidiagrid.net] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..tcp] [..192.168.1.245][57490] -> [..80.84.167.206][49100] [TLS.GeForceNow][Nvidia][Game][Fun][80-84-167-206.cloudmatchbeta.nvidiagrid.net] @@ -20,7 +20,7 @@ [ENTROPIES...: 4.8,5.3,5.2,4.8,7.3,5.2,7.6,5.2,6.1,7.2,7.7,7.3,7.0,5.2,6.9,5.8,5.7,7.9,7.9,7.9,7.9,5.2,7.9,7.9,5.2,7.9,5.2,7.9,5.3,7.9,5.2,7.9] detection-update: [.....1] [ip4][..tcp] [..192.168.1.245][57490] -> [..80.84.167.206][49100] [TLS.GeForceNow][Nvidia][Game][Fun][80-84-167-206.cloudmatchbeta.nvidiagrid.net] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [..192.168.1.245][52441] -> [..80.84.167.206][18452] + new: [.....2] [ip4][..udp] [..192.168.1.245][52441] -> [..80.84.167.206][18452] detected: [.....2] [ip4][..udp] [..192.168.1.245][52441] -> [..80.84.167.206][18452] [STUN][Nvidia][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....2] [ip4][..udp] [..192.168.1.245][52441] -> [..80.84.167.206][18452] [STUN][Nvidia][Network][Acceptable][] diff --git a/test/results/flow-info/default/genshin-impact.pcap.out b/test/results/flow-info/default/genshin-impact.pcap.out index b89a06838..0b8e55939 100644 --- a/test/results/flow-info/default/genshin-impact.pcap.out +++ b/test/results/flow-info/default/genshin-impact.pcap.out @@ -1,35 +1,35 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][58766] -> [..47.245.143.85][22101] + new: [.....1] [ip4][..udp] [..192.168.2.100][58766] -> [..47.245.143.85][22101] detected: [.....1] [ip4][..udp] [..192.168.2.100][58766] -> [..47.245.143.85][22101] [GenshinImpact][Alibaba][Game][Fun] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][59145] -> [.47.254.169.109][22102] + new: [.....2] [ip4][..udp] [..192.168.2.100][59145] -> [.47.254.169.109][22102] detected: [.....2] [ip4][..udp] [..192.168.2.100][59145] -> [.47.254.169.109][22102] [GenshinImpact][Alibaba][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][58766] -> [..47.245.143.85][22101] [GenshinImpact][Alibaba][Game][Fun] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.2.100][52575] -> [...8.209.69.191][22101] + new: [.....3] [ip4][..udp] [..192.168.2.100][52575] -> [...8.209.69.191][22101] detected: [.....3] [ip4][..udp] [..192.168.2.100][52575] -> [...8.209.69.191][22101] [GenshinImpact][Alibaba][Game][Fun] RISK: Known Proto on Non Std Port idle: [.....2] [ip4][..udp] [..192.168.2.100][59145] -> [.47.254.169.109][22102] [GenshinImpact][Alibaba][Game][Fun] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.2.100][39822] -> [..49.51.190.178][...80] + new: [.....4] [ip4][..tcp] [..192.168.2.100][39822] -> [..49.51.190.178][...80] detected: [.....4] [ip4][..tcp] [..192.168.2.100][39822] -> [..49.51.190.178][...80] [GenshinImpact][Tencent][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][52575] -> [...8.209.69.191][22101] [GenshinImpact][Alibaba][Game][Fun] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][39686] -> [..49.51.181.168][...80] + new: [.....5] [ip4][..tcp] [..192.168.2.100][39686] -> [..49.51.181.168][...80] detected: [.....5] [ip4][..tcp] [..192.168.2.100][39686] -> [..49.51.181.168][...80] [GenshinImpact][Tencent][Game][Fun] idle: [.....4] [ip4][..tcp] [..192.168.2.100][39822] -> [..49.51.190.178][...80] [GenshinImpact][Tencent][Game][Fun] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][45246] -> [..49.51.181.168][10012] + new: [.....6] [ip4][..tcp] [..192.168.2.100][45246] -> [..49.51.181.168][10012] detected: [.....6] [ip4][..tcp] [..192.168.2.100][45246] -> [..49.51.181.168][10012] [GenshinImpact][Tencent][Game][Fun] idle: [.....6] [ip4][..tcp] [..192.168.2.100][45246] -> [..49.51.181.168][10012] [GenshinImpact][Tencent][Game][Fun] idle: [.....5] [ip4][..tcp] [..192.168.2.100][39686] -> [..49.51.181.168][...80] [GenshinImpact][Tencent][Game][Fun] diff --git a/test/results/flow-info/default/git.pcap.out b/test/results/flow-info/default/git.pcap.out index 472f29af3..d24c3e915 100644 --- a/test/results/flow-info/default/git.pcap.out +++ b/test/results/flow-info/default/git.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.0.77][47991] -> [...5.153.231.21][.9418] + new: [.....1] [ip4][..tcp] [...192.168.0.77][47991] -> [...5.153.231.21][.9418] detected: [.....1] [ip4][..tcp] [...192.168.0.77][47991] -> [...5.153.231.21][.9418] [Git][Unknown][Collaborative][Safe] analyse: [.....1] [ip4][..tcp] [...192.168.0.77][47991] -> [...5.153.231.21][.9418] [Git][Unknown][Collaborative][Safe] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/gnutella.pcap.out b/test/results/flow-info/default/gnutella.pcap.out index 2cae94ef7..43e9501b7 100644 --- a/test/results/flow-info/default/gnutella.pcap.out +++ b/test/results/flow-info/default/gnutella.pcap.out @@ -1,81 +1,81 @@ DAEMON-EVENT: init ERROR-EVENT: Packet too short [1/16] - new: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffa4:e108] + new: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffa4:e108] detected: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffa4:e108] [ICMPV6][Unknown][Network][Acceptable] - new: [.....2] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::2] + new: [.....2] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::2] detected: [.....2] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] + new: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] detected: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] + new: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] detected: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....5] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....5] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][msedgewin10] - new: [.....6] [ip4][..udp] [.......10.0.2.2][...67] -> [......10.0.2.15][...68] + new: [.....6] [ip4][..udp] [.......10.0.2.2][...67] -> [......10.0.2.15][...68] detected: [.....6] [ip4][..udp] [.......10.0.2.2][...67] -> [......10.0.2.15][...68] [DHCP][Unknown][Network][Acceptable][] - new: [.....7] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][..546] -> [..............................ff02::1:2][..547] + new: [.....7] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][..546] -> [..............................ff02::1:2][..547] detected: [.....7] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] + new: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] detected: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [......10.0.2.15][.5353] -> [....224.0.0.251][.5353] + new: [.....9] [ip4][..udp] [......10.0.2.15][.5353] -> [....224.0.0.251][.5353] detected: [.....9] [ip4][..udp] [......10.0.2.15][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][msedgewin10.local] - new: [....10] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][.5353] -> [...............................ff02::fb][.5353] + new: [....10] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][.5353] -> [...............................ff02::fb][.5353] detected: [....10] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][msedgewin10.local] - new: [....11] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63717] -> [..............................ff02::1:3][.5355] + new: [....11] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63717] -> [..............................ff02::1:3][.5355] detected: [....11] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63717] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] detection-update: [.....9] [ip4][..udp] [......10.0.2.15][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][msedgewin10.local] - new: [....12] [ip4][..udp] [......10.0.2.15][63717] -> [....224.0.0.252][.5355] + new: [....12] [ip4][..udp] [......10.0.2.15][63717] -> [....224.0.0.252][.5355] detected: [....12] [ip4][..udp] [......10.0.2.15][63717] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] detection-update: [....10] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][msedgewin10.local] - new: [....13] [ip4][..udp] [......10.0.2.15][..137] -> [.....10.0.2.255][..137] + new: [....13] [ip4][..udp] [......10.0.2.15][..137] -> [.....10.0.2.255][..137] detected: [....13] [ip4][..udp] [......10.0.2.15][..137] -> [.....10.0.2.255][..137] [NetBIOS][Unknown][System][Acceptable][msedgewin10] - new: [....14] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] + new: [....14] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] detected: [....14] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] - new: [....15] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] + new: [....15] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] detected: [....15] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] - new: [....16] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] + new: [....16] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] detected: [....16] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....17] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63960] -> [................................ff02::c][.1900] + new: [....17] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63960] -> [................................ff02::c][.1900] detected: [....17] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63960] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable][[ff02::c]:1900] - new: [....18] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63965] -> [................................ff02::c][.3702] + new: [....18] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63965] -> [................................ff02::c][.3702] detected: [....18] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63965] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] - new: [....19] [ip4][..udp] [......10.0.2.15][63964] -> [239.255.255.250][.3702] + new: [....19] [ip4][..udp] [......10.0.2.15][63964] -> [239.255.255.250][.3702] detected: [....19] [ip4][..udp] [......10.0.2.15][63964] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] - new: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] + new: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] detected: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][msedgewin10] RISK: Unsafe Protocol - new: [....21] [ip4][..udp] [......10.0.2.15][55708] -> [239.255.255.250][.1900] + new: [....21] [ip4][..udp] [......10.0.2.15][55708] -> [239.255.255.250][.1900] detected: [....21] [ip4][..udp] [......10.0.2.15][55708] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....22] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][62539] -> [..............................ff02::1:3][.5355] + new: [....22] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][62539] -> [..............................ff02::1:3][.5355] detected: [....22] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][62539] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....23] [ip4][..udp] [......10.0.2.15][62539] -> [....224.0.0.252][.5355] + new: [....23] [ip4][..udp] [......10.0.2.15][62539] -> [....224.0.0.252][.5355] detected: [....23] [ip4][..udp] [......10.0.2.15][62539] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....24] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][50435] -> [..............................ff02::1:3][.5355] + new: [....24] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][50435] -> [..............................ff02::1:3][.5355] detected: [....24] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][50435] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] + new: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] detected: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [.....2] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] update: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] update: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] update: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffa4:e108] [ICMPV6][Unknown][Network][Acceptable] - new: [....26] [ip4][..udp] [......10.0.2.15][57619] -> [.......10.0.2.2][.5351] + new: [....26] [ip4][..udp] [......10.0.2.15][57619] -> [.......10.0.2.2][.5351] detected: [....26] [ip4][..udp] [......10.0.2.15][57619] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] + new: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] detected: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [....28] [ip4][..tcp] [......10.0.2.15][50190] -> [..80.140.63.147][29545] - new: [....29] [ip4][..tcp] [......10.0.2.15][50191] -> [.207.38.163.228][.6778] - new: [....30] [ip4][..tcp] [......10.0.2.15][50192] -> [....45.65.87.24][16201] - new: [....31] [ip4][..tcp] [......10.0.2.15][50193] -> [....89.75.52.19][46010] - new: [....32] [ip4][..tcp] [......10.0.2.15][50194] -> [..92.152.66.153][43771] - new: [....33] [ip4][..tcp] [......10.0.2.15][50195] -> [162.157.143.201][29762] - new: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] + new: [....28] [ip4][..tcp] [......10.0.2.15][50190] -> [..80.140.63.147][29545] + new: [....29] [ip4][..tcp] [......10.0.2.15][50191] -> [.207.38.163.228][.6778] + new: [....30] [ip4][..tcp] [......10.0.2.15][50192] -> [....45.65.87.24][16201] + new: [....31] [ip4][..tcp] [......10.0.2.15][50193] -> [....89.75.52.19][46010] + new: [....32] [ip4][..tcp] [......10.0.2.15][50194] -> [..92.152.66.153][43771] + new: [....33] [ip4][..tcp] [......10.0.2.15][50195] -> [162.157.143.201][29762] + new: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] detected: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [....35] [ip4][..tcp] [......10.0.2.15][50196] -> [...218.250.6.59][12556] - new: [....36] [ip4][..tcp] [......10.0.2.15][50197] -> [..118.168.15.71][.3931] - new: [....37] [ip4][..tcp] [......10.0.2.15][50198] -> [..86.129.196.84][.9915] - new: [....38] [ip4][..tcp] [......10.0.2.15][50199] -> [...47.147.52.21][36728] - new: [....39] [ip4][..tcp] [......10.0.2.15][50200] -> [176.128.217.128][45194] - new: [....40] [ip4][..tcp] [......10.0.2.15][50201] -> [..78.122.93.185][.6346] - new: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] + new: [....35] [ip4][..tcp] [......10.0.2.15][50196] -> [...218.250.6.59][12556] + new: [....36] [ip4][..tcp] [......10.0.2.15][50197] -> [..118.168.15.71][.3931] + new: [....37] [ip4][..tcp] [......10.0.2.15][50198] -> [..86.129.196.84][.9915] + new: [....38] [ip4][..tcp] [......10.0.2.15][50199] -> [...47.147.52.21][36728] + new: [....39] [ip4][..tcp] [......10.0.2.15][50200] -> [176.128.217.128][45194] + new: [....40] [ip4][..tcp] [......10.0.2.15][50201] -> [..78.122.93.185][.6346] + new: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] detected: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] detected: [....38] [ip4][..tcp] [......10.0.2.15][50199] -> [...47.147.52.21][36728] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol @@ -83,74 +83,74 @@ RISK: Unsafe Protocol detected: [....36] [ip4][..tcp] [......10.0.2.15][50197] -> [..118.168.15.71][.3931] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....42] [ip4][..tcp] [......10.0.2.15][50202] -> [.61.238.173.128][57648] - new: [....43] [ip4][..tcp] [......10.0.2.15][50203] -> [..61.222.160.99][18994] - new: [....44] [ip4][..tcp] [......10.0.2.15][50204] -> [..124.218.26.16][.9728] - new: [....45] [ip4][..tcp] [......10.0.2.15][50205] -> [.114.46.139.171][52120] - new: [....46] [ip4][..tcp] [......10.0.2.15][50206] -> [175.181.156.244][.8255] - new: [....47] [ip4][..tcp] [......10.0.2.15][50207] -> [..90.78.171.204][.6346] + new: [....42] [ip4][..tcp] [......10.0.2.15][50202] -> [.61.238.173.128][57648] + new: [....43] [ip4][..tcp] [......10.0.2.15][50203] -> [..61.222.160.99][18994] + new: [....44] [ip4][..tcp] [......10.0.2.15][50204] -> [..124.218.26.16][.9728] + new: [....45] [ip4][..tcp] [......10.0.2.15][50205] -> [.114.46.139.171][52120] + new: [....46] [ip4][..tcp] [......10.0.2.15][50206] -> [175.181.156.244][.8255] + new: [....47] [ip4][..tcp] [......10.0.2.15][50207] -> [..90.78.171.204][.6346] detected: [....43] [ip4][..tcp] [......10.0.2.15][50203] -> [..61.222.160.99][18994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [....46] [ip4][..tcp] [......10.0.2.15][50206] -> [175.181.156.244][.8255] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....48] [ip4][..tcp] [......10.0.2.15][50208] -> [.119.237.116.22][.8683] - new: [....49] [ip4][..tcp] [......10.0.2.15][50209] -> [113.252.206.254][49587] - new: [....50] [ip4][..tcp] [......10.0.2.15][50210] -> [..36.234.18.166][61404] - new: [....51] [ip4][..tcp] [......10.0.2.15][50211] -> [...14.199.10.60][23458] - new: [....52] [ip4][..tcp] [......10.0.2.15][50212] -> [...95.17.124.40][.6776] - new: [....53] [ip4][..tcp] [......10.0.2.15][50213] -> [...85.117.153.7][50138] - new: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] + new: [....48] [ip4][..tcp] [......10.0.2.15][50208] -> [.119.237.116.22][.8683] + new: [....49] [ip4][..tcp] [......10.0.2.15][50209] -> [113.252.206.254][49587] + new: [....50] [ip4][..tcp] [......10.0.2.15][50210] -> [..36.234.18.166][61404] + new: [....51] [ip4][..tcp] [......10.0.2.15][50211] -> [...14.199.10.60][23458] + new: [....52] [ip4][..tcp] [......10.0.2.15][50212] -> [...95.17.124.40][.6776] + new: [....53] [ip4][..tcp] [......10.0.2.15][50213] -> [...85.117.153.7][50138] + new: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] detected: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] detected: [....51] [ip4][..tcp] [......10.0.2.15][50211] -> [...14.199.10.60][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....55] [ip4][..tcp] [......10.0.2.15][50214] -> [.80.193.171.146][53808] - new: [....56] [ip4][..tcp] [......10.0.2.15][50215] -> [.124.244.64.237][.4704] - new: [....57] [ip4][..tcp] [......10.0.2.15][50216] -> [182.155.128.228][.3256] - new: [....58] [ip4][..tcp] [......10.0.2.15][50217] -> [.113.252.86.162][54958] - new: [....59] [ip4][..tcp] [......10.0.2.15][50218] -> [..90.103.247.94][59045] - new: [....60] [ip4][..tcp] [......10.0.2.15][50219] -> [.193.121.165.12][55376] - new: [....61] [ip4][..tcp] [......10.0.2.15][50220] -> [.36.233.196.226][.3820] - new: [....62] [ip4][..tcp] [......10.0.2.15][50221] -> [...59.104.173.5][49956] - new: [....63] [ip4][..tcp] [......10.0.2.15][50222] -> [.119.14.143.237][.6523] - new: [....64] [ip4][..tcp] [......10.0.2.15][50223] -> [118.167.248.220][63108] - new: [....65] [ip4][..tcp] [......10.0.2.15][50224] -> [...78.125.63.97][.6346] - new: [....66] [ip4][..tcp] [......10.0.2.15][50225] -> [.109.210.81.147][24800] - new: [....67] [ip4][..tcp] [......10.0.2.15][50226] -> [116.241.162.162][15677] - new: [....68] [ip4][..tcp] [......10.0.2.15][50227] -> [.111.246.157.94][51175] - new: [....69] [ip4][..tcp] [......10.0.2.15][50228] -> [..111.241.31.96][14384] - new: [....70] [ip4][..tcp] [......10.0.2.15][50229] -> [....1.36.249.91][64920] - new: [....71] [ip4][..tcp] [......10.0.2.15][50230] -> [....73.3.103.37][17296] - new: [....72] [ip4][..tcp] [......10.0.2.15][50231] -> [..76.68.138.207][45079] + new: [....55] [ip4][..tcp] [......10.0.2.15][50214] -> [.80.193.171.146][53808] + new: [....56] [ip4][..tcp] [......10.0.2.15][50215] -> [.124.244.64.237][.4704] + new: [....57] [ip4][..tcp] [......10.0.2.15][50216] -> [182.155.128.228][.3256] + new: [....58] [ip4][..tcp] [......10.0.2.15][50217] -> [.113.252.86.162][54958] + new: [....59] [ip4][..tcp] [......10.0.2.15][50218] -> [..90.103.247.94][59045] + new: [....60] [ip4][..tcp] [......10.0.2.15][50219] -> [.193.121.165.12][55376] + new: [....61] [ip4][..tcp] [......10.0.2.15][50220] -> [.36.233.196.226][.3820] + new: [....62] [ip4][..tcp] [......10.0.2.15][50221] -> [...59.104.173.5][49956] + new: [....63] [ip4][..tcp] [......10.0.2.15][50222] -> [.119.14.143.237][.6523] + new: [....64] [ip4][..tcp] [......10.0.2.15][50223] -> [118.167.248.220][63108] + new: [....65] [ip4][..tcp] [......10.0.2.15][50224] -> [...78.125.63.97][.6346] + new: [....66] [ip4][..tcp] [......10.0.2.15][50225] -> [.109.210.81.147][24800] + new: [....67] [ip4][..tcp] [......10.0.2.15][50226] -> [116.241.162.162][15677] + new: [....68] [ip4][..tcp] [......10.0.2.15][50227] -> [.111.246.157.94][51175] + new: [....69] [ip4][..tcp] [......10.0.2.15][50228] -> [..111.241.31.96][14384] + new: [....70] [ip4][..tcp] [......10.0.2.15][50229] -> [....1.36.249.91][64920] + new: [....71] [ip4][..tcp] [......10.0.2.15][50230] -> [....73.3.103.37][17296] + new: [....72] [ip4][..tcp] [......10.0.2.15][50231] -> [..76.68.138.207][45079] detected: [....67] [ip4][..tcp] [......10.0.2.15][50226] -> [116.241.162.162][15677] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....73] [ip4][..tcp] [......10.0.2.15][50232] -> [182.155.242.225][15068] - new: [....74] [ip4][..tcp] [......10.0.2.15][50233] -> [...1.163.14.246][12854] - new: [....75] [ip4][..tcp] [......10.0.2.15][50234] -> [...66.189.28.17][16269] - new: [....76] [ip4][..tcp] [......10.0.2.15][50235] -> [...45.88.118.70][.6906] - new: [....77] [ip4][..tcp] [......10.0.2.15][50236] -> [..93.29.135.209][.6346] - new: [....78] [ip4][..tcp] [......10.0.2.15][50237] -> [.88.123.202.175][37910] + new: [....73] [ip4][..tcp] [......10.0.2.15][50232] -> [182.155.242.225][15068] + new: [....74] [ip4][..tcp] [......10.0.2.15][50233] -> [...1.163.14.246][12854] + new: [....75] [ip4][..tcp] [......10.0.2.15][50234] -> [...66.189.28.17][16269] + new: [....76] [ip4][..tcp] [......10.0.2.15][50235] -> [...45.88.118.70][.6906] + new: [....77] [ip4][..tcp] [......10.0.2.15][50236] -> [..93.29.135.209][.6346] + new: [....78] [ip4][..tcp] [......10.0.2.15][50237] -> [.88.123.202.175][37910] detected: [....77] [ip4][..tcp] [......10.0.2.15][50236] -> [..93.29.135.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [....76] [ip4][..tcp] [......10.0.2.15][50235] -> [...45.88.118.70][.6906] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [....73] [ip4][..tcp] [......10.0.2.15][50232] -> [182.155.242.225][15068] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....79] [ip4][..tcp] [......10.0.2.15][50238] -> [.124.218.41.253][59144] - new: [....80] [ip4][..tcp] [......10.0.2.15][50239] -> [...112.105.52.2][.6384] - new: [....81] [ip4][..tcp] [......10.0.2.15][50240] -> [..36.237.10.152][21293] - new: [....82] [ip4][..tcp] [......10.0.2.15][50241] -> [..98.18.172.208][63172] - new: [....83] [ip4][..tcp] [......10.0.2.15][50242] -> [109.210.203.131][.6346] - new: [....84] [ip4][..tcp] [......10.0.2.15][50243] -> [176.138.129.252][27962] - new: [....85] [ip4][..udp] [......10.0.2.15][28681] -> [..85.138.20.110][.6346] + new: [....79] [ip4][..tcp] [......10.0.2.15][50238] -> [.124.218.41.253][59144] + new: [....80] [ip4][..tcp] [......10.0.2.15][50239] -> [...112.105.52.2][.6384] + new: [....81] [ip4][..tcp] [......10.0.2.15][50240] -> [..36.237.10.152][21293] + new: [....82] [ip4][..tcp] [......10.0.2.15][50241] -> [..98.18.172.208][63172] + new: [....83] [ip4][..tcp] [......10.0.2.15][50242] -> [109.210.203.131][.6346] + new: [....84] [ip4][..tcp] [......10.0.2.15][50243] -> [176.138.129.252][27962] + new: [....85] [ip4][..udp] [......10.0.2.15][28681] -> [..85.138.20.110][.6346] detected: [....85] [ip4][..udp] [......10.0.2.15][28681] -> [..85.138.20.110][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....86] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] + new: [....86] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] detected: [....86] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....87] [ip4][..udp] [......10.0.2.15][28681] -> [..92.131.85.245][31743] + new: [....87] [ip4][..udp] [......10.0.2.15][28681] -> [..92.131.85.245][31743] detected: [....87] [ip4][..udp] [......10.0.2.15][28681] -> [..92.131.85.245][31743] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....88] [ip4][..udp] [......10.0.2.15][28681] -> [.....81.50.24.2][17874] + new: [....88] [ip4][..udp] [......10.0.2.15][28681] -> [.....81.50.24.2][17874] detected: [....88] [ip4][..udp] [......10.0.2.15][28681] -> [.....81.50.24.2][17874] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....15] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] @@ -169,168 +169,168 @@ update: [.....7] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [......10.0.2.15][63717] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....11] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63717] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....89] [ip4][..tcp] [......10.0.2.15][50244] -> [..188.61.52.183][63978] - new: [....90] [ip4][..tcp] [......10.0.2.15][50245] -> [..73.62.225.181][46843] - new: [....91] [ip4][..tcp] [......10.0.2.15][50246] -> [...80.7.252.192][45685] - new: [....92] [ip4][..tcp] [......10.0.2.15][50247] -> [..66.30.221.181][51560] - new: [....93] [ip4][..tcp] [......10.0.2.15][50248] -> [109.214.154.216][.6346] - new: [....94] [ip4][..tcp] [......10.0.2.15][50249] -> [.86.208.180.181][45883] - new: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] + new: [....89] [ip4][..tcp] [......10.0.2.15][50244] -> [..188.61.52.183][63978] + new: [....90] [ip4][..tcp] [......10.0.2.15][50245] -> [..73.62.225.181][46843] + new: [....91] [ip4][..tcp] [......10.0.2.15][50246] -> [...80.7.252.192][45685] + new: [....92] [ip4][..tcp] [......10.0.2.15][50247] -> [..66.30.221.181][51560] + new: [....93] [ip4][..tcp] [......10.0.2.15][50248] -> [109.214.154.216][.6346] + new: [....94] [ip4][..tcp] [......10.0.2.15][50249] -> [.86.208.180.181][45883] + new: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] detected: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] detected: [....94] [ip4][..tcp] [......10.0.2.15][50249] -> [.86.208.180.181][45883] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....96] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] + new: [....96] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] detected: [....96] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....97] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] + new: [....97] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] detected: [....97] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....98] [ip4][..udp] [......10.0.2.15][28681] -> [.203.222.14.170][23332] + new: [....98] [ip4][..udp] [......10.0.2.15][28681] -> [.203.222.14.170][23332] detected: [....98] [ip4][..udp] [......10.0.2.15][28681] -> [.203.222.14.170][23332] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [....99] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] + new: [....99] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] detected: [....99] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...100] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] + new: [...100] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] detected: [...100] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...101] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + new: [...101] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] detected: [...101] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...102] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] + new: [...102] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] detected: [...102] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...103] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] + new: [...103] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] detected: [...103] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...104] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] + new: [...104] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] detected: [...104] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...105] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + new: [...105] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] detected: [...105] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...106] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.154.69][.4832] + new: [...106] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.154.69][.4832] detected: [...106] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.154.69][.4832] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...107] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] + new: [...107] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] detected: [...107] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...108] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][.7922] + new: [...108] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][.7922] detected: [...108] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][.7922] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...109] [ip4][..udp] [......10.0.2.15][28681] -> [...88.169.2.153][52414] + new: [...109] [ip4][..udp] [......10.0.2.15][28681] -> [...88.169.2.153][52414] detected: [...109] [ip4][..udp] [......10.0.2.15][28681] -> [...88.169.2.153][52414] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...110] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] + new: [...110] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] detected: [...110] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] + new: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] detected: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...112] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] + new: [...112] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] detected: [...112] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...113] [ip4][..udp] [......10.0.2.15][28681] -> [105.101.132.146][57746] + new: [...113] [ip4][..udp] [......10.0.2.15][28681] -> [105.101.132.146][57746] detected: [...113] [ip4][..udp] [......10.0.2.15][28681] -> [105.101.132.146][57746] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...114] [ip4][..udp] [......10.0.2.15][28681] -> [....86.23.75.69][.6346] + new: [...114] [ip4][..udp] [......10.0.2.15][28681] -> [....86.23.75.69][.6346] detected: [...114] [ip4][..udp] [......10.0.2.15][28681] -> [....86.23.75.69][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...115] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.104][11804] + new: [...115] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.104][11804] detected: [...115] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.104][11804] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] + new: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] detected: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...117] [ip4][..udp] [......10.0.2.15][28681] -> [200.120.243.143][.6346] + new: [...117] [ip4][..udp] [......10.0.2.15][28681] -> [200.120.243.143][.6346] detected: [...117] [ip4][..udp] [......10.0.2.15][28681] -> [200.120.243.143][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...118] [ip4][..udp] [......10.0.2.15][28681] -> [...5.180.62.100][46385] + new: [...118] [ip4][..udp] [......10.0.2.15][28681] -> [...5.180.62.100][46385] detected: [...118] [ip4][..udp] [......10.0.2.15][28681] -> [...5.180.62.100][46385] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [....93] [ip4][..tcp] [......10.0.2.15][50248] -> [109.214.154.216][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...119] [ip4][..tcp] [......10.0.2.15][50250] -> [...27.94.154.53][.6346] - new: [...120] [ip4][..tcp] [......10.0.2.15][50251] -> [...24.127.1.235][37814] - new: [...121] [ip4][..tcp] [......10.0.2.15][50252] -> [.123.202.31.113][19768] - new: [...122] [ip4][..tcp] [......10.0.2.15][50253] -> [103.232.107.100][43508] - new: [...123] [ip4][..tcp] [......10.0.2.15][50254] -> [..24.78.134.188][49046] + new: [...119] [ip4][..tcp] [......10.0.2.15][50250] -> [...27.94.154.53][.6346] + new: [...120] [ip4][..tcp] [......10.0.2.15][50251] -> [...24.127.1.235][37814] + new: [...121] [ip4][..tcp] [......10.0.2.15][50252] -> [.123.202.31.113][19768] + new: [...122] [ip4][..tcp] [......10.0.2.15][50253] -> [103.232.107.100][43508] + new: [...123] [ip4][..tcp] [......10.0.2.15][50254] -> [..24.78.134.188][49046] detected: [...119] [ip4][..tcp] [......10.0.2.15][50250] -> [...27.94.154.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...121] [ip4][..tcp] [......10.0.2.15][50252] -> [.123.202.31.113][19768] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...122] [ip4][..tcp] [......10.0.2.15][50253] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...124] [ip4][..udp] [......10.0.2.15][28681] -> [...170.254.19.6][24180] + new: [...124] [ip4][..udp] [......10.0.2.15][28681] -> [...170.254.19.6][24180] detected: [...124] [ip4][..udp] [......10.0.2.15][28681] -> [...170.254.19.6][24180] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] + new: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] detected: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...126] [ip4][..udp] [......10.0.2.15][28681] -> [..91.69.159.133][28000] + new: [...126] [ip4][..udp] [......10.0.2.15][28681] -> [..91.69.159.133][28000] detected: [...126] [ip4][..udp] [......10.0.2.15][28681] -> [..91.69.159.133][28000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...127] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.1024] + new: [...127] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.1024] detected: [...127] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.1024] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...128] [ip4][..udp] [......10.0.2.15][28681] -> [..77.141.219.27][37580] + new: [...128] [ip4][..udp] [......10.0.2.15][28681] -> [..77.141.219.27][37580] detected: [...128] [ip4][..udp] [......10.0.2.15][28681] -> [..77.141.219.27][37580] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...129] [ip4][..udp] [......10.0.2.15][28681] -> [.176.138.50.179][29411] + new: [...129] [ip4][..udp] [......10.0.2.15][28681] -> [.176.138.50.179][29411] detected: [...129] [ip4][..udp] [......10.0.2.15][28681] -> [.176.138.50.179][29411] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...130] [ip4][..udp] [......10.0.2.15][28681] -> [..119.224.95.97][46356] + new: [...130] [ip4][..udp] [......10.0.2.15][28681] -> [..119.224.95.97][46356] detected: [...130] [ip4][..udp] [......10.0.2.15][28681] -> [..119.224.95.97][46356] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...131] [ip4][..udp] [......10.0.2.15][28681] -> [.86.225.140.186][.6346] + new: [...131] [ip4][..udp] [......10.0.2.15][28681] -> [.86.225.140.186][.6346] detected: [...131] [ip4][..udp] [......10.0.2.15][28681] -> [.86.225.140.186][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...132] [ip4][..udp] [......10.0.2.15][28681] -> [...79.86.173.45][.6346] + new: [...132] [ip4][..udp] [......10.0.2.15][28681] -> [...79.86.173.45][.6346] detected: [...132] [ip4][..udp] [......10.0.2.15][28681] -> [...79.86.173.45][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...133] [ip4][..udp] [......10.0.2.15][28681] -> [.91.175.220.161][15721] + new: [...133] [ip4][..udp] [......10.0.2.15][28681] -> [.91.175.220.161][15721] detected: [...133] [ip4][..udp] [......10.0.2.15][28681] -> [.91.175.220.161][15721] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...134] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] + new: [...134] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] detected: [...134] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...135] [ip4][..udp] [......10.0.2.15][28681] -> [.193.250.99.158][.6346] + new: [...135] [ip4][..udp] [......10.0.2.15][28681] -> [.193.250.99.158][.6346] detected: [...135] [ip4][..udp] [......10.0.2.15][28681] -> [.193.250.99.158][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...136] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][16047] + new: [...136] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][16047] detected: [...136] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][16047] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...137] [ip4][..udp] [......10.0.2.15][28681] -> [...82.65.70.197][21693] + new: [...137] [ip4][..udp] [......10.0.2.15][28681] -> [...82.65.70.197][21693] detected: [...137] [ip4][..udp] [......10.0.2.15][28681] -> [...82.65.70.197][21693] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] + new: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] detected: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...139] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.226.142][.6346] + new: [...139] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.226.142][.6346] detected: [...139] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.226.142][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...140] [ip4][..udp] [......10.0.2.15][28681] -> [.77.197.111.186][.6346] + new: [...140] [ip4][..udp] [......10.0.2.15][28681] -> [.77.197.111.186][.6346] detected: [...140] [ip4][..udp] [......10.0.2.15][28681] -> [.77.197.111.186][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...141] [ip4][..udp] [......10.0.2.15][28681] -> [..172.97.199.14][.6346] + new: [...141] [ip4][..udp] [......10.0.2.15][28681] -> [..172.97.199.14][.6346] detected: [...141] [ip4][..udp] [......10.0.2.15][28681] -> [..172.97.199.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...142] [ip4][..tcp] [......10.0.2.15][50255] -> [..36.236.203.37][52165] - new: [...143] [ip4][..tcp] [......10.0.2.15][50256] -> [.36.233.201.161][.2886] - new: [...144] [ip4][..tcp] [......10.0.2.15][50257] -> [...219.70.48.23][.3054] - new: [...145] [ip4][..tcp] [......10.0.2.15][50258] -> [122.100.216.210][.7097] - new: [...146] [ip4][..tcp] [......10.0.2.15][50259] -> [.183.179.90.112][.9852] - new: [...147] [ip4][..tcp] [......10.0.2.15][50260] -> [113.255.200.161][51394] - new: [...148] [ip4][..tcp] [......10.0.2.15][50261] -> [....156.57.42.2][33476] - new: [...149] [ip4][..tcp] [......10.0.2.15][50262] -> [..80.61.221.246][30577] + new: [...142] [ip4][..tcp] [......10.0.2.15][50255] -> [..36.236.203.37][52165] + new: [...143] [ip4][..tcp] [......10.0.2.15][50256] -> [.36.233.201.161][.2886] + new: [...144] [ip4][..tcp] [......10.0.2.15][50257] -> [...219.70.48.23][.3054] + new: [...145] [ip4][..tcp] [......10.0.2.15][50258] -> [122.100.216.210][.7097] + new: [...146] [ip4][..tcp] [......10.0.2.15][50259] -> [.183.179.90.112][.9852] + new: [...147] [ip4][..tcp] [......10.0.2.15][50260] -> [113.255.200.161][51394] + new: [...148] [ip4][..tcp] [......10.0.2.15][50261] -> [....156.57.42.2][33476] + new: [...149] [ip4][..tcp] [......10.0.2.15][50262] -> [..80.61.221.246][30577] detected: [...149] [ip4][..tcp] [......10.0.2.15][50262] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...146] [ip4][..tcp] [......10.0.2.15][50259] -> [.183.179.90.112][.9852] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...150] [ip4][..tcp] [......10.0.2.15][50263] -> [..73.182.136.42][27873] - new: [...151] [ip4][..tcp] [......10.0.2.15][50264] -> [...95.10.205.67][48380] - new: [...152] [ip4][..tcp] [......10.0.2.15][50265] -> [.113.255.250.32][52647] - new: [...153] [ip4][..tcp] [......10.0.2.15][50266] -> [.219.70.175.103][.4315] + new: [...150] [ip4][..tcp] [......10.0.2.15][50263] -> [..73.182.136.42][27873] + new: [...151] [ip4][..tcp] [......10.0.2.15][50264] -> [...95.10.205.67][48380] + new: [...152] [ip4][..tcp] [......10.0.2.15][50265] -> [.113.255.250.32][52647] + new: [...153] [ip4][..tcp] [......10.0.2.15][50266] -> [.219.70.175.103][.4315] detected: [...148] [ip4][..tcp] [......10.0.2.15][50261] -> [....156.57.42.2][33476] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [....37] [ip4][..tcp] [......10.0.2.15][50198] -> [..86.129.196.84][.9915] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -339,334 +339,334 @@ update: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] update: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] update: [.....1] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ffa4:e108] [ICMPV6][Unknown][Network][Acceptable] - new: [...154] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.111.224][51984] + new: [...154] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.111.224][51984] detected: [...154] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.111.224][51984] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...155] [ip4][..udp] [......10.0.2.15][28681] -> [.88.168.182.103][.6346] + new: [...155] [ip4][..udp] [......10.0.2.15][28681] -> [.88.168.182.103][.6346] detected: [...155] [ip4][..udp] [......10.0.2.15][28681] -> [.88.168.182.103][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] + new: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] detected: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] + new: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] detected: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] + new: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] detected: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] + new: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] detected: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] + new: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] detected: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] + new: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] detected: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...162] [ip4][..udp] [......10.0.2.15][28681] -> [.88.123.159.111][44729] + new: [...162] [ip4][..udp] [......10.0.2.15][28681] -> [.88.123.159.111][44729] detected: [...162] [ip4][..udp] [......10.0.2.15][28681] -> [.88.123.159.111][44729] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...163] [ip4][..udp] [......10.0.2.15][28681] -> [.88.126.160.158][.6346] + new: [...163] [ip4][..udp] [......10.0.2.15][28681] -> [.88.126.160.158][.6346] detected: [...163] [ip4][..udp] [......10.0.2.15][28681] -> [.88.126.160.158][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...164] [ip4][..udp] [......10.0.2.15][28681] -> [.142.197.219.85][26234] + new: [...164] [ip4][..udp] [......10.0.2.15][28681] -> [.142.197.219.85][26234] detected: [...164] [ip4][..udp] [......10.0.2.15][28681] -> [.142.197.219.85][26234] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...165] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] + new: [...165] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] detected: [...165] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] + new: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] detected: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] + new: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] detected: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...168] [ip4][..udp] [......10.0.2.15][28681] -> [...89.157.59.43][56919] + new: [...168] [ip4][..udp] [......10.0.2.15][28681] -> [...89.157.59.43][56919] detected: [...168] [ip4][..udp] [......10.0.2.15][28681] -> [...89.157.59.43][56919] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...169] [ip4][..udp] [......10.0.2.15][28681] -> [...91.162.52.93][34799] + new: [...169] [ip4][..udp] [......10.0.2.15][28681] -> [...91.162.52.93][34799] detected: [...169] [ip4][..udp] [......10.0.2.15][28681] -> [...91.162.52.93][34799] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...170] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] + new: [...170] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] detected: [...170] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] + new: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] detected: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] + new: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] detected: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...173] [ip4][..udp] [......10.0.2.15][28681] -> [..121.99.222.36][44988] + new: [...173] [ip4][..udp] [......10.0.2.15][28681] -> [..121.99.222.36][44988] detected: [...173] [ip4][..udp] [......10.0.2.15][28681] -> [..121.99.222.36][44988] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...174] [ip4][..udp] [......10.0.2.15][28681] -> [..196.74.159.56][29271] + new: [...174] [ip4][..udp] [......10.0.2.15][28681] -> [..196.74.159.56][29271] detected: [...174] [ip4][..udp] [......10.0.2.15][28681] -> [..196.74.159.56][29271] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] + new: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] detected: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] + new: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] detected: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...177] [ip4][..udp] [......10.0.2.15][28681] -> [.69.157.183.106][.6346] + new: [...177] [ip4][..udp] [......10.0.2.15][28681] -> [.69.157.183.106][.6346] detected: [...177] [ip4][..udp] [......10.0.2.15][28681] -> [.69.157.183.106][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...178] [ip4][..udp] [......10.0.2.15][28681] -> [....83.46.253.7][.6346] + new: [...178] [ip4][..udp] [......10.0.2.15][28681] -> [....83.46.253.7][.6346] detected: [...178] [ip4][..udp] [......10.0.2.15][28681] -> [....83.46.253.7][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...179] [ip4][..udp] [......10.0.2.15][28681] -> [.178.51.146.115][.6346] + new: [...179] [ip4][..udp] [......10.0.2.15][28681] -> [.178.51.146.115][.6346] detected: [...179] [ip4][..udp] [......10.0.2.15][28681] -> [.178.51.146.115][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...180] [ip4][..udp] [......10.0.2.15][28681] -> [...66.131.24.72][30711] + new: [...180] [ip4][..udp] [......10.0.2.15][28681] -> [...66.131.24.72][30711] detected: [...180] [ip4][..udp] [......10.0.2.15][28681] -> [...66.131.24.72][30711] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...181] [ip4][..udp] [......10.0.2.15][28681] -> [...66.177.5.135][.6346] + new: [...181] [ip4][..udp] [......10.0.2.15][28681] -> [...66.177.5.135][.6346] detected: [...181] [ip4][..udp] [......10.0.2.15][28681] -> [...66.177.5.135][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...182] [ip4][..udp] [......10.0.2.15][28681] -> [....73.3.103.37][35589] + new: [...182] [ip4][..udp] [......10.0.2.15][28681] -> [....73.3.103.37][35589] detected: [...182] [ip4][..udp] [......10.0.2.15][28681] -> [....73.3.103.37][35589] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...183] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.15.182][37829] + new: [...183] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.15.182][37829] detected: [...183] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.15.182][37829] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] + new: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] detected: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] + new: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] detected: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...186] [ip4][..udp] [......10.0.2.15][28681] -> [..91.182.44.202][30277] + new: [...186] [ip4][..udp] [......10.0.2.15][28681] -> [..91.182.44.202][30277] detected: [...186] [ip4][..udp] [......10.0.2.15][28681] -> [..91.182.44.202][30277] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] + new: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] detected: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...188] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] + new: [...188] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] detected: [...188] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...189] [ip4][..udp] [......10.0.2.15][28681] -> [115.195.105.243][.6346] + new: [...189] [ip4][..udp] [......10.0.2.15][28681] -> [115.195.105.243][.6346] detected: [...189] [ip4][..udp] [......10.0.2.15][28681] -> [115.195.105.243][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] + new: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] detected: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] + new: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] detected: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...192] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] + new: [...192] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] detected: [...192] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...193] [ip4][..udp] [......10.0.2.15][28681] -> [..188.44.126.74][54633] + new: [...193] [ip4][..udp] [......10.0.2.15][28681] -> [..188.44.126.74][54633] detected: [...193] [ip4][..udp] [......10.0.2.15][28681] -> [..188.44.126.74][54633] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...194] [ip4][..udp] [......10.0.2.15][28681] -> [176.150.126.156][16471] + new: [...194] [ip4][..udp] [......10.0.2.15][28681] -> [176.150.126.156][16471] detected: [...194] [ip4][..udp] [......10.0.2.15][28681] -> [176.150.126.156][16471] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] + new: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] detected: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...196] [ip4][..udp] [......10.0.2.15][28681] -> [..88.127.72.106][.6346] + new: [...196] [ip4][..udp] [......10.0.2.15][28681] -> [..88.127.72.106][.6346] detected: [...196] [ip4][..udp] [......10.0.2.15][28681] -> [..88.127.72.106][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...197] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] + new: [...197] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] detected: [...197] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...198] [ip4][..udp] [......10.0.2.15][28681] -> [..58.182.171.50][15180] + new: [...198] [ip4][..udp] [......10.0.2.15][28681] -> [..58.182.171.50][15180] detected: [...198] [ip4][..udp] [......10.0.2.15][28681] -> [..58.182.171.50][15180] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...199] [ip4][..udp] [......10.0.2.15][28681] -> [..114.73.129.26][53585] + new: [...199] [ip4][..udp] [......10.0.2.15][28681] -> [..114.73.129.26][53585] detected: [...199] [ip4][..udp] [......10.0.2.15][28681] -> [..114.73.129.26][53585] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] + new: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] detected: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...201] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] + new: [...201] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] detected: [...201] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...202] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] + new: [...202] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] detected: [...202] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...203] [ip4][..udp] [......10.0.2.15][28681] -> [.120.156.204.38][54832] + new: [...203] [ip4][..udp] [......10.0.2.15][28681] -> [.120.156.204.38][54832] detected: [...203] [ip4][..udp] [......10.0.2.15][28681] -> [.120.156.204.38][54832] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...204] [ip4][..udp] [......10.0.2.15][28681] -> [..84.126.240.32][45313] + new: [...204] [ip4][..udp] [......10.0.2.15][28681] -> [..84.126.240.32][45313] detected: [...204] [ip4][..udp] [......10.0.2.15][28681] -> [..84.126.240.32][45313] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...205] [ip4][..udp] [......10.0.2.15][28681] -> [..96.29.197.138][.6346] + new: [...205] [ip4][..udp] [......10.0.2.15][28681] -> [..96.29.197.138][.6346] detected: [...205] [ip4][..udp] [......10.0.2.15][28681] -> [..96.29.197.138][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...206] [ip4][..udp] [......10.0.2.15][28681] -> [213.166.132.204][11194] + new: [...206] [ip4][..udp] [......10.0.2.15][28681] -> [213.166.132.204][11194] detected: [...206] [ip4][..udp] [......10.0.2.15][28681] -> [213.166.132.204][11194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...207] [ip4][..udp] [......10.0.2.15][28681] -> [.81.242.191.215][.6346] + new: [...207] [ip4][..udp] [......10.0.2.15][28681] -> [.81.242.191.215][.6346] detected: [...207] [ip4][..udp] [......10.0.2.15][28681] -> [.81.242.191.215][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...208] [ip4][..udp] [......10.0.2.15][28681] -> [..81.249.64.215][25058] + new: [...208] [ip4][..udp] [......10.0.2.15][28681] -> [..81.249.64.215][25058] detected: [...208] [ip4][..udp] [......10.0.2.15][28681] -> [..81.249.64.215][25058] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] + new: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] detected: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...210] [ip4][..udp] [......10.0.2.15][28681] -> [.41.100.120.146][12838] + new: [...210] [ip4][..udp] [......10.0.2.15][28681] -> [.41.100.120.146][12838] detected: [...210] [ip4][..udp] [......10.0.2.15][28681] -> [.41.100.120.146][12838] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...211] [ip4][..udp] [......10.0.2.15][28681] -> [..186.93.139.92][.6346] + new: [...211] [ip4][..udp] [......10.0.2.15][28681] -> [..186.93.139.92][.6346] detected: [...211] [ip4][..udp] [......10.0.2.15][28681] -> [..186.93.139.92][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...212] [ip4][..udp] [......10.0.2.15][28681] -> [...36.233.3.223][12848] + new: [...212] [ip4][..udp] [......10.0.2.15][28681] -> [...36.233.3.223][12848] detected: [...212] [ip4][..udp] [......10.0.2.15][28681] -> [...36.233.3.223][12848] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] + new: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] detected: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...214] [ip4][..udp] [......10.0.2.15][28681] -> [.91.169.215.227][26820] + new: [...214] [ip4][..udp] [......10.0.2.15][28681] -> [.91.169.215.227][26820] detected: [...214] [ip4][..udp] [......10.0.2.15][28681] -> [.91.169.215.227][26820] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...215] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] + new: [...215] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] detected: [...215] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...216] [ip4][..udp] [......10.0.2.15][28681] -> [.212.68.248.153][27223] + new: [...216] [ip4][..udp] [......10.0.2.15][28681] -> [.212.68.248.153][27223] detected: [...216] [ip4][..udp] [......10.0.2.15][28681] -> [.212.68.248.153][27223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] + new: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] detected: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...218] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.52.115][53956] + new: [...218] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.52.115][53956] detected: [...218] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.52.115][53956] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] + new: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] detected: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] - new: [...221] [ip4][..tcp] [......10.0.2.15][50267] -> [.113.252.86.162][.9239] + new: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] + new: [...221] [ip4][..tcp] [......10.0.2.15][50267] -> [.113.252.86.162][.9239] detected: [...221] [ip4][..tcp] [......10.0.2.15][50267] -> [.113.252.86.162][.9239] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...222] [ip4][..tcp] [......10.0.2.15][50268] -> [.210.209.249.84][24751] - new: [...223] [ip4][..tcp] [......10.0.2.15][50269] -> [..218.103.139.2][.3186] - new: [...224] [ip4][..tcp] [......10.0.2.15][50270] -> [...114.27.24.95][11427] - new: [...225] [ip4][..tcp] [......10.0.2.15][50271] -> [.218.164.198.27][60202] + new: [...222] [ip4][..tcp] [......10.0.2.15][50268] -> [.210.209.249.84][24751] + new: [...223] [ip4][..tcp] [......10.0.2.15][50269] -> [..218.103.139.2][.3186] + new: [...224] [ip4][..tcp] [......10.0.2.15][50270] -> [...114.27.24.95][11427] + new: [...225] [ip4][..tcp] [......10.0.2.15][50271] -> [.218.164.198.27][60202] detected: [...222] [ip4][..tcp] [......10.0.2.15][50268] -> [.210.209.249.84][24751] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...223] [ip4][..tcp] [......10.0.2.15][50269] -> [..218.103.139.2][.3186] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...226] [ip4][..tcp] [......10.0.2.15][50272] -> [...1.172.184.48][13298] - new: [...227] [ip4][..tcp] [......10.0.2.15][50273] -> [..24.179.18.242][47329] - new: [...228] [ip4][..tcp] [......10.0.2.15][50274] -> [..68.174.18.115][50679] - new: [...229] [ip4][..tcp] [......10.0.2.15][50275] -> [.122.117.100.78][.9010] - new: [...230] [ip4][..tcp] [......10.0.2.15][50276] -> [.96.246.156.126][56070] - new: [...231] [ip4][..tcp] [......10.0.2.15][50277] -> [.82.181.251.218][36368] - new: [...232] [ip4][..tcp] [......10.0.2.15][50278] -> [..36.231.59.187][62234] - new: [...233] [ip4][..tcp] [......10.0.2.15][50279] -> [.113.252.91.201][.4297] - new: [...234] [ip4][..tcp] [......10.0.2.15][50280] -> [...99.199.148.6][.4338] - new: [...235] [ip4][..tcp] [......10.0.2.15][50281] -> [.94.134.154.158][54130] - new: [...236] [ip4][..tcp] [......10.0.2.15][50282] -> [..221.124.66.33][13060] - new: [...237] [ip4][..tcp] [......10.0.2.15][50283] -> [..51.68.153.214][35004] - new: [...238] [ip4][..tcp] [......10.0.2.15][50284] -> [.104.156.226.72][53258] - new: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] - new: [...240] [ip4][..tcp] [......10.0.2.15][50286] -> [.84.118.116.198][44616] - new: [...241] [ip4][..tcp] [......10.0.2.15][50287] -> [.98.215.130.156][12405] + new: [...226] [ip4][..tcp] [......10.0.2.15][50272] -> [...1.172.184.48][13298] + new: [...227] [ip4][..tcp] [......10.0.2.15][50273] -> [..24.179.18.242][47329] + new: [...228] [ip4][..tcp] [......10.0.2.15][50274] -> [..68.174.18.115][50679] + new: [...229] [ip4][..tcp] [......10.0.2.15][50275] -> [.122.117.100.78][.9010] + new: [...230] [ip4][..tcp] [......10.0.2.15][50276] -> [.96.246.156.126][56070] + new: [...231] [ip4][..tcp] [......10.0.2.15][50277] -> [.82.181.251.218][36368] + new: [...232] [ip4][..tcp] [......10.0.2.15][50278] -> [..36.231.59.187][62234] + new: [...233] [ip4][..tcp] [......10.0.2.15][50279] -> [.113.252.91.201][.4297] + new: [...234] [ip4][..tcp] [......10.0.2.15][50280] -> [...99.199.148.6][.4338] + new: [...235] [ip4][..tcp] [......10.0.2.15][50281] -> [.94.134.154.158][54130] + new: [...236] [ip4][..tcp] [......10.0.2.15][50282] -> [..221.124.66.33][13060] + new: [...237] [ip4][..tcp] [......10.0.2.15][50283] -> [..51.68.153.214][35004] + new: [...238] [ip4][..tcp] [......10.0.2.15][50284] -> [.104.156.226.72][53258] + new: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] + new: [...240] [ip4][..tcp] [......10.0.2.15][50286] -> [.84.118.116.198][44616] + new: [...241] [ip4][..tcp] [......10.0.2.15][50287] -> [.98.215.130.156][12405] detected: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...238] [ip4][..tcp] [......10.0.2.15][50284] -> [.104.156.226.72][53258] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] - new: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] - new: [...244] [ip4][..tcp] [......10.0.2.15][50288] -> [...76.119.55.28][20347] - new: [...245] [ip4][..tcp] [......10.0.2.15][50289] -> [.74.195.236.249][18557] - new: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] + new: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + new: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + new: [...244] [ip4][..tcp] [......10.0.2.15][50288] -> [...76.119.55.28][20347] + new: [...245] [ip4][..tcp] [......10.0.2.15][50289] -> [.74.195.236.249][18557] + new: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] detected: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] + new: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] detected: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] + new: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] detected: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...249] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.218][.6909] + new: [...249] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.218][.6909] detected: [...249] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.218][.6909] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] + new: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] detected: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...251] [ip4][..udp] [......10.0.2.15][28681] -> [.185.203.218.92][56962] + new: [...251] [ip4][..udp] [......10.0.2.15][28681] -> [.185.203.218.92][56962] detected: [...251] [ip4][..udp] [......10.0.2.15][28681] -> [.185.203.218.92][56962] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...252] [ip4][..udp] [......10.0.2.15][28681] -> [..72.140.120.41][47739] + new: [...252] [ip4][..udp] [......10.0.2.15][28681] -> [..72.140.120.41][47739] detected: [...252] [ip4][..udp] [......10.0.2.15][28681] -> [..72.140.120.41][47739] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...253] [ip4][..udp] [......10.0.2.15][28681] -> [.193.37.255.130][61616] + new: [...253] [ip4][..udp] [......10.0.2.15][28681] -> [.193.37.255.130][61616] detected: [...253] [ip4][..udp] [......10.0.2.15][28681] -> [.193.37.255.130][61616] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] + new: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] detected: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] + new: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] detected: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...256] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][50297] + new: [...256] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][50297] detected: [...256] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][50297] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] + new: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] detected: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...258] [ip4][..udp] [......10.0.2.15][28681] -> [...24.26.216.95][13889] + new: [...258] [ip4][..udp] [......10.0.2.15][28681] -> [...24.26.216.95][13889] detected: [...258] [ip4][..udp] [......10.0.2.15][28681] -> [...24.26.216.95][13889] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] + new: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] detected: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] + new: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] detected: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] + new: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] detected: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] + new: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] detected: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...263] [ip4][..udp] [......10.0.2.15][28681] -> [..82.217.176.52][.7446] + new: [...263] [ip4][..udp] [......10.0.2.15][28681] -> [..82.217.176.52][.7446] detected: [...263] [ip4][..udp] [......10.0.2.15][28681] -> [..82.217.176.52][.7446] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...264] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][11603] + new: [...264] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][11603] detected: [...264] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][11603] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] + new: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] detected: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...266] [ip4][..tcp] [......10.0.2.15][50290] -> [....73.89.249.8][50649] - new: [...267] [ip4][..tcp] [......10.0.2.15][50291] -> [..200.7.155.210][28365] - new: [...268] [ip4][..tcp] [......10.0.2.15][50292] -> [...95.10.205.67][11603] - new: [...269] [ip4][..tcp] [......10.0.2.15][50293] -> [..97.83.183.148][.8890] - new: [...270] [ip4][..tcp] [......10.0.2.15][50294] -> [.14.200.255.229][37058] - new: [...271] [ip4][..tcp] [......10.0.2.15][50295] -> [.38.142.119.234][49732] - new: [...272] [ip4][..tcp] [......10.0.2.15][50296] -> [...77.58.211.52][.3806] - new: [...273] [ip4][..tcp] [......10.0.2.15][50297] -> [.14.200.255.229][45710] - new: [...274] [ip4][..tcp] [......10.0.2.15][50298] -> [.46.128.114.107][.6578] - new: [...275] [ip4][..tcp] [......10.0.2.15][50299] -> [203.220.198.244][.1194] - new: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] - new: [...277] [ip4][..tcp] [......10.0.2.15][50301] -> [..87.123.54.234][54130] - new: [...278] [ip4][..tcp] [......10.0.2.15][50302] -> [....75.64.6.175][.4743] - new: [...279] [ip4][..tcp] [......10.0.2.15][50303] -> [..88.120.73.215][24562] - new: [...280] [ip4][..tcp] [......10.0.2.15][50304] -> [..85.168.34.105][39908] - new: [...281] [ip4][..tcp] [......10.0.2.15][50305] -> [....94.54.66.82][63637] - new: [...282] [ip4][..tcp] [......10.0.2.15][50306] -> [.220.238.145.82][33527] - new: [...283] [ip4][..tcp] [......10.0.2.15][50307] -> [..176.99.176.20][.6346] - new: [...284] [ip4][..tcp] [......10.0.2.15][50308] -> [.193.37.255.130][61616] - new: [...285] [ip4][..tcp] [......10.0.2.15][50309] -> [..60.241.48.194][21301] - new: [...286] [ip4][..tcp] [......10.0.2.15][50310] -> [.76.110.153.177][40022] - new: [...287] [ip4][..tcp] [......10.0.2.15][50311] -> [.149.28.163.175][49956] - new: [...288] [ip4][..tcp] [......10.0.2.15][50312] -> [104.238.172.250][23548] - new: [...289] [ip4][..tcp] [......10.0.2.15][50313] -> [...96.65.68.194][35481] - new: [...290] [ip4][..tcp] [......10.0.2.15][50314] -> [...80.7.252.192][.6888] - new: [...291] [ip4][..tcp] [......10.0.2.15][50315] -> [..45.31.152.112][26851] - new: [...292] [ip4][..tcp] [......10.0.2.15][50316] -> [.142.132.165.13][30566] - new: [...293] [ip4][..tcp] [......10.0.2.15][50317] -> [188.165.203.190][21995] - new: [...294] [ip4][..tcp] [......10.0.2.15][50318] -> [.193.32.126.214][59596] - new: [...295] [ip4][..tcp] [......10.0.2.15][50319] -> [.185.187.74.173][53489] - new: [...296] [ip4][..tcp] [......10.0.2.15][50320] -> [194.163.180.126][10825] - new: [...297] [ip4][..tcp] [......10.0.2.15][50321] -> [213.229.111.224][.4876] - new: [...298] [ip4][..tcp] [......10.0.2.15][50322] -> [..164.132.10.25][55302] - new: [...299] [ip4][..tcp] [......10.0.2.15][50323] -> [..51.68.153.214][26253] + new: [...266] [ip4][..tcp] [......10.0.2.15][50290] -> [....73.89.249.8][50649] + new: [...267] [ip4][..tcp] [......10.0.2.15][50291] -> [..200.7.155.210][28365] + new: [...268] [ip4][..tcp] [......10.0.2.15][50292] -> [...95.10.205.67][11603] + new: [...269] [ip4][..tcp] [......10.0.2.15][50293] -> [..97.83.183.148][.8890] + new: [...270] [ip4][..tcp] [......10.0.2.15][50294] -> [.14.200.255.229][37058] + new: [...271] [ip4][..tcp] [......10.0.2.15][50295] -> [.38.142.119.234][49732] + new: [...272] [ip4][..tcp] [......10.0.2.15][50296] -> [...77.58.211.52][.3806] + new: [...273] [ip4][..tcp] [......10.0.2.15][50297] -> [.14.200.255.229][45710] + new: [...274] [ip4][..tcp] [......10.0.2.15][50298] -> [.46.128.114.107][.6578] + new: [...275] [ip4][..tcp] [......10.0.2.15][50299] -> [203.220.198.244][.1194] + new: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] + new: [...277] [ip4][..tcp] [......10.0.2.15][50301] -> [..87.123.54.234][54130] + new: [...278] [ip4][..tcp] [......10.0.2.15][50302] -> [....75.64.6.175][.4743] + new: [...279] [ip4][..tcp] [......10.0.2.15][50303] -> [..88.120.73.215][24562] + new: [...280] [ip4][..tcp] [......10.0.2.15][50304] -> [..85.168.34.105][39908] + new: [...281] [ip4][..tcp] [......10.0.2.15][50305] -> [....94.54.66.82][63637] + new: [...282] [ip4][..tcp] [......10.0.2.15][50306] -> [.220.238.145.82][33527] + new: [...283] [ip4][..tcp] [......10.0.2.15][50307] -> [..176.99.176.20][.6346] + new: [...284] [ip4][..tcp] [......10.0.2.15][50308] -> [.193.37.255.130][61616] + new: [...285] [ip4][..tcp] [......10.0.2.15][50309] -> [..60.241.48.194][21301] + new: [...286] [ip4][..tcp] [......10.0.2.15][50310] -> [.76.110.153.177][40022] + new: [...287] [ip4][..tcp] [......10.0.2.15][50311] -> [.149.28.163.175][49956] + new: [...288] [ip4][..tcp] [......10.0.2.15][50312] -> [104.238.172.250][23548] + new: [...289] [ip4][..tcp] [......10.0.2.15][50313] -> [...96.65.68.194][35481] + new: [...290] [ip4][..tcp] [......10.0.2.15][50314] -> [...80.7.252.192][.6888] + new: [...291] [ip4][..tcp] [......10.0.2.15][50315] -> [..45.31.152.112][26851] + new: [...292] [ip4][..tcp] [......10.0.2.15][50316] -> [.142.132.165.13][30566] + new: [...293] [ip4][..tcp] [......10.0.2.15][50317] -> [188.165.203.190][21995] + new: [...294] [ip4][..tcp] [......10.0.2.15][50318] -> [.193.32.126.214][59596] + new: [...295] [ip4][..tcp] [......10.0.2.15][50319] -> [.185.187.74.173][53489] + new: [...296] [ip4][..tcp] [......10.0.2.15][50320] -> [194.163.180.126][10825] + new: [...297] [ip4][..tcp] [......10.0.2.15][50321] -> [213.229.111.224][.4876] + new: [...298] [ip4][..tcp] [......10.0.2.15][50322] -> [..164.132.10.25][55302] + new: [...299] [ip4][..tcp] [......10.0.2.15][50323] -> [..51.68.153.214][26253] detected: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...292] [ip4][..tcp] [......10.0.2.15][50316] -> [.142.132.165.13][30566] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -699,17 +699,17 @@ RISK: Unsafe Protocol detected: [...283] [ip4][..tcp] [......10.0.2.15][50307] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] - new: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + new: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + new: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] detected: [...271] [ip4][..tcp] [......10.0.2.15][50295] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detection-update: [...290] [ip4][..tcp] [......10.0.2.15][50314] -> [...80.7.252.192][.6888] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Self-signed Cert, TLS Cert Expired, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn, TLS Cert Validity Too Long - new: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] - new: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + new: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + new: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] detected: [...284] [ip4][..tcp] [......10.0.2.15][50308] -> [.193.37.255.130][61616] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + new: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] detected: [...289] [ip4][..tcp] [......10.0.2.15][50313] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...291] [ip4][..tcp] [......10.0.2.15][50315] -> [..45.31.152.112][26851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -735,73 +735,73 @@ update: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....22] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][62539] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....24] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][50435] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...305] [ip4][..udp] [......10.0.2.15][28681] -> [..88.168.175.31][.6346] + new: [...305] [ip4][..udp] [......10.0.2.15][28681] -> [..88.168.175.31][.6346] detected: [...305] [ip4][..udp] [......10.0.2.15][28681] -> [..88.168.175.31][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...306] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] + new: [...306] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] detected: [...306] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...307] [ip4][..udp] [......10.0.2.15][28681] -> [..72.201.208.57][38617] + new: [...307] [ip4][..udp] [......10.0.2.15][28681] -> [..72.201.208.57][38617] detected: [...307] [ip4][..udp] [......10.0.2.15][28681] -> [..72.201.208.57][38617] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...308] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][40137] + new: [...308] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][40137] detected: [...308] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][40137] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...309] [ip4][..udp] [......10.0.2.15][28681] -> [.47.220.186.140][27641] + new: [...309] [ip4][..udp] [......10.0.2.15][28681] -> [.47.220.186.140][27641] detected: [...309] [ip4][..udp] [......10.0.2.15][28681] -> [.47.220.186.140][27641] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...310] [ip4][..udp] [......10.0.2.15][28681] -> [.118.240.69.199][.6348] + new: [...310] [ip4][..udp] [......10.0.2.15][28681] -> [.118.240.69.199][.6348] detected: [...310] [ip4][..udp] [......10.0.2.15][28681] -> [.118.240.69.199][.6348] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] + new: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] detected: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] + new: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] detected: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] + new: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] detected: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] + new: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] detected: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...315] [ip4][..udp] [......10.0.2.15][28681] -> [...92.217.84.16][20223] + new: [...315] [ip4][..udp] [......10.0.2.15][28681] -> [...92.217.84.16][20223] detected: [...315] [ip4][..udp] [......10.0.2.15][28681] -> [...92.217.84.16][20223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] + new: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] detected: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] + new: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] detected: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] + new: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] detected: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...319] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][55302] + new: [...319] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][55302] detected: [...319] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][55302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] + new: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] detected: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...321] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][21995] + new: [...321] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][21995] detected: [...321] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][21995] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...322] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.219][.6909] + new: [...322] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.219][.6909] detected: [...322] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.219][.6909] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...323] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][56070] + new: [...323] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][56070] detected: [...323] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][56070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...324] [ip4][..udp] [......10.0.2.15][28681] -> [.73.250.179.237][20848] + new: [...324] [ip4][..udp] [......10.0.2.15][28681] -> [.73.250.179.237][20848] detected: [...324] [ip4][..udp] [......10.0.2.15][28681] -> [.73.250.179.237][20848] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...325] [ip4][..udp] [......10.0.2.15][28681] -> [..83.160.143.48][37036] + new: [...325] [ip4][..udp] [......10.0.2.15][28681] -> [..83.160.143.48][37036] detected: [...325] [ip4][..udp] [......10.0.2.15][28681] -> [..83.160.143.48][37036] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...326] [ip4][..udp] [......10.0.2.15][28681] -> [..100.1.231.138][56558] + new: [...326] [ip4][..udp] [......10.0.2.15][28681] -> [..100.1.231.138][56558] detected: [...326] [ip4][..udp] [......10.0.2.15][28681] -> [..100.1.231.138][56558] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...327] [ip4][..udp] [......10.0.2.15][28681] -> [...84.28.53.225][44859] + new: [...327] [ip4][..udp] [......10.0.2.15][28681] -> [...84.28.53.225][44859] detected: [...327] [ip4][..udp] [......10.0.2.15][28681] -> [...84.28.53.225][44859] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol analyse: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -834,20 +834,20 @@ [IATS(ms)....: 30.9,31.2,0.4,0.8,29.2,31.6,2.5,501.7,502.0,17.1,17.4,35.1,479.7,480.4,544.2,592.6,8643.7,8692.0,0.6,0.6,0.6,0.6,0.4,0.4,0.5,0.4,0.3,0.4,0.4,0.4,0.4] [PKTLENS.....: 52,44,40,641,40,668,90,40,353,40,182,370,40,67,40,427,40,94,40,50,40,50,40,50,40,50,40,50,40,50,40,50] [ENTROPIES...: 4.5,4.7,4.5,5.8,4.5,5.8,5.6,4.6,7.1,4.4,6.7,7.3,4.7,5.3,4.6,7.4,4.6,5.8,4.5,4.7,4.5,4.7,4.5,4.7,4.5,4.7,4.4,4.7,4.5,4.7,4.5,4.6] - new: [...328] [ip4][..udp] [......10.0.2.15][28681] -> [.203.220.105.27][19260] + new: [...328] [ip4][..udp] [......10.0.2.15][28681] -> [.203.220.105.27][19260] detected: [...328] [ip4][..udp] [......10.0.2.15][28681] -> [.203.220.105.27][19260] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...329] [ip4][..udp] [......10.0.2.15][28681] -> [..92.117.249.98][.6815] + new: [...329] [ip4][..udp] [......10.0.2.15][28681] -> [..92.117.249.98][.6815] detected: [...329] [ip4][..udp] [......10.0.2.15][28681] -> [..92.117.249.98][.6815] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...330] [ip4][..udp] [......10.0.2.15][28681] -> [....82.64.44.11][.1352] + new: [...330] [ip4][..udp] [......10.0.2.15][28681] -> [....82.64.44.11][.1352] detected: [...330] [ip4][..udp] [......10.0.2.15][28681] -> [....82.64.44.11][.1352] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...331] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][26851] + new: [...331] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][26851] detected: [...331] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][26851] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] - new: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] + new: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] detected: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol detected: [...267] [ip4][..tcp] [......10.0.2.15][50291] -> [..200.7.155.210][28365] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -861,18 +861,18 @@ update: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] update: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] update: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] - new: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] + new: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] + new: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] detected: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] [HTTP.Gnutella][Unknown][Download][Potentially Dangerous][69.118.162.229] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol detected: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] [HTTP.Gnutella][Unknown][Download][Potentially Dangerous][189.147.72.83] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol - new: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + new: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] detection-update: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] [HTTP.Gnutella][Unknown][Media][Potentially Dangerous][69.118.162.229] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol detection-update: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] [HTTP.Gnutella][Unknown][Media][Potentially Dangerous][189.147.72.83] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol - new: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] + new: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] detected: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol analyse: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -991,51 +991,51 @@ RISK: Unsafe Protocol update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...337] [ip4][..udp] [......10.0.2.15][28681] -> [..24.116.64.132][51227] + new: [...337] [ip4][..udp] [......10.0.2.15][28681] -> [..24.116.64.132][51227] detected: [...337] [ip4][..udp] [......10.0.2.15][28681] -> [..24.116.64.132][51227] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...338] [ip4][..udp] [......10.0.2.15][28681] -> [221.198.205.196][20778] + new: [...338] [ip4][..udp] [......10.0.2.15][28681] -> [221.198.205.196][20778] detected: [...338] [ip4][..udp] [......10.0.2.15][28681] -> [221.198.205.196][20778] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...339] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][54130] + new: [...339] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][54130] detected: [...339] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][54130] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] + new: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] detected: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...341] [ip4][..udp] [......10.0.2.15][28681] -> [..24.129.233.60][19990] + new: [...341] [ip4][..udp] [......10.0.2.15][28681] -> [..24.129.233.60][19990] detected: [...341] [ip4][..udp] [......10.0.2.15][28681] -> [..24.129.233.60][19990] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] + new: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] detected: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...343] [ip4][..udp] [......10.0.2.15][28681] -> [..89.212.91.155][.5195] + new: [...343] [ip4][..udp] [......10.0.2.15][28681] -> [..89.212.91.155][.5195] detected: [...343] [ip4][..udp] [......10.0.2.15][28681] -> [..89.212.91.155][.5195] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...344] [ip4][..udp] [......10.0.2.15][28681] -> [.207.38.163.228][.6778] + new: [...344] [ip4][..udp] [......10.0.2.15][28681] -> [.207.38.163.228][.6778] detected: [...344] [ip4][..udp] [......10.0.2.15][28681] -> [.207.38.163.228][.6778] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...345] [ip4][..tcp] [......10.0.2.15][50330] -> [.69.118.162.229][46906] + new: [...345] [ip4][..tcp] [......10.0.2.15][50330] -> [.69.118.162.229][46906] detected: [...345] [ip4][..tcp] [......10.0.2.15][50330] -> [.69.118.162.229][46906] [HTTP.Gnutella][Unknown][Download][Potentially Dangerous][69.118.162.229] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol - new: [...346] [ip4][..udp] [......10.0.2.15][28681] -> [..76.226.85.105][.6346] + new: [...346] [ip4][..udp] [......10.0.2.15][28681] -> [..76.226.85.105][.6346] detected: [...346] [ip4][..udp] [......10.0.2.15][28681] -> [..76.226.85.105][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...347] [ip4][..udp] [......10.0.2.15][28681] -> [..176.10.169.10][12799] + new: [...347] [ip4][..udp] [......10.0.2.15][28681] -> [..176.10.169.10][12799] detected: [...347] [ip4][..udp] [......10.0.2.15][28681] -> [..176.10.169.10][12799] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...348] [ip4][..udp] [......10.0.2.15][28681] -> [...84.197.97.94][.1360] + new: [...348] [ip4][..udp] [......10.0.2.15][28681] -> [...84.197.97.94][.1360] detected: [...348] [ip4][..udp] [......10.0.2.15][28681] -> [...84.197.97.94][.1360] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...349] [ip4][.icmp] [...84.197.97.94] -> [......10.0.2.15] + new: [...349] [ip4][.icmp] [...84.197.97.94] -> [......10.0.2.15] detected: [...349] [ip4][.icmp] [...84.197.97.94] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] - new: [...350] [ip4][..udp] [......10.0.2.15][28681] -> [..99.250.253.99][11819] + new: [...350] [ip4][..udp] [......10.0.2.15][28681] -> [..99.250.253.99][11819] detected: [...350] [ip4][..udp] [......10.0.2.15][28681] -> [..99.250.253.99][11819] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...351] [ip4][..udp] [......10.0.2.15][28681] -> [..187.37.87.189][.6346] + new: [...351] [ip4][..udp] [......10.0.2.15][28681] -> [..187.37.87.189][.6346] detected: [...351] [ip4][..udp] [......10.0.2.15][28681] -> [..187.37.87.189][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] + new: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] detected: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [.....4] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [................................ff02::1] [ICMPV6][Unknown][Network][Acceptable] @@ -1053,7 +1053,7 @@ RISK: Unsafe Protocol update: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] + update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1184,22 +1184,22 @@ [IATS(ms)....: 399.9,400.2,2.6,3.1,879.2,880.3,1.1,343.3,15.8,359.6,3.0,2.2,5.1,145.1,145.6,10048.7,10048.7,469.5,2.7,472.7,3557.8,3604.1,6175.3,6222.2,413.8,464.5,22633.8,22684.6,605.3,605.0,15818.9] [PKTLENS.....: 52,44,40,344,40,323,143,40,118,762,40,53,58,40,149,40,104,40,1064,45,40,122,40,70,40,213,40,52,40,123,40,62] [ENTROPIES...: 4.6,4.8,4.6,5.8,4.5,5.6,5.6,4.6,5.6,7.7,4.7,4.7,4.9,4.6,6.3,4.5,5.9,4.5,7.8,4.3,4.8,6.2,4.8,5.5,4.6,6.6,4.7,4.8,4.6,6.2,4.6,4.9] - new: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282] + new: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282] detected: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...354] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][.1032] + new: [...354] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][.1032] detected: [...354] [ip4][..udp] [......10.0.2.15][28681] -> [.80.236.247.120][.1032] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] + new: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] detected: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...356] [ip4][..udp] [......10.0.2.15][28681] -> [.63.228.175.169][.1936] + new: [...356] [ip4][..udp] [......10.0.2.15][28681] -> [.63.228.175.169][.1936] detected: [...356] [ip4][..udp] [......10.0.2.15][28681] -> [.63.228.175.169][.1936] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...357] [ip4][..udp] [......10.0.2.15][28681] -> [...98.35.85.238][32173] + new: [...357] [ip4][..udp] [......10.0.2.15][28681] -> [...98.35.85.238][32173] detected: [...357] [ip4][..udp] [......10.0.2.15][28681] -> [...98.35.85.238][32173] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...358] [ip4][..udp] [......10.0.2.15][28681] -> [.47.224.174.174][.6346] + new: [...358] [ip4][..udp] [......10.0.2.15][28681] -> [.47.224.174.174][.6346] detected: [...358] [ip4][..udp] [......10.0.2.15][28681] -> [.47.224.174.174][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [.....3] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] @@ -1225,10 +1225,10 @@ RISK: Unsafe Protocol update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] update: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1240,7 +1240,7 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -1252,20 +1252,20 @@ update: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....24] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][50435] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] update: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1312,12 +1312,12 @@ RISK: Unsafe Protocol update: [...326] [ip4][..udp] [......10.0.2.15][28681] -> [..100.1.231.138][56558] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...359] [ip4][..udp] [......10.0.2.15][51685] -> [239.255.255.250][.1900] + new: [...359] [ip4][..udp] [......10.0.2.15][51685] -> [239.255.255.250][.1900] detected: [...359] [ip4][..udp] [......10.0.2.15][51685] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] update: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] update: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...349] [ip4][.icmp] [...84.197.97.94] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] @@ -1325,31 +1325,31 @@ update: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] update: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] update: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [...360] [ip4][..udp] [......10.0.2.15][28681] -> [..198.58.218.12][47912] + new: [...360] [ip4][..udp] [......10.0.2.15][28681] -> [..198.58.218.12][47912] detected: [...360] [ip4][..udp] [......10.0.2.15][28681] -> [..198.58.218.12][47912] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...361] [ip4][..udp] [......10.0.2.15][28681] -> [..86.129.196.84][.9915] + new: [...361] [ip4][..udp] [......10.0.2.15][28681] -> [..86.129.196.84][.9915] detected: [...361] [ip4][..udp] [......10.0.2.15][28681] -> [..86.129.196.84][.9915] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...362] [ip4][..udp] [......10.0.2.15][28681] -> [190.192.210.182][.6754] + new: [...362] [ip4][..udp] [......10.0.2.15][28681] -> [190.192.210.182][.6754] detected: [...362] [ip4][..udp] [......10.0.2.15][28681] -> [190.192.210.182][.6754] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...363] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][38297] + new: [...363] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][38297] detected: [...363] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][38297] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...364] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][10825] + new: [...364] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][10825] detected: [...364] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][10825] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...365] [ip4][..udp] [......10.0.2.15][28681] -> [..188.23.24.213][18561] + new: [...365] [ip4][..udp] [......10.0.2.15][28681] -> [..188.23.24.213][18561] detected: [...365] [ip4][..udp] [......10.0.2.15][28681] -> [..188.23.24.213][18561] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...366] [ip4][..udp] [......10.0.2.15][28681] -> [....94.8.55.158][51140] + new: [...366] [ip4][..udp] [......10.0.2.15][28681] -> [....94.8.55.158][51140] detected: [...366] [ip4][..udp] [......10.0.2.15][28681] -> [....94.8.55.158][51140] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...367] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][49956] + new: [...367] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][49956] detected: [...367] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][49956] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...368] [ip4][..udp] [......10.0.2.15][28681] -> [...47.147.52.21][36728] + new: [...368] [ip4][..udp] [......10.0.2.15][28681] -> [...47.147.52.21][36728] detected: [...368] [ip4][..udp] [......10.0.2.15][28681] -> [...47.147.52.21][36728] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...338] [ip4][..udp] [......10.0.2.15][28681] -> [221.198.205.196][20778] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1500,7 +1500,7 @@ RISK: Unsafe Protocol update: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] + update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1648,22 +1648,22 @@ end: [...119] [ip4][..tcp] [......10.0.2.15][50250] -> [...27.94.154.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....42] [ip4][..tcp] [......10.0.2.15][50202] -> [.61.238.173.128][57648] [Unknown][Unknown][Unrated] - end: [....42] [ip4][..tcp] [......10.0.2.15][50202] -> [.61.238.173.128][57648] + end: [....42] [ip4][..tcp] [......10.0.2.15][50202] -> [.61.238.173.128][57648] end: [....36] [ip4][..tcp] [......10.0.2.15][50197] -> [..118.168.15.71][.3931] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol end: [...121] [ip4][..tcp] [......10.0.2.15][50252] -> [.123.202.31.113][19768] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....63] [ip4][..tcp] [......10.0.2.15][50222] -> [.119.14.143.237][.6523] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [....63] [ip4][..tcp] [......10.0.2.15][50222] -> [.119.14.143.237][.6523] + end: [....63] [ip4][..tcp] [......10.0.2.15][50222] -> [.119.14.143.237][.6523] not-detected: [....61] [ip4][..tcp] [......10.0.2.15][50220] -> [.36.233.196.226][.3820] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [....61] [ip4][..tcp] [......10.0.2.15][50220] -> [.36.233.196.226][.3820] + end: [....61] [ip4][..tcp] [......10.0.2.15][50220] -> [.36.233.196.226][.3820] end: [....43] [ip4][..tcp] [......10.0.2.15][50203] -> [..61.222.160.99][18994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....69] [ip4][..tcp] [......10.0.2.15][50228] -> [..111.241.31.96][14384] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [....69] [ip4][..tcp] [......10.0.2.15][50228] -> [..111.241.31.96][14384] + end: [....69] [ip4][..tcp] [......10.0.2.15][50228] -> [..111.241.31.96][14384] end: [...122] [ip4][..tcp] [......10.0.2.15][50253] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....12] [ip4][..udp] [......10.0.2.15][63717] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -1700,10 +1700,10 @@ RISK: Unsafe Protocol update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] update: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1715,7 +1715,7 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....25] [ip4][..udp] [......10.0.2.15][50435] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -1731,20 +1731,20 @@ RISK: Unsafe Protocol update: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] update: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1780,7 +1780,7 @@ RISK: Unsafe Protocol not-detected: [...143] [ip4][..tcp] [......10.0.2.15][50256] -> [.36.233.201.161][.2886] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...143] [ip4][..tcp] [......10.0.2.15][50256] -> [.36.233.201.161][.2886] + end: [...143] [ip4][..tcp] [......10.0.2.15][50256] -> [.36.233.201.161][.2886] end: [...285] [ip4][..tcp] [......10.0.2.15][50309] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol end: [...283] [ip4][..tcp] [......10.0.2.15][50307] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1794,7 +1794,7 @@ idle: [....16] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [...237] [ip4][..tcp] [......10.0.2.15][50283] -> [..51.68.153.214][35004] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...237] [ip4][..tcp] [......10.0.2.15][50283] -> [..51.68.153.214][35004] + end: [...237] [ip4][..tcp] [......10.0.2.15][50283] -> [..51.68.153.214][35004] idle: [....14] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] idle: [....18] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63965] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] end: [...269] [ip4][..tcp] [......10.0.2.15][50293] -> [..97.83.183.148][.8890] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1806,7 +1806,7 @@ idle: [....17] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63960] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [...153] [ip4][..tcp] [......10.0.2.15][50266] -> [.219.70.175.103][.4315] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...153] [ip4][..tcp] [......10.0.2.15][50266] -> [.219.70.175.103][.4315] + end: [...153] [ip4][..tcp] [......10.0.2.15][50266] -> [.219.70.175.103][.4315] end: [....37] [ip4][..tcp] [......10.0.2.15][50198] -> [..86.129.196.84][.9915] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol end: [...287] [ip4][..tcp] [......10.0.2.15][50311] -> [.149.28.163.175][49956] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1850,7 +1850,7 @@ update: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...325] [ip4][..udp] [......10.0.2.15][28681] -> [..83.160.143.48][37036] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -1882,7 +1882,7 @@ update: [....41] [ip4][..udp] [......10.0.2.15][57622] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] update: [...326] [ip4][..udp] [......10.0.2.15][28681] -> [..100.1.231.138][56558] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] + new: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] idle: [....95] [ip4][.icmp] [.......10.0.2.2] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] idle: [....13] [ip4][..udp] [......10.0.2.15][..137] -> [.....10.0.2.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....23] [ip4][..udp] [......10.0.2.15][62539] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -2026,19 +2026,19 @@ RISK: Unsafe Protocol update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...370] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.56.198][11984] + new: [...370] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.56.198][11984] detected: [...370] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.56.198][11984] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...371] [ip4][..udp] [......10.0.2.15][28681] -> [.109.131.202.24][44748] + new: [...371] [ip4][..udp] [......10.0.2.15][28681] -> [.109.131.202.24][44748] detected: [...371] [ip4][..udp] [......10.0.2.15][28681] -> [.109.131.202.24][44748] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...372] [ip4][..udp] [......10.0.2.15][28681] -> [.91.179.185.126][.6346] + new: [...372] [ip4][..udp] [......10.0.2.15][28681] -> [.91.179.185.126][.6346] detected: [...372] [ip4][..udp] [......10.0.2.15][28681] -> [.91.179.185.126][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...373] [ip4][..udp] [......10.0.2.15][28681] -> [..88.122.233.15][11488] + new: [...373] [ip4][..udp] [......10.0.2.15][28681] -> [..88.122.233.15][11488] detected: [...373] [ip4][..udp] [......10.0.2.15][28681] -> [..88.122.233.15][11488] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...374] [ip4][..udp] [......10.0.2.15][28681] -> [....62.35.190.5][18604] + new: [...374] [ip4][..udp] [......10.0.2.15][28681] -> [....62.35.190.5][18604] detected: [...374] [ip4][..udp] [......10.0.2.15][28681] -> [....62.35.190.5][18604] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....21] [ip4][..udp] [......10.0.2.15][55708] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -2064,7 +2064,7 @@ RISK: Unsafe Protocol update: [...353] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][25282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] + update: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2188,31 +2188,31 @@ RISK: Unsafe Protocol update: [...202] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] - new: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] - new: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] - new: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] - new: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] - new: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] - new: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] - new: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] - new: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] - new: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] - new: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] - new: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] - new: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] - new: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] - new: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] - new: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] - new: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] - new: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] - new: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] - new: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] - new: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] - new: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] - new: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] - new: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] - new: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] + new: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + new: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + new: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + new: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + new: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + new: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + new: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + new: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + new: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + new: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + new: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] + new: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + new: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] + new: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + new: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] + new: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] + new: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] + new: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] + new: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + new: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + new: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] + new: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] + new: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] + new: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] + new: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] idle: [....26] [ip4][..udp] [......10.0.2.15][57619] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] idle: [....27] [ip4][..udp] [......10.0.2.15][57620] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] idle: [....34] [ip4][..udp] [......10.0.2.15][57621] -> [.......10.0.2.2][.5351] [NAT-PMP][Unknown][Network][Acceptable] @@ -2241,10 +2241,10 @@ RISK: Unsafe Protocol update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] update: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2255,7 +2255,7 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...256] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][50297] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2268,20 +2268,20 @@ RISK: Unsafe Protocol update: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] update: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2300,191 +2300,191 @@ RISK: Unsafe Protocol update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] + new: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] detected: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] + new: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] detected: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] + new: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] detected: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] + new: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] detected: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] + new: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] detected: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] + new: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] detected: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] + new: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] detected: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] + new: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] detected: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...408] [ip4][..udp] [......10.0.2.15][28681] -> [...90.103.2.245][.6346] + new: [...408] [ip4][..udp] [......10.0.2.15][28681] -> [...90.103.2.245][.6346] detected: [...408] [ip4][..udp] [......10.0.2.15][28681] -> [...90.103.2.245][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] + new: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] detected: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] + new: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] detected: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...411] [ip4][..udp] [......10.0.2.15][28681] -> [...89.143.28.64][.6346] + new: [...411] [ip4][..udp] [......10.0.2.15][28681] -> [...89.143.28.64][.6346] detected: [...411] [ip4][..udp] [......10.0.2.15][28681] -> [...89.143.28.64][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...412] [ip4][..udp] [......10.0.2.15][28681] -> [...58.177.52.73][.6346] + new: [...412] [ip4][..udp] [......10.0.2.15][28681] -> [...58.177.52.73][.6346] detected: [...412] [ip4][..udp] [......10.0.2.15][28681] -> [...58.177.52.73][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] + new: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] detected: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] + new: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] detected: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] + new: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] detected: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] + new: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] detected: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...417] [ip4][..udp] [......10.0.2.15][28681] -> [.94.187.236.179][.6346] + new: [...417] [ip4][..udp] [......10.0.2.15][28681] -> [.94.187.236.179][.6346] detected: [...417] [ip4][..udp] [......10.0.2.15][28681] -> [.94.187.236.179][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...418] [ip4][..udp] [......10.0.2.15][28681] -> [.75.129.149.103][.6346] + new: [...418] [ip4][..udp] [......10.0.2.15][28681] -> [.75.129.149.103][.6346] detected: [...418] [ip4][..udp] [......10.0.2.15][28681] -> [.75.129.149.103][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] + new: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] detected: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] + new: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] detected: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] + new: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] detected: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] + new: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] detected: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] + new: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] detected: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...424] [ip4][..udp] [......10.0.2.15][28681] -> [..93.15.216.216][.6346] + new: [...424] [ip4][..udp] [......10.0.2.15][28681] -> [..93.15.216.216][.6346] detected: [...424] [ip4][..udp] [......10.0.2.15][28681] -> [..93.15.216.216][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] + new: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] detected: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] + new: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] detected: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...427] [ip4][..udp] [......10.0.2.15][28681] -> [...81.249.13.30][15138] + new: [...427] [ip4][..udp] [......10.0.2.15][28681] -> [...81.249.13.30][15138] detected: [...427] [ip4][..udp] [......10.0.2.15][28681] -> [...81.249.13.30][15138] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] + new: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] detected: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] + new: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] detected: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] + new: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] detected: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] + new: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] detected: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] + new: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] detected: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] + new: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] detected: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] + new: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] detected: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] + new: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] detected: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] + new: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] detected: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] + new: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] detected: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] + new: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] detected: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] + new: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] detected: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] + new: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] detected: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] - new: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] - new: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] - new: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - new: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] - new: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] - new: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] - new: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] - new: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] - new: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] - new: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] - new: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] - new: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] - new: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] - new: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] - new: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] - new: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] - new: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] - new: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] - new: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] - new: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] - new: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] - new: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] - new: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] - new: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] + new: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + new: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + new: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + new: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + new: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + new: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + new: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + new: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + new: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + new: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + new: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + new: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + new: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + new: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + new: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + new: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + new: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + new: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + new: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + new: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + new: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + new: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + new: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + new: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + new: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] detected: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...466] [ip4][..udp] [......10.0.2.15][28681] -> [...70.119.248.5][49929] + new: [...466] [ip4][..udp] [......10.0.2.15][28681] -> [...70.119.248.5][49929] detected: [...466] [ip4][..udp] [......10.0.2.15][28681] -> [...70.119.248.5][49929] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] + new: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] detected: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...468] [ip4][..udp] [......10.0.2.15][28681] -> [..94.214.12.247][44001] + new: [...468] [ip4][..udp] [......10.0.2.15][28681] -> [..94.214.12.247][44001] detected: [...468] [ip4][..udp] [......10.0.2.15][28681] -> [..94.214.12.247][44001] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] - new: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] - new: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] - new: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] - new: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] - new: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] - new: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] - new: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] - new: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] - new: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] - new: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] - new: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] - new: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] + new: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + new: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + new: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + new: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + new: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + new: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + new: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + new: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + new: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + new: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + new: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + new: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + new: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] detected: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] + new: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] detected: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] - new: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] + new: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] + new: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] detected: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] + new: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] detected: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] + new: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] detected: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....54] [ip4][..udp] [......10.0.2.15][57623] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -2528,22 +2528,22 @@ RISK: Unsafe Protocol idle: [...105] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...487] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] + new: [...487] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] detected: [...487] [ip4][..udp] [......10.0.2.15][28681] -> [..24.78.134.188][49046] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...488] [ip4][..udp] [......10.0.2.15][28681] -> [.183.179.90.112][.9852] + new: [...488] [ip4][..udp] [......10.0.2.15][28681] -> [.183.179.90.112][.9852] detected: [...488] [ip4][..udp] [......10.0.2.15][28681] -> [.183.179.90.112][.9852] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...489] [ip4][..udp] [......10.0.2.15][28681] -> [...108.44.45.25][.6346] + new: [...489] [ip4][..udp] [......10.0.2.15][28681] -> [...108.44.45.25][.6346] detected: [...489] [ip4][..udp] [......10.0.2.15][28681] -> [...108.44.45.25][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...490] [ip4][..udp] [......10.0.2.15][28681] -> [...90.3.215.132][20356] + new: [...490] [ip4][..udp] [......10.0.2.15][28681] -> [...90.3.215.132][20356] detected: [...490] [ip4][..udp] [......10.0.2.15][28681] -> [...90.3.215.132][20356] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...491] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.42.210][.5512] + new: [...491] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.42.210][.5512] detected: [...491] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.42.210][.5512] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] + new: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] detected: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...170] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2551,7 +2551,7 @@ idle: [...196] [ip4][..udp] [......10.0.2.15][28681] -> [..88.127.72.106][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] [Unknown][Unknown][Unrated] - idle: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] + idle: [...220] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][.9239] idle: [...217] [ip4][..udp] [......10.0.2.15][28681] -> [.126.117.45.151][19323] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...155] [ip4][..udp] [......10.0.2.15][28681] -> [.88.168.182.103][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2648,7 +2648,7 @@ RISK: Unsafe Protocol update: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...325] [ip4][..udp] [......10.0.2.15][28681] -> [..83.160.143.48][37036] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2702,7 +2702,7 @@ RISK: Unsafe Protocol update: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] + update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] update: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...337] [ip4][..udp] [......10.0.2.15][28681] -> [..24.116.64.132][51227] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -2749,312 +2749,312 @@ RISK: Unsafe Protocol update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] + new: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] detected: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...494] [ip4][..udp] [......10.0.2.15][28681] -> [...86.210.81.59][.6346] + new: [...494] [ip4][..udp] [......10.0.2.15][28681] -> [...86.210.81.59][.6346] detected: [...494] [ip4][..udp] [......10.0.2.15][28681] -> [...86.210.81.59][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] + new: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] detected: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] + new: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] detected: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] + new: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] detected: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] + new: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] detected: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] + new: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] detected: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] + new: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] detected: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] + new: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] detected: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] + new: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] detected: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] + new: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] detected: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] + new: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] detected: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] + new: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] detected: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] + new: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] detected: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] + new: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] detected: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] + new: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] detected: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] + new: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] detected: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] + new: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] detected: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] + new: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] detected: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] + new: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] detected: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] + new: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] detected: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] + new: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] detected: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] + new: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] detected: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] + new: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] detected: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] + new: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] detected: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] + new: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] detected: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] + new: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] detected: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] - new: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] - new: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] - new: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] - new: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] - new: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] - new: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] - new: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] - new: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] - new: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] - new: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] - new: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] - new: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] - new: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] - new: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] - new: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] - new: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] - new: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] - new: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] - new: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] - new: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] - new: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] - new: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] - new: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] - new: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] - new: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] - new: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] - new: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] - new: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] - new: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] - new: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] - new: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] - new: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] - new: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] - new: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] - new: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] - new: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] - new: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] - new: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] - new: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] - new: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] - new: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] - new: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] - new: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] - new: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] - new: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] - new: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] - new: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] - new: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] - new: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] - new: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] - new: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] - new: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - new: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] - new: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] - new: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] - new: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] - new: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] - new: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] - new: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] - new: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] - new: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] - new: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] - new: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] - new: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] - new: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] - new: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] - new: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] - new: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] - new: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] - new: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] - new: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] - new: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] - new: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] - new: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] - new: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] - new: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] - new: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] - new: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] - new: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] - new: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] - new: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] - new: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] - new: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] - new: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] - new: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] - new: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] - new: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] - new: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] - new: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] - new: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] - new: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] - new: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] - new: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] - new: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] - new: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] - new: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] - new: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] - new: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] - new: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] - new: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] - new: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] - new: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] - new: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] - new: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] - new: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] - new: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] - new: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] - new: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] - new: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] - new: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] - new: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] - new: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] - new: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] - new: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] - new: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] - new: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] - new: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] - new: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] - new: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] - new: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] - new: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] - new: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] - new: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] - new: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] - new: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] - new: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] - new: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] - new: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] - new: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] - new: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] - new: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] - new: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] - new: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] - new: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] - new: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] - new: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] - new: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] - new: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] - new: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] - new: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] - new: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] - new: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] - new: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] - new: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] - new: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] - new: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] - new: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] - new: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] - new: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] - new: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] - new: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] - new: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] - new: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] - new: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] - new: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] - new: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] - new: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] - new: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] - new: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] - new: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] - new: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] - new: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] - new: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] - new: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] - new: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] - new: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] - new: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] - new: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] - new: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] - new: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] - new: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] - new: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] - new: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] - new: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] - new: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] - new: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] - new: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] - new: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] - new: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] - new: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] - new: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] - new: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] - new: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] - new: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] - new: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] - new: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] - new: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] - new: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] - new: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] - new: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] - new: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] - new: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] - new: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] - new: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] - new: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] - new: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] - new: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] - new: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] - new: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] - new: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] - new: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] - new: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] - new: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] - new: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] - new: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] - new: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] - new: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] - new: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] - new: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] - new: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] - new: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] - new: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] - new: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] - new: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] - new: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] - new: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] - new: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] - new: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] - new: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] - new: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] - new: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] - new: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] - new: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] - new: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] - new: [...745] [ip4][.icmp] [..164.132.10.25] -> [......10.0.2.15] + new: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] + new: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] + new: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] + new: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] + new: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] + new: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] + new: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] + new: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] + new: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + new: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + new: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + new: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + new: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + new: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + new: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + new: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + new: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + new: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + new: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + new: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + new: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + new: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + new: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + new: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + new: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + new: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + new: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + new: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + new: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] + new: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] + new: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] + new: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + new: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + new: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + new: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + new: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + new: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + new: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + new: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + new: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + new: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + new: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + new: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + new: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] + new: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] + new: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] + new: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] + new: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] + new: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] + new: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] + new: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + new: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] + new: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + new: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + new: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + new: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] + new: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] + new: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] + new: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] + new: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] + new: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + new: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] + new: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] + new: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] + new: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] + new: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] + new: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] + new: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] + new: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] + new: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] + new: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] + new: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] + new: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] + new: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] + new: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] + new: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] + new: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] + new: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] + new: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] + new: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] + new: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] + new: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] + new: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] + new: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] + new: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] + new: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] + new: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] + new: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] + new: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] + new: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] + new: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] + new: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] + new: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] + new: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] + new: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] + new: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] + new: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] + new: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] + new: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] + new: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] + new: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] + new: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] + new: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] + new: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] + new: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] + new: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] + new: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] + new: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] + new: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + new: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] + new: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] + new: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] + new: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] + new: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] + new: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] + new: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] + new: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] + new: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] + new: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] + new: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] + new: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] + new: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] + new: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] + new: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] + new: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] + new: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] + new: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] + new: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] + new: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] + new: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] + new: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] + new: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] + new: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] + new: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] + new: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] + new: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] + new: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] + new: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] + new: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] + new: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] + new: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] + new: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] + new: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] + new: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + new: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] + new: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] + new: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] + new: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] + new: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] + new: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] + new: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] + new: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] + new: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] + new: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] + new: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] + new: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] + new: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] + new: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] + new: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] + new: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] + new: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] + new: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] + new: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] + new: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] + new: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] + new: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] + new: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] + new: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] + new: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] + new: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] + new: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] + new: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] + new: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] + new: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] + new: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] + new: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + new: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] + new: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] + new: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] + new: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] + new: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] + new: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] + new: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] + new: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] + new: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] + new: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] + new: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] + new: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] + new: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] + new: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] + new: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] + new: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] + new: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] + new: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] + new: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] + new: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] + new: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] + new: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] + new: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] + new: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + new: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] + new: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] + new: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] + new: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] + new: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] + new: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] + new: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] + new: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] + new: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] + new: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] + new: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] + new: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] + new: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] + new: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] + new: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] + new: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] + new: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] + new: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] + new: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] + new: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] + new: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] + new: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] + new: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] + new: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] + new: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] + new: [...745] [ip4][.icmp] [..164.132.10.25] -> [......10.0.2.15] detected: [...745] [ip4][.icmp] [..164.132.10.25] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] idle: [...320] [ip4][..udp] [......10.0.2.15][28681] -> [185.236.200.137][48142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol @@ -3063,17 +3063,17 @@ idle: [...305] [ip4][..udp] [......10.0.2.15][28681] -> [..88.168.175.31][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....31] [ip4][..tcp] [......10.0.2.15][50193] -> [....89.75.52.19][46010] [Unknown][Unknown][Unrated] - end: [....31] [ip4][..tcp] [......10.0.2.15][50193] -> [....89.75.52.19][46010] + end: [....31] [ip4][..tcp] [......10.0.2.15][50193] -> [....89.75.52.19][46010] idle: [...322] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.219][.6909] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....28] [ip4][..tcp] [......10.0.2.15][50190] -> [..80.140.63.147][29545] [Unknown][Unknown][Unrated] - end: [....28] [ip4][..tcp] [......10.0.2.15][50190] -> [..80.140.63.147][29545] + end: [....28] [ip4][..tcp] [......10.0.2.15][50190] -> [..80.140.63.147][29545] idle: [...314] [ip4][..udp] [......10.0.2.15][28681] -> [..71.237.202.91][16117] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....30] [ip4][..tcp] [......10.0.2.15][50192] -> [....45.65.87.24][16201] [Unknown][Unknown][Unrated] - end: [....30] [ip4][..tcp] [......10.0.2.15][50192] -> [....45.65.87.24][16201] + end: [....30] [ip4][..tcp] [......10.0.2.15][50192] -> [....45.65.87.24][16201] not-detected: [....29] [ip4][..tcp] [......10.0.2.15][50191] -> [.207.38.163.228][.6778] [Unknown][Unknown][Unrated] - end: [....29] [ip4][..tcp] [......10.0.2.15][50191] -> [.207.38.163.228][.6778] + end: [....29] [ip4][..tcp] [......10.0.2.15][50191] -> [.207.38.163.228][.6778] update: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...183] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.15.182][37829] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3154,15 +3154,15 @@ RISK: Unsafe Protocol update: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] - new: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] - update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + new: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + new: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] + update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] update: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] - update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] update: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3177,10 +3177,10 @@ RISK: Unsafe Protocol update: [...309] [ip4][..udp] [......10.0.2.15][28681] -> [.47.220.186.140][27641] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] update: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] update: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...258] [ip4][..udp] [......10.0.2.15][28681] -> [...24.26.216.95][13889] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3189,24 +3189,24 @@ RISK: Unsafe Protocol update: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] - update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] - update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] - update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] - update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] - update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] + update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] update: [...358] [ip4][..udp] [......10.0.2.15][28681] -> [.47.224.174.174][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] update: [...357] [ip4][..udp] [......10.0.2.15][28681] -> [...98.35.85.238][32173] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] update: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] - update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] - update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] update: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3217,19 +3217,19 @@ RISK: Unsafe Protocol update: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] + update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] - update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] - update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] update: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3248,40 +3248,40 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] - update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] - update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] - update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] - update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] - update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + update: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] + update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] update: [...256] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][50297] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] - update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] update: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...249] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.218][.6909] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] - update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] - update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] update: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] - update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] update: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] - update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] + update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] update: [...356] [ip4][..udp] [......10.0.2.15][28681] -> [.63.228.175.169][.1936] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3290,13 +3290,13 @@ RISK: Unsafe Protocol update: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] - update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] - update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] + update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] + update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] update: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3305,46 +3305,46 @@ RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] update: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] update: [...427] [ip4][..udp] [......10.0.2.15][28681] -> [...81.249.13.30][15138] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] update: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] update: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] update: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3357,44 +3357,44 @@ RISK: Unsafe Protocol update: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] - update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] - update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] + update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] update: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] - update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] update: [...252] [ip4][..udp] [......10.0.2.15][28681] -> [..72.140.120.41][47739] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] + update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] update: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] update: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] update: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] - update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] - update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] update: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] - update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] + update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] update: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] - update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] update: [...264] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][11603] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] - update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] - update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] + update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...338] [ip4][..udp] [......10.0.2.15][28681] -> [221.198.205.196][20778] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3443,22 +3443,22 @@ RISK: Unsafe Protocol update: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...748] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] + new: [...748] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] detected: [...748] [ip4][..udp] [......10.0.2.15][28681] -> [.....92.8.59.80][35192] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] + new: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] detected: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] + new: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] detected: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...751] [ip4][..udp] [......10.0.2.15][28681] -> [142.115.218.152][.5900] + new: [...751] [ip4][..udp] [......10.0.2.15][28681] -> [142.115.218.152][.5900] detected: [...751] [ip4][..udp] [......10.0.2.15][28681] -> [142.115.218.152][.5900] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...752] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] + new: [...752] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] detected: [...752] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...753] [ip4][..udp] [......10.0.2.15][28681] -> [..165.84.140.96][14400] + new: [...753] [ip4][..udp] [......10.0.2.15][28681] -> [..165.84.140.96][14400] detected: [...753] [ip4][..udp] [......10.0.2.15][28681] -> [..165.84.140.96][14400] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...329] [ip4][..udp] [......10.0.2.15][28681] -> [..92.117.249.98][.6815] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3476,13 +3476,13 @@ idle: [...357] [ip4][..udp] [......10.0.2.15][28681] -> [...98.35.85.238][32173] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....90] [ip4][..tcp] [......10.0.2.15][50245] -> [..73.62.225.181][46843] [Unknown][Unknown][Unrated] - end: [....90] [ip4][..tcp] [......10.0.2.15][50245] -> [..73.62.225.181][46843] + end: [....90] [ip4][..tcp] [......10.0.2.15][50245] -> [..73.62.225.181][46843] idle: [...318] [ip4][..udp] [......10.0.2.15][28681] -> [173.183.183.110][59920] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...311] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.188.98][62851] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] [Unknown][Unknown][Unrated] - idle: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + idle: [...300] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] idle: [...324] [ip4][..udp] [......10.0.2.15][28681] -> [.73.250.179.237][20848] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...177] [ip4][..udp] [......10.0.2.15][28681] -> [.69.157.183.106][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3504,7 +3504,7 @@ update: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -3546,7 +3546,7 @@ RISK: Unsafe Protocol update: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] + update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] update: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3590,24 +3590,24 @@ RISK: Unsafe Protocol idle: [...249] [ip4][..udp] [......10.0.2.15][28681] -> [..45.88.117.218][.6909] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] - update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] - update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] - update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] - update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] + update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] + update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] + update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] + update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] update: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] - update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] - update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] - update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] + update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] + update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] + update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] + update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] update: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] - update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] - update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] + update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] + update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] update: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3617,117 +3617,117 @@ update: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] - update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] - update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] - update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] + update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] + update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] + update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] + update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] update: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] - update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] - update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] - update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] - update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] - update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] + update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] + update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] + update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] + update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] update: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] - update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] + update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] + update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] - update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] - update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] - update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] - update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] - update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] - update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] - update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] - update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] - update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] - update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] - update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] - update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] - update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] - update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] - update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] - update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] - update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] - update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] - update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] + update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] + update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] + update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] + update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] + update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] + update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] + update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] + update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] + update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] + update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] + update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] + update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] + update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] + update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] + update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] + update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] + update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] update: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] + update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] update: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] - update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] - update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] - update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] - update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] - update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] - update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] - update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] - update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] - update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] + update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] + update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] + update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] + update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] + update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] + update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] + update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] + update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] update: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] - update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] - update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] + update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] + update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] update: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] - update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] - update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] - update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] - update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] - update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] - update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] - update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] - update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] - update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] + update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] + update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] + update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] + update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] + update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] + update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] + update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] + update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] update: [...371] [ip4][..udp] [......10.0.2.15][28681] -> [.109.131.202.24][44748] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] - update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] - update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] - update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] - update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] + update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] + update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] + update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] + update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] + update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] update: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] - update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] + update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] update: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] + update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] update: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] - update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] - update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] - update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] - update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] - update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] - update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] - update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] - update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] - update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] - update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] - update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] + update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] + update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] + update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] + update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] + update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] + update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] + update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] + update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] update: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] - update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] - update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] - update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] - update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] - update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] + update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] + update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] + update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] + update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] + update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] update: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3742,196 +3742,196 @@ RISK: Unsafe Protocol update: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] - update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] - update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] - update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] - update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] - update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] - update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] - update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] - update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] - update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] - update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] - update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] - update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] - update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] - update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] - update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] - update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] - update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] - update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] - update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] + update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] + update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] + update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] + update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] + update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] + update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] + update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] + update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] + update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] + update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] + update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] + update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] + update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] + update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] + update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] + update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] update: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...374] [ip4][..udp] [......10.0.2.15][28681] -> [....62.35.190.5][18604] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] + update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] update: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] - update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] - update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] - update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] - update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] - update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] + update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] + update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] + update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] + update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] + update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] update: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] + update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] update: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] + update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] update: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...372] [ip4][..udp] [......10.0.2.15][28681] -> [.91.179.185.126][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] - update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] - update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] - update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] - update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] - update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] - update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] - update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] - update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] - update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] - update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] - update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] - update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] - update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] + update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] + update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] + update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] + update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] + update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] + update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] + update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] + update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] + update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] + update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] + update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] + update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] + update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] + update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] update: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] - update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] - update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] - update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] - update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] - update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] - update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] - update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] - update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] - update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] - update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] + update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] + update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] + update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] + update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] + update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] + update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] + update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] + update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] update: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] + update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] update: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] - update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] - update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] + update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] + update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] update: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] - update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] - update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] - update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] - update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] - update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] - update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] + update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] + update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] + update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] + update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] + update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] update: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] - update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] - update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] - update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] - update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] - update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] - update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] - update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] - update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] - update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] - update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] + update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] + update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] + update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] + update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] + update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] + update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] + update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] + update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] + update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] update: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] - update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] - update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] + update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] + update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] update: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] - update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] - update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] - update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] - update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] - update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] - update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] - update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] - update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] - update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] - update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] + update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] + update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] + update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] + update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] + update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] + update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] + update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] + update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] + update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] update: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] + update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] update: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] + update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] update: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] + update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] update: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] - update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] - update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] - update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] - update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] - update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] - update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] - update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] - update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] - update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] - update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] - update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] - update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] - update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] - update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] - update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] - update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] - update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] + update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] + update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] + update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] + update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] + update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] + update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] + update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] + update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] + update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] + update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] + update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] + update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] + update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] + update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] update: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] - update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] + update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] update: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] + update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] update: [...373] [ip4][..udp] [......10.0.2.15][28681] -> [..88.122.233.15][11488] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] - update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] - update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] - update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] - update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] - update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] - update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] - update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] - update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] - update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] - update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] - update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] - update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] - update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] - update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] - update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] - update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] - update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] + update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] + update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] + update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] + update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] + update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] + update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] + update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] + update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] + update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] + update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] + update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] + update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] + update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] + update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] + update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] + update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] idle: [...307] [ip4][..udp] [......10.0.2.15][28681] -> [..72.201.208.57][38617] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...258] [ip4][..udp] [......10.0.2.15][28681] -> [...24.26.216.95][13889] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3941,13 +3941,13 @@ RISK: Unsafe Protocol idle: [...252] [ip4][..udp] [......10.0.2.15][28681] -> [..72.140.120.41][47739] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] update: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] - update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] update: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3960,28 +3960,28 @@ RISK: Unsafe Protocol update: [...309] [ip4][..udp] [......10.0.2.15][28681] -> [.47.220.186.140][27641] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] update: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] update: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] - update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] - update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] - update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] - update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] - update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] - update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] - update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] + update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] update: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] - update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] - update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] update: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -3992,17 +3992,17 @@ RISK: Unsafe Protocol update: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] + update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] - update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] - update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] update: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + update: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...412] [ip4][..udp] [......10.0.2.15][28681] -> [...58.177.52.73][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4017,35 +4017,35 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] - update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] - update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] - update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] - update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] + update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] - update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] - update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] update: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] - update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] - update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] update: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] - update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] update: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] - update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] + update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] update: [...356] [ip4][..udp] [......10.0.2.15][28681] -> [.63.228.175.169][.1936] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4054,13 +4054,13 @@ RISK: Unsafe Protocol update: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] - update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] - update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] + update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] + update: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] update: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4069,46 +4069,46 @@ RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] update: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + update: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] update: [...427] [ip4][..udp] [......10.0.2.15][28681] -> [...81.249.13.30][15138] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] update: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] update: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] update: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4121,45 +4121,45 @@ RISK: Unsafe Protocol update: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] - update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] - update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] + update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] update: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] - update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] - update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] + update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] update: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] update: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] update: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] - update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] - update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] update: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] - update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] + update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] update: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] - update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] update: [...264] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][11603] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] - update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] - update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] + update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] + new: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] idle: [...247] [ip4][..udp] [......10.0.2.15][28681] -> [..181.84.178.16][60262] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...366] [ip4][..udp] [......10.0.2.15][28681] -> [....94.8.55.158][51140] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4181,9 +4181,9 @@ idle: [...355] [ip4][..udp] [......10.0.2.15][28681] -> [.181.118.53.212][29998] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] [Unknown][Unknown][Unrated] - idle: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] + idle: [...301] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][11852] not-detected: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] [Unknown][Unknown][Unrated] - idle: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + idle: [...243] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] idle: [...330] [ip4][..udp] [......10.0.2.15][28681] -> [....82.64.44.11][.1352] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...360] [ip4][..udp] [......10.0.2.15][28681] -> [..198.58.218.12][47912] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4205,12 +4205,12 @@ RISK: Unsafe Protocol update: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...755] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] + new: [...755] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] detected: [...755] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] + idle: [...242] [ip4][..udp] [......10.0.2.15][28681] -> [..75.133.101.93][52367] idle: [...308] [ip4][..udp] [......10.0.2.15][28681] -> [...81.205.91.45][40137] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4229,7 +4229,7 @@ RISK: Unsafe Protocol update: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -4270,7 +4270,7 @@ RISK: Unsafe Protocol update: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] + update: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] update: [...125] [ip4][..udp] [......10.0.2.15][28681] -> [..83.92.178.182][57302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4307,7 +4307,7 @@ RISK: Unsafe Protocol update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...756] [ip4][..udp] [......10.0.2.15][28681] -> [..41.100.68.255][12838] + new: [...756] [ip4][..udp] [......10.0.2.15][28681] -> [..41.100.68.255][12838] detected: [...756] [ip4][..udp] [......10.0.2.15][28681] -> [..41.100.68.255][12838] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....20] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] @@ -4316,24 +4316,24 @@ RISK: Unsafe Protocol idle: [...173] [ip4][..udp] [......10.0.2.15][28681] -> [..121.99.222.36][44988] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] - update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] - update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] - update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] - update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] + update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] + update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] + update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] + update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] update: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] - update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] - update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] - update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] + update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] + update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] + update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] + update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] update: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] - update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] - update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] + update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] + update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] update: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4343,117 +4343,117 @@ update: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] - update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] - update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] - update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] + update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] + update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] + update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] + update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] update: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] - update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] - update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] - update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] - update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] - update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] + update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] + update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] + update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] + update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] update: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] - update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] + update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] + update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] - update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] - update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] - update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] - update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] - update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] - update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] - update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] - update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] - update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] - update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] - update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] - update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] - update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] - update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] - update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] - update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] - update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] - update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] - update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] + update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] + update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] + update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] + update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] + update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] + update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] + update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] + update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] + update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] + update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] + update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] + update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] + update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] + update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] + update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] + update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] + update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] update: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] + update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] update: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] - update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] - update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] - update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] - update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] - update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] - update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] - update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] - update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] - update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] + update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] + update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] + update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] + update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] + update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] + update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] + update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] + update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] update: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] - update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] - update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] + update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] + update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] update: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] - update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] - update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] - update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] - update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] - update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] - update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] - update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] - update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] - update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] + update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] + update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] + update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] + update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] + update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] + update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] + update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] + update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] update: [...371] [ip4][..udp] [......10.0.2.15][28681] -> [.109.131.202.24][44748] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] - update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] - update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] - update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] - update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] + update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] + update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] + update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] + update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] + update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] update: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] - update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] + update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] update: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] + update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] update: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] - update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] - update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] - update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] - update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] - update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] - update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] - update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] - update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] - update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] - update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] - update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] + update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] + update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] + update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] + update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] + update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] + update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] + update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] + update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] update: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] - update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] - update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] - update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] - update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] - update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] + update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] + update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] + update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] + update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] + update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] update: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4466,203 +4466,203 @@ RISK: Unsafe Protocol update: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] - update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] - update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] - update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] - update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] - update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] - update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] - update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] - update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] - update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] - update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] - update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] - update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] - update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] - update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] - update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] - update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] - update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] - update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] - update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] + update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] + update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] + update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] + update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] + update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] + update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] + update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] + update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] + update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] + update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] + update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] + update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] + update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] + update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] + update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] + update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] update: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...374] [ip4][..udp] [......10.0.2.15][28681] -> [....62.35.190.5][18604] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] + update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] update: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] - update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] - update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] - update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] - update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] - update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] + update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] + update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] + update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] + update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] + update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] update: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] + update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] update: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] + update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] update: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...372] [ip4][..udp] [......10.0.2.15][28681] -> [.91.179.185.126][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] - update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] - update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] - update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] - update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] - update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] - update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] - update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] - update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] - update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] - update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] - update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] - update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] - update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] + update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] + update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] + update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] + update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] + update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] + update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] + update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] + update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] + update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] + update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] + update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] + update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] + update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] + update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] update: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] - update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] - update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] - update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] - update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] - update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] - update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] - update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] - update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] - update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] - update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] + update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] + update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] + update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] + update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] + update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] + update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] + update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] + update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] update: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] + update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] update: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] - update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] - update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] + update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] + update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] update: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] - update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] - update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] - update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] - update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] - update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] - update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] + update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] + update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] + update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] + update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] + update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] update: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] - update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] - update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] - update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] - update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] - update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] - update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] - update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] - update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] - update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] - update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] + update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] + update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] + update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] + update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] + update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] + update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] + update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] + update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] + update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] update: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] - update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] - update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] + update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] + update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] update: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] - update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] - update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] - update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] - update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] - update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] - update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] - update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] - update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] - update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] - update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] + update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] + update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] + update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] + update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] + update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] + update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] + update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] + update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] + update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] update: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] + update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] update: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] + update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] update: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] + update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] update: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] - update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] - update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] - update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] - update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] - update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] - update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] - update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] - update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] - update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] - update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] - update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] - update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] - update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] - update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] - update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] - update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] - update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] + update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] + update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] + update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] + update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] + update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] + update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] + update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] + update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] + update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] + update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] + update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] + update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] + update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] + update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] update: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] - update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] + update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] update: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] + update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] update: [...373] [ip4][..udp] [......10.0.2.15][28681] -> [..88.122.233.15][11488] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] - update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] - update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] - update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] - update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] - update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] - update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] - update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] - update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] - update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] - update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] - update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] - update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] - update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] - update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] - update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] - update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] - update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] - update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] + update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] + update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] + update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] + update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] + update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] + update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] + update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] + update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] + update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] + update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] + update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] + update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] + update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] + update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] + update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] + update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] update: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...404] [ip4][..udp] [......10.0.2.15][28681] -> [.86.234.216.251][17845] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] - update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] update: [...426] [ip4][..udp] [......10.0.2.15][28681] -> [..219.71.44.121][14398] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...411] [ip4][..udp] [......10.0.2.15][28681] -> [...89.143.28.64][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4671,28 +4671,28 @@ RISK: Unsafe Protocol update: [...424] [ip4][..udp] [......10.0.2.15][28681] -> [..93.15.216.216][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] update: [...422] [ip4][..udp] [......10.0.2.15][28681] -> [..88.123.35.219][42211] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] update: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...439] [ip4][..udp] [......10.0.2.15][28681] -> [..176.135.15.86][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] - update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] - update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] - update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] - update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] - update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] - update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] - update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + update: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] + update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] update: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] - update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] - update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] update: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...465] [ip4][..udp] [......10.0.2.15][28681] -> [.....2.28.39.18][15672] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4701,14 +4701,14 @@ RISK: Unsafe Protocol update: [...421] [ip4][..udp] [......10.0.2.15][28681] -> [..175.182.39.11][12977] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] + update: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] - update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] - update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] + update: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + update: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] update: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4723,45 +4723,45 @@ RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] - update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] - update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] - update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] - update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + update: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] + update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] - update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] - update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] update: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] - update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] - update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] update: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] - update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] update: [...401] [ip4][..udp] [......10.0.2.15][28681] -> [.173.178.192.76][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...484] [ip4][..udp] [......10.0.2.15][28681] -> [...107.4.56.177][10000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...406] [ip4][..udp] [......10.0.2.15][28681] -> [....109.27.3.68][57380] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] - update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + update: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] + update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] update: [...467] [ip4][..udp] [......10.0.2.15][28681] -> [...61.64.177.53][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] - update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + update: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] - update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] + update: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] + update: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] update: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4770,7 +4770,7 @@ RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] update: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4782,34 +4782,34 @@ update: [...405] [ip4][..udp] [......10.0.2.15][28681] -> [.176.155.31.118][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...745] [ip4][.icmp] [..164.132.10.25] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] - update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] update: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...438] [ip4][..udp] [......10.0.2.15][28681] -> [..71.86.190.163][14142] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...403] [ip4][..udp] [......10.0.2.15][28681] -> [197.244.171.132][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] update: [...429] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.215.213][23576] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...436] [ip4][..udp] [......10.0.2.15][28681] -> [.219.68.179.137][.6406] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...414] [ip4][..udp] [......10.0.2.15][28681] -> [175.181.156.244][.8255] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] update: [...409] [ip4][..udp] [......10.0.2.15][28681] -> [...86.194.53.68][33770] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...482] [ip4][..udp] [......10.0.2.15][28681] -> [..86.193.23.172][42227] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4820,54 +4820,54 @@ RISK: Unsafe Protocol update: [...407] [ip4][..udp] [......10.0.2.15][28681] -> [195.181.151.217][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] - update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] - update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] + update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + update: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] update: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] - update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] - update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] + update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + update: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] update: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] update: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] update: [...432] [ip4][..udp] [......10.0.2.15][28681] -> [...104.6.118.53][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] - update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] - update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] update: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] - update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] + update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + update: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] update: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] - update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] - update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] - update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] - update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] + update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + update: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...757] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] + new: [...757] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] detected: [...757] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] + new: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] detected: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...759] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] + new: [...759] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] detected: [...759] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] - update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] + idle: [...369] [ip4][..udp] [......10.0.2.15][28681] -> [.89.187.171.240][.6346] + update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] update: [...488] [ip4][..udp] [......10.0.2.15][28681] -> [.183.179.90.112][.9852] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...490] [ip4][..udp] [......10.0.2.15][28681] -> [...90.3.215.132][20356] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4907,7 +4907,7 @@ RISK: Unsafe Protocol update: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] update: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...118] [ip4][..udp] [......10.0.2.15][28681] -> [...5.180.62.100][46385] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -4984,13 +4984,13 @@ RISK: Unsafe Protocol update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...760] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] + new: [...760] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] detected: [...760] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][msedgewin10] RISK: Unsafe Protocol - new: [...761] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] + new: [...761] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] detected: [...761] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...762] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] + new: [...762] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] detected: [...762] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...433] [ip4][..udp] [......10.0.2.15][28681] -> [.99.255.145.191][47264] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5011,7 +5011,7 @@ RISK: Unsafe Protocol not-detected: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] + idle: [...398] [ip4][..udp] [......10.0.2.15][28681] -> [.62.102.148.166][31332] idle: [...481] [ip4][..udp] [......10.0.2.15][28681] -> [..82.120.219.74][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...435] [ip4][..udp] [......10.0.2.15][28681] -> [.109.24.146.101][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5020,14 +5020,14 @@ RISK: Unsafe Protocol not-detected: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] + idle: [...392] [ip4][..udp] [......10.0.2.15][28681] -> [....42.0.69.215][12608] idle: [...416] [ip4][..udp] [......10.0.2.15][28681] -> [..92.139.61.103][24096] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] [Unknown][Unknown][Unrated] - idle: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] + idle: [...304] [ip4][..udp] [......10.0.2.15][28681] -> [.193.32.126.214][59596] not-detected: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] + idle: [...389] [ip4][..udp] [......10.0.2.15][28681] -> [..94.215.183.71][31310] idle: [...413] [ip4][..udp] [......10.0.2.15][28681] -> [...87.65.188.29][24676] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...412] [ip4][..udp] [......10.0.2.15][28681] -> [...58.177.52.73][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5040,7 +5040,7 @@ RISK: Unsafe Protocol not-detected: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] + idle: [...385] [ip4][..udp] [......10.0.2.15][28681] -> [..66.223.143.31][47978] idle: [...428] [ip4][..udp] [......10.0.2.15][28681] -> [....86.162.97.8][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...425] [ip4][..udp] [......10.0.2.15][28681] -> [..145.82.53.165][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5051,14 +5051,14 @@ RISK: Unsafe Protocol not-detected: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] + idle: [...399] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][31728] idle: [...431] [ip4][..udp] [......10.0.2.15][28681] -> [..88.124.71.246][49035] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] [Unknown][Unknown][Unrated] - idle: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] + idle: [...303] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][30566] not-detected: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] + idle: [...395] [ip4][..udp] [......10.0.2.15][28681] -> [..191.114.88.39][18751] idle: [...402] [ip4][..udp] [......10.0.2.15][28681] -> [...78.219.202.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...420] [ip4][..udp] [......10.0.2.15][28681] -> [..86.227.127.34][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5073,7 +5073,7 @@ RISK: Unsafe Protocol not-detected: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] + idle: [...387] [ip4][..udp] [......10.0.2.15][28681] -> [....220.135.8.7][.1219] idle: [...415] [ip4][..udp] [......10.0.2.15][28681] -> [..90.247.160.96][17817] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...410] [ip4][..udp] [......10.0.2.15][28681] -> [..93.28.130.131][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5096,12 +5096,12 @@ RISK: Unsafe Protocol not-detected: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] + idle: [...390] [ip4][..udp] [......10.0.2.15][28681] -> [144.134.132.206][16401] idle: [...440] [ip4][..udp] [......10.0.2.15][28681] -> [203.165.170.112][37087] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] + idle: [...391] [ip4][..udp] [......10.0.2.15][28681] -> [...161.81.38.67][.9539] idle: [...437] [ip4][..udp] [......10.0.2.15][28681] -> [....31.38.163.2][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...419] [ip4][..udp] [......10.0.2.15][28681] -> [...78.193.236.8][46557] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5110,30 +5110,30 @@ RISK: Unsafe Protocol not-detected: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] + idle: [...397] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][24634] idle: [...430] [ip4][..udp] [......10.0.2.15][28681] -> [....90.8.95.165][40763] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] - update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] - update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] - update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] - update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] - update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] + idle: [...396] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.59.24][28755] + update: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] + update: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] + update: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] + update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + update: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] update: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] - update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] - update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] - update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] + update: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] + update: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] + update: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] + update: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] update: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] - update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] - update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] + update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + update: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] + update: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] update: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5143,115 +5143,115 @@ update: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] - update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] - update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] - update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] + update: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] + update: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] + update: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] + update: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] update: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] - update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] - update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] - update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] - update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] - update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + update: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] + update: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] + update: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] + update: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] + update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + update: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] update: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] - update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] + update: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] + update: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] - update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] - update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] - update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] - update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] - update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] - update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] - update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] - update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] - update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] - update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] - update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] - update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] - update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] - update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] - update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] - update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] - update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] - update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] - update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] + update: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] + update: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] + update: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] + update: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] + update: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] + update: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + update: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] + update: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] + update: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] + update: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] + update: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] + update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + update: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] + update: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] + update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + update: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] + update: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] + update: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] + update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + update: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] + update: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] update: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] + update: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] update: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] - update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] - update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] - update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] - update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] - update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] - update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] - update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] - update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] - update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] + update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + update: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] + update: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] + update: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] + update: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] + update: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] + update: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] + update: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] + update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + update: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] update: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] - update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] - update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] + update: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] + update: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + update: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] update: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] - update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] - update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] - update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] - update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] - update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] - update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] - update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] - update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] - update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] - update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] - update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] - update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] - update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] - update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] + update: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] + update: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] + update: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] + update: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] + update: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] + update: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] + update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + update: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] + update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + update: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] + update: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] + update: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] + update: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] + update: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] + update: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] update: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] - update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + update: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] + update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] update: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] + update: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] update: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] - update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] - update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] - update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] - update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] - update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] - update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] - update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] - update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] - update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] - update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] - update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] + update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + update: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] + update: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] + update: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] + update: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] + update: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] + update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + update: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] + update: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] + update: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] update: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] - update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] - update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] - update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] - update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] - update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] + update: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] + update: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] + update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + update: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] + update: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] + update: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] update: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5262,194 +5262,194 @@ RISK: Unsafe Protocol update: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] - update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] - update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] - update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] - update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] - update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] - update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] - update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] - update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] - update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] - update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] - update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] - update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] - update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] - update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] - update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] - update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] - update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] - update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] - update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + update: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] + update: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] + update: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] + update: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] + update: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] + update: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] + update: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] + update: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] + update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + update: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] + update: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] + update: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] + update: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] + update: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] + update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + update: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] + update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + update: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] + update: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] + update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] update: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] + update: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] update: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] - update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] - update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] - update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] - update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] - update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] + update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + update: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] + update: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] + update: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] + update: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] + update: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] update: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] + update: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] update: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] + update: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] update: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] - update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] - update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] - update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] - update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] - update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] - update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] - update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] - update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] - update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] - update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] - update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] - update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] - update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] + update: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] + update: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] + update: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] + update: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] + update: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] + update: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] + update: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] + update: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] + update: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] + update: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] + update: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] + update: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] + update: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] + update: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] update: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] - update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] - update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] - update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] - update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] - update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] - update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] - update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] - update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] - update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] - update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + update: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] + update: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] + update: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] + update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + update: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] + update: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] + update: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] + update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + update: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] + update: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] + update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] update: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] + update: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] update: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] - update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] - update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + update: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] + update: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] + update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] update: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] - update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] - update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] - update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] - update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] - update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] - update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + update: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] + update: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] + update: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] + update: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] + update: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] + update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] update: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] - update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] - update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] - update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] - update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] - update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] - update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] - update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] - update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] - update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] - update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] + update: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] + update: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] + update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + update: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] + update: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] + update: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] + update: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] + update: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] + update: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] + update: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + update: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] update: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] - update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] - update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + update: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] + update: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] + update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] update: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] - update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] - update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] - update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] - update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] - update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] - update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] - update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] - update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] - update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] - update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] + update: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] + update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + update: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] + update: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] + update: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] + update: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] + update: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] + update: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] + update: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] + update: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + update: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] update: [...175] [ip4][..udp] [......10.0.2.15][28681] -> [...115.69.62.99][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] + update: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] update: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] + update: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] update: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] + update: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] update: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] - update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] - update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] - update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] - update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] - update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] - update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] - update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] - update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] - update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] - update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] - update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] - update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] - update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] - update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] - update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] - update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] - update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] + update: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] + update: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] + update: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] + update: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] + update: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] + update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + update: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] + update: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + update: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] + update: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] + update: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] + update: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] + update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + update: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] + update: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] + update: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] + update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + update: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] update: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] - update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + update: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] + update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] update: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] + update: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] update: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] - update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] - update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] - update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] - update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] - update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] - update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] - update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] - update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] - update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] - update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] - update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] - update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] - update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] - update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] - update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] - update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] - update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] - new: [...763] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] + update: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] + update: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] + update: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] + update: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] + update: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] + update: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] + update: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] + update: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] + update: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] + update: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] + update: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] + update: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] + update: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + update: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] + update: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] + update: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] + update: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] + new: [...763] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] detected: [...763] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...764] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] + new: [...764] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] detected: [...764] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...306] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5462,7 +5462,7 @@ RISK: Unsafe Protocol not-detected: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] + idle: [...483] [ip4][..udp] [.......10.0.2.2][.1026] -> [......10.0.2.15][28681] idle: [...213] [ip4][..udp] [......10.0.2.15][28681] -> [....5.180.62.37][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...423] [ip4][..udp] [......10.0.2.15][28681] -> [..119.247.6.226][.9713] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5473,93 +5473,93 @@ RISK: Unsafe Protocol idle: [...434] [ip4][..udp] [......10.0.2.15][28681] -> [.114.24.182.130][22232] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] - update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] - update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] - update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] - update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + update: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + update: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + update: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + update: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + update: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] update: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] - update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] - update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] - update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] - update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] - update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] - update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] - update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] - update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] - update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + update: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + update: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + update: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + update: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + update: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + update: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + update: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + update: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + update: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + update: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + update: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] update: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + update: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] update: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] - update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] - update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] - update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + update: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + update: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + update: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + update: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] update: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] - update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] - update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] - update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] - update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] - update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + update: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + update: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + update: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + update: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + update: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + update: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] update: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] - update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] - update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] - update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + update: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + update: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + update: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + update: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] update: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + update: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] update: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + update: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] update: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + update: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] - update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] - update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + update: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] update: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...253] [ip4][..udp] [......10.0.2.15][28681] -> [.193.37.255.130][61616] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] - update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] - update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] - update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + update: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + update: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + update: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + update: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] update: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] - update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] - update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] - update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] - update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] - update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] - update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] - update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] - update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] - update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + update: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + update: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + update: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + update: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + update: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + update: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + update: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + update: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + update: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + update: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...488] [ip4][..udp] [......10.0.2.15][28681] -> [.183.179.90.112][.9852] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5574,7 +5574,7 @@ RISK: Unsafe Protocol idle: [...492] [ip4][..udp] [......10.0.2.15][28681] -> [...172.94.41.71][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] + update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] update: [...759] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -5582,36 +5582,36 @@ RISK: Unsafe Protocol not-detected: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] + idle: [...577] [ip4][..udp] [......10.0.2.15][28681] -> [.59.148.100.237][23459] not-detected: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] + idle: [...586] [ip4][..udp] [......10.0.2.15][28681] -> [..221.124.66.33][13060] not-detected: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] + idle: [...618] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][13281] not-detected: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] + idle: [...377] [ip4][..udp] [......10.0.2.15][28681] -> [.180.200.236.13][12082] not-detected: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] + idle: [...526] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.197.93][.1483] idle: [...509] [ip4][..udp] [......10.0.2.15][28681] -> [.92.142.109.190][41370] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] + idle: [...669] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2846] not-detected: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] + idle: [...609] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][59016] not-detected: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] + idle: [...690] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][50637] not-detected: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] + idle: [...441] [ip4][..udp] [......10.0.2.15][28681] -> [.36.237.199.108][56040] not-detected: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] + idle: [...700] [ip4][..udp] [......10.0.2.15][28681] -> [...91.206.27.26][.6578] idle: [...511] [ip4][..udp] [......10.0.2.15][28681] -> [...68.47.223.27][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...331] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][26851] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -5619,754 +5619,754 @@ idle: [...361] [ip4][..udp] [......10.0.2.15][28681] -> [..86.129.196.84][.9915] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] [Unknown][Unknown][Unrated] - idle: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] + idle: [...450] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][23458] idle: [...496] [ip4][..udp] [......10.0.2.15][28681] -> [.218.173.230.98][19004] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] [Unknown][Unknown][Unrated] - idle: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] + idle: [...592] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][.7190] not-detected: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] + idle: [...701] [ip4][..udp] [......10.0.2.15][28681] -> [119.237.190.184][64163] idle: [...495] [ip4][..udp] [......10.0.2.15][28681] -> [...81.247.89.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...493] [ip4][..udp] [......10.0.2.15][57552] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] + idle: [...479] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.13.148][51896] not-detected: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] + idle: [...603] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][64577] not-detected: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] [Unknown][Unknown][Unrated] - idle: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] + idle: [...394] [ip4][..udp] [......10.0.2.15][28681] -> [.165.84.134.136][21407] idle: [...254] [ip4][..udp] [......10.0.2.15][28681] -> [..88.120.73.215][24562] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] + idle: [...740] [ip4][..udp] [......10.0.2.15][28681] -> [...36.237.25.47][21293] not-detected: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] + idle: [...646] [ip4][..udp] [......10.0.2.15][28681] -> [..36.237.10.152][21293] not-detected: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] + idle: [...621] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3227] idle: [...516] [ip4][..udp] [......10.0.2.15][28681] -> [.119.246.147.72][.4572] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] + idle: [...733] [ip4][..udp] [......10.0.2.15][28681] -> [...99.199.148.6][.4338] not-detected: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] + idle: [...597] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52274] not-detected: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] + idle: [...675] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][62191] idle: [...340] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49732] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] + idle: [...738] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3256] not-detected: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] [Unknown][Unknown][Unrated] - idle: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + idle: [...628] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] not-detected: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] [Unknown][Unknown][Unrated] - idle: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] + idle: [...616] [ip4][..udp] [......10.0.2.15][28681] -> [220.208.167.152][30628] not-detected: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] + idle: [...596] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58954] not-detected: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] + idle: [...474] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][45880] not-detected: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] + idle: [...713] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51379] not-detected: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] + idle: [...593] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.9747] not-detected: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] + idle: [...571] [ip4][..udp] [......10.0.2.15][28681] -> [.114.40.163.123][55341] not-detected: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] + idle: [...524] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][65362] not-detected: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] [Unknown][Unknown][Unrated] - idle: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] + idle: [...642] [ip4][..udp] [......10.0.2.15][28681] -> [.220.39.142.122][.6346] not-detected: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] + idle: [...477] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45640] not-detected: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + idle: [...444] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] not-detected: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] [Unknown][Unknown][Unrated] - idle: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + idle: [...572] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] not-detected: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] + idle: [...478] [ip4][..udp] [......10.0.2.15][28681] -> [...36.235.85.44][64914] not-detected: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] + idle: [...449] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][.8826] not-detected: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] + idle: [...649] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][56128] not-detected: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] + idle: [...461] [ip4][..udp] [......10.0.2.15][28681] -> [..69.27.193.124][50555] not-detected: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] [Unknown][Unknown][Unrated] - idle: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] + idle: [...520] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3339] not-detected: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] [Unknown][Unknown][Unrated] - idle: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + idle: [...335] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] not-detected: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] + idle: [...635] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.2556] idle: [...332] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] + idle: [...636] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][53143] not-detected: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] + idle: [...637] [ip4][..udp] [......10.0.2.15][28681] -> [..36.233.194.73][.1995] not-detected: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] + idle: [...676] [ip4][..udp] [......10.0.2.15][28681] -> [...1.64.208.110][55550] not-detected: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] + idle: [...722] [ip4][..udp] [......10.0.2.15][28681] -> [.213.32.245.121][12333] not-detected: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] + idle: [...578] [ip4][..udp] [......10.0.2.15][28681] -> [..77.205.243.44][46006] not-detected: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] + idle: [...737] [ip4][..udp] [......10.0.2.15][28681] -> [174.115.127.251][23897] not-detected: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] [Unknown][Unknown][Unrated] - idle: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] + idle: [...584] [ip4][..udp] [......10.0.2.15][28681] -> [.80.193.171.146][18360] not-detected: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] + idle: [...472] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][45744] not-detected: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] + idle: [...471] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][43457] not-detected: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] + idle: [...744] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][48250] not-detected: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] + idle: [...707] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][64871] idle: [...501] [ip4][..udp] [......10.0.2.15][28681] -> [.88.160.214.137][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] + idle: [...476] [ip4][..udp] [......10.0.2.15][28681] -> [..98.18.172.208][63172] not-detected: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] [Unknown][Unknown][Unrated] - idle: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] + idle: [...381] [ip4][..udp] [......10.0.2.15][28681] -> [...77.58.211.52][.3806] not-detected: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] + idle: [...683] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54459] not-detected: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] + idle: [...386] [ip4][..udp] [......10.0.2.15][28681] -> [...85.172.10.90][40162] idle: [...344] [ip4][..udp] [......10.0.2.15][28681] -> [.207.38.163.228][.6778] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...506] [ip4][..udp] [......10.0.2.15][28681] -> [..136.32.84.139][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] + idle: [...619] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][.1630] idle: [...323] [ip4][..udp] [......10.0.2.15][28681] -> [.96.246.156.126][56070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] + idle: [...691] [ip4][..udp] [......10.0.2.15][28681] -> [..61.93.150.146][62507] idle: [...265] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][.1194] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] + idle: [...620] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53516] not-detected: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] + idle: [...667] [ip4][..udp] [......10.0.2.15][28681] -> [.223.18.211.177][18085] not-detected: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] + idle: [...720] [ip4][..udp] [......10.0.2.15][28681] -> [..76.26.178.132][10053] not-detected: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] + idle: [...443] [ip4][..udp] [......10.0.2.15][28681] -> [..183.179.14.31][54754] not-detected: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] + idle: [...697] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][53906] not-detected: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] + idle: [...622] [ip4][..udp] [......10.0.2.15][28681] -> [..36.234.18.166][61319] not-detected: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] + idle: [...714] [ip4][..udp] [......10.0.2.15][28681] -> [..76.174.174.69][21358] not-detected: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] + idle: [...614] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][60482] not-detected: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] [Unknown][Unknown][Unrated] - idle: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + idle: [...746] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] not-detected: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] + idle: [...606] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][42288] not-detected: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] + idle: [...739] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][19814] not-detected: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] + idle: [...587] [ip4][..udp] [......10.0.2.15][28681] -> [.94.134.154.158][54130] not-detected: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] [Unknown][Unknown][Unrated] - idle: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] + idle: [...550] [ip4][..udp] [......10.0.2.15][28681] -> [.220.238.145.82][33527] not-detected: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] + idle: [...688] [ip4][..udp] [......10.0.2.15][28681] -> [.114.36.234.196][11629] idle: [...260] [ip4][..udp] [......10.0.2.15][28681] -> [.46.128.114.107][.6578] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] + idle: [...670] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52669] not-detected: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] + idle: [...598] [ip4][..udp] [......10.0.2.15][28681] -> [...1.172.184.48][.1512] not-detected: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] + idle: [...685] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.8349] not-detected: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] [Unknown][Unknown][Unrated] - idle: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] + idle: [...721] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][.9897] idle: [...336] [ip4][..udp] [......10.0.2.15][28681] -> [...80.7.252.192][.6888] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] + idle: [...631] [ip4][..udp] [......10.0.2.15][28681] -> [..36.231.59.187][62234] not-detected: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] + idle: [...591] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53707] not-detected: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] + idle: [...594] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7375] not-detected: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] + idle: [...613] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51920] not-detected: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] + idle: [...617] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7380] idle: [...508] [ip4][..udp] [......10.0.2.15][28681] -> [...92.144.99.73][10745] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] [Unknown][Unknown][Unrated] - idle: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] + idle: [...582] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][10624] idle: [...513] [ip4][..udp] [......10.0.2.15][28681] -> [..78.196.216.12][58910] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] + idle: [...568] [ip4][..udp] [......10.0.2.15][28681] -> [.123.205.118.77][56562] not-detected: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] + idle: [...446] [ip4][..udp] [......10.0.2.15][28681] -> [..61.70.199.107][60475] not-detected: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] + idle: [...470] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][46790] not-detected: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] [Unknown][Unknown][Unrated] - idle: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] + idle: [...623] [ip4][..udp] [......10.0.2.15][28681] -> [.210.209.249.84][24751] not-detected: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] [Unknown][Unknown][Unrated] - idle: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] + idle: [...629] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][45710] not-detected: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] + idle: [...692] [ip4][..udp] [......10.0.2.15][28681] -> [.76.110.153.177][40022] not-detected: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] + idle: [...604] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][53291] not-detected: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] + idle: [...718] [ip4][..udp] [......10.0.2.15][28681] -> [218.102.208.175][.9167] not-detected: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] [Unknown][Unknown][Unrated] - idle: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] + idle: [...447] [ip4][..udp] [......10.0.2.15][28681] -> [...14.199.10.60][23458] not-detected: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] + idle: [...451] [ip4][..udp] [......10.0.2.15][28681] -> [...218.35.66.21][22234] not-detected: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] + idle: [...600] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][60092] idle: [...250] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][26253] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] + idle: [...645] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49803] not-detected: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] + idle: [...661] [ip4][..udp] [......10.0.2.15][28681] -> [...24.127.1.235][37814] idle: [...499] [ip4][..udp] [......10.0.2.15][28681] -> [....1.161.80.82][.8656] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] + idle: [...626] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49815] not-detected: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] [Unknown][Unknown][Unrated] - idle: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] + idle: [...384] [ip4][..udp] [......10.0.2.15][28681] -> [....75.64.6.175][.4743] not-detected: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] [Unknown][Unknown][Unrated] - idle: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] + idle: [...378] [ip4][..udp] [......10.0.2.15][28681] -> [.118.241.204.61][43366] not-detected: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] + idle: [...703] [ip4][..udp] [......10.0.2.15][28681] -> [..114.40.67.191][14971] not-detected: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] + idle: [...656] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54914] not-detected: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] + idle: [...727] [ip4][..udp] [......10.0.2.15][28681] -> [101.136.187.253][10914] not-detected: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] [Unknown][Unknown][Unrated] - idle: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] + idle: [...456] [ip4][..udp] [......10.0.2.15][28681] -> [.89.241.112.255][14766] not-detected: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] + idle: [...521] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][23458] idle: [...505] [ip4][..udp] [......10.0.2.15][28681] -> [.....42.2.62.28][.6387] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...494] [ip4][..udp] [......10.0.2.15][28681] -> [...86.210.81.59][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] + idle: [...375] [ip4][..udp] [......10.0.2.15][28681] -> [..73.182.136.42][27873] not-detected: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] + idle: [...455] [ip4][..udp] [......10.0.2.15][28681] -> [.58.153.206.183][16919] not-detected: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] + idle: [...453] [ip4][..udp] [......10.0.2.15][28681] -> [..74.127.26.138][.3083] idle: [...498] [ip4][..udp] [......10.0.2.15][28681] -> [...8.44.149.207][30551] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...257] [ip4][..udp] [......10.0.2.15][28681] -> [.82.181.251.218][36368] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] + idle: [...704] [ip4][..udp] [......10.0.2.15][28681] -> [..123.192.83.59][33513] not-detected: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] + idle: [...641] [ip4][..udp] [......10.0.2.15][28681] -> [.36.233.199.103][.2625] not-detected: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] + idle: [...460] [ip4][..udp] [......10.0.2.15][28681] -> [.210.194.116.78][.8342] not-detected: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] + idle: [...717] [ip4][..udp] [......10.0.2.15][28681] -> [...79.191.58.38][48157] not-detected: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] + idle: [...742] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][36780] not-detected: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] + idle: [...454] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][23183] not-detected: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] + idle: [...674] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.1.236][.9369] not-detected: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] + idle: [...672] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.4765] not-detected: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] + idle: [...681] [ip4][..udp] [......10.0.2.15][28681] -> [..61.220.41.241][53072] not-detected: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] + idle: [...640] [ip4][..udp] [......10.0.2.15][28681] -> [....1.36.249.91][65430] not-detected: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] + idle: [...682] [ip4][..udp] [......10.0.2.15][28681] -> [203.220.198.244][50896] not-detected: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] + idle: [...679] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.83.132][57131] not-detected: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] + idle: [...694] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6514] not-detected: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] + idle: [...469] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][47184] idle: [...321] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][21995] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] + idle: [...665] [ip4][..udp] [......10.0.2.15][28681] -> [..82.36.106.134][.3927] not-detected: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] + idle: [...660] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6527] not-detected: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] + idle: [...615] [ip4][..udp] [......10.0.2.15][28681] -> [.74.195.236.249][18557] not-detected: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] + idle: [...716] [ip4][..udp] [......10.0.2.15][28681] -> [...98.249.190.8][25198] not-detected: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] + idle: [...731] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6564] idle: [...342] [ip4][..udp] [......10.0.2.15][28681] -> [..98.208.26.154][.4994] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] + idle: [...388] [ip4][..udp] [......10.0.2.15][28681] -> [...121.7.145.36][33905] not-detected: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] + idle: [...735] [ip4][..udp] [......10.0.2.15][28681] -> [..45.31.152.112][52420] not-detected: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] + idle: [...747] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6599] not-detected: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] + idle: [...634] [ip4][..udp] [......10.0.2.15][28681] -> [..24.179.18.242][47329] idle: [...246] [ip4][..udp] [......10.0.2.15][28681] -> [...96.65.68.194][35481] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] + idle: [...527] [ip4][..udp] [......10.0.2.15][28681] -> [..42.72.149.140][37848] not-detected: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] [Unknown][Unknown][Unrated] - idle: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] + idle: [...643] [ip4][..udp] [......10.0.2.15][28681] -> [..31.20.248.147][30706] not-detected: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] + idle: [...711] [ip4][..udp] [......10.0.2.15][28681] -> [..220.129.86.65][49723] not-detected: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] + idle: [...563] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6831] idle: [...504] [ip4][..udp] [......10.0.2.15][28681] -> [..85.203.45.107][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] + idle: [...639] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.7849] not-detected: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] + idle: [...729] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][54463] not-detected: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] [Unknown][Unknown][Unrated] - idle: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] + idle: [...732] [ip4][..udp] [......10.0.2.15][28681] -> [..85.168.34.105][39908] not-detected: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] + idle: [...633] [ip4][..udp] [......10.0.2.15][28681] -> [..68.174.18.115][50679] not-detected: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] [Unknown][Unknown][Unrated] - idle: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] + idle: [...607] [ip4][..udp] [......10.0.2.15][28681] -> [..111.241.31.96][.4814] idle: [...317] [ip4][..udp] [......10.0.2.15][28681] -> [...96.236.205.7][34794] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] + idle: [...705] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][.8658] not-detected: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] [Unknown][Unknown][Unrated] - idle: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] + idle: [...698] [ip4][..udp] [......10.0.2.15][28681] -> [..70.81.219.111][19210] not-detected: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] + idle: [...595] [ip4][..udp] [......10.0.2.15][28681] -> [.175.182.21.156][13732] not-detected: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] + idle: [...723] [ip4][..udp] [......10.0.2.15][28681] -> [.175.39.219.223][13482] not-detected: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] [Unknown][Unknown][Unrated] - idle: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] + idle: [...376] [ip4][..udp] [......10.0.2.15][28681] -> [....156.57.42.2][33476] not-detected: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] + idle: [...673] [ip4][..udp] [......10.0.2.15][28681] -> [.125.59.215.249][14571] not-detected: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] + idle: [...611] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59384] not-detected: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] + idle: [...724] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.9070] idle: [...261] [ip4][..udp] [......10.0.2.15][28681] -> [..60.241.48.194][21301] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] + idle: [...666] [ip4][..udp] [......10.0.2.15][28681] -> [.159.196.95.223][.2003] not-detected: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] + idle: [...644] [ip4][..udp] [......10.0.2.15][28681] -> [...173.22.22.94][34245] not-detected: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] [Unknown][Unknown][Unrated] - idle: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] + idle: [...648] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][.4548] idle: [...313] [ip4][..udp] [......10.0.2.15][28681] -> [..176.99.176.20][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] [Unknown][Unknown][Unrated] - idle: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] + idle: [...579] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.170.108][23458] not-detected: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] + idle: [...677] [ip4][..udp] [......10.0.2.15][28681] -> [....223.16.83.5][.9128] not-detected: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] + idle: [...706] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.1968] not-detected: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] + idle: [...654] [ip4][..udp] [......10.0.2.15][28681] -> [.84.118.116.198][44616] not-detected: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] + idle: [...725] [ip4][..udp] [......10.0.2.15][28681] -> [..219.91.30.216][61635] idle: [...319] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][55302] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] [Unknown][Unknown][Unrated] - idle: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] + idle: [...302] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][53489] not-detected: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] + idle: [...668] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][64731] idle: [...255] [ip4][..udp] [......10.0.2.15][28681] -> [..80.61.221.246][30577] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] + idle: [...741] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.4364] not-detected: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] + idle: [...696] [ip4][..udp] [......10.0.2.15][28681] -> [188.165.203.190][55050] not-detected: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] + idle: [...585] [ip4][..udp] [......10.0.2.15][28681] -> [..51.68.153.214][35004] idle: [...502] [ip4][..udp] [......10.0.2.15][28681] -> [..47.156.58.211][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...507] [ip4][..udp] [......10.0.2.15][28681] -> [...50.4.204.220][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] + idle: [...686] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][13965] not-detected: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] [Unknown][Unknown][Unrated] - idle: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] + idle: [...662] [ip4][..udp] [......10.0.2.15][28681] -> [..96.59.117.166][33192] not-detected: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] + idle: [...602] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][53658] not-detected: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] + idle: [...589] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52647] not-detected: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] + idle: [...653] [ip4][..udp] [......10.0.2.15][28681] -> [....82.12.1.136][.6348] not-detected: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] + idle: [...458] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.228.167][12201] not-detected: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] + idle: [...525] [ip4][..udp] [......10.0.2.15][28681] -> [.113.255.250.32][52660] not-detected: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] + idle: [...610] [ip4][..udp] [......10.0.2.15][28681] -> [..61.10.174.159][.4841] idle: [...248] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][12012] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...512] [ip4][..udp] [......10.0.2.15][28681] -> [..209.204.207.5][49256] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] + idle: [...734] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.91.201][.4297] not-detected: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] [Unknown][Unknown][Unrated] - idle: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] + idle: [...627] [ip4][..udp] [......10.0.2.15][28681] -> [..73.62.225.181][46843] not-detected: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] [Unknown][Unknown][Unrated] - idle: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] + idle: [...380] [ip4][..udp] [......10.0.2.15][28681] -> [...83.86.49.195][12019] not-detected: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] + idle: [...702] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10728] not-detected: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] + idle: [...650] [ip4][..udp] [......10.0.2.15][28681] -> [..114.47.227.91][58856] not-detected: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] + idle: [...581] [ip4][..udp] [......10.0.2.15][28681] -> [..58.115.108.10][.4641] not-detected: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] + idle: [...612] [ip4][..udp] [......10.0.2.15][28681] -> [.106.104.88.139][.7423] not-detected: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] + idle: [...583] [ip4][..udp] [......10.0.2.15][28681] -> [...87.75.180.80][35361] not-detected: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] + idle: [...671] [ip4][..udp] [......10.0.2.15][28681] -> [180.218.135.222][49867] not-detected: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] [Unknown][Unknown][Unrated] - idle: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + idle: [...574] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] not-detected: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] + idle: [...678] [ip4][..udp] [......10.0.2.15][28681] -> [150.116.225.105][51438] idle: [...518] [ip4][..udp] [......10.0.2.15][28681] -> [..202.151.63.59][.7624] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] + idle: [...715] [ip4][..udp] [......10.0.2.15][28681] -> [...219.71.72.88][58808] not-detected: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] + idle: [...659] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10791] not-detected: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] + idle: [...457] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.240.113][13867] not-detected: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] + idle: [...564] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53144] not-detected: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] + idle: [...647] [ip4][..udp] [......10.0.2.15][28681] -> [..61.18.212.223][58290] not-detected: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] + idle: [...699] [ip4][..udp] [......10.0.2.15][28681] -> [..77.222.213.44][26536] not-detected: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] + idle: [...651] [ip4][..udp] [......10.0.2.15][28681] -> [....1.64.156.63][65023] not-detected: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] + idle: [...658] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.8075] not-detected: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] + idle: [...712] [ip4][..udp] [......10.0.2.15][28681] -> [.185.187.74.173][59978] not-detected: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] + idle: [...657] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53195] idle: [...364] [ip4][..udp] [......10.0.2.15][28681] -> [194.163.180.126][10825] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] + idle: [...576] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][42925] not-detected: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] [Unknown][Unknown][Unrated] - idle: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + idle: [...570] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] not-detected: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] + idle: [...680] [ip4][..udp] [......10.0.2.15][28681] -> [.61.227.198.100][.6910] idle: [...500] [ip4][..udp] [......10.0.2.15][28681] -> [.220.143.34.225][20071] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] + idle: [...566] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52755] idle: [...514] [ip4][..udp] [......10.0.2.15][28681] -> [..83.114.40.175][23552] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] + idle: [...599] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][59875] idle: [...517] [ip4][..udp] [......10.0.2.15][28681] -> [..36.239.162.27][.7986] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...519] [ip4][..udp] [......10.0.2.15][28681] -> [...219.70.48.23][.8070] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] + idle: [...601] [ip4][..udp] [......10.0.2.15][28681] -> [113.255.200.161][65274] idle: [...253] [ip4][..udp] [......10.0.2.15][28681] -> [.193.37.255.130][61616] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] [Unknown][Unknown][Unrated] - idle: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] + idle: [...638] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.242.225][15068] not-detected: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] [Unknown][Unknown][Unrated] - idle: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] + idle: [...463] [ip4][..udp] [......10.0.2.15][28681] -> [..200.7.155.210][28365] not-detected: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] + idle: [...726] [ip4][..udp] [......10.0.2.15][28681] -> [....1.171.82.65][50072] not-detected: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] [Unknown][Unknown][Unrated] - idle: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] + idle: [...452] [ip4][..udp] [......10.0.2.15][28681] -> [..68.227.193.37][27481] not-detected: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] [Unknown][Unknown][Unrated] - idle: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] + idle: [...608] [ip4][..udp] [......10.0.2.15][28681] -> [...1.163.14.246][23461] not-detected: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] + idle: [...736] [ip4][..udp] [......10.0.2.15][28681] -> [118.166.252.163][14391] not-detected: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] [Unknown][Unknown][Unrated] - idle: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] + idle: [...448] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][15677] not-detected: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] [Unknown][Unknown][Unrated] - idle: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] + idle: [...549] [ip4][..udp] [......10.0.2.15][28681] -> [..84.211.151.48][11105] not-detected: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] + idle: [...459] [ip4][..udp] [......10.0.2.15][28681] -> [...100.89.84.59][11603] not-detected: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] + idle: [...625] [ip4][..udp] [......10.0.2.15][28681] -> [113.252.206.254][49737] not-detected: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + idle: [...580] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] idle: [...339] [ip4][..udp] [......10.0.2.15][28681] -> [..87.123.54.234][54130] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] + idle: [...624] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57492] not-detected: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] + idle: [...567] [ip4][..udp] [......10.0.2.15][28681] -> [...58.176.62.40][52889] not-detected: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] + idle: [...684] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][54436] not-detected: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] [Unknown][Unknown][Unrated] - idle: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] + idle: [...743] [ip4][..udp] [......10.0.2.15][28681] -> [...27.94.154.53][.6346] idle: [...316] [ip4][..udp] [......10.0.2.15][28681] -> [....94.54.66.82][63637] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] + idle: [...730] [ip4][..udp] [......10.0.2.15][28681] -> [124.217.188.105][62849] not-detected: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] + idle: [...710] [ip4][..udp] [......10.0.2.15][28681] -> [113.254.140.225][63637] not-detected: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] + idle: [...709] [ip4][..udp] [......10.0.2.15][28681] -> [.223.16.121.156][.3624] not-detected: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] + idle: [...687] [ip4][..udp] [......10.0.2.15][28681] -> [..66.30.221.181][53454] not-detected: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] + idle: [...445] [ip4][..udp] [......10.0.2.15][28681] -> [118.165.153.100][.4509] idle: [...262] [ip4][..udp] [......10.0.2.15][28681] -> [....89.75.52.19][46010] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...510] [ip4][..udp] [......10.0.2.15][28681] -> [...79.94.85.113][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] + idle: [...652] [ip4][..udp] [......10.0.2.15][28681] -> [..94.139.21.182][50110] idle: [...497] [ip4][..udp] [......10.0.2.15][28681] -> [..84.100.76.123][39628] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] [Unknown][Unknown][Unrated] - idle: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] + idle: [...569] [ip4][..udp] [......10.0.2.15][28681] -> [....73.89.249.8][50649] not-detected: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] + idle: [...393] [ip4][..udp] [......10.0.2.15][28681] -> [.58.115.158.103][.5110] not-detected: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] [Unknown][Unknown][Unrated] - idle: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] + idle: [...464] [ip4][..udp] [......10.0.2.15][28681] -> [...101.128.66.8][34512] idle: [...515] [ip4][..udp] [......10.0.2.15][28681] -> [220.137.106.173][11625] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] + idle: [...522] [ip4][..udp] [......10.0.2.15][28681] -> [119.247.152.218][51153] not-detected: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] + idle: [...480] [ip4][..udp] [......10.0.2.15][28681] -> [..112.119.74.26][65498] not-detected: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] [Unknown][Unknown][Unrated] - idle: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] + idle: [...382] [ip4][..udp] [......10.0.2.15][28681] -> [..76.175.11.126][40958] not-detected: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] + idle: [...590] [ip4][..udp] [......10.0.2.15][28681] -> [...95.10.205.67][48380] guessed: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] [BACnet][Unknown][IoT-Scada][Safe] RISK: Unidirectional Traffic - idle: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] + idle: [...462] [ip4][..udp] [......10.0.2.15][28681] -> [..164.132.10.25][47808] not-detected: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] + idle: [...605] [ip4][..udp] [......10.0.2.15][28681] -> [180.149.125.139][.6578] not-detected: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] + idle: [...689] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][.3688] not-detected: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] + idle: [...664] [ip4][..udp] [......10.0.2.15][28681] -> [..1.172.183.237][.4983] not-detected: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] + idle: [...708] [ip4][..udp] [......10.0.2.15][28681] -> [..124.244.68.65][51967] not-detected: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] [Unknown][Unknown][Unrated] - idle: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] + idle: [...655] [ip4][..udp] [......10.0.2.15][28681] -> [.119.237.116.22][.2566] not-detected: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] + idle: [...728] [ip4][..udp] [......10.0.2.15][28681] -> [..112.10.134.44][19739] not-detected: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] [Unknown][Unknown][Unrated] - idle: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] + idle: [...548] [ip4][..udp] [......10.0.2.15][28681] -> [..74.50.147.205][17735] not-detected: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] + idle: [...632] [ip4][..udp] [......10.0.2.15][28681] -> [...188.149.2.44][20964] not-detected: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] + idle: [...475] [ip4][..udp] [......10.0.2.15][28681] -> [..188.61.52.183][63978] not-detected: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] + idle: [...473] [ip4][..udp] [......10.0.2.15][28681] -> [.142.132.165.13][33564] not-detected: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] [Unknown][Unknown][Unrated] - idle: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] + idle: [...575] [ip4][..udp] [......10.0.2.15][28681] -> [.123.202.31.113][19768] not-detected: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] + idle: [...588] [ip4][..udp] [......10.0.2.15][28681] -> [.219.70.175.103][.4315] not-detected: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] [Unknown][Unknown][Unrated] - idle: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] + idle: [...379] [ip4][..udp] [......10.0.2.15][28681] -> [..80.140.63.147][29545] idle: [...367] [ip4][..udp] [......10.0.2.15][28681] -> [.149.28.163.175][49956] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Unknown][Unknown][Unrated] - idle: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + idle: [...719] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] not-detected: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] + idle: [...442] [ip4][..udp] [......10.0.2.15][28681] -> [..89.204.130.55][29545] not-detected: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] [Unknown][Unknown][Unrated] - idle: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] + idle: [...630] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][.3931] not-detected: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] + idle: [...565] [ip4][..udp] [......10.0.2.15][28681] -> [...114.45.40.28][.2656] not-detected: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] [Unknown][Unknown][Unrated] - idle: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] + idle: [...523] [ip4][..udp] [......10.0.2.15][28681] -> [..1.162.138.200][24018] not-detected: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] - update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + idle: [...693] [ip4][..udp] [......10.0.2.15][28681] -> [.98.215.130.156][12405] + update: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] update: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + update: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] update: [...752] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...128] [ip4][..udp] [......10.0.2.15][28681] -> [..77.141.219.27][37580] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6381,7 +6381,7 @@ RISK: Unsafe Protocol update: [....88] [ip4][..udp] [......10.0.2.15][28681] -> [.....81.50.24.2][17874] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + update: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] update: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6389,17 +6389,17 @@ update: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] - update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] - update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + update: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + update: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + update: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] update: [...760] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol update: [...118] [ip4][..udp] [......10.0.2.15][28681] -> [...5.180.62.100][46385] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + update: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] update: [...117] [ip4][..udp] [......10.0.2.15][28681] -> [200.120.243.143][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + update: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] update: [...191] [ip4][..udp] [......10.0.2.15][28681] -> [.190.153.143.54][65535] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...172] [ip4][..udp] [......10.0.2.15][28681] -> [..87.69.142.133][15471] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6408,11 +6408,11 @@ RISK: Unsafe Protocol update: [....98] [ip4][..udp] [......10.0.2.15][28681] -> [.203.222.14.170][23332] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] - update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + update: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + update: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] update: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] update: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...139] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.226.142][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6421,15 +6421,15 @@ RISK: Unsafe Protocol update: [...141] [ip4][..udp] [......10.0.2.15][28681] -> [..172.97.199.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + update: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] update: [...751] [ip4][..udp] [......10.0.2.15][28681] -> [142.115.218.152][.5900] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] - update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] - update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + update: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + update: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + update: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] update: [...126] [ip4][..udp] [......10.0.2.15][28681] -> [..91.69.159.133][28000] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + update: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] update: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....85] [ip4][..udp] [......10.0.2.15][28681] -> [..85.138.20.110][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6438,19 +6438,19 @@ RISK: Unsafe Protocol update: [...135] [ip4][..udp] [......10.0.2.15][28681] -> [.193.250.99.158][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + update: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] update: [...764] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] - update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] - update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + update: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + update: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + update: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] update: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...176] [ip4][..udp] [......10.0.2.15][28681] -> [....41.99.164.4][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + update: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] update: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6459,37 +6459,37 @@ RISK: Unsafe Protocol update: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] - update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + update: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + update: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] update: [...133] [ip4][..udp] [......10.0.2.15][28681] -> [.91.175.220.161][15721] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + update: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] update: [...753] [ip4][..udp] [......10.0.2.15][28681] -> [..165.84.140.96][14400] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...171] [ip4][..udp] [......10.0.2.15][28681] -> [196.217.132.111][25394] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + update: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] update: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...124] [ip4][..udp] [......10.0.2.15][28681] -> [...170.254.19.6][24180] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] - update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + update: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + update: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] update: [...185] [ip4][..udp] [......10.0.2.15][28681] -> [.109.132.196.58][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...762] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + update: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] update: [...130] [ip4][..udp] [......10.0.2.15][28681] -> [..119.224.95.97][46356] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...129] [ip4][..udp] [......10.0.2.15][28681] -> [.176.138.50.179][29411] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + update: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] update: [...161] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + update: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] update: [...755] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...137] [ip4][..udp] [......10.0.2.15][28681] -> [...82.65.70.197][21693] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6504,42 +6504,42 @@ RISK: Unsafe Protocol update: [...200] [ip4][..udp] [......10.0.2.15][28681] -> [.138.199.16.123][52993] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + update: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] update: [...763] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] - update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] - update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + update: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + update: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + update: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] update: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [....87] [ip4][..udp] [......10.0.2.15][28681] -> [..92.131.85.245][31743] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...761] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + update: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] update: [...138] [ip4][..udp] [......10.0.2.15][28681] -> [167.114.170.156][23844] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] - new: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] - new: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] - new: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] - new: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] - new: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] - new: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] - new: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] - new: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - new: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] - new: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] - new: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] - new: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] - new: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - new: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] - new: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] - new: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] - new: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] - new: [...783] [ip4][.icmp] [.65.182.231.232] -> [......10.0.2.15] + new: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] + new: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + new: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + new: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + new: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] + new: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + new: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] + new: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] + new: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + new: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] + new: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + new: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] + new: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] + new: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + new: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] + new: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] + new: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] + new: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] + new: [...783] [ip4][.icmp] [.65.182.231.232] -> [......10.0.2.15] detected: [...783] [ip4][.icmp] [.65.182.231.232] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] - new: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] + new: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] idle: [....88] [ip4][..udp] [......10.0.2.15][28681] -> [.....81.50.24.2][17874] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...159] [ip4][..udp] [......10.0.2.15][28681] -> [176.163.231.160][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6554,151 +6554,151 @@ RISK: Unsafe Protocol update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] update: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...785] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] + new: [...785] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] detected: [...785] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...786] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] + new: [...786] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] detected: [...786] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...787] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] + new: [...787] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] detected: [...787] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...788] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] + new: [...788] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] detected: [...788] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...789] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] + new: [...789] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] detected: [...789] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...790] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] + new: [...790] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] detected: [...790] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...791] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] + new: [...791] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] detected: [...791] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...792] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] + new: [...792] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] detected: [...792] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...793] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] + new: [...793] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] detected: [...793] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] + idle: [...544] [ip4][..udp] [......10.0.2.15][28681] -> [..111.184.29.35][30582] not-detected: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] + idle: [...533] [ip4][..udp] [......10.0.2.15][28681] -> [..36.229.185.60][.6898] not-detected: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] + idle: [...553] [ip4][..udp] [......10.0.2.15][28681] -> [182.155.128.228][.3259] not-detected: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] + idle: [...546] [ip4][..udp] [......10.0.2.15][28681] -> [.38.142.119.234][49867] not-detected: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] + idle: [...531] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51497] not-detected: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] + idle: [...534] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][54436] not-detected: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] + idle: [...562] [ip4][..udp] [......10.0.2.15][28681] -> [112.119.242.110][59879] not-detected: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] + idle: [...542] [ip4][..udp] [......10.0.2.15][28681] -> [..218.103.139.2][51675] not-detected: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] + idle: [...551] [ip4][..udp] [......10.0.2.15][28681] -> [..92.24.129.230][14766] not-detected: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] + idle: [...555] [ip4][..udp] [......10.0.2.15][28681] -> [..124.218.26.16][20387] idle: [...259] [ip4][..udp] [......10.0.2.15][28681] -> [103.232.107.100][43508] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] + idle: [...538] [ip4][..udp] [......10.0.2.15][28681] -> [.124.218.41.253][14339] not-detected: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] + idle: [...536] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.222.160][56121] not-detected: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] + idle: [...558] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][.6466] not-detected: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] + idle: [...556] [ip4][..udp] [......10.0.2.15][28681] -> [...59.104.173.5][49787] not-detected: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] + idle: [...560] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][53883] not-detected: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] + idle: [...559] [ip4][..udp] [......10.0.2.15][28681] -> [.113.252.86.162][55080] not-detected: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] + idle: [...529] [ip4][..udp] [......10.0.2.15][28681] -> [116.241.162.162][57929] not-detected: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] + idle: [...539] [ip4][..udp] [......10.0.2.15][28681] -> [.119.14.143.237][.7510] not-detected: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] + idle: [...545] [ip4][..udp] [......10.0.2.15][28681] -> [..116.49.159.77][55915] not-detected: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] + idle: [...663] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.163][.6594] not-detected: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] + idle: [...554] [ip4][..udp] [......10.0.2.15][28681] -> [.123.203.72.224][55577] not-detected: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] + idle: [...528] [ip4][..udp] [......10.0.2.15][28681] -> [..118.168.15.71][58442] not-detected: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] + idle: [...537] [ip4][..udp] [......10.0.2.15][28681] -> [218.164.200.235][.2034] idle: [...753] [ip4][..udp] [......10.0.2.15][28681] -> [..165.84.140.96][14400] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] + idle: [...535] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10655] not-detected: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] + idle: [...532] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][10677] not-detected: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] + idle: [...695] [ip4][..udp] [......10.0.2.15][28681] -> [..76.189.72.230][.8161] not-detected: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] + idle: [...552] [ip4][..udp] [......10.0.2.15][28681] -> [...218.250.6.59][60012] not-detected: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] + idle: [...543] [ip4][..udp] [......10.0.2.15][28681] -> [..114.39.159.60][56896] not-detected: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] + idle: [...557] [ip4][..udp] [......10.0.2.15][28681] -> [..61.222.160.99][53163] not-detected: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] + idle: [...561] [ip4][..udp] [......10.0.2.15][28681] -> [.61.238.173.128][57466] not-detected: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] + idle: [...541] [ip4][..udp] [......10.0.2.15][28681] -> [...114.27.24.95][11141] not-detected: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] + idle: [...547] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][43316] not-detected: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] + idle: [...530] [ip4][..udp] [......10.0.2.15][28681] -> [118.167.248.220][59304] not-detected: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] - update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] + idle: [...540] [ip4][..udp] [......10.0.2.15][28681] -> [..36.236.203.37][52131] + update: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] update: [...759] [ip4][..udp] [......10.0.2.15][28681] -> [104.238.172.250][23548] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [...757] [ip4][..udp] [......10.0.2.15][28681] -> [.104.156.226.72][53258] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...794] [ip4][..udp] [......10.0.2.15][50214] -> [239.255.255.250][.1900] + new: [...794] [ip4][..udp] [......10.0.2.15][50214] -> [239.255.255.250][.1900] detected: [...794] [ip4][..udp] [......10.0.2.15][50214] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] update: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol @@ -6736,7 +6736,7 @@ RISK: Unsafe Protocol update: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + update: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] update: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...139] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.226.142][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -6814,65 +6814,65 @@ RISK: Unsafe Protocol not-detected: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] + idle: [...754] [ip4][..udp] [......10.0.2.15][28681] -> [..84.125.218.84][17561] idle: [....98] [ip4][..udp] [......10.0.2.15][28681] -> [.203.222.14.170][23332] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] [Unknown][Unknown][Unrated] - idle: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] + idle: [...573] [ip4][..udp] [......10.0.2.15][28681] -> [..71.239.173.18][23327] not-detected: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] [Unknown][Unknown][Unrated] - idle: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] - update: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] - update: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] - update: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] - update: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] - update: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] - update: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] - update: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] - update: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] + idle: [...383] [ip4][..udp] [......10.0.2.15][28681] -> [...84.71.243.60][34498] + update: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] + update: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] + update: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + update: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + update: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + update: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] + update: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + update: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] update: [...787] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...793] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] - update: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] + update: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] + update: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] update: [...792] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] + update: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] update: [...786] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] - update: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] + update: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] + update: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] update: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] - update: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + update: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] + update: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] update: [...788] [ip4][..udp] [......10.0.2.15][28681] -> [.220.134.167.82][.5820] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...789] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] - update: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + update: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] + update: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] update: [...400] [ip4][..udp] [......10.0.2.15][28681] -> [..129.45.47.167][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...790] [ip4][..udp] [......10.0.2.15][28681] -> [.218.164.39.233][20855] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + update: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] update: [...785] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - update: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] + update: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] update: [...791] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol update: [...312] [ip4][..udp] [......10.0.2.15][28681] -> [..24.167.201.53][47282] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...795] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] + new: [...795] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] detected: [...795] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...796] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] + new: [...796] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] detected: [...796] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol - new: [...797] [ip4][.icmp] [...154.3.42.209] -> [......10.0.2.15] + new: [...797] [ip4][.icmp] [...154.3.42.209] -> [......10.0.2.15] detected: [...797] [ip4][.icmp] [...154.3.42.209] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] idle: [...195] [ip4][..udp] [......10.0.2.15][28681] -> [.177.231.151.16][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol @@ -6997,19 +6997,19 @@ RISK: Unsafe Protocol idle: [...758] [ip4][..udp] [......10.0.2.15][50213] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [...797] [ip4][.icmp] [...154.3.42.209] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] - new: [...798] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] + new: [...798] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] detected: [...798] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...799] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] + new: [...799] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] detected: [...799] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] - new: [...800] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] + new: [...800] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] detected: [...800] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] - new: [...801] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] + new: [...801] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] detected: [...801] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 3882 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 169 / 801|skipped: 0|!detected: 311|guessed: 1|detection-updates: 5|updates: 2519] not-detected: [....52] [ip4][..tcp] [......10.0.2.15][50212] -> [...95.17.124.40][.6776] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....52] [ip4][..tcp] [......10.0.2.15][50212] -> [...95.17.124.40][.6776] + idle: [....52] [ip4][..tcp] [......10.0.2.15][50212] -> [...95.17.124.40][.6776] idle: [...750] [ip4][..udp] [......10.0.2.15][28681] -> [....67.193.8.52][38584] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...752] [ip4][..udp] [......10.0.2.15][28681] -> [...78.231.73.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7019,7 +7019,7 @@ idle: [...166] [ip4][..udp] [......10.0.2.15][28681] -> [..90.59.253.186][15555] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] [Unknown][Unknown][Unrated] - idle: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] + idle: [...777] [ip4][..udp] [......10.0.2.15][28681] -> [.124.244.211.43][23459] idle: [...184] [ip4][..udp] [......10.0.2.15][28681] -> [..86.239.62.213][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...183] [ip4][..udp] [......10.0.2.15][28681] -> [..91.172.15.182][37829] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7028,49 +7028,49 @@ RISK: Unsafe Protocol not-detected: [...245] [ip4][..tcp] [......10.0.2.15][50289] -> [.74.195.236.249][18557] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...245] [ip4][..tcp] [......10.0.2.15][50289] -> [.74.195.236.249][18557] + idle: [...245] [ip4][..tcp] [......10.0.2.15][50289] -> [.74.195.236.249][18557] idle: [...800] [ip4][..udp] [......10.0.2.15][63957] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] not-detected: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] + idle: [...776] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.10.83][.8797] not-detected: [...227] [ip4][..tcp] [......10.0.2.15][50273] -> [..24.179.18.242][47329] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...227] [ip4][..tcp] [......10.0.2.15][50273] -> [..24.179.18.242][47329] + idle: [...227] [ip4][..tcp] [......10.0.2.15][50273] -> [..24.179.18.242][47329] end: [...276] [ip4][..tcp] [......10.0.2.15][50300] -> [..188.61.52.183][11852] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] [Unknown][Unknown][Unrated] - idle: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] + idle: [...767] [ip4][..udp] [......10.0.2.15][28681] -> [....45.65.87.24][16201] idle: [...352] [ip4][..udp] [......10.0.2.15][28681] -> [.176.191.49.159][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....72] [ip4][..tcp] [......10.0.2.15][50231] -> [..76.68.138.207][45079] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....72] [ip4][..tcp] [......10.0.2.15][50231] -> [..76.68.138.207][45079] + idle: [....72] [ip4][..tcp] [......10.0.2.15][50231] -> [..76.68.138.207][45079] not-detected: [...228] [ip4][..tcp] [......10.0.2.15][50274] -> [..68.174.18.115][50679] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...228] [ip4][..tcp] [......10.0.2.15][50274] -> [..68.174.18.115][50679] + idle: [...228] [ip4][..tcp] [......10.0.2.15][50274] -> [..68.174.18.115][50679] idle: [...219] [ip4][..udp] [......10.0.2.15][28681] -> [...76.30.86.144][53821] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] + idle: [...778] [ip4][..udp] [......10.0.2.15][28681] -> [.122.117.100.78][.9010] not-detected: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] [Unknown][Unknown][Unrated] - idle: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] + idle: [...773] [ip4][..udp] [......10.0.2.15][28681] -> [...86.153.21.93][36696] idle: [.....8] [ip4][....2] [......10.0.2.15] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] end: [...238] [ip4][..tcp] [......10.0.2.15][50284] -> [.104.156.226.72][53258] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] + idle: [...779] [ip4][..udp] [......10.0.2.15][28681] -> [...1.65.217.224][18381] not-detected: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] [Unknown][Unknown][Unrated] - idle: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] + idle: [...768] [ip4][..udp] [......10.0.2.15][28681] -> [.14.200.255.229][37058] not-detected: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] [Unknown][Unknown][Unrated] - idle: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] + idle: [...765] [ip4][..udp] [......10.0.2.15][28681] -> [213.229.111.224][.4876] not-detected: [....75] [ip4][..tcp] [......10.0.2.15][50234] -> [...66.189.28.17][16269] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....75] [ip4][..tcp] [......10.0.2.15][50234] -> [...66.189.28.17][16269] + idle: [....75] [ip4][..tcp] [......10.0.2.15][50234] -> [...66.189.28.17][16269] not-detected: [...240] [ip4][..tcp] [......10.0.2.15][50286] -> [.84.118.116.198][44616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...240] [ip4][..tcp] [......10.0.2.15][50286] -> [.84.118.116.198][44616] + idle: [...240] [ip4][..tcp] [......10.0.2.15][50286] -> [.84.118.116.198][44616] idle: [...760] [ip4][..udp] [......10.0.2.15][..138] -> [.....10.0.2.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol idle: [...798] [ip4][..udp] [......10.0.2.15][63962] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -7078,17 +7078,17 @@ RISK: Unsafe Protocol not-detected: [....74] [ip4][..tcp] [......10.0.2.15][50233] -> [...1.163.14.246][12854] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....74] [ip4][..tcp] [......10.0.2.15][50233] -> [...1.163.14.246][12854] + idle: [....74] [ip4][..tcp] [......10.0.2.15][50233] -> [...1.163.14.246][12854] not-detected: [...152] [ip4][..tcp] [......10.0.2.15][50265] -> [.113.255.250.32][52647] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...152] [ip4][..tcp] [......10.0.2.15][50265] -> [.113.255.250.32][52647] + idle: [...152] [ip4][..tcp] [......10.0.2.15][50265] -> [.113.255.250.32][52647] idle: [...796] [ip4][..udp] [......10.0.2.15][28681] -> [..41.249.63.200][22582] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...787] [ip4][..udp] [......10.0.2.15][28681] -> [220.133.122.217][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...233] [ip4][..tcp] [......10.0.2.15][50279] -> [.113.252.91.201][.4297] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...233] [ip4][..tcp] [......10.0.2.15][50279] -> [.113.252.91.201][.4297] + idle: [...233] [ip4][..tcp] [......10.0.2.15][50279] -> [.113.252.91.201][.4297] idle: [...117] [ip4][..udp] [......10.0.2.15][28681] -> [200.120.243.143][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...793] [ip4][..udp] [......10.0.2.15][28681] -> [123.205.126.102][.5193] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7100,24 +7100,24 @@ idle: [...801] [ip6][icmp6] [..............fe80::c50d:519f:96a4:e108] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] not-detected: [...123] [ip4][..tcp] [......10.0.2.15][50254] -> [..24.78.134.188][49046] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...123] [ip4][..tcp] [......10.0.2.15][50254] -> [..24.78.134.188][49046] + idle: [...123] [ip4][..tcp] [......10.0.2.15][50254] -> [..24.78.134.188][49046] idle: [...799] [ip6][..udp] [..............fe80::c50d:519f:96a4:e108][63958] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] idle: [...333] [ip4][..tcp] [......10.0.2.15][50327] -> [.69.118.162.229][46906] [HTTP.Gnutella][Unknown][Media][Potentially Dangerous] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unsafe Protocol not-detected: [....64] [ip4][..tcp] [......10.0.2.15][50223] -> [118.167.248.220][63108] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....64] [ip4][..tcp] [......10.0.2.15][50223] -> [118.167.248.220][63108] + idle: [....64] [ip4][..tcp] [......10.0.2.15][50223] -> [118.167.248.220][63108] not-detected: [....59] [ip4][..tcp] [......10.0.2.15][50218] -> [..90.103.247.94][59045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....59] [ip4][..tcp] [......10.0.2.15][50218] -> [..90.103.247.94][59045] + idle: [....59] [ip4][..tcp] [......10.0.2.15][50218] -> [..90.103.247.94][59045] idle: [...111] [ip4][..udp] [......10.0.2.15][28681] -> [..90.65.141.157][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....49] [ip4][..tcp] [......10.0.2.15][50209] -> [113.252.206.254][49587] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....49] [ip4][..tcp] [......10.0.2.15][50209] -> [113.252.206.254][49587] + idle: [....49] [ip4][..tcp] [......10.0.2.15][50209] -> [113.252.206.254][49587] not-detected: [....65] [ip4][..tcp] [......10.0.2.15][50224] -> [...78.125.63.97][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....65] [ip4][..tcp] [......10.0.2.15][50224] -> [...78.125.63.97][.6346] + idle: [....65] [ip4][..tcp] [......10.0.2.15][50224] -> [...78.125.63.97][.6346] idle: [...187] [ip4][..udp] [......10.0.2.15][28681] -> [....92.88.92.56][21009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...190] [ip4][..udp] [......10.0.2.15][28681] -> [165.169.195.227][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7126,7 +7126,7 @@ RISK: Unsafe Protocol not-detected: [....68] [ip4][..tcp] [......10.0.2.15][50227] -> [.111.246.157.94][51175] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....68] [ip4][..tcp] [......10.0.2.15][50227] -> [.111.246.157.94][51175] + idle: [....68] [ip4][..tcp] [......10.0.2.15][50227] -> [.111.246.157.94][51175] idle: [...141] [ip4][..udp] [......10.0.2.15][28681] -> [..172.97.199.14][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...751] [ip4][..udp] [......10.0.2.15][28681] -> [142.115.218.152][.5900] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7135,54 +7135,54 @@ RISK: Unsafe Protocol not-detected: [....56] [ip4][..tcp] [......10.0.2.15][50215] -> [.124.244.64.237][.4704] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....56] [ip4][..tcp] [......10.0.2.15][50215] -> [.124.244.64.237][.4704] + idle: [....56] [ip4][..tcp] [......10.0.2.15][50215] -> [.124.244.64.237][.4704] not-detected: [....71] [ip4][..tcp] [......10.0.2.15][50230] -> [....73.3.103.37][17296] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....71] [ip4][..tcp] [......10.0.2.15][50230] -> [....73.3.103.37][17296] + idle: [....71] [ip4][..tcp] [......10.0.2.15][50230] -> [....73.3.103.37][17296] idle: [...503] [ip4][..udp] [......10.0.2.15][28681] -> [..74.210.244.72][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....85] [ip4][..udp] [......10.0.2.15][28681] -> [..85.138.20.110][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...244] [ip4][..tcp] [......10.0.2.15][50288] -> [...76.119.55.28][20347] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...244] [ip4][..tcp] [......10.0.2.15][50288] -> [...76.119.55.28][20347] + idle: [...244] [ip4][..tcp] [......10.0.2.15][50288] -> [...76.119.55.28][20347] not-detected: [....47] [ip4][..tcp] [......10.0.2.15][50207] -> [..90.78.171.204][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....47] [ip4][..tcp] [......10.0.2.15][50207] -> [..90.78.171.204][.6346] + idle: [....47] [ip4][..tcp] [......10.0.2.15][50207] -> [..90.78.171.204][.6346] idle: [...180] [ip4][..udp] [......10.0.2.15][28681] -> [...66.131.24.72][30711] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...281] [ip4][..tcp] [......10.0.2.15][50305] -> [....94.54.66.82][63637] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...281] [ip4][..tcp] [......10.0.2.15][50305] -> [....94.54.66.82][63637] + idle: [...281] [ip4][..tcp] [......10.0.2.15][50305] -> [....94.54.66.82][63637] end: [....93] [ip4][..tcp] [......10.0.2.15][50248] -> [109.214.154.216][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....48] [ip4][..tcp] [......10.0.2.15][50208] -> [.119.237.116.22][.8683] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....48] [ip4][..tcp] [......10.0.2.15][50208] -> [.119.237.116.22][.8683] + idle: [....48] [ip4][..tcp] [......10.0.2.15][50208] -> [.119.237.116.22][.8683] idle: [...794] [ip4][..udp] [......10.0.2.15][50214] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [...266] [ip4][..tcp] [......10.0.2.15][50290] -> [....73.89.249.8][50649] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...266] [ip4][..tcp] [......10.0.2.15][50290] -> [....73.89.249.8][50649] + idle: [...266] [ip4][..tcp] [......10.0.2.15][50290] -> [....73.89.249.8][50649] idle: [...797] [ip4][.icmp] [...154.3.42.209] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] idle: [...135] [ip4][..udp] [......10.0.2.15][28681] -> [.193.250.99.158][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....78] [ip4][..tcp] [......10.0.2.15][50237] -> [.88.123.202.175][37910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....78] [ip4][..tcp] [......10.0.2.15][50237] -> [.88.123.202.175][37910] + idle: [....78] [ip4][..tcp] [......10.0.2.15][50237] -> [.88.123.202.175][37910] not-detected: [...151] [ip4][..tcp] [......10.0.2.15][50264] -> [...95.10.205.67][48380] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...151] [ip4][..tcp] [......10.0.2.15][50264] -> [...95.10.205.67][48380] + idle: [...151] [ip4][..tcp] [......10.0.2.15][50264] -> [...95.10.205.67][48380] idle: [...764] [ip4][..udp] [......10.0.2.15][28681] -> [.208.92.106.151][32476] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....89] [ip4][..tcp] [......10.0.2.15][50244] -> [..188.61.52.183][63978] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....89] [ip4][..tcp] [......10.0.2.15][50244] -> [..188.61.52.183][63978] + idle: [....89] [ip4][..tcp] [......10.0.2.15][50244] -> [..188.61.52.183][63978] not-detected: [....92] [ip4][..tcp] [......10.0.2.15][50247] -> [..66.30.221.181][51560] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....92] [ip4][..tcp] [......10.0.2.15][50247] -> [..66.30.221.181][51560] + idle: [....92] [ip4][..tcp] [......10.0.2.15][50247] -> [..66.30.221.181][51560] not-detected: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] + idle: [...784] [ip4][..udp] [......10.0.2.15][28681] -> [..23.19.141.110][.6346] idle: [...749] [ip4][..udp] [......10.0.2.15][28681] -> [...78.159.27.22][17563] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...156] [ip4][..udp] [......10.0.2.15][28681] -> [..86.244.228.86][10131] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7191,62 +7191,62 @@ RISK: Unsafe Protocol not-detected: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] + idle: [...774] [ip4][..udp] [......10.0.2.15][28681] -> [..50.58.238.149][.6599] not-detected: [...268] [ip4][..tcp] [......10.0.2.15][50292] -> [...95.10.205.67][11603] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...268] [ip4][..tcp] [......10.0.2.15][50292] -> [...95.10.205.67][11603] + idle: [...268] [ip4][..tcp] [......10.0.2.15][50292] -> [...95.10.205.67][11603] not-detected: [....84] [ip4][..tcp] [......10.0.2.15][50243] -> [176.138.129.252][27962] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....84] [ip4][..tcp] [......10.0.2.15][50243] -> [176.138.129.252][27962] + idle: [....84] [ip4][..tcp] [......10.0.2.15][50243] -> [176.138.129.252][27962] idle: [...792] [ip4][..udp] [......10.0.2.15][28681] -> [.36.239.213.146][21750] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...157] [ip4][..udp] [......10.0.2.15][28681] -> [.86.227.162.150][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...142] [ip4][..tcp] [......10.0.2.15][50255] -> [..36.236.203.37][52165] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...142] [ip4][..tcp] [......10.0.2.15][50255] -> [..36.236.203.37][52165] + idle: [...142] [ip4][..tcp] [......10.0.2.15][50255] -> [..36.236.203.37][52165] idle: [...209] [ip4][..udp] [......10.0.2.15][28681] -> [..91.179.98.234][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...241] [ip4][..tcp] [......10.0.2.15][50287] -> [.98.215.130.156][12405] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...241] [ip4][..tcp] [......10.0.2.15][50287] -> [.98.215.130.156][12405] + idle: [...241] [ip4][..tcp] [......10.0.2.15][50287] -> [.98.215.130.156][12405] idle: [...116] [ip4][..udp] [......10.0.2.15][28681] -> [.124.44.190.145][10170] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...236] [ip4][..tcp] [......10.0.2.15][50282] -> [..221.124.66.33][13060] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...236] [ip4][..tcp] [......10.0.2.15][50282] -> [..221.124.66.33][13060] + idle: [...236] [ip4][..tcp] [......10.0.2.15][50282] -> [..221.124.66.33][13060] not-detected: [...226] [ip4][..tcp] [......10.0.2.15][50272] -> [...1.172.184.48][13298] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...226] [ip4][..tcp] [......10.0.2.15][50272] -> [...1.172.184.48][13298] + idle: [...226] [ip4][..tcp] [......10.0.2.15][50272] -> [...1.172.184.48][13298] not-detected: [...225] [ip4][..tcp] [......10.0.2.15][50271] -> [.218.164.198.27][60202] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...225] [ip4][..tcp] [......10.0.2.15][50271] -> [.218.164.198.27][60202] + idle: [...225] [ip4][..tcp] [......10.0.2.15][50271] -> [.218.164.198.27][60202] not-detected: [...224] [ip4][..tcp] [......10.0.2.15][50270] -> [...114.27.24.95][11427] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...224] [ip4][..tcp] [......10.0.2.15][50270] -> [...114.27.24.95][11427] + idle: [...224] [ip4][..tcp] [......10.0.2.15][50270] -> [...114.27.24.95][11427] idle: [...485] [ip4][..udp] [......10.0.2.15][28681] -> [...154.3.42.209][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...145] [ip4][..tcp] [......10.0.2.15][50258] -> [122.100.216.210][.7097] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...145] [ip4][..tcp] [......10.0.2.15][50258] -> [122.100.216.210][.7097] + idle: [...145] [ip4][..tcp] [......10.0.2.15][50258] -> [122.100.216.210][.7097] not-detected: [...147] [ip4][..tcp] [......10.0.2.15][50260] -> [113.255.200.161][51394] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...147] [ip4][..tcp] [......10.0.2.15][50260] -> [113.255.200.161][51394] + idle: [...147] [ip4][..tcp] [......10.0.2.15][50260] -> [113.255.200.161][51394] not-detected: [....81] [ip4][..tcp] [......10.0.2.15][50240] -> [..36.237.10.152][21293] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....81] [ip4][..tcp] [......10.0.2.15][50240] -> [..36.237.10.152][21293] + idle: [....81] [ip4][..tcp] [......10.0.2.15][50240] -> [..36.237.10.152][21293] not-detected: [....57] [ip4][..tcp] [......10.0.2.15][50216] -> [182.155.128.228][.3256] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....57] [ip4][..tcp] [......10.0.2.15][50216] -> [182.155.128.228][.3256] + idle: [....57] [ip4][..tcp] [......10.0.2.15][50216] -> [182.155.128.228][.3256] not-detected: [....44] [ip4][..tcp] [......10.0.2.15][50204] -> [..124.218.26.16][.9728] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....44] [ip4][..tcp] [......10.0.2.15][50204] -> [..124.218.26.16][.9728] + idle: [....44] [ip4][..tcp] [......10.0.2.15][50204] -> [..124.218.26.16][.9728] not-detected: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] + idle: [...771] [ip4][..udp] [......10.0.2.15][28681] -> [...202.27.193.6][.6346] not-detected: [...234] [ip4][..tcp] [......10.0.2.15][50280] -> [...99.199.148.6][.4338] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...234] [ip4][..tcp] [......10.0.2.15][50280] -> [...99.199.148.6][.4338] + idle: [...234] [ip4][..tcp] [......10.0.2.15][50280] -> [...99.199.148.6][.4338] idle: [...133] [ip4][..udp] [......10.0.2.15][28681] -> [.91.175.220.161][15721] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...167] [ip4][..udp] [......10.0.2.15][28681] -> [..93.29.107.176][20363] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7255,14 +7255,14 @@ RISK: Unsafe Protocol not-detected: [...229] [ip4][..tcp] [......10.0.2.15][50275] -> [.122.117.100.78][.9010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...229] [ip4][..tcp] [......10.0.2.15][50275] -> [.122.117.100.78][.9010] + idle: [...229] [ip4][..tcp] [......10.0.2.15][50275] -> [.122.117.100.78][.9010] idle: [...786] [ip4][..udp] [......10.0.2.15][28681] -> [....114.38.9.82][24223] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] [Unknown][Unknown][Unrated] - idle: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] + idle: [...781] [ip4][..udp] [......10.0.2.15][28681] -> [...112.105.52.2][23458] not-detected: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] + idle: [...782] [ip4][..udp] [......10.0.2.15][28681] -> [.65.182.231.232][.7890] idle: [...160] [ip4][..udp] [......10.0.2.15][28681] -> [...83.150.49.35][32448] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...486] [ip4][..udp] [......10.0.2.15][28681] -> [...88.68.45.203][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7271,23 +7271,23 @@ RISK: Unsafe Protocol not-detected: [....39] [ip4][..tcp] [......10.0.2.15][50200] -> [176.128.217.128][45194] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....39] [ip4][..tcp] [......10.0.2.15][50200] -> [176.128.217.128][45194] + idle: [....39] [ip4][..tcp] [......10.0.2.15][50200] -> [176.128.217.128][45194] not-detected: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] + idle: [...769] [ip4][..udp] [......10.0.2.15][28681] -> [.123.110.61.169][11973] not-detected: [....53] [ip4][..tcp] [......10.0.2.15][50213] -> [...85.117.153.7][50138] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....53] [ip4][..tcp] [......10.0.2.15][50213] -> [...85.117.153.7][50138] + idle: [....53] [ip4][..tcp] [......10.0.2.15][50213] -> [...85.117.153.7][50138] idle: [...762] [ip4][..udp] [......10.0.2.15][28681] -> [...86.75.43.182][43502] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....82] [ip4][..tcp] [......10.0.2.15][50241] -> [..98.18.172.208][63172] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....82] [ip4][..tcp] [......10.0.2.15][50241] -> [..98.18.172.208][63172] + idle: [....82] [ip4][..tcp] [......10.0.2.15][50241] -> [..98.18.172.208][63172] not-detected: [...297] [ip4][..tcp] [......10.0.2.15][50321] -> [213.229.111.224][.4876] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...297] [ip4][..tcp] [......10.0.2.15][50321] -> [213.229.111.224][.4876] + idle: [...297] [ip4][..tcp] [......10.0.2.15][50321] -> [213.229.111.224][.4876] not-detected: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] [Unknown][Unknown][Unrated] - idle: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] + idle: [...775] [ip4][..udp] [......10.0.2.15][28681] -> [..223.17.132.18][23458] idle: [...130] [ip4][..udp] [......10.0.2.15][28681] -> [..119.224.95.97][46356] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...129] [ip4][..udp] [......10.0.2.15][28681] -> [.176.138.50.179][29411] [Gnutella][Unknown][Download][Potentially Dangerous] @@ -7296,49 +7296,49 @@ RISK: Unsafe Protocol not-detected: [....79] [ip4][..tcp] [......10.0.2.15][50238] -> [.124.218.41.253][59144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....79] [ip4][..tcp] [......10.0.2.15][50238] -> [.124.218.41.253][59144] + idle: [....79] [ip4][..tcp] [......10.0.2.15][50238] -> [.124.218.41.253][59144] not-detected: [...230] [ip4][..tcp] [......10.0.2.15][50276] -> [.96.246.156.126][56070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...230] [ip4][..tcp] [......10.0.2.15][50276] -> [.96.246.156.126][56070] + idle: [...230] [ip4][..tcp] [......10.0.2.15][50276] -> [.96.246.156.126][56070] not-detected: [....70] [ip4][..tcp] [......10.0.2.15][50229] -> [....1.36.249.91][64920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....70] [ip4][..tcp] [......10.0.2.15][50229] -> [....1.36.249.91][64920] + idle: [....70] [ip4][..tcp] [......10.0.2.15][50229] -> [....1.36.249.91][64920] idle: [...789] [ip4][..udp] [......10.0.2.15][28681] -> [..42.98.115.128][23458] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...795] [ip4][..udp] [......10.0.2.15][28681] -> [..213.120.26.86][29946] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....33] [ip4][..tcp] [......10.0.2.15][50195] -> [162.157.143.201][29762] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....33] [ip4][..tcp] [......10.0.2.15][50195] -> [162.157.143.201][29762] + idle: [....33] [ip4][..tcp] [......10.0.2.15][50195] -> [162.157.143.201][29762] not-detected: [....91] [ip4][..tcp] [......10.0.2.15][50246] -> [...80.7.252.192][45685] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....91] [ip4][..tcp] [......10.0.2.15][50246] -> [...80.7.252.192][45685] + idle: [....91] [ip4][..tcp] [......10.0.2.15][50246] -> [...80.7.252.192][45685] idle: [...755] [ip4][..udp] [......10.0.2.15][28681] -> [..83.134.107.32][38836] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....50] [ip4][..tcp] [......10.0.2.15][50210] -> [..36.234.18.166][61404] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....50] [ip4][..tcp] [......10.0.2.15][50210] -> [..36.234.18.166][61404] + idle: [....50] [ip4][..tcp] [......10.0.2.15][50210] -> [..36.234.18.166][61404] idle: [...137] [ip4][..udp] [......10.0.2.15][28681] -> [...82.65.70.197][21693] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....45] [ip4][..tcp] [......10.0.2.15][50205] -> [.114.46.139.171][52120] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....45] [ip4][..tcp] [......10.0.2.15][50205] -> [.114.46.139.171][52120] + idle: [....45] [ip4][..tcp] [......10.0.2.15][50205] -> [.114.46.139.171][52120] not-detected: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] + idle: [...772] [ip4][..udp] [......10.0.2.15][28681] -> [.73.192.231.237][.9676] idle: [...109] [ip4][..udp] [......10.0.2.15][28681] -> [...88.169.2.153][52414] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...140] [ip4][..udp] [......10.0.2.15][28681] -> [.77.197.111.186][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] [Unknown][Unknown][Unrated] - idle: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] + idle: [...770] [ip4][..udp] [......10.0.2.15][28681] -> [..97.83.183.148][.8890] not-detected: [...235] [ip4][..tcp] [......10.0.2.15][50281] -> [.94.134.154.158][54130] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...235] [ip4][..tcp] [......10.0.2.15][50281] -> [.94.134.154.158][54130] + idle: [...235] [ip4][..tcp] [......10.0.2.15][50281] -> [.94.134.154.158][54130] idle: [...783] [ip4][.icmp] [.65.182.231.232] -> [......10.0.2.15] [ICMP][Unknown][Network][Acceptable] not-detected: [....60] [ip4][..tcp] [......10.0.2.15][50219] -> [.193.121.165.12][55376] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....60] [ip4][..tcp] [......10.0.2.15][50219] -> [.193.121.165.12][55376] + idle: [....60] [ip4][..tcp] [......10.0.2.15][50219] -> [.193.121.165.12][55376] end: [...239] [ip4][..tcp] [......10.0.2.15][50285] -> [..75.133.101.93][52367] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [...334] [ip4][..tcp] [......10.0.2.15][50328] -> [..189.147.72.83][26108] [HTTP.Gnutella][Unknown][Media][Potentially Dangerous] @@ -7351,64 +7351,64 @@ RISK: Unsafe Protocol not-detected: [....80] [ip4][..tcp] [......10.0.2.15][50239] -> [...112.105.52.2][.6384] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....80] [ip4][..tcp] [......10.0.2.15][50239] -> [...112.105.52.2][.6384] + idle: [....80] [ip4][..tcp] [......10.0.2.15][50239] -> [...112.105.52.2][.6384] not-detected: [...232] [ip4][..tcp] [......10.0.2.15][50278] -> [..36.231.59.187][62234] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...232] [ip4][..tcp] [......10.0.2.15][50278] -> [..36.231.59.187][62234] + idle: [...232] [ip4][..tcp] [......10.0.2.15][50278] -> [..36.231.59.187][62234] not-detected: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] + idle: [...766] [ip4][..udp] [......10.0.2.15][28681] -> [...76.119.55.28][20347] idle: [...763] [ip4][..udp] [......10.0.2.15][28681] -> [.85.170.209.214][46210] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol end: [...288] [ip4][..tcp] [......10.0.2.15][50312] -> [104.238.172.250][23548] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...120] [ip4][..tcp] [......10.0.2.15][50251] -> [...24.127.1.235][37814] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...120] [ip4][..tcp] [......10.0.2.15][50251] -> [...24.127.1.235][37814] + idle: [...120] [ip4][..tcp] [......10.0.2.15][50251] -> [...24.127.1.235][37814] not-detected: [...144] [ip4][..tcp] [......10.0.2.15][50257] -> [...219.70.48.23][.3054] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...144] [ip4][..tcp] [......10.0.2.15][50257] -> [...219.70.48.23][.3054] + idle: [...144] [ip4][..tcp] [......10.0.2.15][50257] -> [...219.70.48.23][.3054] not-detected: [...286] [ip4][..tcp] [......10.0.2.15][50310] -> [.76.110.153.177][40022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...286] [ip4][..tcp] [......10.0.2.15][50310] -> [.76.110.153.177][40022] + idle: [...286] [ip4][..tcp] [......10.0.2.15][50310] -> [.76.110.153.177][40022] not-detected: [....40] [ip4][..tcp] [......10.0.2.15][50201] -> [..78.122.93.185][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....40] [ip4][..tcp] [......10.0.2.15][50201] -> [..78.122.93.185][.6346] + idle: [....40] [ip4][..tcp] [......10.0.2.15][50201] -> [..78.122.93.185][.6346] not-detected: [....58] [ip4][..tcp] [......10.0.2.15][50217] -> [.113.252.86.162][54958] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....58] [ip4][..tcp] [......10.0.2.15][50217] -> [.113.252.86.162][54958] + idle: [....58] [ip4][..tcp] [......10.0.2.15][50217] -> [.113.252.86.162][54958] idle: [...158] [ip4][..udp] [......10.0.2.15][28681] -> [.118.166.226.70][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....32] [ip4][..tcp] [......10.0.2.15][50194] -> [..92.152.66.153][43771] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....32] [ip4][..tcp] [......10.0.2.15][50194] -> [..92.152.66.153][43771] + idle: [....32] [ip4][..tcp] [......10.0.2.15][50194] -> [..92.152.66.153][43771] idle: [....87] [ip4][..udp] [......10.0.2.15][28681] -> [..92.131.85.245][31743] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....83] [ip4][..tcp] [......10.0.2.15][50242] -> [109.210.203.131][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....83] [ip4][..tcp] [......10.0.2.15][50242] -> [109.210.203.131][.6346] + idle: [....83] [ip4][..tcp] [......10.0.2.15][50242] -> [109.210.203.131][.6346] not-detected: [....66] [ip4][..tcp] [......10.0.2.15][50225] -> [.109.210.81.147][24800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....66] [ip4][..tcp] [......10.0.2.15][50225] -> [.109.210.81.147][24800] + idle: [....66] [ip4][..tcp] [......10.0.2.15][50225] -> [.109.210.81.147][24800] not-detected: [...150] [ip4][..tcp] [......10.0.2.15][50263] -> [..73.182.136.42][27873] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...150] [ip4][..tcp] [......10.0.2.15][50263] -> [..73.182.136.42][27873] + idle: [...150] [ip4][..tcp] [......10.0.2.15][50263] -> [..73.182.136.42][27873] not-detected: [....62] [ip4][..tcp] [......10.0.2.15][50221] -> [...59.104.173.5][49956] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....62] [ip4][..tcp] [......10.0.2.15][50221] -> [...59.104.173.5][49956] + idle: [....62] [ip4][..tcp] [......10.0.2.15][50221] -> [...59.104.173.5][49956] idle: [...785] [ip4][..udp] [......10.0.2.15][28681] -> [.176.134.139.39][.6346] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] + idle: [...780] [ip4][..udp] [......10.0.2.15][28681] -> [...68.66.94.132][17735] idle: [...761] [ip4][..udp] [......10.0.2.15][28681] -> [..195.132.75.56][56009] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol not-detected: [....55] [ip4][..tcp] [......10.0.2.15][50214] -> [.80.193.171.146][53808] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....55] [ip4][..tcp] [......10.0.2.15][50214] -> [.80.193.171.146][53808] + idle: [....55] [ip4][..tcp] [......10.0.2.15][50214] -> [.80.193.171.146][53808] not-detected: [...231] [ip4][..tcp] [......10.0.2.15][50277] -> [.82.181.251.218][36368] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...231] [ip4][..tcp] [......10.0.2.15][50277] -> [.82.181.251.218][36368] + idle: [...231] [ip4][..tcp] [......10.0.2.15][50277] -> [.82.181.251.218][36368] idle: [...791] [ip4][..udp] [......10.0.2.15][28681] -> [...219.85.11.85][10722] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol end: [....94] [ip4][..tcp] [......10.0.2.15][50249] -> [.86.208.180.181][45883] [Gnutella][Unknown][Download][Potentially Dangerous] diff --git a/test/results/flow-info/default/google_ssl.pcap.out b/test/results/flow-info/default/google_ssl.pcap.out index 9ba4d0224..183937428 100644 --- a/test/results/flow-info/default/google_ssl.pcap.out +++ b/test/results/flow-info/default/google_ssl.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.31.3.224][42835] -> [.216.58.212.100][..443] + new: [.....1] [ip4][..tcp] [...172.31.3.224][42835] -> [.216.58.212.100][..443] guessed: [.....1] [ip4][..tcp] [...172.31.3.224][42835] -> [.216.58.212.100][..443] [TLS][Google][Web][Safe] - end: [.....1] [ip4][..tcp] [...172.31.3.224][42835] -> [.216.58.212.100][..443] + end: [.....1] [ip4][..tcp] [...172.31.3.224][42835] -> [.216.58.212.100][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/googledns_android10.pcap.out b/test/results/flow-info/default/googledns_android10.pcap.out index b65fe9ba9..0da214d5b 100644 --- a/test/results/flow-info/default/googledns_android10.pcap.out +++ b/test/results/flow-info/default/googledns_android10.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [........8.8.8.8][..853] -> [..192.168.1.159][55856] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [..192.168.1.159][48044] -> [........8.8.4.4][..853] - new: [.....3] [ip4][..tcp] [..192.168.1.159][56024] -> [........8.8.8.8][..853] + new: [.....1] [ip4][..tcp] [........8.8.8.8][..853] -> [..192.168.1.159][55856] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.1.159][48044] -> [........8.8.4.4][..853] + new: [.....3] [ip4][..tcp] [..192.168.1.159][56024] -> [........8.8.8.8][..853] detected: [.....2] [ip4][..tcp] [..192.168.1.159][48044] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] RISK: TLS (probably) Not Carrying HTTPS detected: [.....3] [ip4][..tcp] [..192.168.1.159][56024] -> [........8.8.8.8][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] @@ -16,7 +16,7 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [..192.168.1.159][56024] -> [........8.8.8.8][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] RISK: TLS (probably) Not Carrying HTTPS - new: [.....4] [ip4][..tcp] [..192.168.1.159][48048] -> [........8.8.4.4][..853] + new: [.....4] [ip4][..tcp] [..192.168.1.159][48048] -> [........8.8.4.4][..853] detected: [.....4] [ip4][..tcp] [..192.168.1.159][48048] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....4] [ip4][..tcp] [..192.168.1.159][48048] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] @@ -33,11 +33,11 @@ [IATS(ms)....: 12.8,14.6,0.3,14.8,16.2,1.1,0.1,31.1,1.0,0.5,12.5,28.6,36.9,41.2,19.2,12.5,6.2,5.0,24.3,307.1,326.2,13.8,74.3,386.7,447.4,5.0,23.8,155.7,173.7,5.0,23.2] [PKTLENS.....: 60,60,52,206,52,1470,1470,291,52,52,52,145,344,211,52,211,551,52,551,52,211,52,551,52,211,52,551,52,211,52,551,52] [ENTROPIES...: 4.3,5.0,5.0,5.4,5.0,7.1,7.5,7.1,5.1,5.0,5.1,6.1,7.1,6.7,5.0,6.8,7.6,4.9,7.6,5.1,6.8,5.1,7.5,5.1,6.8,5.0,7.6,5.1,6.8,5.0,7.6,5.1] - new: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] + new: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] detected: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] [ICMP][Google][Network][Acceptable] - new: [.....6] [ip4][..tcp] [........8.8.4.4][..853] -> [..192.168.1.159][47968] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [........8.8.4.4][..853] -> [..192.168.1.159][47968] [MIDSTREAM] update: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] [ICMP][Google][Network][Acceptable] - new: [.....7] [ip4][..tcp] [..192.168.1.159][48098] -> [........8.8.4.4][..853] + new: [.....7] [ip4][..tcp] [..192.168.1.159][48098] -> [........8.8.4.4][..853] detected: [.....7] [ip4][..tcp] [..192.168.1.159][48098] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....7] [ip4][..tcp] [..192.168.1.159][48098] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] @@ -55,16 +55,16 @@ update: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] [ICMP][Google][Network][Acceptable] idle: [.....5] [ip4][.icmp] [..192.168.1.159] -> [........8.8.8.8] [ICMP][Google][Network][Acceptable] guessed: [.....1] [ip4][..tcp] [........8.8.8.8][..853] -> [..192.168.1.159][55856] [DoH_DoT][Google][Network][Acceptable] - end: [.....1] [ip4][..tcp] [........8.8.8.8][..853] -> [..192.168.1.159][55856] + end: [.....1] [ip4][..tcp] [........8.8.8.8][..853] -> [..192.168.1.159][55856] end: [.....3] [ip4][..tcp] [..192.168.1.159][56024] -> [........8.8.8.8][..853] [TLS.DoH_DoT][Google][Network][Acceptable] RISK: TLS (probably) Not Carrying HTTPS end: [.....2] [ip4][..tcp] [..192.168.1.159][48044] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable] RISK: TLS (probably) Not Carrying HTTPS guessed: [.....6] [ip4][..tcp] [........8.8.4.4][..853] -> [..192.168.1.159][47968] [DoH_DoT][Google][Network][Acceptable] - end: [.....6] [ip4][..tcp] [........8.8.4.4][..853] -> [..192.168.1.159][47968] + end: [.....6] [ip4][..tcp] [........8.8.4.4][..853] -> [..192.168.1.159][47968] end: [.....4] [ip4][..tcp] [..192.168.1.159][48048] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable] RISK: TLS (probably) Not Carrying HTTPS - new: [.....8] [ip4][..tcp] [..192.168.1.159][48210] -> [........8.8.4.4][..853] + new: [.....8] [ip4][..tcp] [..192.168.1.159][48210] -> [........8.8.4.4][..853] detected: [.....8] [ip4][..tcp] [..192.168.1.159][48210] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....8] [ip4][..tcp] [..192.168.1.159][48210] -> [........8.8.4.4][..853] [TLS.DoH_DoT][Google][Network][Acceptable][dns.google] diff --git a/test/results/flow-info/default/gquic.pcap.out b/test/results/flow-info/default/gquic.pcap.out index 2aadd0832..15e286777 100644 --- a/test/results/flow-info/default/gquic.pcap.out +++ b/test/results/flow-info/default/gquic.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.44.5.25][61097] -> [.216.58.213.163][..443] + new: [.....1] [ip4][..udp] [.....10.44.5.25][61097] -> [.216.58.213.163][..443] detected: [.....1] [ip4][..udp] [.....10.44.5.25][61097] -> [.216.58.213.163][..443] [QUIC.Google][Google][Web][Acceptable][www.gstatic.com] idle: [.....1] [ip4][..udp] [.....10.44.5.25][61097] -> [.216.58.213.163][..443] [QUIC.Google][Google][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/gtp_c.pcap.out b/test/results/flow-info/default/gtp_c.pcap.out index be044ad43..cbeaebaed 100644 --- a/test/results/flow-info/default/gtp_c.pcap.out +++ b/test/results/flow-info/default/gtp_c.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.101.0.2][.1024] -> [.....10.102.0.2][.2123] + new: [.....1] [ip4][..udp] [.....10.101.0.2][.1024] -> [.....10.102.0.2][.2123] detected: [.....1] [ip4][..udp] [.....10.101.0.2][.1024] -> [.....10.102.0.2][.2123] [GTP.GTP_C][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [.....10.101.0.2][.1024] -> [.....10.102.0.2][.2123] [GTP.GTP_C][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/gtp_false_positive.pcapng.out b/test/results/flow-info/default/gtp_false_positive.pcapng.out index ef2ab6f9d..65e6186e3 100644 --- a/test/results/flow-info/default/gtp_false_positive.pcapng.out +++ b/test/results/flow-info/default/gtp_false_positive.pcapng.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] - update: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] + new: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] + update: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....2] [ip4][..udp] [...50.7.111.134][17000] -> [103.225.103.159][.2123] + new: [.....2] [ip4][..udp] [...50.7.111.134][17000] -> [103.225.103.159][.2123] not-detected: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] + idle: [.....1] [ip4][..udp] [.....24.1.33.66][29255] -> [..62.56.122.232][.3386] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 1|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [119.185.190.173][.2123] -> [...66.86.98.114][50140] + new: [.....3] [ip4][..udp] [119.185.190.173][.2123] -> [...66.86.98.114][50140] guessed: [.....2] [ip4][..udp] [...50.7.111.134][17000] -> [103.225.103.159][.2123] [GTP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [.....2] [ip4][..udp] [...50.7.111.134][17000] -> [103.225.103.159][.2123] + idle: [.....2] [ip4][..udp] [...50.7.111.134][17000] -> [103.225.103.159][.2123] guessed: [.....3] [ip4][..udp] [119.185.190.173][.2123] -> [...66.86.98.114][50140] [GTP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [.....3] [ip4][..udp] [119.185.190.173][.2123] -> [...66.86.98.114][50140] + idle: [.....3] [ip4][..udp] [119.185.190.173][.2123] -> [...66.86.98.114][50140] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/h323-overflow.pcap.out b/test/results/flow-info/default/h323-overflow.pcap.out index 5ca162658..4db57c2f7 100644 --- a/test/results/flow-info/default/h323-overflow.pcap.out +++ b/test/results/flow-info/default/h323-overflow.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.1.1][31337] -> [....192.168.1.2][...80] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....192.168.1.1][31337] -> [....192.168.1.2][...80] [MIDSTREAM] guessed: [.....1] [ip4][..tcp] [....192.168.1.1][31337] -> [....192.168.1.2][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [....192.168.1.1][31337] -> [....192.168.1.2][...80] + idle: [.....1] [ip4][..tcp] [....192.168.1.1][31337] -> [....192.168.1.2][...80] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/h323.pcap.out b/test/results/flow-info/default/h323.pcap.out index b8d0f10b0..4aca46e03 100644 --- a/test/results/flow-info/default/h323.pcap.out +++ b/test/results/flow-info/default/h323.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....17.2.0.124][.2034] -> [.....17.2.0.161][.1719] + new: [.....1] [ip4][..udp] [.....17.2.0.124][.2034] -> [.....17.2.0.161][.1719] detected: [.....1] [ip4][..udp] [.....17.2.0.124][.2034] -> [.....17.2.0.161][.1719] [H323][Apple][VoIP][Acceptable] - new: [.....2] [ip4][..tcp] [.....17.2.0.124][.3032] -> [.....17.2.0.122][.1720] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.....17.2.0.124][.3032] -> [.....17.2.0.122][.1720] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [.....17.2.0.124][.3032] -> [.....17.2.0.122][.1720] [H323][Apple][VoIP][Acceptable] idle: [.....1] [ip4][..udp] [.....17.2.0.124][.2034] -> [.....17.2.0.161][.1719] [H323][Apple][VoIP][Acceptable] idle: [.....2] [ip4][..tcp] [.....17.2.0.124][.3032] -> [.....17.2.0.122][.1720] [H323][Apple][VoIP][Acceptable] diff --git a/test/results/flow-info/default/haproxy.pcap.out b/test/results/flow-info/default/haproxy.pcap.out index da73c855a..c38f25757 100644 --- a/test/results/flow-info/default/haproxy.pcap.out +++ b/test/results/flow-info/default/haproxy.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [........1.1.1.1][48502] -> [........2.2.2.2][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [........1.1.1.1][48502] -> [........2.2.2.2][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [........1.1.1.1][48502] -> [........2.2.2.2][..443] [HAProxy][Unknown][Web][Safe] idle: [.....1] [ip4][..tcp] [........1.1.1.1][48502] -> [........2.2.2.2][..443] [HAProxy][Unknown][Web][Safe] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out b/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out index 1a95b0232..ad0e39c70 100644 --- a/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out +++ b/test/results/flow-info/default/heuristic_tcp_ack_payload.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] - analyse: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + new: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + analyse: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 28.648| 1.860| 7.030| 49424738.812| 1.100] [PKTLEN......: 42.000| 2960.000| 308.700| 576.000| 331721.900| 3.600] @@ -14,11 +14,11 @@ [ENTROPIES...: 4.7,4.8,4.7,5.8,4.4,5.8,7.2,7.3,4.7,7.4,4.8,4.7,6.2,6.3,7.6,7.6,6.6,5.4,6.1,4.4,4.7,5.4,7.5,5.4,4.7,4.5,6.0,5.6,7.8,4.4,4.5,5.5] DAEMON-EVENT: [Processed: 63 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] + new: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] guessed: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] [TLS][AmazonAWS][Web][Safe] - end: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] - new: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] - analyse: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + end: [.....1] [ip4][..tcp] [.194.226.199.21][58155] -> [..52.18.127.189][..443] + new: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + analyse: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.030| 0.007| 0.011| 122.098| 3.500] [PKTLEN......: 42.000| 2864.000| 672.800| 1000.300| 1000640.100| 3.700] @@ -29,14 +29,14 @@ [PKTLENS.....: 52,52,42,258,46,2088,2088,462,42,42,133,318,109,42,217,361,78,46,78,364,1452,42,1452,2864,42,42,2864,42,2864,42,2864,42] [ENTROPIES...: 4.6,5.0,4.7,5.7,4.5,7.4,7.6,7.4,4.7,4.7,5.8,7.0,5.8,4.7,6.9,7.4,5.3,4.5,5.2,7.3,7.9,4.6,7.9,7.9,4.7,4.8,7.9,4.8,7.9,4.8,7.9,4.6] guessed: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] + end: [.....2] [ip4][..tcp] [194.226.199.226][34101] -> [..8.247.226.126][...80] DAEMON-EVENT: [Processed: 160 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 2|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] - new: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + new: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] + new: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] guessed: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] [TLS][GoogleCloud][Web][Safe] - end: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] - analyse: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + end: [.....3] [ip4][..tcp] [.194.226.199.61][27453] -> [...35.241.9.150][..443] + analyse: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 5.456| 0.293| 1.017| 1033283.961| 1.700] [PKTLEN......: 42.000| 2883.000| 385.900| 734.400| 539373.900| 3.400] @@ -46,8 +46,8 @@ [IATS(ms)....: 0.0,10.5,0.0,1548.8,0.0,1559.9,0.0,2.5,0.0,14.1,0.0,4.4,0.0,0.1,0.0,17.1,0.0,0.0,0.0,4.7,0.0,18.5,0.0,216.2,0.0,213.8,0.0,10.4,0.0,5455.6,0.0] [PKTLENS.....: 52,52,46,46,46,46,42,42,609,609,46,46,1450,1450,2883,2883,42,42,42,42,166,166,298,298,42,42,298,298,42,42,71,71] [ENTROPIES...: 4.5,4.5,4.8,4.8,4.8,4.8,4.8,4.8,7.1,7.1,4.6,4.6,7.2,7.2,7.5,7.5,4.7,4.7,4.7,4.7,6.3,6.3,7.1,7.1,4.8,4.8,7.1,7.1,4.7,4.7,5.2,5.2] - new: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] - analyse: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + new: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + analyse: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.635| 0.323| 0.688| 472790.598| 2.800] [PKTLEN......: 42.000| 2960.000| 481.700| 697.200| 486142.700| 3.800] @@ -58,9 +58,9 @@ [PKTLENS.....: 52,52,52,52,42,561,52,52,46,2960,1216,1500,52,46,1500,1500,1500,52,52,42,42,120,138,46,311,327,46,101,71,1500,658,673] [ENTROPIES...: 4.8,5.0,5.0,4.8,4.6,6.8,5.0,5.0,4.6,7.9,7.8,7.9,4.8,5.1,7.9,7.9,7.9,4.9,4.8,4.7,4.8,6.3,6.6,4.6,7.3,7.3,4.6,6.2,5.8,7.9,7.6,7.7] guessed: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] [TLS][Unknown][Web][Safe] - idle: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] + idle: [.....6] [ip4][..tcp] [.194.226.199.61][.6946] -> [....2.22.40.186][..443] guessed: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] [TLS][Unknown][Web][Safe] - end: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] + end: [.....4] [ip4][..tcp] [..194.226.199.9][49756] -> [..92.223.106.21][..443] guessed: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] [TLS][Unknown][Web][Safe] - end: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] + end: [.....5] [ip4][..tcp] [194.226.199.103][62580] -> [..217.69.139.59][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/hots.pcapng.out b/test/results/flow-info/default/hots.pcapng.out index 1e9200ab2..680a29d42 100644 --- a/test/results/flow-info/default/hots.pcapng.out +++ b/test/results/flow-info/default/hots.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] + new: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] detected: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] [Heroes_of_the_Storm][Starcraft][Game][Fun] analyse: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] [Heroes_of_the_Storm][Starcraft][Game][Fun] min| max| avg| stddev| variance| entropy @@ -16,12 +16,12 @@ update: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] [Heroes_of_the_Storm][Starcraft][Game][Fun] DAEMON-EVENT: [Processed: 35 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....2] [ip4][..udp] [..24.105.57.183][.1119] -> [...192.168.0.73][50609] + new: [.....2] [ip4][..udp] [..24.105.57.183][.1119] -> [...192.168.0.73][50609] detected: [.....2] [ip4][..udp] [..24.105.57.183][.1119] -> [...192.168.0.73][50609] [Heroes_of_the_Storm][Starcraft][Game][Fun] idle: [.....1] [ip4][..udp] [...192.168.0.73][54598] -> [...24.105.56.13][.3724] [Heroes_of_the_Storm][Starcraft][Game][Fun] DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [...24.105.57.16][.3724] -> [...192.168.0.73][50609] + new: [.....3] [ip4][..udp] [...24.105.57.16][.3724] -> [...192.168.0.73][50609] detected: [.....3] [ip4][..udp] [...24.105.57.16][.3724] -> [...192.168.0.73][50609] [Heroes_of_the_Storm][Starcraft][Game][Fun] analyse: [.....3] [ip4][..udp] [...24.105.57.16][.3724] -> [...192.168.0.73][50609] [Heroes_of_the_Storm][Starcraft][Game][Fun] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/hpvirtgrp.pcap.out b/test/results/flow-info/default/hpvirtgrp.pcap.out index 68c92e2a8..28809d3a7 100644 --- a/test/results/flow-info/default/hpvirtgrp.pcap.out +++ b/test/results/flow-info/default/hpvirtgrp.pcap.out @@ -1,43 +1,43 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][46570] -> [..160.44.194.66][.5223] + new: [.....1] [ip4][..tcp] [..192.168.2.100][46570] -> [..160.44.194.66][.5223] detected: [.....1] [ip4][..tcp] [..192.168.2.100][46570] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][59200] -> [..160.44.194.66][.5223] + new: [.....2] [ip4][..tcp] [..192.168.2.100][59200] -> [..160.44.194.66][.5223] detected: [.....2] [ip4][..tcp] [..192.168.2.100][59200] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.2.100][46570] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] - new: [.....3] [ip4][..tcp] [..192.168.2.100][59324] -> [..160.44.194.66][.5223] + new: [.....3] [ip4][..tcp] [..192.168.2.100][59324] -> [..160.44.194.66][.5223] detected: [.....3] [ip4][..tcp] [..192.168.2.100][59324] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.2.100][59920] -> [..160.44.194.66][.5223] + new: [.....4] [ip4][..tcp] [..192.168.2.100][59920] -> [..160.44.194.66][.5223] detected: [.....4] [ip4][..tcp] [..192.168.2.100][59920] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....2] [ip4][..tcp] [..192.168.2.100][59200] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....3] [ip4][..tcp] [..192.168.2.100][59324] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][40152] -> [..160.44.194.66][.5223] + new: [.....5] [ip4][..tcp] [..192.168.2.100][40152] -> [..160.44.194.66][.5223] detected: [.....5] [ip4][..tcp] [..192.168.2.100][40152] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][35634] -> [..160.44.194.66][.5223] + new: [.....6] [ip4][..tcp] [..192.168.2.100][35634] -> [..160.44.194.66][.5223] detected: [.....6] [ip4][..tcp] [..192.168.2.100][35634] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.2.100][49838] -> [..160.44.194.66][.5223] + new: [.....7] [ip4][..tcp] [..192.168.2.100][49838] -> [..160.44.194.66][.5223] detected: [.....7] [ip4][..tcp] [..192.168.2.100][49838] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....4] [ip4][..tcp] [..192.168.2.100][59920] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....6] [ip4][..tcp] [..192.168.2.100][35634] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....5] [ip4][..tcp] [..192.168.2.100][40152] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 105 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..tcp] [..192.168.2.100][42552] -> [..160.44.194.66][.5223] + new: [.....8] [ip4][..tcp] [..192.168.2.100][42552] -> [..160.44.194.66][.5223] detected: [.....8] [ip4][..tcp] [..192.168.2.100][42552] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 120 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.2.100][42764] -> [..160.44.194.66][.5223] + new: [.....9] [ip4][..tcp] [..192.168.2.100][42764] -> [..160.44.194.66][.5223] detected: [.....9] [ip4][..tcp] [..192.168.2.100][42764] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....8] [ip4][..tcp] [..192.168.2.100][42552] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] idle: [.....9] [ip4][..tcp] [..192.168.2.100][42764] -> [..160.44.194.66][.5223] [HP_VIRTGRP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/hsrp0.pcap.out b/test/results/flow-info/default/hsrp0.pcap.out index 939962774..90acfed7b 100644 --- a/test/results/flow-info/default/hsrp0.pcap.out +++ b/test/results/flow-info/default/hsrp0.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..10.28.168.253][.1985] -> [......224.0.0.2][.1985] + new: [.....1] [ip4][..udp] [..10.28.168.253][.1985] -> [......224.0.0.2][.1985] detected: [.....1] [ip4][..udp] [..10.28.168.253][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [..10.28.170.253][.1985] -> [......224.0.0.2][.1985] + new: [.....2] [ip4][..udp] [..10.28.170.253][.1985] -> [......224.0.0.2][.1985] detected: [.....2] [ip4][..udp] [..10.28.170.253][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [..10.28.171.253][.1985] -> [......224.0.0.2][.1985] + new: [.....3] [ip4][..udp] [..10.28.171.253][.1985] -> [......224.0.0.2][.1985] detected: [.....3] [ip4][..udp] [..10.28.171.253][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [..10.28.168.252][.1985] -> [......224.0.0.2][.1985] + new: [.....4] [ip4][..udp] [..10.28.168.252][.1985] -> [......224.0.0.2][.1985] detected: [.....4] [ip4][..udp] [..10.28.168.252][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] idle: [.....3] [ip4][..udp] [..10.28.171.253][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] idle: [.....2] [ip4][..udp] [..10.28.170.253][.1985] -> [......224.0.0.2][.1985] [HSRP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/hsrp2.pcap.out b/test/results/flow-info/default/hsrp2.pcap.out index 05c977c9d..23fdfc13c 100644 --- a/test/results/flow-info/default/hsrp2.pcap.out +++ b/test/results/flow-info/default/hsrp2.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..10.52.220.125][.1985] -> [....224.0.0.102][.1985] + new: [.....1] [ip4][..udp] [..10.52.220.125][.1985] -> [....224.0.0.102][.1985] detected: [.....1] [ip4][..udp] [..10.52.220.125][.1985] -> [....224.0.0.102][.1985] [HSRP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [..10.52.253.125][.1985] -> [....224.0.0.102][.1985] + new: [.....2] [ip4][..udp] [..10.52.253.125][.1985] -> [....224.0.0.102][.1985] detected: [.....2] [ip4][..udp] [..10.52.253.125][.1985] -> [....224.0.0.102][.1985] [HSRP][Unknown][Network][Acceptable] idle: [.....2] [ip4][..udp] [..10.52.253.125][.1985] -> [....224.0.0.102][.1985] [HSRP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [..10.52.220.125][.1985] -> [....224.0.0.102][.1985] [HSRP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/hsrp2_ipv6.pcapng.out b/test/results/flow-info/default/hsrp2_ipv6.pcapng.out index 417fd21db..fedb959b1 100644 --- a/test/results/flow-info/default/hsrp2_ipv6.pcapng.out +++ b/test/results/flow-info/default/hsrp2_ipv6.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [................................fe80::1][.2029] -> [...............................ff02::66][.2029] + new: [.....1] [ip6][..udp] [................................fe80::1][.2029] -> [...............................ff02::66][.2029] detected: [.....1] [ip6][..udp] [................................fe80::1][.2029] -> [...............................ff02::66][.2029] [HSRP][Unknown][Network][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip6][..udp] [................................fe80::2][.2029] -> [...............................ff02::66][.2029] + new: [.....2] [ip6][..udp] [................................fe80::2][.2029] -> [...............................ff02::66][.2029] detected: [.....2] [ip6][..udp] [................................fe80::2][.2029] -> [...............................ff02::66][.2029] [HSRP][Unknown][Network][Acceptable] RISK: Known Proto on Non Std Port update: [.....1] [ip6][..udp] [................................fe80::1][.2029] -> [...............................ff02::66][.2029] [HSRP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/http-crash-content-disposition.pcap.out b/test/results/flow-info/default/http-crash-content-disposition.pcap.out index a40dad5fd..f1773cdbd 100644 --- a/test/results/flow-info/default/http-crash-content-disposition.pcap.out +++ b/test/results/flow-info/default/http-crash-content-disposition.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.0.103][51171] -> [...174.129.0.10][...80] + new: [.....1] [ip4][..tcp] [..192.168.0.103][51171] -> [...174.129.0.10][...80] detected: [.....1] [ip4][..tcp] [..192.168.0.103][51171] -> [...174.129.0.10][...80] [HTTP][AmazonAWS][Web][Acceptable][khu.sh] idle: [.....1] [ip4][..tcp] [..192.168.0.103][51171] -> [...174.129.0.10][...80] [HTTP][AmazonAWS][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/http-lines-split.pcap.out b/test/results/flow-info/default/http-lines-split.pcap.out index e922f3216..7f8c23d2c 100644 --- a/test/results/flow-info/default/http-lines-split.pcap.out +++ b/test/results/flow-info/default/http-lines-split.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.0.1][39236] -> [...192.168.0.20][31337] + new: [.....1] [ip4][..tcp] [....192.168.0.1][39236] -> [...192.168.0.20][31337] detected: [.....1] [ip4][..tcp] [....192.168.0.1][39236] -> [...192.168.0.20][31337] [HTTP][Unknown][Web][Acceptable][toni.lan] RISK: Known Proto on Non Std Port, HTTP Susp User-Agent detection-update: [.....1] [ip4][..tcp] [....192.168.0.1][39236] -> [...192.168.0.20][31337] [HTTP][Unknown][Web][Acceptable][toni.lan] diff --git a/test/results/flow-info/default/http-manipulated.pcap.out b/test/results/flow-info/default/http-manipulated.pcap.out index b40fcfafa..f46de147b 100644 --- a/test/results/flow-info/default/http-manipulated.pcap.out +++ b/test/results/flow-info/default/http-manipulated.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.0.20][33632] -> [....192.168.0.7][.8080] + new: [.....1] [ip4][..tcp] [...192.168.0.20][33632] -> [....192.168.0.7][.8080] detected: [.....1] [ip4][..tcp] [...192.168.0.20][33632] -> [....192.168.0.7][.8080] [HTTP][Unknown][Web][Acceptable][wwww.lan] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 10 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [...192.168.0.20][33684] -> [....192.168.0.7][.8080] + new: [.....2] [ip4][..tcp] [...192.168.0.20][33684] -> [....192.168.0.7][.8080] detected: [.....2] [ip4][..tcp] [...192.168.0.20][33684] -> [....192.168.0.7][.8080] [HTTP][Unknown][Web][Acceptable][www.lan] RISK: Known Proto on Non Std Port end: [.....1] [ip4][..tcp] [...192.168.0.20][33632] -> [....192.168.0.7][.8080] [HTTP][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/http-proxy.pcapng.out b/test/results/flow-info/default/http-proxy.pcapng.out index b1c515e31..35baf31dc 100644 --- a/test/results/flow-info/default/http-proxy.pcapng.out +++ b/test/results/flow-info/default/http-proxy.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.103][.1241] -> [..192.168.1.146][.8080] + new: [.....1] [ip4][..tcp] [..192.168.1.103][.1241] -> [..192.168.1.146][.8080] detected: [.....1] [ip4][..tcp] [..192.168.1.103][.1241] -> [..192.168.1.146][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][http.com] end: [.....1] [ip4][..tcp] [..192.168.1.103][.1241] -> [..192.168.1.146][.8080] [HTTP_Proxy][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/http2.pcapng.out b/test/results/flow-info/default/http2.pcapng.out index cc0eff76d..82f4b189f 100644 --- a/test/results/flow-info/default/http2.pcapng.out +++ b/test/results/flow-info/default/http2.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][37824] -> [......127.0.0.1][29518] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [......127.0.0.1][37824] -> [......127.0.0.1][29518] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [......127.0.0.1][37824] -> [......127.0.0.1][29518] [HTTP2][Unknown][Web][Safe] idle: [.....1] [ip4][..tcp] [......127.0.0.1][37824] -> [......127.0.0.1][29518] [HTTP2][Unknown][Web][Safe] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/http_asymmetric.pcapng.out b/test/results/flow-info/default/http_asymmetric.pcapng.out index 48745d716..1481b9b76 100644 --- a/test/results/flow-info/default/http_asymmetric.pcapng.out +++ b/test/results/flow-info/default/http_asymmetric.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.0.1][.1044] -> [.....10.10.10.1][...80] - new: [.....2] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] + new: [.....1] [ip4][..tcp] [....192.168.0.1][.1044] -> [.....10.10.10.1][...80] + new: [.....2] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] detected: [.....1] [ip4][..tcp] [....192.168.0.1][.1044] -> [.....10.10.10.1][...80] [HTTP][Unknown][Web][Acceptable][proxy.wiresharkfest.acropolis.local] RISK: Unidirectional Traffic detected: [.....2] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] [HTTP][Unknown][Web][Acceptable][] diff --git a/test/results/flow-info/default/http_auth.pcap.out b/test/results/flow-info/default/http_auth.pcap.out index 44edac12f..9ee4c195b 100644 --- a/test/results/flow-info/default/http_auth.pcap.out +++ b/test/results/flow-info/default/http_auth.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.0.4][54337] -> [192.254.189.169][...80] + new: [.....1] [ip4][..tcp] [....192.168.0.4][54337] -> [192.254.189.169][...80] detected: [.....1] [ip4][..tcp] [....192.168.0.4][54337] -> [192.254.189.169][...80] [HTTP][Unknown][Web][Acceptable][browserspy.dk] RISK: Clear-Text Credentials detection-update: [.....1] [ip4][..tcp] [....192.168.0.4][54337] -> [192.254.189.169][...80] [HTTP][Unknown][Web][Acceptable][browserspy.dk] diff --git a/test/results/flow-info/default/http_connect.pcap.out b/test/results/flow-info/default/http_connect.pcap.out index 0bf2556b5..58c378062 100644 --- a/test/results/flow-info/default/http_connect.pcap.out +++ b/test/results/flow-info/default/http_connect.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.103][.1714] -> [..192.168.1.146][.8080] + new: [.....1] [ip4][..tcp] [..192.168.1.103][.1714] -> [..192.168.1.146][.8080] detected: [.....1] [ip4][..tcp] [..192.168.1.103][.1714] -> [..192.168.1.146][.8080] [HTTP_Connect][Unknown][Web][Acceptable][apache.org] - new: [.....2] [ip4][..udp] [..192.168.1.146][47767] -> [....192.168.1.2][...53] + new: [.....2] [ip4][..udp] [..192.168.1.146][47767] -> [....192.168.1.2][...53] detected: [.....2] [ip4][..udp] [..192.168.1.146][47767] -> [....192.168.1.2][...53] [DNS][Unknown][Network][Acceptable][apache.org] detection-update: [.....2] [ip4][..udp] [..192.168.1.146][47767] -> [....192.168.1.2][...53] [DNS][Unknown][Network][Acceptable][apache.org] - new: [.....3] [ip4][..tcp] [..192.168.1.146][35968] -> [..151.101.2.132][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.146][35968] -> [..151.101.2.132][..443] detected: [.....3] [ip4][..tcp] [..192.168.1.146][35968] -> [..151.101.2.132][..443] [TLS][Unknown][Web][Safe][apache.org] detection-update: [.....3] [ip4][..tcp] [..192.168.1.146][35968] -> [..151.101.2.132][..443] [TLS][Unknown][Web][Safe][apache.org] analyse: [.....3] [ip4][..tcp] [..192.168.1.146][35968] -> [..151.101.2.132][..443] [TLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/http_guessed_host_and_guessed.pcapng.out b/test/results/flow-info/default/http_guessed_host_and_guessed.pcapng.out index 4df05e87b..48418eb26 100644 --- a/test/results/flow-info/default/http_guessed_host_and_guessed.pcapng.out +++ b/test/results/flow-info/default/http_guessed_host_and_guessed.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....170.33.13.5][..110] -> [....192.168.0.1][..179] + new: [.....1] [ip4][..tcp] [....170.33.13.5][..110] -> [....192.168.0.1][..179] guessed: [.....1] [ip4][..tcp] [....170.33.13.5][..110] -> [....192.168.0.1][..179] [POP3][Alibaba][Email][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic, TCP Connection Issues - end: [.....1] [ip4][..tcp] [....170.33.13.5][..110] -> [....192.168.0.1][..179] + end: [.....1] [ip4][..tcp] [....170.33.13.5][..110] -> [....192.168.0.1][..179] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/http_invalid_server.pcap.out b/test/results/flow-info/default/http_invalid_server.pcap.out index ff7867f95..a4e0e1205 100644 --- a/test/results/flow-info/default/http_invalid_server.pcap.out +++ b/test/results/flow-info/default/http_invalid_server.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.29][51536] -> [.143.204.14.183][...80] + new: [.....1] [ip4][..tcp] [...192.168.1.29][51536] -> [.143.204.14.183][...80] detected: [.....1] [ip4][..tcp] [...192.168.1.29][51536] -> [.143.204.14.183][...80] [HTTP][AmazonAWS][Web][Acceptable][ocsp.rootg2.amazontrust.com] RISK: HTTP Susp User-Agent detection-update: [.....1] [ip4][..tcp] [...192.168.1.29][51536] -> [.143.204.14.183][...80] [HTTP.OCSP][AmazonAWS][Web][Safe][ocsp.rootg2.amazontrust.com] diff --git a/test/results/flow-info/default/http_ipv6.pcap.out b/test/results/flow-info/default/http_ipv6.pcap.out index 17ac2706e..a3b6c7740 100644 --- a/test/results/flow-info/default/http_ipv6.pcap.out +++ b/test/results/flow-info/default/http_ipv6.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40526] -> [...............2a00:1450:4006:804::200e][..443] [MIDSTREAM] - new: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [MIDSTREAM] + new: [.....1] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40526] -> [...............2a00:1450:4006:804::200e][..443] [MIDSTREAM] + new: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [MIDSTREAM] detected: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [TLS][Google][Web][Safe] detection-update: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic - new: [.....3] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][45931] -> [...............2a00:1450:4001:803::1017][..443] + new: [.....3] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][45931] -> [...............2a00:1450:4001:803::1017][..443] detected: [.....3] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][45931] -> [...............2a00:1450:4001:803::1017][..443] [QUIC.Google][Google][Web][Acceptable][www.google.it] detection-update: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [TLS][Google][Web][Safe] - new: [.....4] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][58660] -> [...............2a00:1450:4006:803::2008][..443] [MIDSTREAM] - new: [.....5] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][55145] -> [.................2a00:1450:400b:c02::5f][..443] + new: [.....4] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][58660] -> [...............2a00:1450:4006:803::2008][..443] [MIDSTREAM] + new: [.....5] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][55145] -> [.................2a00:1450:400b:c02::5f][..443] analyse: [.....3] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][45931] -> [...............2a00:1450:4001:803::1017][..443] [QUIC.Google][Google][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.002| 6.009| 0.604| 1.486| 2208638.173| 2.800] @@ -21,8 +21,8 @@ [IATS(ms)....: 25.4,26.2,172.4,219.5,15.7,87.2,38.8,110.2,47.0,1.5,26.7,45.8,1752.5,1778.7,6.8,78.3,246.6,318.1,6008.8,6008.7,4.8,76.9,102.6,174.5,2.4,73.9,70.9,142.5,2.9,74.3,992.4] [PKTLENS.....: 1398,1398,85,1202,80,660,88,238,80,88,567,88,77,243,80,623,91,88,80,248,77,575,91,249,80,572,88,250,80,547,88,251] [ENTROPIES...: 4.7,7.9,5.3,7.8,5.2,7.6,5.4,6.9,5.2,5.4,7.5,5.4,4.9,6.9,5.2,7.7,5.6,5.5,5.2,7.0,4.9,7.6,5.5,6.9,5.3,7.6,5.5,6.9,5.2,7.6,5.4,7.0] - new: [.....6] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37486] -> [................2a03:b0c0:3:d0::70:1001][..443] - new: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] + new: [.....6] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37486] -> [................2a03:b0c0:3:d0::70:1001][..443] + new: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] detected: [.....6] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37486] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detected: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] @@ -31,22 +31,22 @@ RISK: TLS Cert Mismatch detection-update: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] RISK: TLS Cert Mismatch - new: [.....8] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37494] -> [................2a03:b0c0:3:d0::70:1001][..443] + new: [.....8] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37494] -> [................2a03:b0c0:3:d0::70:1001][..443] detected: [.....8] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37494] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....8] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37494] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [.....8] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37494] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] RISK: TLS Cert Mismatch - new: [.....9] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][60124] -> [..................2a02:26f0:ad:1a1::eed][..443] [MIDSTREAM] - new: [....10] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40308] -> [....2a03:2880:1010:3f20:face:b00c::25de][..443] [MIDSTREAM] - new: [....11] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][33062] -> [.................2a00:1450:400b:c02::9a][..443] [MIDSTREAM] - new: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] + new: [.....9] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][60124] -> [..................2a02:26f0:ad:1a1::eed][..443] [MIDSTREAM] + new: [....10] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40308] -> [....2a03:2880:1010:3f20:face:b00c::25de][..443] [MIDSTREAM] + new: [....11] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][33062] -> [.................2a00:1450:400b:c02::9a][..443] [MIDSTREAM] + new: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] detected: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] detection-update: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe][www.ntop.org] RISK: TLS Cert Mismatch - new: [....13] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][59690] -> [...............2a00:1450:4001:803::1012][..443] [MIDSTREAM] - new: [....14] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53132] -> [..................2a02:26f0:ad:197::236][..443] - new: [....15] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53134] -> [..................2a02:26f0:ad:197::236][..443] + new: [....13] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][59690] -> [...............2a00:1450:4001:803::1012][..443] [MIDSTREAM] + new: [....14] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53132] -> [..................2a02:26f0:ad:197::236][..443] + new: [....15] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53134] -> [..................2a02:26f0:ad:197::236][..443] detected: [....15] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53134] -> [..................2a02:26f0:ad:197::236][..443] [TLS.Facebook][Unknown][SocialNetwork][Fun][s-static.ak.facebook.com] detected: [....14] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53132] -> [..................2a02:26f0:ad:197::236][..443] [TLS.Facebook][Unknown][SocialNetwork][Fun][s-static.ak.facebook.com] detection-update: [....15] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][53134] -> [..................2a02:26f0:ad:197::236][..443] [TLS.Facebook][Unknown][SocialNetwork][Fun][s-static.ak.facebook.com] @@ -57,9 +57,9 @@ idle: [.....2] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][41776] -> [...............2a00:1450:4001:803::1017][..443] [TLS][Google][Web][Safe] idle: [.....3] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][45931] -> [...............2a00:1450:4001:803::1017][..443] [QUIC.Google][Google][Web][Acceptable] guessed: [.....9] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][60124] -> [..................2a02:26f0:ad:1a1::eed][..443] [TLS][Unknown][Web][Safe] - idle: [.....9] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][60124] -> [..................2a02:26f0:ad:1a1::eed][..443] + idle: [.....9] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][60124] -> [..................2a02:26f0:ad:1a1::eed][..443] guessed: [.....4] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][58660] -> [...............2a00:1450:4006:803::2008][..443] [TLS][Google][Web][Safe] - idle: [.....4] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][58660] -> [...............2a00:1450:4006:803::2008][..443] + idle: [.....4] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][58660] -> [...............2a00:1450:4006:803::2008][..443] end: [.....6] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37486] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe] RISK: TLS Cert Mismatch end: [.....7] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37488] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe] @@ -69,13 +69,13 @@ idle: [....12] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][37506] -> [................2a03:b0c0:3:d0::70:1001][..443] [TLS.ntop][Unknown][Network][Safe] RISK: TLS Cert Mismatch guessed: [.....1] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40526] -> [...............2a00:1450:4006:804::200e][..443] [TLS][Google][Web][Safe] - idle: [.....1] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40526] -> [...............2a00:1450:4006:804::200e][..443] + idle: [.....1] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40526] -> [...............2a00:1450:4006:804::200e][..443] guessed: [....10] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40308] -> [....2a03:2880:1010:3f20:face:b00c::25de][..443] [TLS][Facebook][Web][Safe] - idle: [....10] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40308] -> [....2a03:2880:1010:3f20:face:b00c::25de][..443] + idle: [....10] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][40308] -> [....2a03:2880:1010:3f20:face:b00c::25de][..443] guessed: [.....5] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][55145] -> [.................2a00:1450:400b:c02::5f][..443] [QUIC][Google][Web][Acceptable] - idle: [.....5] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][55145] -> [.................2a00:1450:400b:c02::5f][..443] + idle: [.....5] [ip6][..udp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][55145] -> [.................2a00:1450:400b:c02::5f][..443] guessed: [....11] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][33062] -> [.................2a00:1450:400b:c02::9a][..443] [TLS][Google][Web][Safe] - idle: [....11] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][33062] -> [.................2a00:1450:400b:c02::9a][..443] + idle: [....11] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][33062] -> [.................2a00:1450:400b:c02::9a][..443] guessed: [....13] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][59690] -> [...............2a00:1450:4001:803::1012][..443] [TLS][Google][Web][Safe] - idle: [....13] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][59690] -> [...............2a00:1450:4001:803::1012][..443] + idle: [....13] [ip6][..tcp] [........2a00:d40:1:3:7aac:c0ff:fea7:d4c][59690] -> [...............2a00:1450:4001:803::1012][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/http_on_sip_port.pcap.out b/test/results/flow-info/default/http_on_sip_port.pcap.out index d88e3353e..3758c4af6 100644 --- a/test/results/flow-info/default/http_on_sip_port.pcap.out +++ b/test/results/flow-info/default/http_on_sip_port.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.82.178.111.221][.5060] -> [....45.58.148.2][.8888] + new: [.....1] [ip4][..tcp] [.82.178.111.221][.5060] -> [....45.58.148.2][.8888] detected: [.....1] [ip4][..tcp] [.82.178.111.221][.5060] -> [....45.58.148.2][.8888] [HTTP][Unknown][Web][Acceptable][45.58.148.2] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....1] [ip4][..tcp] [.82.178.111.221][.5060] -> [....45.58.148.2][.8888] [HTTP][Unknown][Web][Acceptable][45.58.148.2] diff --git a/test/results/flow-info/default/http_starting_with_reply.pcapng.out b/test/results/flow-info/default/http_starting_with_reply.pcapng.out index 536b89b00..d0978f7ba 100644 --- a/test/results/flow-info/default/http_starting_with_reply.pcapng.out +++ b/test/results/flow-info/default/http_starting_with_reply.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent detection-update: [.....1] [ip4][..tcp] [..192.168.1.146][...80] -> [..192.168.1.103][.1044] [HTTP][Unknown][Web][Acceptable][] diff --git a/test/results/flow-info/default/http_ua_splitted_in_two_pkts.pcapng.out b/test/results/flow-info/default/http_ua_splitted_in_two_pkts.pcapng.out index cb8bc78a1..e968036af 100644 --- a/test/results/flow-info/default/http_ua_splitted_in_two_pkts.pcapng.out +++ b/test/results/flow-info/default/http_ua_splitted_in_two_pkts.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [254.125.135.128][21359] -> [..66.152.103.45][...80] + new: [.....1] [ip4][..tcp] [254.125.135.128][21359] -> [..66.152.103.45][...80] detected: [.....1] [ip4][..tcp] [254.125.135.128][21359] -> [..66.152.103.45][...80] [HTTP][Unknown][Web][Acceptable][] detection-update: [.....1] [ip4][..tcp] [254.125.135.128][21359] -> [..66.152.103.45][...80] [HTTP][Unknown][Web][Acceptable][va.origin.startappservice.com] analyse: [.....1] [ip4][..tcp] [254.125.135.128][21359] -> [..66.152.103.45][...80] [HTTP][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/i3d.pcap.out b/test/results/flow-info/default/i3d.pcap.out index 833a32574..ffa090a64 100644 --- a/test/results/flow-info/default/i3d.pcap.out +++ b/test/results/flow-info/default/i3d.pcap.out @@ -1,19 +1,19 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][60476] -> [..213.163.87.47][50004] + new: [.....1] [ip4][..udp] [..192.168.2.100][60476] -> [..213.163.87.47][50004] detected: [.....1] [ip4][..udp] [..192.168.2.100][60476] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][55205] -> [..213.163.87.47][50004] + new: [.....2] [ip4][..udp] [..192.168.2.100][55205] -> [..213.163.87.47][50004] detected: [.....2] [ip4][..udp] [..192.168.2.100][55205] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][60476] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.2.100][62620] -> [..213.163.87.47][50004] + new: [.....3] [ip4][..udp] [..192.168.2.100][62620] -> [..213.163.87.47][50004] detected: [.....3] [ip4][..udp] [..192.168.2.100][62620] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][55205] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] - new: [.....4] [ip4][..udp] [..192.168.2.100][62461] -> [..213.163.87.47][50004] + new: [.....4] [ip4][..udp] [..192.168.2.100][62461] -> [..213.163.87.47][50004] detected: [.....4] [ip4][..udp] [..192.168.2.100][62461] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] idle: [.....4] [ip4][..udp] [..192.168.2.100][62461] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][62620] -> [..213.163.87.47][50004] [i3D][Discord][Game][Fun] diff --git a/test/results/flow-info/default/iax.pcap.out b/test/results/flow-info/default/iax.pcap.out index 3e8f99eb2..0c948d0bb 100644 --- a/test/results/flow-info/default/iax.pcap.out +++ b/test/results/flow-info/default/iax.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...82.110.36.84][.4569] -> [..192.168.2.120][.4566] + new: [.....1] [ip4][..udp] [...82.110.36.84][.4569] -> [..192.168.2.120][.4566] detected: [.....1] [ip4][..udp] [...82.110.36.84][.4569] -> [..192.168.2.120][.4566] [IAX][Unknown][VoIP][Acceptable] analyse: [.....1] [ip4][..udp] [...82.110.36.84][.4569] -> [..192.168.2.120][.4566] [IAX][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/icmp-tunnel.pcap.out b/test/results/flow-info/default/icmp-tunnel.pcap.out index b5ee16aa0..5c8158798 100644 --- a/test/results/flow-info/default/icmp-tunnel.pcap.out +++ b/test/results/flow-info/default/icmp-tunnel.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][.icmp] [192.168.154.131] -> [192.168.154.132] + new: [.....1] [ip4][.icmp] [192.168.154.131] -> [192.168.154.132] detected: [.....1] [ip4][.icmp] [192.168.154.131] -> [192.168.154.132] [ICMP][Unknown][Network][Acceptable] RISK: Malformed Packet analyse: [.....1] [ip4][.icmp] [192.168.154.131] -> [192.168.154.132] [ICMP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/iec60780-5-104.pcap.out b/test/results/flow-info/default/iec60780-5-104.pcap.out index c890acf1e..2980e70ec 100644 --- a/test/results/flow-info/default/iec60780-5-104.pcap.out +++ b/test/results/flow-info/default/iec60780-5-104.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.172.27.248.109][.1568] -> [..172.27.248.79][.2404] + new: [.....1] [ip4][..tcp] [.172.27.248.109][.1568] -> [..172.27.248.79][.2404] detected: [.....1] [ip4][..tcp] [.172.27.248.109][.1568] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] - new: [.....2] [ip4][..tcp] [.172.27.248.109][.1570] -> [..172.27.248.79][.2404] + new: [.....2] [ip4][..tcp] [.172.27.248.109][.1570] -> [..172.27.248.79][.2404] detected: [.....2] [ip4][..tcp] [.172.27.248.109][.1570] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] - new: [.....3] [ip4][..tcp] [.172.27.248.109][.1571] -> [..172.27.248.79][.2404] + new: [.....3] [ip4][..tcp] [.172.27.248.109][.1571] -> [..172.27.248.79][.2404] detected: [.....3] [ip4][..tcp] [.172.27.248.109][.1571] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] end: [.....1] [ip4][..tcp] [.172.27.248.109][.1568] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] - new: [.....4] [ip4][..tcp] [.172.27.248.109][.1572] -> [..172.27.248.79][.2404] + new: [.....4] [ip4][..tcp] [.172.27.248.109][.1572] -> [..172.27.248.79][.2404] detected: [.....4] [ip4][..tcp] [.172.27.248.109][.1572] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] end: [.....2] [ip4][..tcp] [.172.27.248.109][.1570] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] end: [.....3] [ip4][..tcp] [.172.27.248.109][.1571] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] - new: [.....5] [ip4][..tcp] [.172.27.248.109][.1577] -> [..172.27.248.79][.2404] + new: [.....5] [ip4][..tcp] [.172.27.248.109][.1577] -> [..172.27.248.79][.2404] detected: [.....5] [ip4][..tcp] [.172.27.248.109][.1577] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] - new: [.....6] [ip4][..tcp] [.172.27.248.109][.1578] -> [..172.27.248.79][.2404] + new: [.....6] [ip4][..tcp] [.172.27.248.109][.1578] -> [..172.27.248.79][.2404] detected: [.....6] [ip4][..tcp] [.172.27.248.109][.1578] -> [..172.27.248.79][.2404] [IEC60870][Unknown][IoT-Scada][Acceptable] DAEMON-EVENT: [Processed: 106 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] diff --git a/test/results/flow-info/default/imap-starttls.pcap.out b/test/results/flow-info/default/imap-starttls.pcap.out index be955eb2d..63fa7a136 100644 --- a/test/results/flow-info/default/imap-starttls.pcap.out +++ b/test/results/flow-info/default/imap-starttls.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] + new: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] detected: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] [IMAPS][Unknown][Email][Safe] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..tcp] [..192.168.17.53][49640] -> [.212.227.17.186][..143] [IMAPS][Unknown][Email][Safe] diff --git a/test/results/flow-info/default/imap.pcap.out b/test/results/flow-info/default/imap.pcap.out index 897fd4b50..df8bfa860 100644 --- a/test/results/flow-info/default/imap.pcap.out +++ b/test/results/flow-info/default/imap.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......10.40.4.2][46045] -> [......10.40.3.2][..143] + new: [.....1] [ip4][..tcp] [......10.40.4.2][46045] -> [......10.40.3.2][..143] detected: [.....1] [ip4][..tcp] [......10.40.4.2][46045] -> [......10.40.3.2][..143] [IMAP][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials analyse: [.....1] [ip4][..tcp] [......10.40.4.2][46045] -> [......10.40.3.2][..143] [IMAP][Unknown][Email][Unsafe] diff --git a/test/results/flow-info/default/imaps.pcap.out b/test/results/flow-info/default/imaps.pcap.out index 34fc6a15f..9e7ccf398 100644 --- a/test/results/flow-info/default/imaps.pcap.out +++ b/test/results/flow-info/default/imaps.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.1.8][50506] -> [.167.99.215.164][..993] + new: [.....1] [ip4][..tcp] [....192.168.1.8][50506] -> [.167.99.215.164][..993] detected: [.....1] [ip4][..tcp] [....192.168.1.8][50506] -> [.167.99.215.164][..993] [IMAPS.ntop][Unknown][Email][Safe] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [....192.168.1.8][50506] -> [.167.99.215.164][..993] [IMAPS.ntop][Unknown][Email][Safe] @@ -10,7 +10,7 @@ RISK: TLS (probably) Not Carrying HTTPS DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..tcp] [....192.168.0.1][51529] -> [.....10.10.10.1][..993] + new: [.....2] [ip4][..tcp] [....192.168.0.1][51529] -> [.....10.10.10.1][..993] detected: [.....2] [ip4][..tcp] [....192.168.0.1][51529] -> [.....10.10.10.1][..993] [IMAPS][Unknown][Email][Safe] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....2] [ip4][..tcp] [....192.168.0.1][51529] -> [.....10.10.10.1][..993] [IMAPS][Unknown][Email][Safe] diff --git a/test/results/flow-info/default/imo.pcap.out b/test/results/flow-info/default/imo.pcap.out index f7ea0e3f0..28d29ef4c 100644 --- a/test/results/flow-info/default/imo.pcap.out +++ b/test/results/flow-info/default/imo.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.169][49207] -> [.185.155.137.30][36535] + new: [.....1] [ip4][..udp] [.192.168.12.169][49207] -> [.185.155.137.30][36535] detected: [.....1] [ip4][..udp] [.192.168.12.169][49207] -> [.185.155.137.30][36535] [IMO][Unknown][VoIP][Acceptable] - new: [.....2] [ip4][..udp] [.192.168.12.169][49207] -> [....93.33.47.58][57604] + new: [.....2] [ip4][..udp] [.192.168.12.169][49207] -> [....93.33.47.58][57604] detected: [.....2] [ip4][..udp] [.192.168.12.169][49207] -> [....93.33.47.58][57604] [IMO][Unknown][VoIP][Acceptable] analyse: [.....2] [ip4][..udp] [.192.168.12.169][49207] -> [....93.33.47.58][57604] [IMO][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/instagram.pcap.out b/test/results/flow-info/default/instagram.pcap.out index 2a40744e7..69471bf9f 100644 --- a/test/results/flow-info/default/instagram.pcap.out +++ b/test/results/flow-info/default/instagram.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.0.103][56382] -> [..173.252.107.4][..443] - new: [.....2] [ip4][..tcp] [..192.168.0.103][33936] -> [....31.13.93.52][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.0.103][56382] -> [..173.252.107.4][..443] + new: [.....2] [ip4][..tcp] [..192.168.0.103][33936] -> [....31.13.93.52][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.0.103][33936] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] detected: [.....1] [ip4][..tcp] [..192.168.0.103][56382] -> [..173.252.107.4][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][telegraph-ash.instagram.com] RISK: Obsolete TLS (v1.1 or older) @@ -19,13 +19,13 @@ [PKTLENS.....: 1417,52,665,52,1049,52,1450,52,195,52,1450,52,1283,52,1450,52,1450,52,1450,52,1450,52,1450,52,1450,52,1450,52,1450,52,1450,52] [ENTROPIES...: 7.9,5.1,7.7,5.0,7.8,5.0,7.9,5.1,6.7,5.1,7.9,5.1,7.8,5.1,7.9,5.0,7.8,5.1,7.9,5.1,7.8,5.1,7.9,5.1,7.9,5.1,7.9,5.1,7.9,5.1,7.9,5.1] detection-update: [.....2] [ip4][..tcp] [..192.168.0.103][33936] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] - new: [.....3] [ip4][..tcp] [..192.168.0.103][38816] -> [...46.33.70.160][...80] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.0.103][38816] -> [...46.33.70.160][...80] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..192.168.0.103][38816] -> [...46.33.70.160][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-h.ak.instagram.com] - new: [.....4] [ip4][..tcp] [..192.168.0.103][57936] -> [...82.85.26.162][...80] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.0.103][57936] -> [...82.85.26.162][...80] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.0.103][57936] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-g.ak.instagram.com] - new: [.....5] [ip4][..tcp] [..192.168.0.103][44379] -> [...82.85.26.186][...80] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..192.168.0.103][44379] -> [...82.85.26.186][...80] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..192.168.0.103][44379] -> [...82.85.26.186][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-e.ak.instagram.com] - new: [.....6] [ip4][..tcp] [..192.168.0.103][57965] -> [...82.85.26.185][...80] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.0.103][57965] -> [...82.85.26.185][...80] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..192.168.0.103][57965] -> [...82.85.26.185][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-f.ak.instagram.com] analyse: [.....3] [ip4][..tcp] [..192.168.0.103][38816] -> [...46.33.70.160][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy @@ -47,7 +47,7 @@ [IATS(ms)....: 56.8,57.1,1.2,1.0,0.6,0.6,0.4,0.4,0.5,0.5,0.7,0.7,1.3,1.3,1.2,1.2,0.5,0.5,0.4,0.5,111.5,0.0,112.0,0.3,1.3,0.1,0.0,1.0,0.9,0.8,0.5] [PKTLENS.....: 305,1470,52,1431,52,1470,52,1470,52,1470,52,1470,52,172,52,1470,52,1470,52,1470,52,1470,1470,52,52,1470,1470,1470,52,1470,52,1470] [ENTROPIES...: 5.8,6.9,5.0,7.6,5.0,7.8,5.0,7.8,5.0,7.8,5.1,7.8,5.0,6.5,5.0,6.9,5.0,7.5,5.0,7.8,5.0,7.8,7.8,5.1,5.1,7.8,7.8,7.8,5.1,7.8,5.1,7.8] - new: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] [MIDSTREAM] analyse: [.....5] [ip4][..tcp] [..192.168.0.103][44379] -> [...82.85.26.186][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.372| 0.037| 0.093| 8582.227| 2.300] @@ -58,23 +58,23 @@ [IATS(ms)....: 185.5,185.9,0.4,0.5,0.6,0.1,1.4,0.1,1.4,0.1,0.6,0.7,1.4,0.1,310.3,372.1,63.2,2.2,2.2,0.3,0.3,0.5,0.4,0.7,0.8,0.6,0.5,0.5,0.5,1.0,1.0] [PKTLENS.....: 311,1470,80,1470,1470,80,80,1470,1470,80,80,1470,80,1470,1470,311,1470,52,1470,52,1460,52,1470,52,1470,52,1470,52,1470,52,1470,1470] [ENTROPIES...: 5.9,7.8,5.2,7.8,7.8,5.2,5.3,7.8,7.8,5.3,5.3,7.8,5.2,7.8,7.8,5.8,7.2,5.0,7.6,5.0,7.7,5.0,7.8,5.0,7.8,5.0,7.8,5.0,7.8,5.0,7.8,7.8] - new: [.....8] [ip4][..tcp] [..192.168.0.103][37350] -> [...82.85.26.153][...80] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [..192.168.0.103][37350] -> [...82.85.26.153][...80] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [..192.168.0.103][37350] -> [...82.85.26.153][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-a.ak.instagram.com] - new: [.....9] [ip4][..udp] [..192.168.0.106][17500] -> [255.255.255.255][17500] + new: [.....9] [ip4][..udp] [..192.168.0.106][17500] -> [255.255.255.255][17500] detected: [.....9] [ip4][..udp] [..192.168.0.106][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....10] [ip4][..udp] [..192.168.0.106][17500] -> [..192.168.0.255][17500] + new: [....10] [ip4][..udp] [..192.168.0.106][17500] -> [..192.168.0.255][17500] detected: [....10] [ip4][..udp] [..192.168.0.106][17500] -> [..192.168.0.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] - new: [....12] [ip4][..tcp] [....31.13.93.52][..443] -> [..192.168.0.103][33934] [MIDSTREAM] + new: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] + new: [....12] [ip4][..tcp] [....31.13.93.52][..443] -> [..192.168.0.103][33934] [MIDSTREAM] detected: [....12] [ip4][..tcp] [....31.13.93.52][..443] -> [..192.168.0.103][33934] [TLS][Facebook][Web][Safe] - new: [....13] [ip4][..tcp] [..192.168.0.103][33935] -> [....31.13.93.52][..443] [MIDSTREAM] + new: [....13] [ip4][..tcp] [..192.168.0.103][33935] -> [....31.13.93.52][..443] [MIDSTREAM] detected: [....13] [ip4][..tcp] [..192.168.0.103][33935] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] - new: [....14] [ip4][.icmp] [..192.168.0.103] -> [..192.168.0.103] + new: [....14] [ip4][.icmp] [..192.168.0.103] -> [..192.168.0.103] detected: [....14] [ip4][.icmp] [..192.168.0.103] -> [..192.168.0.103] [ICMP][Unknown][Network][Acceptable] - new: [....15] [ip4][..tcp] [..192.168.0.103][33763] -> [....31.13.93.52][..443] [MIDSTREAM] + new: [....15] [ip4][..tcp] [..192.168.0.103][33763] -> [....31.13.93.52][..443] [MIDSTREAM] detected: [....15] [ip4][..tcp] [..192.168.0.103][33763] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] - new: [....16] [ip4][..tcp] [..192.168.0.103][38817] -> [...46.33.70.160][...80] [MIDSTREAM] - analyse: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] + new: [....16] [ip4][..tcp] [..192.168.0.103][38817] -> [...46.33.70.160][...80] [MIDSTREAM] + analyse: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 7.322| 0.237| 1.293| 1672842.314| 0.100] [PKTLEN......: 52.000| 1470.000| 889.300| 693.100| 480370.200| 4.400] @@ -84,20 +84,20 @@ [IATS(ms)....: 0.2,0.9,1.5,2.7,0.5,0.4,0.3,0.4,1.5,0.5,1.2,1.8,0.1,0.0,2.3,0.1,3.2,0.4,3.6,1.0,0.5,0.4,2.0,0.9,0.9,0.7,3.6,0.1,4.7,0.2,7321.5] [PKTLENS.....: 52,52,1470,1470,52,1470,1470,1470,1470,52,52,1470,1470,1470,1470,52,52,1470,1470,52,1470,1470,1470,52,1470,52,1470,1470,1323,52,52,52] [ENTROPIES...: 5.0,5.0,7.8,7.8,5.0,7.8,7.8,7.8,7.8,5.0,5.1,7.8,7.8,7.8,7.8,5.1,5.0,7.8,7.8,5.0,7.8,7.8,7.8,5.1,7.8,5.0,7.8,7.8,7.8,5.1,5.1,5.1] - new: [....17] [ip4][..udp] [..192.168.0.103][51219] -> [........8.8.8.8][...53] + new: [....17] [ip4][..udp] [..192.168.0.103][51219] -> [........8.8.8.8][...53] detected: [....17] [ip4][..udp] [..192.168.0.103][51219] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-h-a.akamaihd.net] - new: [....18] [ip4][..udp] [..192.168.0.103][33603] -> [........8.8.8.8][...53] + new: [....18] [ip4][..udp] [..192.168.0.103][33603] -> [........8.8.8.8][...53] detected: [....18] [ip4][..udp] [..192.168.0.103][33603] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-a-a.akamaihd.net] - new: [....19] [ip4][..tcp] [..192.168.0.103][57966] -> [...82.85.26.185][...80] [MIDSTREAM] - new: [....20] [ip4][..udp] [..192.168.0.103][26540] -> [........8.8.8.8][...53] + new: [....19] [ip4][..tcp] [..192.168.0.103][57966] -> [...82.85.26.185][...80] [MIDSTREAM] + new: [....20] [ip4][..udp] [..192.168.0.103][26540] -> [........8.8.8.8][...53] detected: [....20] [ip4][..udp] [..192.168.0.103][26540] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-g-a.akamaihd.net] detection-update: [....17] [ip4][..udp] [..192.168.0.103][51219] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-h-a.akamaihd.net] - new: [....21] [ip4][..tcp] [..192.168.0.103][44558] -> [...46.33.70.174][..443] + new: [....21] [ip4][..tcp] [..192.168.0.103][44558] -> [...46.33.70.174][..443] detection-update: [....18] [ip4][..udp] [..192.168.0.103][33603] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-a-a.akamaihd.net] - new: [....22] [ip4][..tcp] [..192.168.0.103][41181] -> [...82.85.26.154][..443] - new: [....23] [ip4][..tcp] [..192.168.0.103][41182] -> [...82.85.26.154][..443] + new: [....22] [ip4][..tcp] [..192.168.0.103][41181] -> [...82.85.26.154][..443] + new: [....23] [ip4][..tcp] [..192.168.0.103][41182] -> [...82.85.26.154][..443] detection-update: [....20] [ip4][..udp] [..192.168.0.103][26540] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][igcdn-photos-g-a.akamaihd.net] - new: [....24] [ip4][..tcp] [..192.168.0.103][60908] -> [...46.33.70.136][..443] + new: [....24] [ip4][..tcp] [..192.168.0.103][60908] -> [...46.33.70.136][..443] detected: [....21] [ip4][..tcp] [..192.168.0.103][44558] -> [...46.33.70.174][..443] [TLS.Instagram][Unknown][SocialNetwork][Fun][igcdn-photos-h-a.akamaihd.net] RISK: Obsolete TLS (v1.1 or older) detected: [....24] [ip4][..tcp] [..192.168.0.103][60908] -> [...46.33.70.136][..443] [TLS.Instagram][Unknown][SocialNetwork][Fun][igcdn-photos-g-a.akamaihd.net] @@ -122,10 +122,10 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....23] [ip4][..tcp] [..192.168.0.103][41182] -> [...82.85.26.154][..443] [TLS.Instagram][Unknown][SocialNetwork][Fun][igcdn-photos-a-a.akamaihd.net] RISK: Obsolete TLS (v1.1 or older) - new: [....25] [ip4][..tcp] [..92.122.48.138][...80] -> [..192.168.0.103][41562] [MIDSTREAM] - new: [....26] [ip4][..tcp] [..192.168.0.103][58052] -> [...82.85.26.162][...80] [MIDSTREAM] + new: [....25] [ip4][..tcp] [..92.122.48.138][...80] -> [..192.168.0.103][41562] [MIDSTREAM] + new: [....26] [ip4][..tcp] [..192.168.0.103][58052] -> [...82.85.26.162][...80] [MIDSTREAM] detected: [....26] [ip4][..tcp] [..192.168.0.103][58052] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-g.ak.instagram.com] - new: [....27] [ip4][..tcp] [..192.168.0.103][58053] -> [...82.85.26.162][...80] [MIDSTREAM] + new: [....27] [ip4][..tcp] [..192.168.0.103][58053] -> [...82.85.26.162][...80] [MIDSTREAM] detected: [....27] [ip4][..tcp] [..192.168.0.103][58053] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun][photos-g.ak.instagram.com] analyse: [....26] [ip4][..tcp] [..192.168.0.103][58052] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy @@ -137,8 +137,8 @@ [IATS(ms)....: 61.3,0.2,0.4,62.2,0.3,0.3,1.4,0.7,0.9,0.9,1.6,0.1,0.1,1.6,0.1,0.1,1.3,0.1,0.0,1.3,0.1,0.1,0.0,0.1,0.5,0.5,2.4,2.4,1.4,0.1,0.0] [PKTLENS.....: 312,1470,1470,1461,52,52,52,1470,52,1470,52,1470,1470,1470,52,52,52,1470,1470,1470,52,52,1470,52,52,1470,52,1470,52,382,1470,1470] [ENTROPIES...: 5.9,7.4,7.8,7.9,5.0,5.0,5.0,7.8,5.0,7.9,5.0,7.8,7.8,7.8,5.0,5.0,5.0,7.8,7.9,7.8,5.0,5.0,7.8,5.0,5.0,7.7,5.0,7.8,5.0,7.4,7.7,7.7] - new: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] [MIDSTREAM] - analyse: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] + new: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] [MIDSTREAM] + analyse: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.002| 0.001| 0.001| 0.353| 4.600] [PKTLEN......: 52.000| 1450.000| 969.400| 664.000| 440886.100| 4.500] @@ -149,12 +149,12 @@ [PKTLENS.....: 1450,52,1450,52,1450,1450,52,1450,1450,1450,52,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450,1450,52,1450] [ENTROPIES...: 7.8,5.0,7.5,5.0,7.9,7.9,5.0,7.8,7.4,7.5,5.0,7.9,5.0,7.8,7.9,5.0,7.8,7.8,5.0,7.2,7.8,5.0,7.8,7.9,5.0,7.8,7.8,5.0,7.4,7.9,5.0,7.9] update: [....14] [ip4][.icmp] [..192.168.0.103] -> [..192.168.0.103] [ICMP][Unknown][Network][Acceptable] - new: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] [MIDSTREAM] - new: [....30] [ip4][..tcp] [..192.168.0.103][58690] -> [...46.33.70.159][..443] [MIDSTREAM] + new: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] [MIDSTREAM] + new: [....30] [ip4][..tcp] [..192.168.0.103][58690] -> [...46.33.70.159][..443] [MIDSTREAM] detected: [....30] [ip4][..tcp] [..192.168.0.103][58690] -> [...46.33.70.159][..443] [TLS][Unknown][Web][Safe] - new: [....31] [ip4][..udp] [..192.168.0.103][27124] -> [........8.8.8.8][...53] + new: [....31] [ip4][..udp] [..192.168.0.103][27124] -> [........8.8.8.8][...53] detected: [....31] [ip4][..udp] [..192.168.0.103][27124] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun][photos-b.ak.instagram.com] - analyse: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] + analyse: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.004| 0.001| 0.001| 1.362| 4.300] [PKTLEN......: 52.000| 1470.000| 805.300| 707.600| 500717.400| 4.300] @@ -164,18 +164,18 @@ [IATS(ms)....: 0.1,2.1,0.4,3.4,0.0,3.2,2.3,0.4,0.9,1.9,0.2,2.6,1.8,3.8,0.1,3.8,0.2,1.3,1.3,0.4,0.2,0.2,0.3,0.5,0.5,0.9,0.9,2.1,2.1,2.0,0.1] [PKTLENS.....: 1470,52,1470,1470,52,52,1470,52,1470,1470,52,52,1470,52,1470,1470,52,52,1470,52,1470,52,1470,52,1470,52,1470,52,1470,52,1470,1470] [ENTROPIES...: 7.8,5.1,7.8,7.8,5.1,5.1,7.8,5.1,7.8,7.7,5.0,5.1,7.7,5.1,7.7,7.8,5.2,5.1,7.7,5.2,7.8,5.2,7.8,5.2,7.8,5.1,7.8,5.1,7.8,5.1,7.8,7.8] - new: [....32] [ip4][..tcp] [...46.33.70.150][...80] -> [..192.168.0.103][40855] + new: [....32] [ip4][..tcp] [...46.33.70.150][...80] -> [..192.168.0.103][40855] update: [.....9] [ip4][..udp] [..192.168.0.106][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [....10] [ip4][..udp] [..192.168.0.106][17500] -> [..192.168.0.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - update: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] + update: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] DAEMON-EVENT: [Processed: 633 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 32 / 32|skipped: 0|!detected: 0|guessed: 0|detection-updates: 13|updates: 4] - new: [....33] [ip4][..tcp] [...192.168.2.17][49355] -> [....31.13.86.52][..443] + new: [....33] [ip4][..tcp] [...192.168.2.17][49355] -> [....31.13.86.52][..443] detected: [....33] [ip4][..tcp] [...192.168.2.17][49355] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] detection-update: [....33] [ip4][..tcp] [...192.168.2.17][49355] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] - new: [....34] [ip4][..tcp] [...192.168.2.17][49357] -> [....31.13.86.52][..443] - new: [....35] [ip4][..tcp] [...192.168.2.17][49358] -> [....31.13.86.52][..443] - new: [....36] [ip4][..tcp] [...192.168.2.17][49359] -> [....31.13.86.52][..443] + new: [....34] [ip4][..tcp] [...192.168.2.17][49357] -> [....31.13.86.52][..443] + new: [....35] [ip4][..tcp] [...192.168.2.17][49358] -> [....31.13.86.52][..443] + new: [....36] [ip4][..tcp] [...192.168.2.17][49359] -> [....31.13.86.52][..443] detected: [....34] [ip4][..tcp] [...192.168.2.17][49357] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] detected: [....35] [ip4][..tcp] [...192.168.2.17][49358] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] detected: [....36] [ip4][..tcp] [...192.168.2.17][49359] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] @@ -191,10 +191,10 @@ idle: [....20] [ip4][..udp] [..192.168.0.103][26540] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun] idle: [.....6] [ip4][..tcp] [..192.168.0.103][57965] -> [...82.85.26.185][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] guessed: [....19] [ip4][..tcp] [..192.168.0.103][57966] -> [...82.85.26.185][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....19] [ip4][..tcp] [..192.168.0.103][57966] -> [...82.85.26.185][...80] + end: [....19] [ip4][..tcp] [..192.168.0.103][57966] -> [...82.85.26.185][...80] end: [....30] [ip4][..tcp] [..192.168.0.103][58690] -> [...46.33.70.159][..443] [TLS][Unknown][Web][Safe] guessed: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] + end: [.....7] [ip4][..tcp] [..192.168.0.103][33976] -> [....77.67.29.17][...80] idle: [....17] [ip4][..udp] [..192.168.0.103][51219] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun] idle: [....26] [ip4][..tcp] [..192.168.0.103][58052] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] idle: [....27] [ip4][..tcp] [..192.168.0.103][58053] -> [...82.85.26.162][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] @@ -203,32 +203,32 @@ idle: [....24] [ip4][..tcp] [..192.168.0.103][60908] -> [...46.33.70.136][..443] [TLS.Instagram][Unknown][SocialNetwork][Fun] RISK: Obsolete TLS (v1.1 or older) guessed: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] [HTTP][Facebook][Web][Acceptable][] - idle: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] + idle: [....28] [ip4][..tcp] [....31.13.86.52][...80] -> [..192.168.0.103][58216] idle: [....21] [ip4][..tcp] [..192.168.0.103][44558] -> [...46.33.70.174][..443] [TLS.Instagram][Unknown][SocialNetwork][Fun] RISK: Obsolete TLS (v1.1 or older) guessed: [....32] [ip4][..tcp] [...46.33.70.150][...80] -> [..192.168.0.103][40855] [HTTP][Unknown][Web][Acceptable][] - idle: [....32] [ip4][..tcp] [...46.33.70.150][...80] -> [..192.168.0.103][40855] + idle: [....32] [ip4][..tcp] [...46.33.70.150][...80] -> [..192.168.0.103][40855] idle: [.....3] [ip4][..tcp] [..192.168.0.103][38816] -> [...46.33.70.160][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] guessed: [....16] [ip4][..tcp] [..192.168.0.103][38817] -> [...46.33.70.160][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....16] [ip4][..tcp] [..192.168.0.103][38817] -> [...46.33.70.160][...80] + end: [....16] [ip4][..tcp] [..192.168.0.103][38817] -> [...46.33.70.160][...80] idle: [....10] [ip4][..udp] [..192.168.0.106][17500] -> [..192.168.0.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [....31] [ip4][..udp] [..192.168.0.103][27124] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun] idle: [.....1] [ip4][..tcp] [..192.168.0.103][56382] -> [..173.252.107.4][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun] RISK: Obsolete TLS (v1.1 or older) idle: [....15] [ip4][..tcp] [..192.168.0.103][33763] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] guessed: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] [HTTP][Unknown][Web][Acceptable][] - idle: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] + idle: [....29] [ip4][..tcp] [....2.22.236.51][...80] -> [..192.168.0.103][44151] end: [.....5] [ip4][..tcp] [..192.168.0.103][44379] -> [...82.85.26.186][...80] [HTTP.Instagram][Unknown][SocialNetwork][Fun] idle: [....12] [ip4][..tcp] [....31.13.93.52][..443] -> [..192.168.0.103][33934] [TLS][Facebook][Web][Safe] idle: [....13] [ip4][..tcp] [..192.168.0.103][33935] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] idle: [.....2] [ip4][..tcp] [..192.168.0.103][33936] -> [....31.13.93.52][..443] [TLS][Facebook][Web][Safe] idle: [....18] [ip4][..udp] [..192.168.0.103][33603] -> [........8.8.8.8][...53] [DNS.Instagram][Google][Network][Fun] not-detected: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] [Unknown][Unknown][Unrated] - idle: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] + idle: [....11] [ip4][..udp] [....192.168.0.1][..520] -> [..192.168.0.255][..520] guessed: [....25] [ip4][..tcp] [..92.122.48.138][...80] -> [..192.168.0.103][41562] [HTTP][Unknown][Web][Acceptable][] - idle: [....25] [ip4][..tcp] [..92.122.48.138][...80] -> [..192.168.0.103][41562] - new: [....37] [ip4][..tcp] [...192.168.2.17][49360] -> [....31.13.86.52][..443] - new: [....38] [ip4][..tcp] [...192.168.2.17][49361] -> [....31.13.86.52][..443] + idle: [....25] [ip4][..tcp] [..92.122.48.138][...80] -> [..192.168.0.103][41562] + new: [....37] [ip4][..tcp] [...192.168.2.17][49360] -> [....31.13.86.52][..443] + new: [....38] [ip4][..tcp] [...192.168.2.17][49361] -> [....31.13.86.52][..443] detected: [....37] [ip4][..tcp] [...192.168.2.17][49360] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] detected: [....38] [ip4][..tcp] [...192.168.2.17][49361] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] detection-update: [....37] [ip4][..tcp] [...192.168.2.17][49360] -> [....31.13.86.52][..443] [TLS.Instagram][Facebook][SocialNetwork][Fun][scontent-mxp1-1.cdninstagram.com] diff --git a/test/results/flow-info/default/ip_fragmented_garbage.pcap.out b/test/results/flow-info/default/ip_fragmented_garbage.pcap.out index 2c7fa73d1..f36ccbffb 100644 --- a/test/results/flow-info/default/ip_fragmented_garbage.pcap.out +++ b/test/results/flow-info/default/ip_fragmented_garbage.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.2][24102] -> [.....10.128.0.2][10792] + new: [.....1] [ip4][..tcp] [.......10.0.0.2][24102] -> [.....10.128.0.2][10792] ERROR-EVENT: TCP packet smaller than expected [1/16] ERROR-EVENT: TCP packet smaller than expected [2/16] ERROR-EVENT: TCP packet smaller than expected [3/16] @@ -18,90 +18,90 @@ ERROR-EVENT: TCP packet smaller than expected [14/16] ERROR-EVENT: TCP packet smaller than expected [15/16] ERROR-EVENT: TCP packet smaller than expected [16/16] - new: [.....2] [ip4][..tcp] [.......10.0.0.2][18730] -> [.....10.128.0.2][20304] [MIDSTREAM] - new: [.....3] [ip4][..tcp] [.......10.0.0.2][.9253] -> [.....10.128.0.2][24102] - new: [.....4] [ip4][..tcp] [.......10.0.0.2][16417] -> [.....10.128.0.2][16419] - new: [.....5] [ip4][..tcp] [.......10.0.0.2][21029] -> [.....10.128.0.2][22878] [MIDSTREAM] - new: [.....6] [ip4][..tcp] [.......10.0.0.2][24101] -> [.....10.128.0.2][.9251] - new: [.....7] [ip4][..tcp] [.......10.0.0.2][10790] -> [.....10.128.0.2][24101] - new: [.....8] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8995] - new: [.....9] [ip4][..tcp] [.......10.0.0.2][13617] -> [.....10.128.0.2][10536] [MIDSTREAM] - new: [....10] [ip4][..tcp] [.......10.0.0.2][14387] -> [.....10.128.0.2][14646] [MIDSTREAM] - new: [....11] [ip4][..tcp] [.......10.0.0.2][18248] -> [.....10.128.0.2][19019] [MIDSTREAM] - new: [....12] [ip4][..tcp] [.......10.0.0.2][13105] -> [.....10.128.0.2][14648] [MIDSTREAM] - new: [....13] [ip4][..tcp] [.......10.0.0.2][16243] -> [.....10.128.0.2][21055] - new: [....14] [ip4][..tcp] [.......10.0.0.2][17458] -> [.....10.128.0.2][10790] [MIDSTREAM] - new: [....15] [ip4][..tcp] [.......10.0.0.2][.2612] -> [.....10.128.0.2][12849] [MIDSTREAM] - new: [....16] [ip4][..tcp] [.......10.0.0.2][16199] -> [.....10.128.0.2][21055] - new: [....17] [ip4][..tcp] [.......10.0.0.2][19273] -> [.....10.128.0.2][19016] [MIDSTREAM] - new: [....18] [ip4][..tcp] [.......10.0.0.2][.9566] -> [.....10.128.0.2][18498] [MIDSTREAM] - new: [....19] [ip4][..tcp] [.......10.0.0.2][11892] -> [.....10.128.0.2][26470] - new: [....20] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8998] - new: [....21] [ip4][..tcp] [.......10.0.0.2][13362] -> [.....10.128.0.2][12596] [MIDSTREAM] - new: [....22] [ip4][..tcp] [.......10.0.0.2][18258] -> [.....10.128.0.2][16199] [MIDSTREAM] - new: [....23] [ip4][..tcp] [.......10.0.0.2][18762] -> [.....10.128.0.2][18503] - new: [....24] [ip4][..tcp] [.......10.0.0.2][24136] -> [.....10.128.0.2][16967] [MIDSTREAM] - new: [....25] [ip4][..tcp] [.......10.0.0.2][29799] -> [.....10.128.0.2][26228] - new: [....26] [ip4][..tcp] [.......10.0.0.2][.9251] -> [.....10.128.0.2][.9770] - new: [....27] [ip4][..tcp] [.......10.0.0.2][17751] -> [.....10.128.0.2][.9024] - new: [....28] [ip4][..tcp] [.......10.0.0.2][27502] -> [.....10.128.0.2][30307] - new: [....29] [ip4][..tcp] [.......10.0.0.2][10792] -> [.....10.128.0.2][10790] + new: [.....2] [ip4][..tcp] [.......10.0.0.2][18730] -> [.....10.128.0.2][20304] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [.......10.0.0.2][.9253] -> [.....10.128.0.2][24102] + new: [.....4] [ip4][..tcp] [.......10.0.0.2][16417] -> [.....10.128.0.2][16419] + new: [.....5] [ip4][..tcp] [.......10.0.0.2][21029] -> [.....10.128.0.2][22878] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [.......10.0.0.2][24101] -> [.....10.128.0.2][.9251] + new: [.....7] [ip4][..tcp] [.......10.0.0.2][10790] -> [.....10.128.0.2][24101] + new: [.....8] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8995] + new: [.....9] [ip4][..tcp] [.......10.0.0.2][13617] -> [.....10.128.0.2][10536] [MIDSTREAM] + new: [....10] [ip4][..tcp] [.......10.0.0.2][14387] -> [.....10.128.0.2][14646] [MIDSTREAM] + new: [....11] [ip4][..tcp] [.......10.0.0.2][18248] -> [.....10.128.0.2][19019] [MIDSTREAM] + new: [....12] [ip4][..tcp] [.......10.0.0.2][13105] -> [.....10.128.0.2][14648] [MIDSTREAM] + new: [....13] [ip4][..tcp] [.......10.0.0.2][16243] -> [.....10.128.0.2][21055] + new: [....14] [ip4][..tcp] [.......10.0.0.2][17458] -> [.....10.128.0.2][10790] [MIDSTREAM] + new: [....15] [ip4][..tcp] [.......10.0.0.2][.2612] -> [.....10.128.0.2][12849] [MIDSTREAM] + new: [....16] [ip4][..tcp] [.......10.0.0.2][16199] -> [.....10.128.0.2][21055] + new: [....17] [ip4][..tcp] [.......10.0.0.2][19273] -> [.....10.128.0.2][19016] [MIDSTREAM] + new: [....18] [ip4][..tcp] [.......10.0.0.2][.9566] -> [.....10.128.0.2][18498] [MIDSTREAM] + new: [....19] [ip4][..tcp] [.......10.0.0.2][11892] -> [.....10.128.0.2][26470] + new: [....20] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8998] + new: [....21] [ip4][..tcp] [.......10.0.0.2][13362] -> [.....10.128.0.2][12596] [MIDSTREAM] + new: [....22] [ip4][..tcp] [.......10.0.0.2][18258] -> [.....10.128.0.2][16199] [MIDSTREAM] + new: [....23] [ip4][..tcp] [.......10.0.0.2][18762] -> [.....10.128.0.2][18503] + new: [....24] [ip4][..tcp] [.......10.0.0.2][24136] -> [.....10.128.0.2][16967] [MIDSTREAM] + new: [....25] [ip4][..tcp] [.......10.0.0.2][29799] -> [.....10.128.0.2][26228] + new: [....26] [ip4][..tcp] [.......10.0.0.2][.9251] -> [.....10.128.0.2][.9770] + new: [....27] [ip4][..tcp] [.......10.0.0.2][17751] -> [.....10.128.0.2][.9024] + new: [....28] [ip4][..tcp] [.......10.0.0.2][27502] -> [.....10.128.0.2][30307] + new: [....29] [ip4][..tcp] [.......10.0.0.2][10792] -> [.....10.128.0.2][10790] not-detected: [.....4] [ip4][..tcp] [.......10.0.0.2][16417] -> [.....10.128.0.2][16419] [Unknown][Unknown][Unrated] - end: [.....4] [ip4][..tcp] [.......10.0.0.2][16417] -> [.....10.128.0.2][16419] + end: [.....4] [ip4][..tcp] [.......10.0.0.2][16417] -> [.....10.128.0.2][16419] not-detected: [.....8] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8995] [Unknown][Unknown][Unrated] - idle: [.....8] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8995] + idle: [.....8] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8995] not-detected: [....20] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8998] [Unknown][Unknown][Unrated] - idle: [....20] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8998] + idle: [....20] [ip4][..tcp] [.......10.0.0.2][.9508] -> [.....10.128.0.2][.8998] not-detected: [.....7] [ip4][..tcp] [.......10.0.0.2][10790] -> [.....10.128.0.2][24101] [Unknown][Unknown][Unrated] - end: [.....7] [ip4][..tcp] [.......10.0.0.2][10790] -> [.....10.128.0.2][24101] + end: [.....7] [ip4][..tcp] [.......10.0.0.2][10790] -> [.....10.128.0.2][24101] not-detected: [.....1] [ip4][..tcp] [.......10.0.0.2][24102] -> [.....10.128.0.2][10792] [Unknown][Unknown][Unrated] - end: [.....1] [ip4][..tcp] [.......10.0.0.2][24102] -> [.....10.128.0.2][10792] + end: [.....1] [ip4][..tcp] [.......10.0.0.2][24102] -> [.....10.128.0.2][10792] not-detected: [.....2] [ip4][..tcp] [.......10.0.0.2][18730] -> [.....10.128.0.2][20304] [Unknown][Unknown][Unrated] - end: [.....2] [ip4][..tcp] [.......10.0.0.2][18730] -> [.....10.128.0.2][20304] + end: [.....2] [ip4][..tcp] [.......10.0.0.2][18730] -> [.....10.128.0.2][20304] not-detected: [....24] [ip4][..tcp] [.......10.0.0.2][24136] -> [.....10.128.0.2][16967] [Unknown][Unknown][Unrated] - end: [....24] [ip4][..tcp] [.......10.0.0.2][24136] -> [.....10.128.0.2][16967] + end: [....24] [ip4][..tcp] [.......10.0.0.2][24136] -> [.....10.128.0.2][16967] not-detected: [....27] [ip4][..tcp] [.......10.0.0.2][17751] -> [.....10.128.0.2][.9024] [Unknown][Unknown][Unrated] - idle: [....27] [ip4][..tcp] [.......10.0.0.2][17751] -> [.....10.128.0.2][.9024] + idle: [....27] [ip4][..tcp] [.......10.0.0.2][17751] -> [.....10.128.0.2][.9024] not-detected: [....10] [ip4][..tcp] [.......10.0.0.2][14387] -> [.....10.128.0.2][14646] [Unknown][Unknown][Unrated] - end: [....10] [ip4][..tcp] [.......10.0.0.2][14387] -> [.....10.128.0.2][14646] + end: [....10] [ip4][..tcp] [.......10.0.0.2][14387] -> [.....10.128.0.2][14646] not-detected: [....16] [ip4][..tcp] [.......10.0.0.2][16199] -> [.....10.128.0.2][21055] [Unknown][Unknown][Unrated] - end: [....16] [ip4][..tcp] [.......10.0.0.2][16199] -> [.....10.128.0.2][21055] + end: [....16] [ip4][..tcp] [.......10.0.0.2][16199] -> [.....10.128.0.2][21055] not-detected: [....23] [ip4][..tcp] [.......10.0.0.2][18762] -> [.....10.128.0.2][18503] [Unknown][Unknown][Unrated] - idle: [....23] [ip4][..tcp] [.......10.0.0.2][18762] -> [.....10.128.0.2][18503] + idle: [....23] [ip4][..tcp] [.......10.0.0.2][18762] -> [.....10.128.0.2][18503] not-detected: [....11] [ip4][..tcp] [.......10.0.0.2][18248] -> [.....10.128.0.2][19019] [Unknown][Unknown][Unrated] - end: [....11] [ip4][..tcp] [.......10.0.0.2][18248] -> [.....10.128.0.2][19019] + end: [....11] [ip4][..tcp] [.......10.0.0.2][18248] -> [.....10.128.0.2][19019] not-detected: [....13] [ip4][..tcp] [.......10.0.0.2][16243] -> [.....10.128.0.2][21055] [Unknown][Unknown][Unrated] - end: [....13] [ip4][..tcp] [.......10.0.0.2][16243] -> [.....10.128.0.2][21055] + end: [....13] [ip4][..tcp] [.......10.0.0.2][16243] -> [.....10.128.0.2][21055] not-detected: [....28] [ip4][..tcp] [.......10.0.0.2][27502] -> [.....10.128.0.2][30307] [Unknown][Unknown][Unrated] - idle: [....28] [ip4][..tcp] [.......10.0.0.2][27502] -> [.....10.128.0.2][30307] + idle: [....28] [ip4][..tcp] [.......10.0.0.2][27502] -> [.....10.128.0.2][30307] not-detected: [.....6] [ip4][..tcp] [.......10.0.0.2][24101] -> [.....10.128.0.2][.9251] [Unknown][Unknown][Unrated] - end: [.....6] [ip4][..tcp] [.......10.0.0.2][24101] -> [.....10.128.0.2][.9251] + end: [.....6] [ip4][..tcp] [.......10.0.0.2][24101] -> [.....10.128.0.2][.9251] not-detected: [.....3] [ip4][..tcp] [.......10.0.0.2][.9253] -> [.....10.128.0.2][24102] [Unknown][Unknown][Unrated] - end: [.....3] [ip4][..tcp] [.......10.0.0.2][.9253] -> [.....10.128.0.2][24102] + end: [.....3] [ip4][..tcp] [.......10.0.0.2][.9253] -> [.....10.128.0.2][24102] not-detected: [....26] [ip4][..tcp] [.......10.0.0.2][.9251] -> [.....10.128.0.2][.9770] [Unknown][Unknown][Unrated] - idle: [....26] [ip4][..tcp] [.......10.0.0.2][.9251] -> [.....10.128.0.2][.9770] + idle: [....26] [ip4][..tcp] [.......10.0.0.2][.9251] -> [.....10.128.0.2][.9770] not-detected: [....25] [ip4][..tcp] [.......10.0.0.2][29799] -> [.....10.128.0.2][26228] [Unknown][Unknown][Unrated] - idle: [....25] [ip4][..tcp] [.......10.0.0.2][29799] -> [.....10.128.0.2][26228] + idle: [....25] [ip4][..tcp] [.......10.0.0.2][29799] -> [.....10.128.0.2][26228] not-detected: [.....5] [ip4][..tcp] [.......10.0.0.2][21029] -> [.....10.128.0.2][22878] [Unknown][Unknown][Unrated] - idle: [.....5] [ip4][..tcp] [.......10.0.0.2][21029] -> [.....10.128.0.2][22878] + idle: [.....5] [ip4][..tcp] [.......10.0.0.2][21029] -> [.....10.128.0.2][22878] not-detected: [....29] [ip4][..tcp] [.......10.0.0.2][10792] -> [.....10.128.0.2][10790] [Unknown][Unknown][Unrated] - idle: [....29] [ip4][..tcp] [.......10.0.0.2][10792] -> [.....10.128.0.2][10790] + idle: [....29] [ip4][..tcp] [.......10.0.0.2][10792] -> [.....10.128.0.2][10790] not-detected: [....15] [ip4][..tcp] [.......10.0.0.2][.2612] -> [.....10.128.0.2][12849] [Unknown][Unknown][Unrated] - end: [....15] [ip4][..tcp] [.......10.0.0.2][.2612] -> [.....10.128.0.2][12849] + end: [....15] [ip4][..tcp] [.......10.0.0.2][.2612] -> [.....10.128.0.2][12849] not-detected: [....12] [ip4][..tcp] [.......10.0.0.2][13105] -> [.....10.128.0.2][14648] [Unknown][Unknown][Unrated] - end: [....12] [ip4][..tcp] [.......10.0.0.2][13105] -> [.....10.128.0.2][14648] + end: [....12] [ip4][..tcp] [.......10.0.0.2][13105] -> [.....10.128.0.2][14648] not-detected: [....21] [ip4][..tcp] [.......10.0.0.2][13362] -> [.....10.128.0.2][12596] [Unknown][Unknown][Unrated] - end: [....21] [ip4][..tcp] [.......10.0.0.2][13362] -> [.....10.128.0.2][12596] + end: [....21] [ip4][..tcp] [.......10.0.0.2][13362] -> [.....10.128.0.2][12596] not-detected: [....17] [ip4][..tcp] [.......10.0.0.2][19273] -> [.....10.128.0.2][19016] [Unknown][Unknown][Unrated] - idle: [....17] [ip4][..tcp] [.......10.0.0.2][19273] -> [.....10.128.0.2][19016] + idle: [....17] [ip4][..tcp] [.......10.0.0.2][19273] -> [.....10.128.0.2][19016] not-detected: [....18] [ip4][..tcp] [.......10.0.0.2][.9566] -> [.....10.128.0.2][18498] [Unknown][Unknown][Unrated] - end: [....18] [ip4][..tcp] [.......10.0.0.2][.9566] -> [.....10.128.0.2][18498] + end: [....18] [ip4][..tcp] [.......10.0.0.2][.9566] -> [.....10.128.0.2][18498] not-detected: [....19] [ip4][..tcp] [.......10.0.0.2][11892] -> [.....10.128.0.2][26470] [Unknown][Unknown][Unrated] - end: [....19] [ip4][..tcp] [.......10.0.0.2][11892] -> [.....10.128.0.2][26470] + end: [....19] [ip4][..tcp] [.......10.0.0.2][11892] -> [.....10.128.0.2][26470] not-detected: [....14] [ip4][..tcp] [.......10.0.0.2][17458] -> [.....10.128.0.2][10790] [Unknown][Unknown][Unrated] - end: [....14] [ip4][..tcp] [.......10.0.0.2][17458] -> [.....10.128.0.2][10790] + end: [....14] [ip4][..tcp] [.......10.0.0.2][17458] -> [.....10.128.0.2][10790] not-detected: [.....9] [ip4][..tcp] [.......10.0.0.2][13617] -> [.....10.128.0.2][10536] [Unknown][Unknown][Unrated] - end: [.....9] [ip4][..tcp] [.......10.0.0.2][13617] -> [.....10.128.0.2][10536] + end: [.....9] [ip4][..tcp] [.......10.0.0.2][13617] -> [.....10.128.0.2][10536] not-detected: [....22] [ip4][..tcp] [.......10.0.0.2][18258] -> [.....10.128.0.2][16199] [Unknown][Unknown][Unrated] - end: [....22] [ip4][..tcp] [.......10.0.0.2][18258] -> [.....10.128.0.2][16199] + end: [....22] [ip4][..tcp] [.......10.0.0.2][18258] -> [.....10.128.0.2][16199] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/iphone.pcap.out b/test/results/flow-info/default/iphone.pcap.out index c88cebf65..aa0846c88 100644 --- a/test/results/flow-info/default/iphone.pcap.out +++ b/test/results/flow-info/default/iphone.pcap.out @@ -1,63 +1,63 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [.....1] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [.....1] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....2] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....2] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....2] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [.....3] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] + new: [.....3] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] detected: [.....3] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas imac._odisk._tcp.local] - new: [.....4] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] + new: [.....4] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] detected: [.....4] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][lucas imac._odisk._tcp.local] - new: [.....5] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] + new: [.....5] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] detected: [.....5] [ip4][..udp] [169.254.225.216][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas imac._odisk._tcp.local] - new: [.....6] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....6] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....6] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....7] [ip4][..udp] [....192.168.2.1][.5351] -> [......224.0.0.1][.5350] - new: [.....8] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] + new: [.....7] [ip4][..udp] [....192.168.2.1][.5351] -> [......224.0.0.1][.5350] + new: [.....8] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] detected: [.....8] [ip4][..udp] [169.254.225.216][60538] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....9] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] + new: [.....9] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] detected: [.....9] [ip4][..udp] [....192.168.2.1][51411] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....10] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.17][...68] + new: [....10] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.17][...68] detected: [....10] [ip4][..udp] [....192.168.2.1][...67] -> [...192.168.2.17][...68] [DHCP][Unknown][Network][Acceptable][] - new: [....11] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff98:a29c] + new: [....11] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff98:a29c] detected: [....11] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff98:a29c] [ICMPV6][Unknown][Network][Acceptable] - new: [....12] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [................................ff02::2] + new: [....12] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [................................ff02::2] detected: [....12] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [....13] [ip6][..udp] [...............fe80::823:3f17:8298:a29c][.5353] -> [...............................ff02::fb][.5353] + new: [....13] [ip6][..udp] [...............fe80::823:3f17:8298:a29c][.5353] -> [...............................ff02::fb][.5353] detected: [....13] [ip6][..udp] [...............fe80::823:3f17:8298:a29c][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....14] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [...............................ff02::16] + new: [....14] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [...............................ff02::16] detected: [....14] [ip6][icmp6] [...............fe80::823:3f17:8298:a29c] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....15] [ip4][..udp] [...192.168.2.17][63381] -> [....192.168.2.1][...53] + new: [....15] [ip4][..udp] [...192.168.2.17][63381] -> [....192.168.2.1][...53] detected: [....15] [ip4][..udp] [...192.168.2.17][63381] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p26-keyvalueservice.icloud.com] - new: [....16] [ip4][..udp] [...192.168.2.17][63143] -> [....192.168.2.1][...53] + new: [....16] [ip4][..udp] [...192.168.2.17][63143] -> [....192.168.2.1][...53] detected: [....16] [ip4][..udp] [...192.168.2.17][63143] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p26-fmfmobile.icloud.com] - new: [....17] [ip4][..udp] [...192.168.2.17][61862] -> [....192.168.2.1][...53] + new: [....17] [ip4][..udp] [...192.168.2.17][61862] -> [....192.168.2.1][...53] detected: [....17] [ip4][..udp] [...192.168.2.17][61862] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gspe35-ssl.ls.apple.com] - new: [....18] [ip4][..udp] [...192.168.2.17][55914] -> [....192.168.2.1][...53] + new: [....18] [ip4][..udp] [...192.168.2.17][55914] -> [....192.168.2.1][...53] detected: [....18] [ip4][..udp] [...192.168.2.17][55914] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsp85-ssl.ls.apple.com] - new: [....19] [ip4][..udp] [...192.168.2.17][51007] -> [....192.168.2.1][...53] + new: [....19] [ip4][..udp] [...192.168.2.17][51007] -> [....192.168.2.1][...53] detected: [....19] [ip4][..udp] [...192.168.2.17][51007] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com] detection-update: [....16] [ip4][..udp] [...192.168.2.17][63143] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p26-fmfmobile.icloud.com] detection-update: [....15] [ip4][..udp] [...192.168.2.17][63381] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p26-keyvalueservice.icloud.com] detection-update: [....17] [ip4][..udp] [...192.168.2.17][61862] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gspe35-ssl.ls.apple.com] detection-update: [....18] [ip4][..udp] [...192.168.2.17][55914] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsp85-ssl.ls.apple.com] - new: [....20] [ip4][..tcp] [...192.168.2.17][50575] -> [.17.248.185.140][..443] + new: [....20] [ip4][..tcp] [...192.168.2.17][50575] -> [.17.248.185.140][..443] detection-update: [....19] [ip4][..udp] [...192.168.2.17][51007] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com] - new: [....21] [ip4][..udp] [...192.168.2.17][55457] -> [....192.168.2.1][...53] + new: [....21] [ip4][..udp] [...192.168.2.17][55457] -> [....192.168.2.1][...53] detected: [....21] [ip4][..udp] [...192.168.2.17][55457] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][mesu.apple.com] - new: [....22] [ip4][..udp] [...192.168.2.17][.5353] -> [....224.0.0.251][.5353] + new: [....22] [ip4][..udp] [...192.168.2.17][.5353] -> [....224.0.0.251][.5353] detected: [....22] [ip4][..udp] [...192.168.2.17][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....23] [ip4][..tcp] [...192.168.2.17][50576] -> [...95.101.25.53][..443] - new: [....24] [ip4][..tcp] [...192.168.2.17][50577] -> [....17.130.2.46][..443] - new: [....25] [ip4][..tcp] [...192.168.2.17][49152] -> [.17.253.105.202][...80] + new: [....23] [ip4][..tcp] [...192.168.2.17][50576] -> [...95.101.25.53][..443] + new: [....24] [ip4][..tcp] [...192.168.2.17][50577] -> [....17.130.2.46][..443] + new: [....25] [ip4][..tcp] [...192.168.2.17][49152] -> [.17.253.105.202][...80] detected: [....20] [ip4][..tcp] [...192.168.2.17][50575] -> [.17.248.185.140][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-fmfmobile.icloud.com] detection-update: [....21] [ip4][..udp] [...192.168.2.17][55457] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][mesu.apple.com] detected: [....23] [ip4][..tcp] [...192.168.2.17][50576] -> [...95.101.25.53][..443] [TLS.Apple][Unknown][Web][Safe][gspe35-ssl.ls.apple.com] - new: [....26] [ip4][..tcp] [...192.168.2.17][50578] -> [.17.253.105.202][..443] - new: [....27] [ip4][..tcp] [...192.168.2.17][50579] -> [.17.253.105.202][..443] + new: [....26] [ip4][..tcp] [...192.168.2.17][50578] -> [.17.253.105.202][..443] + new: [....27] [ip4][..tcp] [...192.168.2.17][50579] -> [.17.253.105.202][..443] detection-update: [....23] [ip4][..tcp] [...192.168.2.17][50576] -> [...95.101.25.53][..443] [TLS.Apple][Unknown][Web][Safe][gspe35-ssl.ls.apple.com] - new: [....28] [ip4][..udp] [...192.168.2.17][52852] -> [....192.168.2.1][...53] + new: [....28] [ip4][..udp] [...192.168.2.17][52852] -> [....192.168.2.1][...53] detected: [....28] [ip4][..udp] [...192.168.2.17][52852] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][gateway.icloud.com] detected: [....25] [ip4][..tcp] [...192.168.2.17][49152] -> [.17.253.105.202][...80] [HTTP.Apple][Apple][ConnCheck][Safe][captive.apple.com] detected: [....24] [ip4][..tcp] [...192.168.2.17][50577] -> [....17.130.2.46][..443] [TLS.Apple][Apple][Web][Safe][gsp85-ssl.ls.apple.com] @@ -67,27 +67,27 @@ detection-update: [....20] [ip4][..tcp] [...192.168.2.17][50575] -> [.17.248.185.140][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-fmfmobile.icloud.com] detection-update: [....28] [ip4][..udp] [...192.168.2.17][52852] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][gateway.icloud.com] detection-update: [....27] [ip4][..tcp] [...192.168.2.17][50579] -> [.17.253.105.202][..443] [TLS.Apple][Apple][Web][Safe][mesu.apple.com] - new: [....29] [ip4][..tcp] [...192.168.2.17][50580] -> [..17.248.176.75][..443] + new: [....29] [ip4][..tcp] [...192.168.2.17][50580] -> [..17.248.176.75][..443] detection-update: [....26] [ip4][..tcp] [...192.168.2.17][50578] -> [.17.253.105.202][..443] [TLS.Apple][Apple][Web][Safe][mesu.apple.com] detection-update: [....24] [ip4][..tcp] [...192.168.2.17][50577] -> [....17.130.2.46][..443] [TLS.Apple][Apple][Web][Safe][gsp85-ssl.ls.apple.com] detection-update: [....24] [ip4][..tcp] [...192.168.2.17][50577] -> [....17.130.2.46][..443] [TLS.Apple][Apple][Web][Safe][gsp85-ssl.ls.apple.com] - new: [....30] [ip4][..udp] [...192.168.2.17][52682] -> [....192.168.2.1][...53] + new: [....30] [ip4][..udp] [...192.168.2.17][52682] -> [....192.168.2.1][...53] detected: [....30] [ip4][..udp] [...192.168.2.17][52682] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][www.icloud.com] - new: [....31] [ip4][..udp] [...192.168.2.17][64203] -> [....192.168.2.1][...53] + new: [....31] [ip4][..udp] [...192.168.2.17][64203] -> [....192.168.2.1][...53] detected: [....31] [ip4][..udp] [...192.168.2.17][64203] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][basejumper.apple.com] - new: [....32] [ip4][..udp] [...192.168.2.17][53317] -> [....192.168.2.1][...53] + new: [....32] [ip4][..udp] [...192.168.2.17][53317] -> [....192.168.2.1][...53] detected: [....32] [ip4][..udp] [...192.168.2.17][53317] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][iphone-ld.apple.com] - new: [....33] [ip4][..udp] [...192.168.2.17][62526] -> [....192.168.2.1][...53] + new: [....33] [ip4][..udp] [...192.168.2.17][62526] -> [....192.168.2.1][...53] detected: [....33] [ip4][..udp] [...192.168.2.17][62526] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][cl4.apple.com] - new: [....34] [ip4][..udp] [...192.168.2.17][63377] -> [....192.168.2.1][...53] + new: [....34] [ip4][..udp] [...192.168.2.17][63377] -> [....192.168.2.1][...53] detected: [....34] [ip4][..udp] [...192.168.2.17][63377] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][bag.itunes.apple.com] - new: [....35] [ip4][..udp] [...192.168.2.17][53272] -> [....192.168.2.1][...53] + new: [....35] [ip4][..udp] [...192.168.2.17][53272] -> [....192.168.2.1][...53] detected: [....35] [ip4][..udp] [...192.168.2.17][53272] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][play.itunes.apple.com] - new: [....36] [ip4][..udp] [...192.168.2.17][53983] -> [....192.168.2.1][...53] + new: [....36] [ip4][..udp] [...192.168.2.17][53983] -> [....192.168.2.1][...53] detected: [....36] [ip4][..udp] [...192.168.2.17][53983] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][bag.itunes.apple.com] - new: [....37] [ip4][..udp] [...192.168.2.17][49880] -> [....192.168.2.1][...53] + new: [....37] [ip4][..udp] [...192.168.2.17][49880] -> [....192.168.2.1][...53] detected: [....37] [ip4][..udp] [...192.168.2.17][49880] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][init.itunes.apple.com] - new: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] + new: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] detected: [....29] [ip4][..tcp] [...192.168.2.17][50580] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] detection-update: [....30] [ip4][..udp] [...192.168.2.17][52682] -> [....192.168.2.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][www.icloud.com] detection-update: [....32] [ip4][..udp] [...192.168.2.17][53317] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][iphone-ld.apple.com] @@ -98,11 +98,11 @@ detection-update: [....37] [ip4][..udp] [...192.168.2.17][49880] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][init.itunes.apple.com] detection-update: [....35] [ip4][..udp] [...192.168.2.17][53272] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][play.itunes.apple.com] detection-update: [....33] [ip4][..udp] [...192.168.2.17][62526] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][cl4.apple.com] - new: [....39] [ip4][..tcp] [...192.168.2.17][50582] -> [..92.122.252.82][..443] + new: [....39] [ip4][..tcp] [...192.168.2.17][50582] -> [..92.122.252.82][..443] detection-update: [....29] [ip4][..tcp] [...192.168.2.17][50580] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] - new: [....40] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] + new: [....40] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] detected: [....40] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] [ICMP][Unknown][Network][Acceptable] - new: [....41] [ip4][..tcp] [...192.168.2.17][50583] -> [...104.73.61.30][..443] + new: [....41] [ip4][..tcp] [...192.168.2.17][50583] -> [...104.73.61.30][..443] detected: [....39] [ip4][..tcp] [...192.168.2.17][50582] -> [..92.122.252.82][..443] [TLS.Apple][Unknown][Web][Safe][iphone-ld.apple.com] detected: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-keyvalueservice.icloud.com] detection-update: [....39] [ip4][..tcp] [...192.168.2.17][50582] -> [..92.122.252.82][..443] [TLS.Apple][Unknown][Web][Safe][iphone-ld.apple.com] @@ -110,27 +110,27 @@ detection-update: [....41] [ip4][..tcp] [...192.168.2.17][50583] -> [...104.73.61.30][..443] [TLS.Apple][Unknown][Web][Safe][cl4.apple.com] detection-update: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-keyvalueservice.icloud.com] detection-update: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-keyvalueservice.icloud.com] - new: [....42] [ip4][....2] [...192.168.2.17] -> [.....224.0.0.22] + new: [....42] [ip4][....2] [...192.168.2.17] -> [.....224.0.0.22] detected: [....42] [ip4][....2] [...192.168.2.17] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [....43] [ip4][..udp] [...192.168.2.17][62160] -> [....192.168.2.1][...53] + new: [....43] [ip4][..udp] [...192.168.2.17][62160] -> [....192.168.2.1][...53] detected: [....43] [ip4][..udp] [...192.168.2.17][62160] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsa.apple.com] - new: [....44] [ip4][..udp] [...192.168.2.17][52031] -> [....192.168.2.1][...53] + new: [....44] [ip4][..udp] [...192.168.2.17][52031] -> [....192.168.2.1][...53] detected: [....44] [ip4][..udp] [...192.168.2.17][52031] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsa.apple.com] detection-update: [....43] [ip4][..udp] [...192.168.2.17][62160] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsa.apple.com] detection-update: [....44] [ip4][..udp] [...192.168.2.17][52031] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][gsa.apple.com] - new: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] + new: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] detected: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] detection-update: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] detection-update: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] - new: [....46] [ip4][..tcp] [...192.168.2.17][50585] -> [..17.137.166.35][..443] + new: [....46] [ip4][..tcp] [...192.168.2.17][50585] -> [..17.137.166.35][..443] detected: [....46] [ip4][..tcp] [...192.168.2.17][50585] -> [..17.137.166.35][..443] [TLS.Apple][Apple][Web][Safe][gsa.apple.com] - new: [....47] [ip4][..tcp] [...192.168.2.17][50586] -> [..17.248.176.75][..443] + new: [....47] [ip4][..tcp] [...192.168.2.17][50586] -> [..17.248.176.75][..443] detected: [....47] [ip4][..tcp] [...192.168.2.17][50586] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] detection-update: [....46] [ip4][..tcp] [...192.168.2.17][50585] -> [..17.137.166.35][..443] [TLS.Apple][Apple][Web][Safe][gsa.apple.com] detection-update: [....46] [ip4][..tcp] [...192.168.2.17][50585] -> [..17.137.166.35][..443] [TLS.Apple][Apple][Web][Safe][gsa.apple.com] detection-update: [....47] [ip4][..tcp] [...192.168.2.17][50586] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] detection-update: [....47] [ip4][..tcp] [...192.168.2.17][50586] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][gateway.icloud.com] - new: [....48] [ip4][..udp] [...192.168.2.17][65079] -> [....192.168.2.1][...53] + new: [....48] [ip4][..udp] [...192.168.2.17][65079] -> [....192.168.2.1][...53] detected: [....48] [ip4][..udp] [...192.168.2.17][65079] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][play.itunes.apple.com] detection-update: [....48] [ip4][..udp] [...192.168.2.17][65079] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][play.itunes.apple.com] analyse: [....29] [ip4][..tcp] [...192.168.2.17][50580] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] @@ -143,7 +143,7 @@ [IATS(ms)....: 34.0,135.8,0.2,135.5,2.1,0.2,8.7,0.0,162.5,0.9,167.4,319.4,0.0,34.7,0.1,651.1,0.6,0.0,0.1,0.1,0.0,0.1,0.2,686.2,0.0,1.2,0.0,33.7,32.5,122.6,156.5] [PKTLENS.....: 64,60,52,569,52,1492,1492,1492,566,52,52,145,103,121,52,52,105,102,94,1076,424,90,186,424,52,90,52,52,52,52,623,52] [ENTROPIES...: 4.4,5.0,5.0,4.5,4.9,6.7,7.5,7.5,7.3,4.9,4.9,6.0,5.5,6.0,5.0,4.9,5.7,5.6,5.5,7.8,7.4,5.3,6.6,7.4,4.9,5.4,5.0,5.0,4.9,5.1,7.7,5.0] - new: [....49] [ip4][..tcp] [...192.168.2.17][50587] -> [...92.123.77.26][..443] + new: [....49] [ip4][..tcp] [...192.168.2.17][50587] -> [...92.123.77.26][..443] detected: [....49] [ip4][..tcp] [...192.168.2.17][50587] -> [...92.123.77.26][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][play.itunes.apple.com] detection-update: [....49] [ip4][..tcp] [...192.168.2.17][50587] -> [...92.123.77.26][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][play.itunes.apple.com] analyse: [....45] [ip4][..tcp] [...192.168.2.17][50584] -> [..17.248.176.75][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] @@ -177,10 +177,10 @@ [PKTLENS.....: 64,60,52,569,52,1492,1492,1492,1492,1474,52,52,52,52,145,103,52,1169,344,52,996,52,1164,1492,1492,1492,52,52,1492,1492,1492,1492] [ENTROPIES...: 4.4,5.0,4.9,4.7,5.0,6.2,4.6,7.1,7.5,7.5,4.9,4.9,4.9,4.8,6.0,5.6,5.0,7.8,7.2,5.1,7.8,4.9,7.8,7.9,7.9,7.9,5.0,5.0,7.9,7.9,7.9,7.8] detection-update: [....38] [ip4][..tcp] [...192.168.2.17][50581] -> [..17.248.185.87][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p26-keyvalueservice.icloud.com] - new: [....50] [ip4][..udp] [...192.168.2.17][63677] -> [....192.168.2.1][...53] + new: [....50] [ip4][..udp] [...192.168.2.17][63677] -> [....192.168.2.1][...53] detected: [....50] [ip4][..udp] [...192.168.2.17][63677] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][sync.itunes.apple.com] detection-update: [....50] [ip4][..udp] [...192.168.2.17][63677] -> [....192.168.2.1][...53] [DNS.AppleiTunes][Unknown][Network][Fun][sync.itunes.apple.com] - new: [....51] [ip4][..tcp] [...192.168.2.17][50588] -> [...95.101.24.53][..443] + new: [....51] [ip4][..tcp] [...192.168.2.17][50588] -> [...95.101.24.53][..443] detected: [....51] [ip4][..tcp] [...192.168.2.17][50588] -> [...95.101.24.53][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][sync.itunes.apple.com] detection-update: [....51] [ip4][..tcp] [...192.168.2.17][50588] -> [...95.101.24.53][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][sync.itunes.apple.com] idle: [....20] [ip4][..tcp] [...192.168.2.17][50575] -> [.17.248.185.140][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] @@ -215,7 +215,7 @@ idle: [....17] [ip4][..udp] [...192.168.2.17][61862] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe] idle: [....49] [ip4][..tcp] [...192.168.2.17][50587] -> [...92.123.77.26][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun] guessed: [.....7] [ip4][..udp] [....192.168.2.1][.5351] -> [......224.0.0.1][.5350] [NAT-PMP][Unknown][Network][Acceptable] - idle: [.....7] [ip4][..udp] [....192.168.2.1][.5351] -> [......224.0.0.1][.5350] + idle: [.....7] [ip4][..udp] [....192.168.2.1][.5351] -> [......224.0.0.1][.5350] idle: [....22] [ip4][..udp] [...192.168.2.17][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] idle: [.....3] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] idle: [.....6] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] diff --git a/test/results/flow-info/default/ipp.pcap.out b/test/results/flow-info/default/ipp.pcap.out index e79503ea1..732bb0ae5 100644 --- a/test/results/flow-info/default/ipp.pcap.out +++ b/test/results/flow-info/default/ipp.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....10.10.10.49][55341] -> [...10.10.10.251][..631] + new: [.....1] [ip4][..tcp] [....10.10.10.49][55341] -> [...10.10.10.251][..631] detected: [.....1] [ip4][..tcp] [....10.10.10.49][55341] -> [...10.10.10.251][..631] [HTTP.IPP][Unknown][System][Acceptable][10.10.10.251] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [.....2] [ip4][..tcp] [....10.10.10.49][55342] -> [...10.10.10.251][..631] + new: [.....2] [ip4][..tcp] [....10.10.10.49][55342] -> [...10.10.10.251][..631] detected: [.....2] [ip4][..tcp] [....10.10.10.49][55342] -> [...10.10.10.251][..631] [HTTP.IPP][Unknown][System][Acceptable][10.10.10.251] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI analyse: [.....2] [ip4][..tcp] [....10.10.10.49][55342] -> [...10.10.10.251][..631] [HTTP.IPP][Unknown][System][Acceptable] @@ -17,7 +17,7 @@ [IATS(ms)....: 0.7,0.7,0.1,0.0,3.6,1.6,5.1,0.1,0.0,5.8,5.7,0.0,3.7,3.6,0.0,7.3,7.3,0.0,8.8,8.8,0.0,9.1,9.1,0.0,7.2,7.2,0.0,7.6,7.6,0.0,7.2] [PKTLENS.....: 60,60,52,196,200,52,77,52,2948,1500,52,2948,1572,52,1428,1596,52,1404,1620,52,1380,1644,52,1356,1668,52,1332,1692,52,1308,1716,52] [ENTROPIES...: 4.4,4.7,4.6,5.5,5.4,4.7,5.2,4.6,4.1,4.0,4.7,3.7,3.5,4.7,3.5,3.5,4.6,4.1,4.5,4.7,4.3,4.2,4.7,4.2,4.7,4.7,4.7,4.3,4.7,4.2,4.1,4.6] - new: [.....3] [ip4][..tcp] [....10.10.10.49][55343] -> [...10.10.10.251][..631] + new: [.....3] [ip4][..tcp] [....10.10.10.49][55343] -> [...10.10.10.251][..631] detected: [.....3] [ip4][..tcp] [....10.10.10.49][55343] -> [...10.10.10.251][..631] [HTTP.IPP][Unknown][System][Acceptable][10.10.10.251] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI end: [.....1] [ip4][..tcp] [....10.10.10.49][55341] -> [...10.10.10.251][..631] [HTTP.IPP][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out b/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out index 840e90e5f..eae372270 100644 --- a/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out +++ b/test/results/flow-info/default/ipsec_isakmp_esp.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] + new: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] detected: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] + new: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] detected: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] update: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] @@ -27,7 +27,7 @@ DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] idle: [.....2] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] + new: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] detected: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] update: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] @@ -35,12 +35,12 @@ DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] idle: [.....1] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - new: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] + new: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] detected: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] update: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - new: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] + new: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] detected: [.....5] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] + new: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] detected: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] idle: [.....3] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] update: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] @@ -51,9 +51,9 @@ update: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] DAEMON-EVENT: [Processed: 145 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] + new: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] detected: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - new: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] + new: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] detected: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] idle: [.....4] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] idle: [.....6] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] @@ -65,17 +65,17 @@ update: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] DAEMON-EVENT: [Processed: 187 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 18] - new: [.....9] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] + new: [.....9] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] detected: [.....9] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] [IPSec][Unknown][VPN][Safe] - new: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] + new: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] detected: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet idle: [.....8] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] idle: [.....7] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - new: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] + new: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] detected: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet - new: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] + new: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] detected: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] idle: [....10] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet @@ -87,36 +87,36 @@ RISK: Malformed Packet DAEMON-EVENT: [Processed: 244 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] + new: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] detected: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] + new: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] detected: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] idle: [....12] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] idle: [....11] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] RISK: Malformed Packet DAEMON-EVENT: [Processed: 267 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 14|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [....15] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.129][..500] + new: [....15] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.129][..500] detected: [....15] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.129][..500] [IPSec][Unknown][VPN][Safe] - new: [....16] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.129][.4500] + new: [....16] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.129][.4500] detected: [....16] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.129][.4500] [IPSec][Unknown][VPN][Safe] idle: [....13] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] idle: [....14] [ip4][..udp] [..192.168.2.100][43811] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - new: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] + new: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] detected: [....17] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.225][..500] [IPSec][Unknown][VPN][Safe] - new: [....18] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] + new: [....18] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] detected: [....18] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.225][.4500] [IPSec][Unknown][VPN][Safe] - new: [....19] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] + new: [....19] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] detected: [....19] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.131][..500] [IPSec][Unknown][VPN][Safe] - new: [....20] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] + new: [....20] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] detected: [....20] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.131][.4500] [IPSec][Unknown][VPN][Safe] - new: [....21] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] + new: [....21] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] detected: [....21] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - new: [....22] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] + new: [....22] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] detected: [....22] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [....23] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.227][..500] + new: [....23] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.227][..500] detected: [....23] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.227][..500] [IPSec][Unknown][VPN][Safe] - new: [....24] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.227][.4500] + new: [....24] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.227][.4500] detected: [....24] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.227][.4500] [IPSec][Unknown][VPN][Safe] analyse: [....24] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.227][.4500] [IPSec][Unknown][VPN][Safe] min| max| avg| stddev| variance| entropy @@ -138,13 +138,13 @@ [IATS(ms)....: 0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316,804,80,828,316] [ENTROPIES...: 4.9,4.6,5.0,6.6,5.0,4.6,5.0,6.6,4.9,4.6,5.0,6.4,4.9,4.6,5.0,6.6,4.9,4.6,5.0,6.5,4.9,4.6,5.0,6.6,4.9,4.7,5.0,6.6,4.9,4.6,5.0,6.5] - new: [....25] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.226][..500] + new: [....25] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.226][..500] detected: [....25] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.226][..500] [IPSec][Unknown][VPN][Safe] - new: [....26] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.226][.4500] + new: [....26] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.226][.4500] detected: [....26] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.226][.4500] [IPSec][Unknown][VPN][Safe] - new: [....27] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.130][..500] + new: [....27] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.130][..500] detected: [....27] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.130][..500] [IPSec][Unknown][VPN][Safe] - new: [....28] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.130][.4500] + new: [....28] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.130][.4500] detected: [....28] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.130][.4500] [IPSec][Unknown][VPN][Safe] analyse: [....28] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.130][.4500] [IPSec][Unknown][VPN][Safe] min| max| avg| stddev| variance| entropy @@ -156,21 +156,21 @@ [IATS(ms)....: 0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236,140,108,124,444,1360,1056,160,160,1056,160,1360,1360,1312,844,236] [ENTROPIES...: 7.7,6.8,6.3,5.8,6.0,7.4,7.9,7.8,6.6,6.6,7.8,6.6,7.8,7.9,7.9,7.8,6.8,6.3,5.9,6.1,7.4,7.9,7.8,6.6,6.7,7.8,6.7,7.9,7.8,7.8,7.7,6.9] - new: [....29] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][.4500] + new: [....29] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][.4500] detected: [....29] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][.4500] [IPSec][Unknown][VPN][Safe] - new: [....30] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][..500] + new: [....30] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][..500] detected: [....30] [ip4][..udp] [..192.168.2.100][42593] -> [109.237.187.193][..500] [IPSec][Unknown][VPN][Safe] - new: [....31] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] + new: [....31] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] detected: [....31] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - new: [....32] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] + new: [....32] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] detected: [....32] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - new: [....33] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][.4500] + new: [....33] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][.4500] detected: [....33] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][.4500] [IPSec][Unknown][VPN][Safe] - new: [....34] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] + new: [....34] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] detected: [....34] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] - new: [....35] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][..500] + new: [....35] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][..500] detected: [....35] [ip4][..udp] [..192.168.2.100][41618] -> [109.237.187.194][..500] [IPSec][Unknown][VPN][Safe] - new: [....36] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] + new: [....36] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] detected: [....36] [ip4][..udp] [..192.168.2.100][10500] -> [109.237.187.195][..500] [IPSec][Unknown][VPN][Safe] analyse: [....34] [ip4][..udp] [..192.168.2.100][14500] -> [109.237.187.195][.4500] [IPSec][Unknown][VPN][Safe] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/irc.pcap.out b/test/results/flow-info/default/irc.pcap.out index f25c6f99d..6fa4f9241 100644 --- a/test/results/flow-info/default/irc.pcap.out +++ b/test/results/flow-info/default/irc.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.10.180.156.249][45921] -> [...38.229.70.20][.8000] + new: [.....1] [ip4][..tcp] [.10.180.156.249][45921] -> [...38.229.70.20][.8000] detected: [.....1] [ip4][..tcp] [.10.180.156.249][45921] -> [...38.229.70.20][.8000] [IRC][Unknown][Chat][Unsafe] RISK: Known Proto on Non Std Port, Unsafe Protocol, Clear-Text Credentials idle: [.....1] [ip4][..tcp] [.10.180.156.249][45921] -> [...38.229.70.20][.8000] [IRC][Unknown][Chat][Unsafe] diff --git a/test/results/flow-info/default/ja3_lots_of_cipher_suites_2_anon.pcap.out b/test/results/flow-info/default/ja3_lots_of_cipher_suites_2_anon.pcap.out index 0fbd67a55..d9c6ea4f1 100644 --- a/test/results/flow-info/default/ja3_lots_of_cipher_suites_2_anon.pcap.out +++ b/test/results/flow-info/default/ja3_lots_of_cipher_suites_2_anon.pcap.out @@ -2,7 +2,7 @@ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] ERROR-EVENT: Captured packet size is smaller than expected packet size [1/16] - new: [.....1] [ip4][..udp] [.132.190.244.12][.2152] -> [.151.121.185.44][.2152] + new: [.....1] [ip4][..udp] [.132.190.244.12][.2152] -> [.151.121.185.44][.2152] detected: [.....1] [ip4][..udp] [.132.190.244.12][.2152] -> [.151.121.185.44][.2152] [GTP.GTP_U][Unknown][Network][Acceptable] ERROR-EVENT: Captured packet size is smaller than expected packet size [2/16] ERROR-EVENT: Captured packet size is smaller than expected packet size [3/16] diff --git a/test/results/flow-info/default/jabber.pcap.out b/test/results/flow-info/default/jabber.pcap.out index 2b5cfdc2f..3fd29400b 100644 --- a/test/results/flow-info/default/jabber.pcap.out +++ b/test/results/flow-info/default/jabber.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....172.16.0.62][57094] -> [...172.16.1.138][.5222] + new: [.....1] [ip4][..tcp] [....172.16.0.62][57094] -> [...172.16.1.138][.5222] detected: [.....1] [ip4][..tcp] [....172.16.0.62][57094] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] analyse: [.....1] [ip4][..tcp] [....172.16.0.62][57094] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy @@ -13,7 +13,7 @@ [IATS(ms)....: 0.4,0.5,0.4,0.8,0.4,0.4,12.4,12.8,2.4,2.4,0.3,2.0,1.6,0.2,40.8,37.0,77.5,0.2,0.6,337.3,337.7,0.4,0.8,51.1,51.5,6.4,6.4,0.3,0.8,109.1,109.6] [PKTLENS.....: 64,60,52,74,52,168,52,231,52,337,52,214,212,52,390,52,172,52,104,52,103,52,168,52,231,52,431,52,175,52,184,52] [ENTROPIES...: 4.2,5.0,4.9,5.5,4.9,5.4,4.9,5.6,4.7,5.4,4.7,5.6,6.1,4.7,6.1,4.9,5.9,4.9,5.4,4.8,5.5,4.8,5.4,4.8,5.6,4.6,5.4,4.8,5.5,4.8,5.6,4.8] - new: [.....2] [ip4][..tcp] [....172.16.0.62][57122] -> [...172.16.1.138][.5222] + new: [.....2] [ip4][..tcp] [....172.16.0.62][57122] -> [...172.16.1.138][.5222] detected: [.....2] [ip4][..tcp] [....172.16.0.62][57122] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] analyse: [.....2] [ip4][..tcp] [....172.16.0.62][57122] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy @@ -25,16 +25,16 @@ [IATS(ms)....: 0.7,0.7,0.1,0.5,0.4,0.3,0.2,0.5,0.1,0.1,0.2,1.4,1.3,0.2,39.8,41.0,80.7,0.2,0.6,336.4,336.8,0.3,0.8,51.2,51.7,0.1,0.1,0.3,0.8,115.1,115.6] [PKTLENS.....: 64,60,52,74,52,168,52,229,52,337,52,214,212,52,390,52,172,52,104,52,103,52,168,52,231,52,431,52,175,52,184,52] [ENTROPIES...: 4.3,5.1,4.8,5.4,4.9,5.4,4.8,5.6,4.7,5.4,4.8,5.6,6.1,4.8,6.1,4.9,6.0,4.7,5.4,4.8,5.4,4.6,5.4,4.9,5.6,4.8,5.4,4.7,5.4,4.8,5.5,4.7] - new: [.....3] [ip4][..tcp] [....172.16.0.62][57126] -> [...172.16.1.138][.5222] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [....172.16.0.62][57126] -> [...172.16.1.138][.5222] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [....172.16.0.62][57126] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] - new: [.....4] [ip4][..tcp] [....172.16.0.62][57129] -> [...172.16.1.138][.5222] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....172.16.0.62][57129] -> [...172.16.1.138][.5222] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [....172.16.0.62][57129] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 189 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] end: [.....3] [ip4][..tcp] [....172.16.0.62][57126] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] - new: [.....5] [ip4][..tcp] [....172.16.0.62][57147] -> [...172.16.1.138][.5222] + new: [.....5] [ip4][..tcp] [....172.16.0.62][57147] -> [...172.16.1.138][.5222] detected: [.....5] [ip4][..tcp] [....172.16.0.62][57147] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] - new: [.....6] [ip4][..tcp] [....172.16.0.62][57149] -> [...172.16.1.138][.5222] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [....172.16.0.62][57149] -> [...172.16.1.138][.5222] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [....172.16.0.62][57149] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] end: [.....5] [ip4][..tcp] [....172.16.0.62][57147] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 243 pkts][ZLib][compressions: 0|diff: 0 / 0] @@ -51,7 +51,7 @@ [ENTROPIES...: 5.6,5.5,5.5,4.9,4.9,5.5,5.3,4.9,5.5,5.5,4.9,5.5,5.6,5.5,5.5,4.7,5.6,4.8,5.5,4.9,5.4,4.9,5.6,4.6,5.4,5.5,4.7,4.8,5.7,4.6,5.4,4.9] DAEMON-EVENT: [Processed: 270 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [...192.168.58.1][53460] -> [.192.168.58.153][.5222] + new: [.....7] [ip4][..tcp] [...192.168.58.1][53460] -> [.192.168.58.153][.5222] detected: [.....7] [ip4][..tcp] [...192.168.58.1][53460] -> [.192.168.58.153][.5222] [Jabber][Unknown][Web][Acceptable] idle: [.....1] [ip4][..tcp] [....172.16.0.62][57094] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] idle: [.....2] [ip4][..tcp] [....172.16.0.62][57122] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] @@ -59,27 +59,27 @@ idle: [.....6] [ip4][..tcp] [....172.16.0.62][57149] -> [...172.16.1.138][.5222] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 283 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..tcp] [..192.168.2.100][34218] -> [.160.44.201.102][.5223] + new: [.....8] [ip4][..tcp] [..192.168.2.100][34218] -> [.160.44.201.102][.5223] detected: [.....8] [ip4][..tcp] [..192.168.2.100][34218] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] end: [.....7] [ip4][..tcp] [...192.168.58.1][53460] -> [.192.168.58.153][.5222] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 298 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.2.100][37614] -> [.160.44.201.102][.5223] + new: [.....9] [ip4][..tcp] [..192.168.2.100][37614] -> [.160.44.201.102][.5223] detected: [.....9] [ip4][..tcp] [..192.168.2.100][37614] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] idle: [.....8] [ip4][..tcp] [..192.168.2.100][34218] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 313 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..tcp] [..192.168.2.100][58388] -> [.160.44.201.102][.5223] + new: [....10] [ip4][..tcp] [..192.168.2.100][58388] -> [.160.44.201.102][.5223] detected: [....10] [ip4][..tcp] [..192.168.2.100][58388] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] idle: [.....9] [ip4][..tcp] [..192.168.2.100][37614] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 328 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....11] [ip4][..tcp] [..192.168.2.100][41420] -> [.160.44.201.102][.5223] + new: [....11] [ip4][..tcp] [..192.168.2.100][41420] -> [.160.44.201.102][.5223] detected: [....11] [ip4][..tcp] [..192.168.2.100][41420] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] idle: [....10] [ip4][..tcp] [..192.168.2.100][58388] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 343 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....12] [ip4][..tcp] [..192.168.2.100][34070] -> [.160.44.201.102][.5223] + new: [....12] [ip4][..tcp] [..192.168.2.100][34070] -> [.160.44.201.102][.5223] detected: [....12] [ip4][..tcp] [..192.168.2.100][34070] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] idle: [....11] [ip4][..tcp] [..192.168.2.100][41420] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] idle: [....12] [ip4][..tcp] [..192.168.2.100][34070] -> [.160.44.201.102][.5223] [Jabber][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/kerberos-error.pcap.out b/test/results/flow-info/default/kerberos-error.pcap.out index 6a8aa1a74..6e874eb33 100644 --- a/test/results/flow-info/default/kerberos-error.pcap.out +++ b/test/results/flow-info/default/kerberos-error.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.148.151.79.183][34473] -> [.144.199.10.233][...88] + new: [.....1] [ip4][..udp] [.148.151.79.183][34473] -> [.144.199.10.233][...88] detected: [.....1] [ip4][..udp] [.148.151.79.183][34473] -> [.144.199.10.233][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [.148.151.79.183][34473] -> [.144.199.10.233][...88] [Kerberos][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/kerberos-login.pcap.out b/test/results/flow-info/default/kerberos-login.pcap.out index 774499db9..3678814f3 100644 --- a/test/results/flow-info/default/kerberos-login.pcap.out +++ b/test/results/flow-info/default/kerberos-login.pcap.out @@ -1,29 +1,29 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......10.1.12.2][.1061] -> [.......10.5.3.1][...88] + new: [.....1] [ip4][..udp] [......10.1.12.2][.1061] -> [.......10.5.3.1][...88] detected: [.....1] [ip4][..udp] [......10.1.12.2][.1061] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [......10.1.12.2][.1065] -> [.......10.5.3.1][...88] + new: [.....2] [ip4][..udp] [......10.1.12.2][.1065] -> [.......10.5.3.1][...88] detected: [.....2] [ip4][..udp] [......10.1.12.2][.1065] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [......10.1.12.2][.1067] -> [.......10.5.3.1][...88] + new: [.....3] [ip4][..udp] [......10.1.12.2][.1067] -> [.......10.5.3.1][...88] detected: [.....3] [ip4][..udp] [......10.1.12.2][.1067] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [......10.1.12.2][.1068] -> [.......10.5.3.1][...88] + new: [.....4] [ip4][..udp] [......10.1.12.2][.1068] -> [.......10.5.3.1][...88] detected: [.....4] [ip4][..udp] [......10.1.12.2][.1068] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [......10.1.12.2][.1069] -> [.......10.5.3.1][...88] + new: [.....5] [ip4][..udp] [......10.1.12.2][.1069] -> [.......10.5.3.1][...88] detected: [.....5] [ip4][..udp] [......10.1.12.2][.1069] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....6] [ip4][..udp] [......10.1.12.2][.1074] -> [.......10.5.3.1][...88] + new: [.....6] [ip4][..udp] [......10.1.12.2][.1074] -> [.......10.5.3.1][...88] detected: [.....6] [ip4][..udp] [......10.1.12.2][.1074] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....7] [ip4][..udp] [......10.1.12.2][.1076] -> [.......10.5.3.1][...88] + new: [.....7] [ip4][..udp] [......10.1.12.2][.1076] -> [.......10.5.3.1][...88] detected: [.....7] [ip4][..udp] [......10.1.12.2][.1076] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....8] [ip4][..udp] [......10.1.12.2][.1084] -> [.......10.5.3.1][...88] + new: [.....8] [ip4][..udp] [......10.1.12.2][.1084] -> [.......10.5.3.1][...88] detected: [.....8] [ip4][..udp] [......10.1.12.2][.1084] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [......10.1.12.2][.1089] -> [.......10.5.3.1][...88] + new: [.....9] [ip4][..udp] [......10.1.12.2][.1089] -> [.......10.5.3.1][...88] detected: [.....9] [ip4][..udp] [......10.1.12.2][.1089] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....10] [ip4][..udp] [......10.1.12.2][.1090] -> [.......10.5.3.1][...88] + new: [....10] [ip4][..udp] [......10.1.12.2][.1090] -> [.......10.5.3.1][...88] detected: [....10] [ip4][..udp] [......10.1.12.2][.1090] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....11] [ip4][..udp] [......10.1.12.2][.1092] -> [.......10.5.3.1][...88] + new: [....11] [ip4][..udp] [......10.1.12.2][.1092] -> [.......10.5.3.1][...88] detected: [....11] [ip4][..udp] [......10.1.12.2][.1092] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....12] [ip4][..udp] [......10.1.12.2][.1096] -> [.......10.5.3.1][...88] + new: [....12] [ip4][..udp] [......10.1.12.2][.1096] -> [.......10.5.3.1][...88] detected: [....12] [ip4][..udp] [......10.1.12.2][.1096] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [......10.1.12.2][.1061] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [......10.1.12.2][.1065] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] @@ -34,7 +34,7 @@ update: [.....7] [ip4][..udp] [......10.1.12.2][.1076] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 24 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 7] - new: [....13] [ip4][..tcp] [..192.168.10.12][44256] -> [...192.168.10.3][...88] + new: [....13] [ip4][..tcp] [..192.168.10.12][44256] -> [...192.168.10.3][...88] detected: [....13] [ip4][..tcp] [..192.168.10.12][44256] -> [...192.168.10.3][...88] [Kerberos][Unknown][Network][Acceptable] detection-update: [....13] [ip4][..tcp] [..192.168.10.12][44256] -> [...192.168.10.3][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [......10.1.12.2][.1061] -> [.......10.5.3.1][...88] [Kerberos][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/kerberos.pcap.out b/test/results/flow-info/default/kerberos.pcap.out index f86418680..b64d1fa07 100644 --- a/test/results/flow-info/default/kerberos.pcap.out +++ b/test/results/flow-info/default/kerberos.pcap.out @@ -1,115 +1,115 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] detection-update: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....5] [ip4][..tcp] [...172.16.8.201][49156] -> [.....172.16.8.8][..445] [MIDSTREAM] - new: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [...172.16.8.201][49161] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [...172.16.8.201][49156] -> [.....172.16.8.8][..445] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [...172.16.8.201][49161] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] [MIDSTREAM] - new: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....14] [ip4][..tcp] [...172.16.8.201][49171] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] [MIDSTREAM] + new: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....14] [ip4][..tcp] [...172.16.8.201][49171] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....14] [ip4][..tcp] [...172.16.8.201][49171] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] detection-update: [....14] [ip4][..tcp] [...172.16.8.201][49171] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....15] [ip4][..tcp] [...172.16.8.201][49173] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....16] [ip4][..tcp] [...172.16.8.201][49172] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....15] [ip4][..tcp] [...172.16.8.201][49173] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....16] [ip4][..tcp] [...172.16.8.201][49172] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] detection-update: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....19] [ip4][..tcp] [...172.16.8.201][49174] -> [.....172.16.8.8][..445] [MIDSTREAM] - new: [....20] [ip4][..tcp] [...172.16.8.201][49179] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....21] [ip4][..tcp] [...172.16.8.201][49180] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....19] [ip4][..tcp] [...172.16.8.201][49174] -> [.....172.16.8.8][..445] [MIDSTREAM] + new: [....20] [ip4][..tcp] [...172.16.8.201][49179] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....21] [ip4][..tcp] [...172.16.8.201][49180] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] [MIDSTREAM] - new: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] [MIDSTREAM] + new: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - new: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....32] [ip4][..tcp] [...172.16.8.201][49191] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....33] [ip4][..tcp] [...172.16.8.201][49193] -> [.....172.16.8.8][..389] [MIDSTREAM] - new: [....34] [ip4][..tcp] [...172.16.8.201][49195] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....35] [ip4][..tcp] [...172.16.8.201][49196] -> [.....172.16.8.8][...88] [MIDSTREAM] - new: [....36] [ip4][..tcp] [...172.16.8.201][49194] -> [.....172.16.8.8][..445] [MIDSTREAM] + new: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....32] [ip4][..tcp] [...172.16.8.201][49191] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....33] [ip4][..tcp] [...172.16.8.201][49193] -> [.....172.16.8.8][..389] [MIDSTREAM] + new: [....34] [ip4][..tcp] [...172.16.8.201][49195] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....35] [ip4][..tcp] [...172.16.8.201][49196] -> [.....172.16.8.8][...88] [MIDSTREAM] + new: [....36] [ip4][..tcp] [...172.16.8.201][49194] -> [.....172.16.8.8][..445] [MIDSTREAM] not-detected: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] [Unknown][Unknown][Unrated] - idle: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] + idle: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] not-detected: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] [Unknown][Unknown][Unrated] - idle: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] + idle: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] idle: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] + idle: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] idle: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] + idle: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] idle: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] + idle: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] guessed: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] + idle: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] idle: [....14] [ip4][..tcp] [...172.16.8.201][49171] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....15] [ip4][..tcp] [...172.16.8.201][49173] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....15] [ip4][..tcp] [...172.16.8.201][49173] -> [.....172.16.8.8][...88] + idle: [....15] [ip4][..tcp] [...172.16.8.201][49173] -> [.....172.16.8.8][...88] guessed: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] + idle: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] idle: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] + idle: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] guessed: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] + idle: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] idle: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] + idle: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] guessed: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] + idle: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] guessed: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] + idle: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] guessed: [....34] [ip4][..tcp] [...172.16.8.201][49195] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....34] [ip4][..tcp] [...172.16.8.201][49195] -> [.....172.16.8.8][...88] + idle: [....34] [ip4][..tcp] [...172.16.8.201][49195] -> [.....172.16.8.8][...88] guessed: [....35] [ip4][..tcp] [...172.16.8.201][49196] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....35] [ip4][..tcp] [...172.16.8.201][49196] -> [.....172.16.8.8][...88] + idle: [....35] [ip4][..tcp] [...172.16.8.201][49196] -> [.....172.16.8.8][...88] guessed: [.....7] [ip4][..tcp] [...172.16.8.201][49161] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [.....7] [ip4][..tcp] [...172.16.8.201][49161] -> [.....172.16.8.8][..389] + idle: [.....7] [ip4][..tcp] [...172.16.8.201][49161] -> [.....172.16.8.8][..389] guessed: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] + idle: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] guessed: [....16] [ip4][..tcp] [...172.16.8.201][49172] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....16] [ip4][..tcp] [...172.16.8.201][49172] -> [.....172.16.8.8][..389] + idle: [....16] [ip4][..tcp] [...172.16.8.201][49172] -> [.....172.16.8.8][..389] guessed: [....20] [ip4][..tcp] [...172.16.8.201][49179] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....20] [ip4][..tcp] [...172.16.8.201][49179] -> [.....172.16.8.8][..389] + idle: [....20] [ip4][..tcp] [...172.16.8.201][49179] -> [.....172.16.8.8][..389] guessed: [....21] [ip4][..tcp] [...172.16.8.201][49180] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....21] [ip4][..tcp] [...172.16.8.201][49180] -> [.....172.16.8.8][..389] + idle: [....21] [ip4][..tcp] [...172.16.8.201][49180] -> [.....172.16.8.8][..389] guessed: [....32] [ip4][..tcp] [...172.16.8.201][49191] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....32] [ip4][..tcp] [...172.16.8.201][49191] -> [.....172.16.8.8][..389] + idle: [....32] [ip4][..tcp] [...172.16.8.201][49191] -> [.....172.16.8.8][..389] guessed: [....33] [ip4][..tcp] [...172.16.8.201][49193] -> [.....172.16.8.8][..389] [LDAP][Unknown][System][Acceptable] - idle: [....33] [ip4][..tcp] [...172.16.8.201][49193] -> [.....172.16.8.8][..389] + idle: [....33] [ip4][..tcp] [...172.16.8.201][49193] -> [.....172.16.8.8][..389] guessed: [.....5] [ip4][..tcp] [...172.16.8.201][49156] -> [.....172.16.8.8][..445] [SMBv23][Unknown][System][Acceptable] - idle: [.....5] [ip4][..tcp] [...172.16.8.201][49156] -> [.....172.16.8.8][..445] + idle: [.....5] [ip4][..tcp] [...172.16.8.201][49156] -> [.....172.16.8.8][..445] guessed: [....19] [ip4][..tcp] [...172.16.8.201][49174] -> [.....172.16.8.8][..445] [SMBv23][Unknown][System][Acceptable] - idle: [....19] [ip4][..tcp] [...172.16.8.201][49174] -> [.....172.16.8.8][..445] + idle: [....19] [ip4][..tcp] [...172.16.8.201][49174] -> [.....172.16.8.8][..445] guessed: [....36] [ip4][..tcp] [...172.16.8.201][49194] -> [.....172.16.8.8][..445] [SMBv23][Unknown][System][Acceptable] - idle: [....36] [ip4][..tcp] [...172.16.8.201][49194] -> [.....172.16.8.8][..445] + idle: [....36] [ip4][..tcp] [...172.16.8.201][49194] -> [.....172.16.8.8][..445] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/kerberos_fuzz.pcapng.out b/test/results/flow-info/default/kerberos_fuzz.pcapng.out index 29ff00757..305d07224 100644 --- a/test/results/flow-info/default/kerberos_fuzz.pcapng.out +++ b/test/results/flow-info/default/kerberos_fuzz.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......126.4.1.0][...88] -> [.......19.0.0.0][53646] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [......126.4.1.0][...88] -> [.......19.0.0.0][53646] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [......126.4.1.0][...88] -> [.......19.0.0.0][53646] [Kerberos][Unknown][Network][Acceptable] end: [.....1] [ip4][..tcp] [......126.4.1.0][...88] -> [.......19.0.0.0][53646] [Kerberos][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/kismet.pcap.out b/test/results/flow-info/default/kismet.pcap.out index 9a3bec150..4dcacd8fe 100644 --- a/test/results/flow-info/default/kismet.pcap.out +++ b/test/results/flow-info/default/kismet.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][34065] -> [......127.0.0.1][.2501] + new: [.....1] [ip4][..tcp] [......127.0.0.1][34065] -> [......127.0.0.1][.2501] detected: [.....1] [ip4][..tcp] [......127.0.0.1][34065] -> [......127.0.0.1][.2501] [Kismet][Unknown][Network][Acceptable] analyse: [.....1] [ip4][..tcp] [......127.0.0.1][34065] -> [......127.0.0.1][.2501] [Kismet][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/kontiki.pcap.out b/test/results/flow-info/default/kontiki.pcap.out index f2a88263b..c477ed9d8 100644 --- a/test/results/flow-info/default/kontiki.pcap.out +++ b/test/results/flow-info/default/kontiki.pcap.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....10.25.32.59][19948] -> [255.255.255.255][19948] - new: [.....2] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.82][.1948] - new: [.....3] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.86][.8888] + new: [.....1] [ip4][..udp] [....10.25.32.59][19948] -> [255.255.255.255][19948] + new: [.....2] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.82][.1948] + new: [.....3] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.86][.8888] detected: [.....3] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.86][.8888] [Kontiki][Unknown][Media][Potentially Dangerous] RISK: Unsafe Protocol - new: [.....4] [ip4][.icmp] [...10.25.249.14] -> [....10.25.32.59] + new: [.....4] [ip4][.icmp] [...10.25.249.14] -> [....10.25.32.59] detected: [.....4] [ip4][.icmp] [...10.25.249.14] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.88][...80] + new: [.....5] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.88][...80] detected: [.....5] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.88][...80] [Kontiki][Unknown][Media][Potentially Dangerous] RISK: Unsafe Protocol - new: [.....6] [ip4][.icmp] [.....10.25.32.3] -> [....10.25.32.59] + new: [.....6] [ip4][.icmp] [.....10.25.32.3] -> [....10.25.32.59] detected: [.....6] [ip4][.icmp] [.....10.25.32.3] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] - new: [.....7] [ip4][.icmp] [216.168.241.157] -> [....10.25.32.59] + new: [.....7] [ip4][.icmp] [216.168.241.157] -> [....10.25.32.59] detected: [.....7] [ip4][.icmp] [216.168.241.157] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] - new: [.....8] [ip4][.icmp] [...4.79.219.125] -> [....10.25.32.59] + new: [.....8] [ip4][.icmp] [...4.79.219.125] -> [....10.25.32.59] detected: [.....8] [ip4][.icmp] [...4.79.219.125] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] analyse: [.....3] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.86][.8888] [Kontiki][Unknown][Media][Potentially Dangerous] min| max| avg| stddev| variance| entropy @@ -34,9 +34,9 @@ idle: [.....6] [ip4][.icmp] [.....10.25.32.3] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] idle: [.....4] [ip4][.icmp] [...10.25.249.14] -> [....10.25.32.59] [ICMP][Unknown][Network][Acceptable] not-detected: [.....1] [ip4][..udp] [....10.25.32.59][19948] -> [255.255.255.255][19948] [Unknown][Unknown][Unrated] - idle: [.....1] [ip4][..udp] [....10.25.32.59][19948] -> [255.255.255.255][19948] + idle: [.....1] [ip4][..udp] [....10.25.32.59][19948] -> [255.255.255.255][19948] not-detected: [.....2] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.82][.1948] [Unknown][Unknown][Unrated] - idle: [.....2] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.82][.1948] + idle: [.....2] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.82][.1948] idle: [.....5] [ip4][..udp] [....10.25.32.59][19948] -> [..64.200.148.88][...80] [Kontiki][Unknown][Media][Potentially Dangerous] RISK: Unsafe Protocol DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/line.pcap.out b/test/results/flow-info/default/line.pcap.out index 2d7cacbd2..ce1adff37 100644 --- a/test/results/flow-info/default/line.pcap.out +++ b/test/results/flow-info/default/line.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......10.0.2.15][50835] -> [125.209.252.210][20610] + new: [.....1] [ip4][..udp] [......10.0.2.15][50835] -> [125.209.252.210][20610] detected: [.....1] [ip4][..udp] [......10.0.2.15][50835] -> [125.209.252.210][20610] [LineCall][Line][VoIP][Acceptable] analyse: [.....1] [ip4][..udp] [......10.0.2.15][50835] -> [125.209.252.210][20610] [LineCall][Line][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,9 +15,9 @@ [ENTROPIES...: 7.8,7.8,6.6,7.6,5.2,7.4,6.7,6.8,7.4,5.1,5.1,5.3,5.1,5.2,5.3,5.2,5.2,5.3,5.3,5.3,5.2,5.3,5.3,5.3,5.3,5.2,4.1,4.5,5.4,5.3,5.2,5.2] DAEMON-EVENT: [Processed: 50 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [...10.200.3.125][57841] -> [.147.92.165.194][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...10.200.3.125][57841] -> [.147.92.165.194][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [...10.200.3.125][57841] -> [.147.92.165.194][..443] [TLS][Line][Web][Safe] - new: [.....3] [ip4][..tcp] [...10.200.3.125][58160] -> [.147.92.242.232][..443] + new: [.....3] [ip4][..tcp] [...10.200.3.125][58160] -> [.147.92.242.232][..443] detected: [.....3] [ip4][..tcp] [...10.200.3.125][58160] -> [.147.92.242.232][..443] [TLS.Line][Line][Chat][Acceptable][uts-front.line-apps.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [...10.200.3.125][58160] -> [.147.92.242.232][..443] [TLS.Line][Line][Chat][Acceptable][uts-front.line-apps.com] @@ -45,7 +45,7 @@ [PKTLENS.....: 52,52,40,557,46,1500,1500,381,40,133,314,335,46,581,46,224,75,40,335,46,613,46,224,75,40,335,46,612,46,224,75,40] [ENTROPIES...: 4.5,4.9,4.8,4.8,4.5,7.2,7.5,7.4,4.8,6.2,7.2,7.3,4.5,7.6,4.5,7.0,5.7,4.8,7.4,4.4,7.6,4.6,7.0,5.8,4.6,7.3,4.5,7.6,4.5,7.0,5.7,4.7] idle: [.....1] [ip4][..udp] [......10.0.2.15][50835] -> [125.209.252.210][20610] [LineCall][Line][VoIP][Acceptable] - new: [.....4] [ip4][..udp] [...10.200.3.125][51161] -> [..147.92.169.90][29070] + new: [.....4] [ip4][..udp] [...10.200.3.125][51161] -> [..147.92.169.90][29070] detected: [.....4] [ip4][..udp] [...10.200.3.125][51161] -> [..147.92.169.90][29070] [LineCall][Line][VoIP][Acceptable] analyse: [.....4] [ip4][..udp] [...10.200.3.125][51161] -> [..147.92.169.90][29070] [LineCall][Line][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -57,7 +57,7 @@ [IATS(ms)....: 175.7,225.0,0.1,0.0,0.0,0.0,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.1,84.3,0.0,0.0,0.0,0.0,0.0,0.0,0.2,0.0,0.0,0.0,0.0] [PKTLENS.....: 881,419,569,569,569,569,569,569,569,569,569,569,569,569,569,569,569,569,59,161,398,570,570,570,570,570,570,570,570,570,570,570] [ENTROPIES...: 7.8,7.2,7.6,7.6,7.6,7.7,7.7,7.6,7.5,7.6,7.6,7.6,7.6,7.6,7.7,7.6,7.6,7.7,5.3,6.7,7.5,7.6,7.7,7.6,7.6,7.6,7.7,7.6,7.6,7.7,7.7,7.6] - new: [.....5] [ip4][..udp] [...10.200.3.125][51170] -> [..147.92.169.90][29070] + new: [.....5] [ip4][..udp] [...10.200.3.125][51170] -> [..147.92.169.90][29070] detected: [.....5] [ip4][..udp] [...10.200.3.125][51170] -> [..147.92.169.90][29070] [LineCall][Line][VoIP][Acceptable] update: [.....4] [ip4][..udp] [...10.200.3.125][51161] -> [..147.92.169.90][29070] [LineCall][Line][VoIP][Acceptable] idle: [.....2] [ip4][..tcp] [...10.200.3.125][57841] -> [.147.92.165.194][..443] [TLS][Line][Web][Safe] diff --git a/test/results/flow-info/default/lisp_registration.pcap.out b/test/results/flow-info/default/lisp_registration.pcap.out index 8bfc30640..39ca5cfd8 100644 --- a/test/results/flow-info/default/lisp_registration.pcap.out +++ b/test/results/flow-info/default/lisp_registration.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.0.123.2][.4342] -> [.....10.0.123.1][.4342] + new: [.....1] [ip4][..udp] [.....10.0.123.2][.4342] -> [.....10.0.123.1][.4342] detected: [.....1] [ip4][..udp] [.....10.0.123.2][.4342] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] - new: [.....2] [ip4][..tcp] [.....10.0.123.2][15373] -> [.....10.0.123.1][.4342] + new: [.....2] [ip4][..tcp] [.....10.0.123.2][15373] -> [.....10.0.123.1][.4342] detected: [.....2] [ip4][..tcp] [.....10.0.123.2][15373] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] - new: [.....3] [ip4][..udp] [.....10.0.123.3][.4342] -> [.....10.0.123.1][.4342] + new: [.....3] [ip4][..udp] [.....10.0.123.3][.4342] -> [.....10.0.123.1][.4342] detected: [.....3] [ip4][..udp] [.....10.0.123.3][.4342] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] - new: [.....4] [ip4][..tcp] [.....10.0.123.3][52995] -> [.....10.0.123.1][.4342] + new: [.....4] [ip4][..tcp] [.....10.0.123.3][52995] -> [.....10.0.123.1][.4342] detected: [.....4] [ip4][..tcp] [.....10.0.123.3][52995] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] idle: [.....4] [ip4][..tcp] [.....10.0.123.3][52995] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] idle: [.....3] [ip4][..udp] [.....10.0.123.3][.4342] -> [.....10.0.123.1][.4342] [LISP][Unknown][Cloud][Acceptable] diff --git a/test/results/flow-info/default/log4j-webapp-exploit.pcap.out b/test/results/flow-info/default/log4j-webapp-exploit.pcap.out index a366862ff..493ca5aa4 100644 --- a/test/results/flow-info/default/log4j-webapp-exploit.pcap.out +++ b/test/results/flow-info/default/log4j-webapp-exploit.pcap.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.16.238.1][.1984] -> [..172.16.238.10][.8080] + new: [.....1] [ip4][..tcp] [...172.16.238.1][.1984] -> [..172.16.238.10][.8080] detected: [.....1] [ip4][..tcp] [...172.16.238.1][.1984] -> [..172.16.238.10][.8080] [HTTP][Unknown][Web][Acceptable][192.168.13.31] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header, Possible Exploit ERROR-EVENT: Unknown L3 protocol [1/16] ERROR-EVENT: Unknown L3 protocol [2/16] - new: [.....2] [ip4][..tcp] [..172.16.238.10][57650] -> [..172.16.238.11][.1389] + new: [.....2] [ip4][..tcp] [..172.16.238.10][57650] -> [..172.16.238.11][.1389] detected: [.....2] [ip4][..tcp] [..172.16.238.10][57650] -> [..172.16.238.11][.1389] [LDAP][Unknown][System][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..tcp] [..172.16.238.10][48444] -> [..172.16.238.11][...80] + new: [.....3] [ip4][..tcp] [..172.16.238.10][48444] -> [..172.16.238.11][...80] detected: [.....3] [ip4][..tcp] [..172.16.238.10][48444] -> [..172.16.238.11][...80] [HTTP][Unknown][Web][Acceptable][172.16.238.11] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....3] [ip4][..tcp] [..172.16.238.10][48444] -> [..172.16.238.11][...80] [HTTP][Unknown][Download][Acceptable][172.16.238.11] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI, Possible Exploit - new: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] + new: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] ERROR-EVENT: Unknown L3 protocol [3/16] ERROR-EVENT: Unknown L3 protocol [4/16] - analyse: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] + analyse: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 7.289| 0.474| 1.790| 3202664.366| 1.100] [PKTLEN......: 52.000| 60.000| 53.500| 2.200| 4.600| 5.000] @@ -27,24 +27,24 @@ [IATS(ms)....: 0.1,0.2,7288.6,7288.6,60.5,60.7,0.3,0.2,0.1,0.1,0.1,0.1,0.1,0.1,0.2,0.2,0.1,0.1,0.1,0.1,0.1,0.1,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.1] [PKTLENS.....: 60,60,52,55,52,53,52,53,52,53,52,53,52,53,52,53,52,53,52,55,52,57,52,55,52,55,52,55,52,55,52,55] [ENTROPIES...: 4.5,5.1,5.0,5.1,4.9,5.0,4.9,5.0,4.8,4.9,4.9,5.0,4.9,5.0,4.9,4.9,4.9,4.9,4.9,4.9,4.9,5.0,4.8,5.0,4.9,5.0,4.9,5.0,4.9,5.0,4.9,4.9] - new: [.....5] [ip4][..tcp] [..172.16.238.10][57742] -> [..172.16.238.11][.1389] + new: [.....5] [ip4][..tcp] [..172.16.238.10][57742] -> [..172.16.238.11][.1389] detected: [.....5] [ip4][..tcp] [..172.16.238.10][57742] -> [..172.16.238.11][.1389] [LDAP][Unknown][System][Acceptable] RISK: Known Proto on Non Std Port - new: [.....6] [ip4][..tcp] [..172.16.238.10][48534] -> [..172.16.238.11][...80] + new: [.....6] [ip4][..tcp] [..172.16.238.10][48534] -> [..172.16.238.11][...80] detected: [.....6] [ip4][..tcp] [..172.16.238.10][48534] -> [..172.16.238.11][...80] [HTTP][Unknown][Web][Acceptable][172.16.238.11] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....6] [ip4][..tcp] [..172.16.238.10][48534] -> [..172.16.238.11][...80] [HTTP][Unknown][Download][Acceptable][172.16.238.11] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI, Possible Exploit - new: [.....7] [ip4][..tcp] [..172.16.238.10][55498] -> [....10.10.10.31][.9001] + new: [.....7] [ip4][..tcp] [..172.16.238.10][55498] -> [....10.10.10.31][.9001] end: [.....5] [ip4][..tcp] [..172.16.238.10][57742] -> [..172.16.238.11][.1389] [LDAP][Unknown][System][Acceptable] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..tcp] [...172.16.238.1][.1984] -> [..172.16.238.10][.8080] [HTTP][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, HTTP Susp Header, Possible Exploit not-detected: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] [Unknown][Unknown][Unrated] - end: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] + end: [.....4] [ip4][..tcp] [..172.16.238.10][55408] -> [....10.10.10.31][.9001] not-detected: [.....7] [ip4][..tcp] [..172.16.238.10][55498] -> [....10.10.10.31][.9001] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [.....7] [ip4][..tcp] [..172.16.238.10][55498] -> [....10.10.10.31][.9001] + end: [.....7] [ip4][..tcp] [..172.16.238.10][55498] -> [....10.10.10.31][.9001] end: [.....3] [ip4][..tcp] [..172.16.238.10][48444] -> [..172.16.238.11][...80] [HTTP][Unknown][Download][Acceptable] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI, Possible Exploit end: [.....6] [ip4][..tcp] [..172.16.238.10][48534] -> [..172.16.238.11][...80] [HTTP][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/long_tls_certificate.pcap.out b/test/results/flow-info/default/long_tls_certificate.pcap.out index de2cf8182..be4814b75 100644 --- a/test/results/flow-info/default/long_tls_certificate.pcap.out +++ b/test/results/flow-info/default/long_tls_certificate.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.60][55333] -> [.106.15.100.123][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.60][55333] -> [.106.15.100.123][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.60][55333] -> [.106.15.100.123][..443] [TLS.Alibaba][Alibaba][Web][Acceptable][beacon-api.aliyuncs.com] detection-update: [.....1] [ip4][..tcp] [...192.168.1.60][55333] -> [.106.15.100.123][..443] [TLS.Alibaba][Alibaba][Web][Acceptable][beacon-api.aliyuncs.com] detection-update: [.....1] [ip4][..tcp] [...192.168.1.60][55333] -> [.106.15.100.123][..443] [TLS.Alibaba][Alibaba][Web][Acceptable][beacon-api.aliyuncs.com] diff --git a/test/results/flow-info/default/lru_ipv6_caches.pcapng.out b/test/results/flow-info/default/lru_ipv6_caches.pcapng.out index abc6bae1e..a0e16d76a 100644 --- a/test/results/flow-info/default/lru_ipv6_caches.pcapng.out +++ b/test/results/flow-info/default/lru_ipv6_caches.pcapng.out @@ -1,47 +1,47 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] + new: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] detected: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] [STUN][Unknown][Network][Acceptable][] - new: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] - new: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] - new: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] + new: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] + new: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] + new: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] detected: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] + new: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] detected: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port detected: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] + new: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] detected: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port detected: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] - new: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] + new: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] detected: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS][Unknown][Web][Safe][] RISK: Unidirectional Traffic detection-update: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - new: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] + new: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] detected: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] + new: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] detected: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - new: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] - new: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] idle: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS.Cloudflare][Unknown][Web][Acceptable] RISK: Unidirectional Traffic diff --git a/test/results/flow-info/default/malformed_dns.pcap.out b/test/results/flow-info/default/malformed_dns.pcap.out index 76d8d642e..71820ff16 100644 --- a/test/results/flow-info/default/malformed_dns.pcap.out +++ b/test/results/flow-info/default/malformed_dns.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][50435] -> [......127.0.0.1][...53] + new: [.....1] [ip4][..udp] [......127.0.0.1][50435] -> [......127.0.0.1][...53] detected: [.....1] [ip4][..udp] [......127.0.0.1][50435] -> [......127.0.0.1][...53] [DNS][Unknown][Network][Acceptable][www.xt.com] detection-update: [.....1] [ip4][..udp] [......127.0.0.1][50435] -> [......127.0.0.1][...53] [DNS][Unknown][Network][Acceptable][www.xt.com] RISK: Malformed Packet, Large DNS Packet (512+ bytes), Minor Issues diff --git a/test/results/flow-info/default/malformed_icmp.pcap.out b/test/results/flow-info/default/malformed_icmp.pcap.out index e1ab101c6..fc7f9bda3 100644 --- a/test/results/flow-info/default/malformed_icmp.pcap.out +++ b/test/results/flow-info/default/malformed_icmp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][.icmp] [218.152.179.213] -> [.218.152.179.54] + new: [.....1] [ip4][.icmp] [218.152.179.213] -> [.218.152.179.54] detected: [.....1] [ip4][.icmp] [218.152.179.213] -> [.218.152.179.54] [ICMP][Unknown][Network][Acceptable] RISK: Malformed Packet idle: [.....1] [ip4][.icmp] [218.152.179.213] -> [.218.152.179.54] [ICMP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/malware.pcap.out b/test/results/flow-info/default/malware.pcap.out index 518c6a4ee..0d3a63ccd 100644 --- a/test/results/flow-info/default/malware.pcap.out +++ b/test/results/flow-info/default/malware.pcap.out @@ -1,29 +1,29 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.7.7][42370] -> [........1.1.1.1][...53] + new: [.....1] [ip4][..udp] [....192.168.7.7][42370] -> [........1.1.1.1][...53] detected: [.....1] [ip4][..udp] [....192.168.7.7][42370] -> [........1.1.1.1][...53] [DNS][Unknown][Network][Acceptable][www.internetbadguys.com] detection-update: [.....1] [ip4][..udp] [....192.168.7.7][42370] -> [........1.1.1.1][...53] [DNS][Unknown][Network][Acceptable][www.internetbadguys.com] - new: [.....2] [ip4][.icmp] [....192.168.7.7] -> [144.139.247.220] + new: [.....2] [ip4][.icmp] [....192.168.7.7] -> [144.139.247.220] detected: [.....2] [ip4][.icmp] [....192.168.7.7] -> [144.139.247.220] [ICMP][Unknown][Network][Acceptable] - new: [.....3] [ip4][..tcp] [....192.168.7.7][33706] -> [144.139.247.220][...80] + new: [.....3] [ip4][..tcp] [....192.168.7.7][33706] -> [144.139.247.220][...80] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....4] [ip4][..tcp] [....192.168.7.7][48394] -> [..67.215.92.210][...80] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....192.168.7.7][48394] -> [..67.215.92.210][...80] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [....192.168.7.7][48394] -> [..67.215.92.210][...80] [HTTP][OpenDNS][Web][Acceptable][www.internetbadguys.com] - new: [.....5] [ip4][..tcp] [....192.168.7.7][35236] -> [..67.215.92.210][..443] + new: [.....5] [ip4][..tcp] [....192.168.7.7][35236] -> [..67.215.92.210][..443] detected: [.....5] [ip4][..tcp] [....192.168.7.7][35236] -> [..67.215.92.210][..443] [TLS][OpenDNS][Web][Safe][www.internetbadguys.com] detection-update: [.....5] [ip4][..tcp] [....192.168.7.7][35236] -> [..67.215.92.210][..443] [TLS][OpenDNS][Web][Safe][www.internetbadguys.com] detection-update: [.....5] [ip4][..tcp] [....192.168.7.7][35236] -> [..67.215.92.210][..443] [TLS.OpenDNS][OpenDNS][Network][Acceptable][www.internetbadguys.com] RISK: TLS Cert Mismatch guessed: [.....3] [ip4][..tcp] [....192.168.7.7][33706] -> [144.139.247.220][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....3] [ip4][..tcp] [....192.168.7.7][33706] -> [144.139.247.220][...80] + idle: [.....3] [ip4][..tcp] [....192.168.7.7][33706] -> [144.139.247.220][...80] idle: [.....2] [ip4][.icmp] [....192.168.7.7] -> [144.139.247.220] [ICMP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [....192.168.7.7][42370] -> [........1.1.1.1][...53] [DNS][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 26 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 1|detection-updates: 3|updates: 0] - new: [.....6] [ip4][..tcp] [...192.168.0.20][41240] -> [.193.109.85.123][..443] + new: [.....6] [ip4][..tcp] [...192.168.0.20][41240] -> [.193.109.85.123][..443] detected: [.....6] [ip4][..tcp] [...192.168.0.20][41240] -> [.193.109.85.123][..443] [TLS][Unknown][Web][Safe][hobbeach.com] detection-update: [.....6] [ip4][..tcp] [...192.168.0.20][41240] -> [.193.109.85.123][..443] [TLS][Unknown][Web][Safe][hobbeach.com] analyse: [.....6] [ip4][..tcp] [...192.168.0.20][41240] -> [.193.109.85.123][..443] [TLS][Unknown][Web][Safe] diff --git a/test/results/flow-info/default/memcached.cap.out b/test/results/flow-info/default/memcached.cap.out index f7c85dbac..fa2f33aa7 100644 --- a/test/results/flow-info/default/memcached.cap.out +++ b/test/results/flow-info/default/memcached.cap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][59604] -> [......127.0.0.1][11211] + new: [.....1] [ip4][..tcp] [......127.0.0.1][59604] -> [......127.0.0.1][11211] detected: [.....1] [ip4][..tcp] [......127.0.0.1][59604] -> [......127.0.0.1][11211] [Memcached][Unknown][Network][Acceptable] end: [.....1] [ip4][..tcp] [......127.0.0.1][59604] -> [......127.0.0.1][11211] [Memcached][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/merakicloud.pcapng.out b/test/results/flow-info/default/merakicloud.pcapng.out index e963ea45b..7cf748ec0 100644 --- a/test/results/flow-info/default/merakicloud.pcapng.out +++ b/test/results/flow-info/default/merakicloud.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...2.36.234.133][47301] -> [..209.206.59.34][.7351] + new: [.....1] [ip4][..udp] [...2.36.234.133][47301] -> [..209.206.59.34][.7351] detected: [.....1] [ip4][..udp] [...2.36.234.133][47301] -> [..209.206.59.34][.7351] [MerakiCloud][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...2.36.234.133][47301] -> [..209.206.59.34][.7351] [MerakiCloud][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...2.36.234.133][47301] -> [..209.206.59.34][.7351] [MerakiCloud][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/mgcp.pcap.out b/test/results/flow-info/default/mgcp.pcap.out index de8723a73..17f31f123 100644 --- a/test/results/flow-info/default/mgcp.pcap.out +++ b/test/results/flow-info/default/mgcp.pcap.out @@ -1,27 +1,27 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...172.16.1.116][.2427] -> [...172.16.1.119][.2427] + new: [.....1] [ip4][..udp] [...172.16.1.116][.2427] -> [...172.16.1.119][.2427] detected: [.....1] [ip4][..udp] [...172.16.1.116][.2427] -> [...172.16.1.119][.2427] [MGCP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [...172.16.1.116][.2427] -> [...172.16.1.119][.2427] [MGCP][Unknown][VoIP][Acceptable] DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....2] [ip4][..udp] [...10.10.228.72][.2427] -> [....10.10.244.2][.2427] + new: [.....2] [ip4][..udp] [...10.10.228.72][.2427] -> [....10.10.244.2][.2427] detected: [.....2] [ip4][..udp] [...10.10.228.72][.2427] -> [....10.10.244.2][.2427] [MGCP][Unknown][VoIP][Acceptable] idle: [.....1] [ip4][..udp] [...172.16.1.116][.2427] -> [...172.16.1.119][.2427] [MGCP][Unknown][VoIP][Acceptable] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [..187.43.37.188][40798] -> [.196.167.59.124][.2427] + new: [.....3] [ip4][..udp] [..187.43.37.188][40798] -> [.196.167.59.124][.2427] detected: [.....3] [ip4][..udp] [..187.43.37.188][40798] -> [.196.167.59.124][.2427] [MGCP][Unknown][VoIP][Acceptable] idle: [.....2] [ip4][..udp] [...10.10.228.72][.2427] -> [....10.10.244.2][.2427] [MGCP][Unknown][VoIP][Acceptable] DAEMON-EVENT: [Processed: 21 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....4] [ip4][..udp] [.67.232.180.250][38238] -> [186.112.128.179][.2427] + new: [.....4] [ip4][..udp] [.67.232.180.250][38238] -> [186.112.128.179][.2427] detected: [.....4] [ip4][..udp] [.67.232.180.250][38238] -> [186.112.128.179][.2427] [MGCP][Unknown][VoIP][Acceptable] idle: [.....3] [ip4][..udp] [..187.43.37.188][40798] -> [.196.167.59.124][.2427] [MGCP][Unknown][VoIP][Acceptable] DAEMON-EVENT: [Processed: 22 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....5] [ip4][..udp] [.92.173.166.213][51954] -> [..83.250.239.33][.2427] + new: [.....5] [ip4][..udp] [.92.173.166.213][51954] -> [..83.250.239.33][.2427] detected: [.....5] [ip4][..udp] [.92.173.166.213][51954] -> [..83.250.239.33][.2427] [MGCP][Unknown][VoIP][Acceptable] idle: [.....5] [ip4][..udp] [.92.173.166.213][51954] -> [..83.250.239.33][.2427] [MGCP][Unknown][VoIP][Acceptable] idle: [.....4] [ip4][..udp] [.67.232.180.250][38238] -> [186.112.128.179][.2427] [MGCP][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/modbus.pcap.out b/test/results/flow-info/default/modbus.pcap.out index 6e4dddbf2..731bf11d8 100644 --- a/test/results/flow-info/default/modbus.pcap.out +++ b/test/results/flow-info/default/modbus.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [192.168.110.131][.2074] -> [192.168.110.138][..502] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [192.168.110.131][.2074] -> [192.168.110.138][..502] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [192.168.110.131][.2074] -> [192.168.110.138][..502] [Modbus][Unknown][IoT-Scada][Acceptable] analyse: [.....1] [ip4][..tcp] [192.168.110.131][.2074] -> [192.168.110.138][..502] [Modbus][Unknown][IoT-Scada][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/monero.pcap.out b/test/results/flow-info/default/monero.pcap.out index eae5e213b..d17b2ee1e 100644 --- a/test/results/flow-info/default/monero.pcap.out +++ b/test/results/flow-info/default/monero.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.148][46838] -> [..94.23.199.191][.3333] + new: [.....1] [ip4][..tcp] [..192.168.2.148][46838] -> [..94.23.199.191][.3333] detected: [.....1] [ip4][..tcp] [..192.168.2.148][46838] -> [..94.23.199.191][.3333] [Mining][Unknown][Mining][Unsafe] RISK: Unsafe Protocol - new: [.....2] [ip4][..tcp] [..192.168.2.148][53846] -> [116.211.167.195][.3333] + new: [.....2] [ip4][..tcp] [..192.168.2.148][53846] -> [116.211.167.195][.3333] detected: [.....2] [ip4][..tcp] [..192.168.2.148][53846] -> [116.211.167.195][.3333] [Mining][Unknown][Mining][Unsafe] RISK: Unsafe Protocol analyse: [.....1] [ip4][..tcp] [..192.168.2.148][46838] -> [..94.23.199.191][.3333] [Mining][Unknown][Mining][Unsafe] diff --git a/test/results/flow-info/default/mongo_false_positive.pcapng.out b/test/results/flow-info/default/mongo_false_positive.pcapng.out index 8201fa0cb..4e9d419ae 100644 --- a/test/results/flow-info/default/mongo_false_positive.pcapng.out +++ b/test/results/flow-info/default/mongo_false_positive.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..188.75.184.20][49542] -> [.251.182.120.32][..443] + new: [.....1] [ip4][..tcp] [..188.75.184.20][49542] -> [.251.182.120.32][..443] guessed: [.....1] [ip4][..tcp] [..188.75.184.20][49542] -> [.251.182.120.32][..443] [TLS][Unknown][Web][Safe] RISK: Fully encrypted flow - end: [.....1] [ip4][..tcp] [..188.75.184.20][49542] -> [.251.182.120.32][..443] + end: [.....1] [ip4][..tcp] [..188.75.184.20][49542] -> [.251.182.120.32][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/mongodb.pcap.out b/test/results/flow-info/default/mongodb.pcap.out index 806919c6b..5324c968e 100644 --- a/test/results/flow-info/default/mongodb.pcap.out +++ b/test/results/flow-info/default/mongodb.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....10.10.10.10][51822] -> [....10.10.10.11][27017] + new: [.....1] [ip4][..tcp] [....10.10.10.10][51822] -> [....10.10.10.11][27017] detected: [.....1] [ip4][..tcp] [....10.10.10.10][51822] -> [....10.10.10.11][27017] [MongoDB][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [....10.10.10.12][55582] -> [....10.10.10.13][27017] + new: [.....2] [ip4][..tcp] [....10.10.10.12][55582] -> [....10.10.10.13][27017] detected: [.....2] [ip4][..tcp] [....10.10.10.12][55582] -> [....10.10.10.13][27017] [MongoDB][Unknown][Database][Acceptable] idle: [.....1] [ip4][..tcp] [....10.10.10.10][51822] -> [....10.10.10.11][27017] [MongoDB][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [....10.10.10.14][61503] -> [....10.10.10.15][27017] + new: [.....3] [ip4][..tcp] [....10.10.10.14][61503] -> [....10.10.10.15][27017] detected: [.....3] [ip4][..tcp] [....10.10.10.14][61503] -> [....10.10.10.15][27017] [MongoDB][Unknown][Database][Acceptable] idle: [.....2] [ip4][..tcp] [....10.10.10.12][55582] -> [....10.10.10.13][27017] [MongoDB][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [....10.10.10.16][51358] -> [....10.10.10.17][27017] + new: [.....4] [ip4][..tcp] [....10.10.10.16][51358] -> [....10.10.10.17][27017] detected: [.....4] [ip4][..tcp] [....10.10.10.16][51358] -> [....10.10.10.17][27017] [MongoDB][Unknown][Database][Acceptable] idle: [.....3] [ip4][..tcp] [....10.10.10.14][61503] -> [....10.10.10.15][27017] [MongoDB][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [....10.10.10.18][64566] -> [....10.10.10.19][30000] + new: [.....5] [ip4][..tcp] [....10.10.10.18][64566] -> [....10.10.10.19][30000] detected: [.....5] [ip4][..tcp] [....10.10.10.18][64566] -> [....10.10.10.19][30000] [MongoDB][Unknown][Database][Acceptable] RISK: Known Proto on Non Std Port idle: [.....5] [ip4][..tcp] [....10.10.10.18][64566] -> [....10.10.10.19][30000] [MongoDB][Unknown][Database][Acceptable] diff --git a/test/results/flow-info/default/mpeg-dash.pcap.out b/test/results/flow-info/default/mpeg-dash.pcap.out index dc047edec..2232a4e81 100644 --- a/test/results/flow-info/default/mpeg-dash.pcap.out +++ b/test/results/flow-info/default/mpeg-dash.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.84.1.81][60926] -> [.166.248.152.10][...80] + new: [.....1] [ip4][..tcp] [.....10.84.1.81][60926] -> [.166.248.152.10][...80] detected: [.....1] [ip4][..tcp] [.....10.84.1.81][60926] -> [.166.248.152.10][...80] [HTTP.MpegDash][Unknown][Media][Fun][gdl.news-cdn.site] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.105][59142] -> [..54.161.101.85][...80] + new: [.....2] [ip4][..tcp] [..192.168.2.105][59142] -> [..54.161.101.85][...80] detected: [.....2] [ip4][..tcp] [..192.168.2.105][59142] -> [..54.161.101.85][...80] [HTTP.MpegDash][AmazonAWS][Media][Fun][livesim.dashif.org] - new: [.....3] [ip4][..tcp] [..54.161.101.85][...80] -> [..192.168.2.105][59144] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..54.161.101.85][...80] -> [..192.168.2.105][59144] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..54.161.101.85][...80] -> [..192.168.2.105][59144] [HTTP.MpegDash][AmazonAWS][Media][Fun][] RISK: HTTP Susp User-Agent detection-update: [.....3] [ip4][..tcp] [..54.161.101.85][...80] -> [..192.168.2.105][59144] [HTTP.MpegDash][AmazonAWS][Media][Fun][livesim.dashif.org] - new: [.....4] [ip4][..tcp] [..192.168.2.105][59146] -> [..54.161.101.85][...80] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.2.105][59146] -> [..54.161.101.85][...80] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.2.105][59146] -> [..54.161.101.85][...80] [HTTP.MpegDash][AmazonAWS][Media][Fun][livesim.dashif.org] idle: [.....2] [ip4][..tcp] [..192.168.2.105][59142] -> [..54.161.101.85][...80] [HTTP.MpegDash][AmazonAWS][Media][Fun] idle: [.....3] [ip4][..tcp] [..54.161.101.85][...80] -> [..192.168.2.105][59144] [HTTP.MpegDash][AmazonAWS][Media][Fun] diff --git a/test/results/flow-info/default/mpeg.pcap.out b/test/results/flow-info/default/mpeg.pcap.out index 6e266bd5b..149d4fd65 100644 --- a/test/results/flow-info/default/mpeg.pcap.out +++ b/test/results/flow-info/default/mpeg.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.80.160][55804] -> [.46.101.157.119][...80] + new: [.....1] [ip4][..tcp] [.192.168.80.160][55804] -> [.46.101.157.119][...80] detected: [.....1] [ip4][..tcp] [.192.168.80.160][55804] -> [.46.101.157.119][...80] [HTTP.ntop][Unknown][Network][Safe][luca.ntop.org] detection-update: [.....1] [ip4][..tcp] [.192.168.80.160][55804] -> [.46.101.157.119][...80] [HTTP.ntop][Unknown][Media][Safe][luca.ntop.org] end: [.....1] [ip4][..tcp] [.192.168.80.160][55804] -> [.46.101.157.119][...80] [HTTP.ntop][Unknown][Media][Safe] diff --git a/test/results/flow-info/default/mpegts.pcap.out b/test/results/flow-info/default/mpegts.pcap.out index 0d9a788b1..f643c1fbe 100644 --- a/test/results/flow-info/default/mpegts.pcap.out +++ b/test/results/flow-info/default/mpegts.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.1.16.48][40737] -> [.230.200.201.23][.1234] + new: [.....1] [ip4][..udp] [.....10.1.16.48][40737] -> [.230.200.201.23][.1234] detected: [.....1] [ip4][..udp] [.....10.1.16.48][40737] -> [.230.200.201.23][.1234] [MPEG_TS][Unknown][Media][Fun] idle: [.....1] [ip4][..udp] [.....10.1.16.48][40737] -> [.230.200.201.23][.1234] [MPEG_TS][Unknown][Media][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/mqtt.pcap.out b/test/results/flow-info/default/mqtt.pcap.out index a6c4aa86a..d1ea983a1 100644 --- a/test/results/flow-info/default/mqtt.pcap.out +++ b/test/results/flow-info/default/mqtt.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][.1883] -> [....192.168.0.1][41892] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][.1883] -> [....192.168.0.1][41892] detected: [.....1] [ip4][..tcp] [.....10.10.10.1][.1883] -> [....192.168.0.1][41892] [MQTT][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..tcp] [..100.67.35.238][35035] -> [..51.137.28.239][.1883] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..100.67.35.238][35035] -> [..51.137.28.239][.1883] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..100.67.35.238][35035] -> [..51.137.28.239][.1883] [MQTT][Azure][RPC][Acceptable] idle: [.....2] [ip4][..tcp] [..100.67.35.238][35035] -> [..51.137.28.239][.1883] [MQTT][Azure][RPC][Acceptable] idle: [.....1] [ip4][..tcp] [.....10.10.10.1][.1883] -> [....192.168.0.1][41892] [MQTT][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/mssql_tds.pcap.out b/test/results/flow-info/default/mssql_tds.pcap.out index 957e0dfb5..d3fbd1743 100644 --- a/test/results/flow-info/default/mssql_tds.pcap.out +++ b/test/results/flow-info/default/mssql_tds.pcap.out @@ -1,33 +1,33 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.10.111.111.111][.1111] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.10.111.111.111][.1111] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.10.111.111.111][.1111] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [.10.111.111.111][.2222] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.10.111.111.111][.2222] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [.10.111.111.111][.2222] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [.....3] [ip4][..tcp] [.10.111.111.111][.3333] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [.10.111.111.111][.3333] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [.10.111.111.111][.3333] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [.....4] [ip4][..tcp] [.10.111.111.111][.4444] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [.10.111.111.111][.4444] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [.10.111.111.111][.4444] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [.....5] [ip4][..tcp] [.10.111.111.111][.5555] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [.10.111.111.111][.5555] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [.10.111.111.111][.5555] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] idle: [.....1] [ip4][..tcp] [.10.111.111.111][.1111] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [.....6] [ip4][..tcp] [.10.111.111.111][.6666] -> [.......10.0.0.1][.1433] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [.10.111.111.111][.7777] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [.10.111.111.111][.6666] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [.10.111.111.111][.7777] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [.10.111.111.111][.7777] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [.....8] [ip4][..tcp] [.10.111.111.111][.8888] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [.10.111.111.111][.8888] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [.10.111.111.111][.8888] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 34 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [.10.111.111.111][.9999] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [.10.111.111.111][.9999] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [.10.111.111.111][.9999] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [....10] [ip4][..tcp] [.10.111.111.111][11111] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [....10] [ip4][..tcp] [.10.111.111.111][11111] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [....10] [ip4][..tcp] [.10.111.111.111][11111] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [....11] [ip4][..tcp] [.10.111.111.111][22222] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [....11] [ip4][..tcp] [.10.111.111.111][22222] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [....11] [ip4][..tcp] [.10.111.111.111][22222] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] - new: [....12] [ip4][..tcp] [.10.111.111.111][33333] -> [.......10.0.0.1][.1433] [MIDSTREAM] + new: [....12] [ip4][..tcp] [.10.111.111.111][33333] -> [.......10.0.0.1][.1433] [MIDSTREAM] detected: [....12] [ip4][..tcp] [.10.111.111.111][33333] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] idle: [....10] [ip4][..tcp] [.10.111.111.111][11111] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] idle: [.....3] [ip4][..tcp] [.10.111.111.111][.3333] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] @@ -39,7 +39,7 @@ idle: [.....4] [ip4][..tcp] [.10.111.111.111][.4444] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] guessed: [.....6] [ip4][..tcp] [.10.111.111.111][.6666] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..tcp] [.10.111.111.111][.6666] -> [.......10.0.0.1][.1433] + idle: [.....6] [ip4][..tcp] [.10.111.111.111][.6666] -> [.......10.0.0.1][.1433] idle: [....12] [ip4][..tcp] [.10.111.111.111][33333] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] idle: [.....8] [ip4][..tcp] [.10.111.111.111][.8888] -> [.......10.0.0.1][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/mullvad_dns.pcap.out b/test/results/flow-info/default/mullvad_dns.pcap.out index a866deac4..b3fc11705 100644 --- a/test/results/flow-info/default/mullvad_dns.pcap.out +++ b/test/results/flow-info/default/mullvad_dns.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.122.11][51696] -> [........9.9.9.9][...53] + new: [.....1] [ip4][..udp] [.192.168.122.11][51696] -> [........9.9.9.9][...53] detected: [.....1] [ip4][..udp] [.192.168.122.11][51696] -> [........9.9.9.9][...53] [DNS.Mullvad][Unknown][Network][Acceptable][www.mullvad.net] detection-update: [.....1] [ip4][..udp] [.192.168.122.11][51696] -> [........9.9.9.9][...53] [DNS.Mullvad][Unknown][Network][Acceptable][www.mullvad.net] idle: [.....1] [ip4][..udp] [.192.168.122.11][51696] -> [........9.9.9.9][...53] [DNS.Mullvad][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/mullvad_wireguard.pcap.out b/test/results/flow-info/default/mullvad_wireguard.pcap.out index 392ed7c24..f2ca169a2 100644 --- a/test/results/flow-info/default/mullvad_wireguard.pcap.out +++ b/test/results/flow-info/default/mullvad_wireguard.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.122.11][22595] -> [..198.54.131.98][.5060] + new: [.....1] [ip4][..udp] [.192.168.122.11][22595] -> [..198.54.131.98][.5060] detected: [.....1] [ip4][..udp] [.192.168.122.11][22595] -> [..198.54.131.98][.5060] [WireGuard][Mullvad][VPN][Acceptable] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..udp] [.192.168.122.11][22595] -> [..198.54.131.98][.5060] [WireGuard][Mullvad][VPN][Acceptable] diff --git a/test/results/flow-info/default/munin.pcap.out b/test/results/flow-info/default/munin.pcap.out index 308512e28..201b24ac2 100644 --- a/test/results/flow-info/default/munin.pcap.out +++ b/test/results/flow-info/default/munin.pcap.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..172.16.16.108][45654] -> [..172.16.17.103][.4949] + new: [.....1] [ip4][..tcp] [..172.16.16.108][45654] -> [..172.16.17.103][.4949] detected: [.....1] [ip4][..tcp] [..172.16.16.108][45654] -> [..172.16.17.103][.4949] [Munin][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..172.16.16.108][55256] -> [..172.16.17.102][.4949] + new: [.....2] [ip4][..tcp] [..172.16.16.108][55256] -> [..172.16.17.102][.4949] detected: [.....2] [ip4][..tcp] [..172.16.16.108][55256] -> [..172.16.17.102][.4949] [Munin][Unknown][System][Acceptable] idle: [.....1] [ip4][..tcp] [..172.16.16.108][45654] -> [..172.16.17.103][.4949] [Munin][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..172.16.16.108][53314] -> [..172.16.17.101][.4949] + new: [.....3] [ip4][..tcp] [..172.16.16.108][53314] -> [..172.16.17.101][.4949] detected: [.....3] [ip4][..tcp] [..172.16.16.108][53314] -> [..172.16.17.101][.4949] [Munin][Unknown][System][Acceptable] idle: [.....2] [ip4][..tcp] [..172.16.16.108][55256] -> [..172.16.17.102][.4949] [Munin][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 45 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..172.16.16.108][59958] -> [....172.16.17.1][.4949] + new: [.....4] [ip4][..tcp] [..172.16.16.108][59958] -> [....172.16.17.1][.4949] detected: [.....4] [ip4][..tcp] [..172.16.16.108][59958] -> [....172.16.17.1][.4949] [Munin][Unknown][System][Acceptable] idle: [.....3] [ip4][..tcp] [..172.16.16.108][53314] -> [..172.16.17.101][.4949] [Munin][Unknown][System][Acceptable] idle: [.....4] [ip4][..tcp] [..172.16.16.108][59958] -> [....172.16.17.1][.4949] [Munin][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/mysql-8.pcap.out b/test/results/flow-info/default/mysql-8.pcap.out index ebb14f340..fd867ebd8 100644 --- a/test/results/flow-info/default/mysql-8.pcap.out +++ b/test/results/flow-info/default/mysql-8.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.105][.8738] -> [...10.42.18.198][.3306] + new: [.....1] [ip4][..tcp] [..192.168.1.105][.8738] -> [...10.42.18.198][.3306] detected: [.....1] [ip4][..tcp] [..192.168.1.105][.8738] -> [...10.42.18.198][.3306] [MySQL][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.20.80][47044] -> [.192.168.20.108][.3306] + new: [.....2] [ip4][..tcp] [..192.168.20.80][47044] -> [.192.168.20.108][.3306] detected: [.....2] [ip4][..tcp] [..192.168.20.80][47044] -> [.192.168.20.108][.3306] [MySQL][Unknown][Database][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.1.105][.8738] -> [...10.42.18.198][.3306] [MySQL][Unknown][Database][Acceptable] end: [.....2] [ip4][..tcp] [..192.168.20.80][47044] -> [.192.168.20.108][.3306] [MySQL][Unknown][Database][Acceptable] diff --git a/test/results/flow-info/default/natpmp.pcap.out b/test/results/flow-info/default/natpmp.pcap.out index a10809eb9..bba1b1bdf 100644 --- a/test/results/flow-info/default/natpmp.pcap.out +++ b/test/results/flow-info/default/natpmp.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] + new: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] detected: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] [NAT-PMP][Unknown][Network][Acceptable] detection-update: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] [NAT-PMP][Unknown][Network][Acceptable] detection-update: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] [NAT-PMP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][36845] -> [....192.168.2.1][.5351] + new: [.....2] [ip4][..udp] [..192.168.2.100][36845] -> [....192.168.2.1][.5351] detected: [.....2] [ip4][..udp] [..192.168.2.100][36845] -> [....192.168.2.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [..192.168.1.128][36852] -> [..192.168.1.254][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [..192.168.2.100][59817] -> [....192.168.2.1][.5351] + new: [.....3] [ip4][..udp] [..192.168.2.100][59817] -> [....192.168.2.1][.5351] detected: [.....3] [ip4][..udp] [..192.168.2.100][59817] -> [....192.168.2.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] detection-update: [.....3] [ip4][..udp] [..192.168.2.100][59817] -> [....192.168.2.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [.....4] [ip4][..udp] [..192.168.2.100][35763] -> [....192.168.2.1][.5351] + new: [.....4] [ip4][..udp] [..192.168.2.100][35763] -> [....192.168.2.1][.5351] detected: [.....4] [ip4][..udp] [..192.168.2.100][35763] -> [....192.168.2.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] detection-update: [.....4] [ip4][..udp] [..192.168.2.100][35763] -> [....192.168.2.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic diff --git a/test/results/flow-info/default/nats.pcap.out b/test/results/flow-info/default/nats.pcap.out index 0b63d305c..50686afb2 100644 --- a/test/results/flow-info/default/nats.pcap.out +++ b/test/results/flow-info/default/nats.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][54820] -> [......127.0.0.1][.4222] + new: [.....1] [ip4][..tcp] [......127.0.0.1][54820] -> [......127.0.0.1][.4222] detected: [.....1] [ip4][..tcp] [......127.0.0.1][54820] -> [......127.0.0.1][.4222] [Nats][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..tcp] [......127.0.0.1][54821] -> [......127.0.0.1][.4222] + new: [.....2] [ip4][..tcp] [......127.0.0.1][54821] -> [......127.0.0.1][.4222] detected: [.....2] [ip4][..tcp] [......127.0.0.1][54821] -> [......127.0.0.1][.4222] [Nats][Unknown][RPC][Acceptable] end: [.....1] [ip4][..tcp] [......127.0.0.1][54820] -> [......127.0.0.1][.4222] [Nats][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..tcp] [......127.0.0.1][54821] -> [......127.0.0.1][.4222] [Nats][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/ndpi_match_string_subprotocol__error.pcapng.out b/test/results/flow-info/default/ndpi_match_string_subprotocol__error.pcapng.out index 080276827..36a4d6237 100644 --- a/test/results/flow-info/default/ndpi_match_string_subprotocol__error.pcapng.out +++ b/test/results/flow-info/default/ndpi_match_string_subprotocol__error.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......10.3.9.19][40632] -> [..10.68.137.118][.8091] + new: [.....1] [ip4][..tcp] [......10.3.9.19][40632] -> [..10.68.137.118][.8091] detected: [.....1] [ip4][..tcp] [......10.3.9.19][40632] -> [..10.68.137.118][.8091] [HTTP.SOAP][Unknown][RPC][Acceptable][10.68.137.118] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI, Unidirectional Traffic detection-update: [.....1] [ip4][..tcp] [......10.3.9.19][40632] -> [..10.68.137.118][.8091] [HTTP.SOAP][Unknown][RPC][Acceptable][10.68.137.118] diff --git a/test/results/flow-info/default/nest_log_sink.pcap.out b/test/results/flow-info/default/nest_log_sink.pcap.out index 0e227124e..a76bf74a3 100644 --- a/test/results/flow-info/default/nest_log_sink.pcap.out +++ b/test/results/flow-info/default/nest_log_sink.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.242.15][63340] -> [..35.174.82.237][11095] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.192.168.242.15][63340] -> [..35.174.82.237][11095] [MIDSTREAM] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - analyse: [.....1] [ip4][..tcp] [.192.168.242.15][63340] -> [..35.174.82.237][11095] + analyse: [.....1] [ip4][..tcp] [.192.168.242.15][63340] -> [..35.174.82.237][11095] min| max| avg| stddev| variance| entropy [IAT.........: 0.061| 60.122| 38.821| 28.558| 815563555.209| 4.300] [PKTLEN......: 40.000| 46.000| 43.000| 3.000| 9.000| 5.000] @@ -18,10 +18,10 @@ detected: [.....1] [ip4][..tcp] [.192.168.242.15][63340] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] DAEMON-EVENT: [Processed: 60 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] + new: [.....2] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] detected: [.....2] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] detection-update: [.....2] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] - new: [.....3] [ip4][..tcp] [.192.168.242.15][63342] -> [.35.188.154.186][11095] + new: [.....3] [ip4][..tcp] [.192.168.242.15][63342] -> [.35.188.154.186][11095] detected: [.....3] [ip4][..tcp] [.192.168.242.15][63342] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] analyse: [.....3] [ip4][..tcp] [.192.168.242.15][63342] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -33,9 +33,9 @@ [IATS(ms)....: 69.7,72.2,635.6,708.3,5.3,110.8,1347.4,1490.6,118.0,84.3,0.1,88.9,80.3,82.8,83.4,80.0,80.0,80.2,79.6,79.6,80.9,81.4,80.7,80.0,79.3,79.3,79.9,72.2,8.5,80.0,81.8] [PKTLENS.....: 46,44,46,571,40,719,46,92,40,110,40,97,495,95,495,95,495,95,495,95,495,95,495,95,495,95,495,95,46,495,95,495] [ENTROPIES...: 4.3,4.9,4.4,6.9,4.8,7.1,4.5,5.4,5.0,5.9,5.0,5.7,7.5,5.7,7.5,5.7,7.5,5.7,7.5,5.8,7.5,5.6,7.5,5.7,7.6,5.6,7.6,5.8,4.4,7.5,5.7,7.5] - new: [.....4] [ip4][..tcp] [.192.168.242.15][63343] -> [..35.174.82.237][11095] + new: [.....4] [ip4][..tcp] [.192.168.242.15][63343] -> [..35.174.82.237][11095] detected: [.....4] [ip4][..tcp] [.192.168.242.15][63343] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] - new: [.....5] [ip4][..tcp] [.192.168.242.15][63344] -> [.35.188.154.186][11095] + new: [.....5] [ip4][..tcp] [.192.168.242.15][63344] -> [.35.188.154.186][11095] detected: [.....5] [ip4][..tcp] [.192.168.242.15][63344] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] update: [.....2] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable] analyse: [.....4] [ip4][..tcp] [.192.168.242.15][63343] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] @@ -59,10 +59,10 @@ DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 1|detection-updates: 1|updates: 2] DAEMON-EVENT: [Processed: 275 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 1|detection-updates: 1|updates: 2] - new: [.....6] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] + new: [.....6] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] detected: [.....6] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] detection-update: [.....6] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] - new: [.....7] [ip4][..tcp] [.192.168.242.15][63345] -> [.35.188.154.186][11095] + new: [.....7] [ip4][..tcp] [.192.168.242.15][63345] -> [.35.188.154.186][11095] detected: [.....7] [ip4][..tcp] [.192.168.242.15][63345] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] analyse: [.....7] [ip4][..tcp] [.192.168.242.15][63345] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -74,9 +74,9 @@ [IATS(ms)....: 61.0,66.3,638.6,696.7,5.2,274.7,1166.9,1477.5,96.3,57.0,0.0,69.6,64.9,63.5,66.2,66.3,63.9,64.1,63.9,63.8,65.2,65.0,63.2,63.3,64.2,64.1,63.8,54.1,11.8,65.2,63.5] [PKTLENS.....: 46,44,46,570,40,718,46,92,40,110,40,97,495,95,495,95,495,95,495,95,495,95,495,95,495,95,495,95,46,495,95,495] [ENTROPIES...: 4.4,5.0,4.4,6.9,4.8,7.1,4.3,5.4,4.7,5.8,4.7,5.6,7.5,5.7,7.5,5.7,7.5,5.7,7.6,5.7,7.5,5.6,7.5,5.6,7.5,5.7,7.5,5.7,4.4,7.5,5.7,7.6] - new: [.....8] [ip4][..tcp] [.192.168.242.15][63346] -> [..35.174.82.237][11095] + new: [.....8] [ip4][..tcp] [.192.168.242.15][63346] -> [..35.174.82.237][11095] detected: [.....8] [ip4][..tcp] [.192.168.242.15][63346] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] - new: [.....9] [ip4][..tcp] [.192.168.242.15][63347] -> [.35.188.154.186][11095] + new: [.....9] [ip4][..tcp] [.192.168.242.15][63347] -> [.35.188.154.186][11095] detected: [.....9] [ip4][..tcp] [.192.168.242.15][63347] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] update: [.....6] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable] end: [.....4] [ip4][..tcp] [.192.168.242.15][63343] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] @@ -98,12 +98,12 @@ DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 1|detection-updates: 2|updates: 4] DAEMON-EVENT: [Processed: 452 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 1|detection-updates: 2|updates: 4] - new: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] + new: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] detected: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] detection-update: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] RISK: Unidirectional Traffic detection-update: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] - new: [....11] [ip4][..tcp] [.192.168.242.15][63348] -> [.35.188.154.186][11095] + new: [....11] [ip4][..tcp] [.192.168.242.15][63348] -> [.35.188.154.186][11095] detected: [....11] [ip4][..tcp] [.192.168.242.15][63348] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] analyse: [....11] [ip4][..tcp] [.192.168.242.15][63348] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -115,7 +115,7 @@ [IATS(ms)....: 56.8,63.4,631.1,692.5,5.0,275.3,1167.1,1475.0,94.9,57.0,0.0,68.3,63.6,63.6,63.3,63.5,64.3,71.1,70.3,64.3,64.5,64.0,64.3,64.3,63.7,63.2,62.9,53.1,10.8,65.0,64.0] [PKTLENS.....: 46,44,46,570,40,718,46,92,40,110,40,97,495,95,495,95,495,95,495,95,495,95,495,95,495,95,495,95,46,495,95,495] [ENTROPIES...: 4.4,5.0,4.4,6.9,4.9,7.1,4.5,5.4,5.0,5.9,4.9,5.7,7.5,5.7,7.6,5.7,7.5,5.7,7.5,5.7,7.5,5.6,7.5,5.7,7.5,5.9,7.5,5.7,4.4,7.5,5.7,7.5] - new: [....12] [ip4][..tcp] [.192.168.242.15][63349] -> [..35.174.82.237][11095] + new: [....12] [ip4][..tcp] [.192.168.242.15][63349] -> [..35.174.82.237][11095] detected: [....12] [ip4][..tcp] [.192.168.242.15][63349] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] update: [....10] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable] end: [.....8] [ip4][..tcp] [.192.168.242.15][63346] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] @@ -134,13 +134,13 @@ [ENTROPIES...: 4.3,5.0,4.4,7.0,4.9,7.1,4.5,5.4,5.0,6.9,4.9,5.6,6.4,7.6,4.3,6.8,6.7,4.5,6.8,6.8,7.3,5.8,4.5,4.4,4.9,4.5,4.9,4.5,4.9,4.5,4.9,5.0] DAEMON-EVENT: [Processed: 562 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 12|skipped: 0|!detected: 0|guessed: 1|detection-updates: 4|updates: 6] - new: [....13] [ip4][..tcp] [.192.168.242.15][63350] -> [..35.174.82.237][11095] + new: [....13] [ip4][..tcp] [.192.168.242.15][63350] -> [..35.174.82.237][11095] detected: [....13] [ip4][..tcp] [.192.168.242.15][63350] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] end: [....12] [ip4][..tcp] [.192.168.242.15][63349] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] - new: [....14] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] + new: [....14] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] detected: [....14] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] detection-update: [....14] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable][weave-logsink.nest.com] - new: [....15] [ip4][..tcp] [.192.168.242.15][63351] -> [.35.188.154.186][11095] + new: [....15] [ip4][..tcp] [.192.168.242.15][63351] -> [.35.188.154.186][11095] detected: [....15] [ip4][..tcp] [.192.168.242.15][63351] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] analyse: [....15] [ip4][..tcp] [.192.168.242.15][63351] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] min| max| avg| stddev| variance| entropy @@ -152,7 +152,7 @@ [IATS(ms)....: 55.5,58.1,637.6,698.6,8.3,132.5,1319.8,1484.0,100.9,62.4,0.0,73.7,66.3,66.1,64.4,70.8,72.5,66.2,63.7,65.4,67.1,65.6,63.5,64.0,64.9,67.0,66.2,76.4,5.2,82.4,64.4] [PKTLENS.....: 46,44,46,570,40,719,46,92,40,110,40,97,495,95,495,95,495,95,495,95,495,95,495,95,495,95,495,95,46,495,95,495] [ENTROPIES...: 4.3,5.0,4.4,7.0,5.0,7.1,4.5,5.5,5.0,5.8,4.9,5.6,7.6,5.8,7.5,5.7,7.5,5.7,7.5,5.7,7.5,5.7,7.5,5.7,7.6,5.7,7.5,5.7,4.3,7.5,5.7,7.5] - new: [....16] [ip4][..tcp] [.192.168.242.15][63352] -> [..35.174.82.237][11095] + new: [....16] [ip4][..tcp] [.192.168.242.15][63352] -> [..35.174.82.237][11095] analyse: [....13] [ip4][..tcp] [.192.168.242.15][63350] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.001| 60.156| 9.910| 20.689| 428051338.887| 2.700] @@ -164,7 +164,7 @@ [PKTLENS.....: 46,44,46,571,40,717,46,92,40,244,40,100,162,669,46,220,190,220,201,46,332,102,46,46,40,40,46,102,40,46,46,40] [ENTROPIES...: 4.3,4.9,4.4,6.9,4.9,7.1,4.5,5.3,5.0,6.9,5.0,5.8,6.5,7.7,4.4,6.8,6.5,6.9,6.8,4.5,7.2,5.9,4.5,4.5,5.0,5.0,4.5,5.6,5.0,4.5,4.6,5.0] detected: [....16] [ip4][..tcp] [.192.168.242.15][63352] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] - new: [....17] [ip4][..tcp] [.192.168.242.15][63353] -> [.35.188.154.186][11095] + new: [....17] [ip4][..tcp] [.192.168.242.15][63353] -> [.35.188.154.186][11095] detected: [....17] [ip4][..tcp] [.192.168.242.15][63353] -> [.35.188.154.186][11095] [NestLogSink][GoogleCloud][Cloud][Acceptable] update: [....14] [ip4][..udp] [.192.168.242.15][52849] -> [..192.168.242.1][...53] [DNS][Unknown][Network][Acceptable] end: [....13] [ip4][..tcp] [.192.168.242.15][63350] -> [..35.174.82.237][11095] [NestLogSink][AmazonAWS][Cloud][Acceptable] diff --git a/test/results/flow-info/default/netbios.pcap.out b/test/results/flow-info/default/netbios.pcap.out index fb107369b..b9ccd0936 100644 --- a/test/results/flow-info/default/netbios.pcap.out +++ b/test/results/flow-info/default/netbios.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.0.4.131][..137] -> [.....10.0.5.255][..137] + new: [.....1] [ip4][..udp] [.....10.0.4.131][..137] -> [.....10.0.5.255][..137] detected: [.....1] [ip4][..udp] [.....10.0.4.131][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][xstream_hy] - new: [.....2] [ip4][..udp] [.....10.0.5.233][..137] -> [.....10.0.5.255][..137] + new: [.....2] [ip4][..udp] [.....10.0.5.233][..137] -> [.....10.0.5.255][..137] detected: [.....2] [ip4][..udp] [.....10.0.5.233][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][ozi] - new: [.....3] [ip4][..udp] [.......10.0.5.9][..138] -> [.....10.0.5.255][..138] + new: [.....3] [ip4][..udp] [.......10.0.5.9][..138] -> [.....10.0.5.255][..138] detected: [.....3] [ip4][..udp] [.......10.0.5.9][..138] -> [.....10.0.5.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][nvr9] RISK: Unsafe Protocol - new: [.....4] [ip4][..tcp] [......10.0.4.24][..139] -> [.....10.0.4.131][.1398] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [......10.0.4.24][..139] -> [.....10.0.4.131][.1398] [MIDSTREAM] analyse: [.....1] [ip4][..udp] [.....10.0.4.131][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.014| 0.750| 0.325| 0.215| 46083.158| 4.600] @@ -19,26 +19,26 @@ [IATS(ms)....: 471.3,14.0,264.7,470.8,80.2,113.8,555.8,80.0,113.3,146.8,489.8,113.3,146.4,750.0,33.7,749.5,308.6,441.4,307.6,628.9,121.0,628.9,471.0,279.0,470.7,458.5,291.5,334.2,123.8,93.1,532.9] [PKTLENS.....: 78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78] [ENTROPIES...: 4.1,4.1,4.2,4.1,4.1,4.1,4.1,4.1,4.2,4.2,4.2,4.2,4.2,4.2,4.2,4.1,4.1,4.2,4.1,4.2,4.1,4.2,4.1,4.2,4.1,4.2,4.2,4.2,4.1,4.2,4.2,4.2] - new: [.....5] [ip4][..udp] [......10.0.1.87][57836] -> [......10.0.4.24][..137] + new: [.....5] [ip4][..udp] [......10.0.1.87][57836] -> [......10.0.4.24][..137] detected: [.....5] [ip4][..udp] [......10.0.1.87][57836] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable][*] - new: [.....6] [ip4][..udp] [.....10.0.4.101][..137] -> [.....10.0.5.255][..137] + new: [.....6] [ip4][..udp] [.....10.0.4.101][..137] -> [.....10.0.5.255][..137] detected: [.....6] [ip4][..udp] [.....10.0.4.101][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][muli] - new: [.....7] [ip4][..udp] [.....10.0.4.165][..137] -> [.....10.0.5.255][..137] + new: [.....7] [ip4][..udp] [.....10.0.4.165][..137] -> [.....10.0.5.255][..137] detected: [.....7] [ip4][..udp] [.....10.0.4.165][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][gunnar] - new: [.....8] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.4.165][..137] + new: [.....8] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.4.165][..137] detected: [.....8] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.4.165][..137] [NetBIOS][Unknown][System][Acceptable][gunnar] - new: [.....9] [ip4][..udp] [......10.0.4.66][..137] -> [.....10.0.5.255][..137] + new: [.....9] [ip4][..udp] [......10.0.4.66][..137] -> [.....10.0.5.255][..137] detected: [.....9] [ip4][..udp] [......10.0.4.66][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][guru] - new: [....10] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.5.255][..137] + new: [....10] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.5.255][..137] detected: [....10] [ip4][..udp] [......10.0.4.24][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][guru] - new: [....11] [ip4][..udp] [.......10.0.5.1][..137] -> [......10.0.4.24][..137] + new: [....11] [ip4][..udp] [.......10.0.5.1][..137] -> [......10.0.4.24][..137] detected: [....11] [ip4][..udp] [.......10.0.5.1][..137] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable][guru] - new: [....12] [ip4][..udp] [......10.0.5.93][..138] -> [.....10.0.5.255][..138] + new: [....12] [ip4][..udp] [......10.0.5.93][..138] -> [.....10.0.5.255][..138] detected: [....12] [ip4][..udp] [......10.0.5.93][..138] -> [.....10.0.5.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][bowie] RISK: Unsafe Protocol - new: [....13] [ip4][..udp] [.....10.0.5.233][..137] -> [......10.0.4.24][..137] + new: [....13] [ip4][..udp] [.....10.0.5.233][..137] -> [......10.0.4.24][..137] detected: [....13] [ip4][..udp] [.....10.0.5.233][..137] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable][*] - new: [....14] [ip4][..udp] [......10.0.4.14][..137] -> [.....10.0.5.255][..137] + new: [....14] [ip4][..udp] [......10.0.4.14][..137] -> [.....10.0.5.255][..137] detected: [....14] [ip4][..udp] [......10.0.4.14][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable][guru] analyse: [.....2] [ip4][..udp] [.....10.0.5.233][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable] min| max| avg| stddev| variance| entropy @@ -50,7 +50,7 @@ [IATS(ms)....: 749.4,750.1,1510.9,749.4,750.1,1512.1,749.1,750.1,1513.7,749.6,750.2,1509.2,749.9,750.1,1511.1,749.1,750.1,1516.0,749.2,750.1,1508.0,749.3,750.1,1513.5,749.8,750.0,1513.1,749.2,750.1,1506.9,749.4] [PKTLENS.....: 78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78,78] [ENTROPIES...: 3.9,3.9,3.9,3.9,3.8,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.9,3.8,3.9] - new: [....15] [ip4][..udp] [......10.0.1.87][57921] -> [......10.0.4.24][..137] + new: [....15] [ip4][..udp] [......10.0.1.87][57921] -> [......10.0.4.24][..137] detected: [....15] [ip4][..udp] [......10.0.1.87][57921] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable][*] update: [.....1] [ip4][..udp] [.....10.0.4.131][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [.....2] [ip4][..udp] [.....10.0.5.233][..137] -> [.....10.0.5.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -73,5 +73,5 @@ idle: [.....5] [ip4][..udp] [......10.0.1.87][57836] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....15] [ip4][..udp] [......10.0.1.87][57921] -> [......10.0.4.24][..137] [NetBIOS][Unknown][System][Acceptable] guessed: [.....4] [ip4][..tcp] [......10.0.4.24][..139] -> [.....10.0.4.131][.1398] [NetBIOS][Unknown][System][Acceptable][] - idle: [.....4] [ip4][..tcp] [......10.0.4.24][..139] -> [.....10.0.4.131][.1398] + idle: [.....4] [ip4][..tcp] [......10.0.4.24][..139] -> [.....10.0.4.131][.1398] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/netbios_wildcard_dns_query.pcap.out b/test/results/flow-info/default/netbios_wildcard_dns_query.pcap.out index 599ac8855..66500377b 100644 --- a/test/results/flow-info/default/netbios_wildcard_dns_query.pcap.out +++ b/test/results/flow-info/default/netbios_wildcard_dns_query.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....10.1.67.250][41335] -> [.....10.1.66.20][...53] + new: [.....1] [ip4][..udp] [....10.1.67.250][41335] -> [.....10.1.66.20][...53] detected: [.....1] [ip4][..udp] [....10.1.67.250][41335] -> [.....10.1.66.20][...53] [DNS][Unknown][Network][Acceptable][ckaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa] idle: [.....1] [ip4][..udp] [....10.1.67.250][41335] -> [.....10.1.66.20][...53] [DNS][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/netflix.pcap.out b/test/results/flow-info/default/netflix.pcap.out index 9dd848333..2f75626d8 100644 --- a/test/results/flow-info/default/netflix.pcap.out +++ b/test/results/flow-info/default/netflix.pcap.out @@ -1,22 +1,22 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.1.7][52929] -> [.....52.24.87.6][..443] [MIDSTREAM] - new: [.....2] [ip4][..udp] [....192.168.1.7][51543] -> [....192.168.1.1][...53] + new: [.....1] [ip4][..tcp] [....192.168.1.7][52929] -> [.....52.24.87.6][..443] [MIDSTREAM] + new: [.....2] [ip4][..udp] [....192.168.1.7][51543] -> [....192.168.1.1][...53] detected: [.....2] [ip4][..udp] [....192.168.1.7][51543] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] detection-update: [.....2] [ip4][..udp] [....192.168.1.7][51543] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] RISK: Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [....192.168.1.7][51543] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] - new: [.....3] [ip4][..udp] [....192.168.1.7][52116] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [....192.168.1.7][52116] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [....192.168.1.7][52116] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ichnaea.us-west-2.prodaa.netflix.com] detection-update: [.....3] [ip4][..udp] [....192.168.1.7][52116] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ichnaea.us-west-2.prodaa.netflix.com] - new: [.....4] [ip4][..tcp] [....192.168.1.7][53105] -> [..54.69.204.241][..443] - new: [.....5] [ip4][..tcp] [....192.168.1.7][53114] -> [...54.191.17.51][..443] + new: [.....4] [ip4][..tcp] [....192.168.1.7][53105] -> [..54.69.204.241][..443] + new: [.....5] [ip4][..tcp] [....192.168.1.7][53114] -> [...54.191.17.51][..443] detected: [.....4] [ip4][..tcp] [....192.168.1.7][53105] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detected: [.....5] [ip4][..tcp] [....192.168.1.7][53114] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....6] [ip4][..tcp] [....192.168.1.7][53115] -> [...52.32.196.36][..443] - new: [.....7] [ip4][..tcp] [....192.168.1.7][53116] -> [...52.32.196.36][..443] + new: [.....6] [ip4][..tcp] [....192.168.1.7][53115] -> [...52.32.196.36][..443] + new: [.....7] [ip4][..tcp] [....192.168.1.7][53116] -> [...52.32.196.36][..443] detection-update: [.....4] [ip4][..tcp] [....192.168.1.7][53105] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [.....4] [ip4][..tcp] [....192.168.1.7][53105] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [.....5] [ip4][..tcp] [....192.168.1.7][53114] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] @@ -29,7 +29,7 @@ detection-update: [.....6] [ip4][..tcp] [....192.168.1.7][53115] -> [...52.32.196.36][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] detection-update: [.....7] [ip4][..tcp] [....192.168.1.7][53116] -> [...52.32.196.36][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] detection-update: [.....7] [ip4][..tcp] [....192.168.1.7][53116] -> [...52.32.196.36][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] - new: [.....8] [ip4][..tcp] [....192.168.1.7][53117] -> [...52.32.196.36][..443] + new: [.....8] [ip4][..tcp] [....192.168.1.7][53117] -> [...52.32.196.36][..443] detected: [.....8] [ip4][..tcp] [....192.168.1.7][53117] -> [...52.32.196.36][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....8] [ip4][..tcp] [....192.168.1.7][53117] -> [...52.32.196.36][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] @@ -44,23 +44,23 @@ [IATS(ms)....: 46.0,48.6,0.6,54.0,1.6,1.0,54.9,11.1,13.5,9.4,0.3,0.4,58.7,4.6,50.8,1.9,0.2,59.5,0.6,62.1,8.5,4.7,310.9,0.6,363.7,5.8,0.1,0.1,58.1,0.2,0.1] [PKTLENS.....: 64,60,52,260,52,1500,1500,52,215,52,127,58,97,52,103,52,408,362,52,992,52,112,52,408,361,52,992,107,86,52,52,52] [ENTROPIES...: 4.6,5.3,5.1,5.7,5.2,7.3,7.3,5.1,6.9,5.2,6.4,5.1,6.1,5.2,5.9,5.2,7.5,7.4,5.2,7.8,5.1,6.1,5.1,7.4,7.4,5.2,7.8,6.1,5.8,5.2,5.2,5.1] - new: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] + new: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] detected: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] - new: [....10] [ip4][..udp] [....192.168.1.7][53776] -> [239.255.255.250][.1900] + new: [....10] [ip4][..udp] [....192.168.1.7][53776] -> [239.255.255.250][.1900] detected: [....10] [ip4][..udp] [....192.168.1.7][53776] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] + new: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] detected: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] detection-update: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] - new: [....12] [ip4][....2] [....192.168.1.7] -> [239.255.255.250] + new: [....12] [ip4][....2] [....192.168.1.7] -> [239.255.255.250] detected: [....12] [ip4][....2] [....192.168.1.7] -> [239.255.255.250] [IGMP][Unknown][Network][Acceptable] - new: [....13] [ip4][..udp] [....192.168.1.7][51949] -> [....192.168.1.1][...53] + new: [....13] [ip4][..udp] [....192.168.1.7][51949] -> [....192.168.1.1][...53] detected: [....13] [ip4][..udp] [....192.168.1.7][51949] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][api-global.latency.prodaa.netflix.com] detection-update: [....13] [ip4][..udp] [....192.168.1.7][51949] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][api-global.latency.prodaa.netflix.com] - new: [....14] [ip4][..tcp] [....192.168.1.7][53132] -> [...52.89.39.139][..443] - new: [....15] [ip4][..tcp] [....192.168.1.7][53133] -> [...52.89.39.139][..443] + new: [....14] [ip4][..tcp] [....192.168.1.7][53132] -> [...52.89.39.139][..443] + new: [....15] [ip4][..tcp] [....192.168.1.7][53133] -> [...52.89.39.139][..443] detected: [....14] [ip4][..tcp] [....192.168.1.7][53132] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....15] [ip4][..tcp] [....192.168.1.7][53133] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] @@ -73,7 +73,7 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....15] [ip4][..tcp] [....192.168.1.7][53133] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....16] [ip4][..tcp] [....192.168.1.7][53134] -> [...52.89.39.139][..443] + new: [....16] [ip4][..tcp] [....192.168.1.7][53134] -> [...52.89.39.139][..443] detected: [....16] [ip4][..tcp] [....192.168.1.7][53134] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....16] [ip4][..tcp] [....192.168.1.7][53134] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] @@ -90,10 +90,10 @@ [ENTROPIES...: 4.6,5.2,5.1,6.0,5.2,7.3,7.3,5.1,7.0,5.1,6.3,5.0,6.0,5.2,5.9,5.1,7.9,7.7,5.2,7.9,7.9,5.1,7.9,7.9,5.1,7.9,5.0,7.1,5.1,7.9,7.8,5.1] detection-update: [....15] [ip4][..tcp] [....192.168.1.7][53133] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....17] [ip4][..udp] [....192.168.1.7][57719] -> [....192.168.1.1][...53] + new: [....17] [ip4][..udp] [....192.168.1.7][57719] -> [....192.168.1.1][...53] detected: [....17] [ip4][..udp] [....192.168.1.7][57719] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][sha2.san.akam.nflximg.net] detection-update: [....17] [ip4][..udp] [....192.168.1.7][57719] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][sha2.san.akam.nflximg.net] - new: [....18] [ip4][..tcp] [....192.168.1.7][53141] -> [..104.86.97.179][..443] + new: [....18] [ip4][..tcp] [....192.168.1.7][53141] -> [..104.86.97.179][..443] detected: [....18] [ip4][..tcp] [....192.168.1.7][53141] -> [..104.86.97.179][..443] [TLS.NetFlix][Unknown][Video][Fun][art-s.nflximg.net] detection-update: [....18] [ip4][..tcp] [....192.168.1.7][53141] -> [..104.86.97.179][..443] [TLS.NetFlix][Unknown][Video][Fun][art-s.nflximg.net] detection-update: [....18] [ip4][..tcp] [....192.168.1.7][53141] -> [..104.86.97.179][..443] [TLS.NetFlix][Unknown][Video][Fun][art-s.nflximg.net] @@ -109,19 +109,19 @@ [ENTROPIES...: 4.6,5.3,5.1,6.0,5.2,7.3,7.3,5.1,7.1,5.1,6.4,5.1,6.0,5.2,6.0,5.2,7.9,7.7,5.2,5.2,6.8,6.1,5.9,5.2,5.2,5.2,7.9,7.7,5.2,5.2,7.9,7.5] detection-update: [....14] [ip4][..tcp] [....192.168.1.7][53132] -> [...52.89.39.139][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....19] [ip4][..udp] [....192.168.1.7][59180] -> [....192.168.1.1][...53] + new: [....19] [ip4][..udp] [....192.168.1.7][59180] -> [....192.168.1.1][...53] detected: [....19] [ip4][..udp] [....192.168.1.7][59180] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][artwork.akam.nflximg.net] detection-update: [....19] [ip4][..udp] [....192.168.1.7][59180] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][artwork.akam.nflximg.net] - new: [....20] [ip4][..tcp] [....192.168.1.7][53148] -> [..184.25.204.25][...80] - new: [....21] [ip4][..tcp] [....192.168.1.7][53149] -> [..184.25.204.25][...80] + new: [....20] [ip4][..tcp] [....192.168.1.7][53148] -> [..184.25.204.25][...80] + new: [....21] [ip4][..tcp] [....192.168.1.7][53149] -> [..184.25.204.25][...80] detected: [....20] [ip4][..tcp] [....192.168.1.7][53148] -> [..184.25.204.25][...80] [HTTP.NetFlix][Unknown][Video][Fun][art-2.nflximg.net] detected: [....21] [ip4][..tcp] [....192.168.1.7][53149] -> [..184.25.204.25][...80] [HTTP.NetFlix][Unknown][Video][Fun][art-2.nflximg.net] - new: [....22] [ip4][..tcp] [....192.168.1.7][53150] -> [..184.25.204.25][...80] + new: [....22] [ip4][..tcp] [....192.168.1.7][53150] -> [..184.25.204.25][...80] detected: [....22] [ip4][..tcp] [....192.168.1.7][53150] -> [..184.25.204.25][...80] [HTTP.NetFlix][Unknown][Video][Fun][art-2.nflximg.net] - new: [....23] [ip4][..udp] [....192.168.1.7][58102] -> [....192.168.1.1][...53] + new: [....23] [ip4][..udp] [....192.168.1.7][58102] -> [....192.168.1.1][...53] detected: [....23] [ip4][..udp] [....192.168.1.7][58102] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][appboot.netflix.com] detection-update: [....23] [ip4][..udp] [....192.168.1.7][58102] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][appboot.netflix.com] - new: [....24] [ip4][..tcp] [....192.168.1.7][53151] -> [.54.201.191.132][...80] + new: [....24] [ip4][..tcp] [....192.168.1.7][53151] -> [.54.201.191.132][...80] detected: [....24] [ip4][..tcp] [....192.168.1.7][53151] -> [.54.201.191.132][...80] [HTTP.NetFlix][AmazonAWS][Video][Fun][appboot.netflix.com] analyse: [....24] [ip4][..tcp] [....192.168.1.7][53151] -> [.54.201.191.132][...80] [HTTP.NetFlix][AmazonAWS][Video][Fun] min| max| avg| stddev| variance| entropy @@ -133,11 +133,11 @@ [IATS(ms)....: 44.1,45.6,3.9,10.7,0.2,60.0,5.7,1.0,135.1,0.3,187.2,5.7,5.7,13.9,14.0,13.3,14.4,27.8,13.3,13.1,9.2,13.3,22.5,13.4,39.3,13.3,13.3,13.9,13.3,13.3,124.5] [PKTLENS.....: 64,60,52,365,1500,903,52,52,52,714,1500,52,1500,52,1500,52,1500,1500,52,1012,52,1500,1293,52,1500,1500,1500,1500,1500,1500,1500,64] [ENTROPIES...: 4.5,5.3,5.2,5.7,6.0,6.1,5.3,5.3,5.3,6.0,5.7,5.1,6.1,5.2,5.9,5.0,5.8,5.8,5.2,5.8,5.2,5.8,5.8,5.2,5.8,5.8,5.8,5.8,5.8,5.8,5.8,5.2] - new: [....25] [ip4][..tcp] [....192.168.1.7][53152] -> [...52.89.39.139][...80] + new: [....25] [ip4][..tcp] [....192.168.1.7][53152] -> [...52.89.39.139][...80] detected: [....25] [ip4][..tcp] [....192.168.1.7][53152] -> [...52.89.39.139][...80] [HTTP.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] - new: [....26] [ip4][..udp] [....192.168.1.7][51728] -> [....192.168.1.1][...53] + new: [....26] [ip4][..udp] [....192.168.1.7][51728] -> [....192.168.1.1][...53] detected: [....26] [ip4][..udp] [....192.168.1.7][51728] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][a803.dscg.akamai.net] - new: [....27] [ip4][..udp] [....192.168.1.7][52347] -> [....192.168.1.1][...53] + new: [....27] [ip4][..udp] [....192.168.1.7][52347] -> [....192.168.1.1][...53] detected: [....27] [ip4][..udp] [....192.168.1.7][52347] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] analyse: [....20] [ip4][..tcp] [....192.168.1.7][53148] -> [..184.25.204.25][...80] [HTTP.NetFlix][Unknown][Video][Fun] min| max| avg| stddev| variance| entropy @@ -150,9 +150,9 @@ [PKTLENS.....: 64,60,52,298,52,1500,1500,52,1500,52,1500,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,80,80,80,72,64,52,52,297,1500,1500] [ENTROPIES...: 4.6,5.2,5.1,5.9,5.3,7.5,7.8,5.1,7.8,5.0,7.8,7.8,5.2,7.8,7.8,7.8,7.8,7.8,7.8,7.9,7.9,7.9,5.4,5.2,5.3,5.4,5.3,5.2,5.2,5.8,7.2,7.8] detection-update: [....26] [ip4][..udp] [....192.168.1.7][51728] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][a803.dscg.akamai.net] - new: [....28] [ip4][..tcp] [....192.168.1.7][53153] -> [..184.25.204.24][...80] + new: [....28] [ip4][..tcp] [....192.168.1.7][53153] -> [..184.25.204.24][...80] detection-update: [....27] [ip4][..udp] [....192.168.1.7][52347] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] - new: [....29] [ip4][..tcp] [....192.168.1.7][53162] -> [...54.191.17.51][..443] + new: [....29] [ip4][..tcp] [....192.168.1.7][53162] -> [...54.191.17.51][..443] detected: [....28] [ip4][..tcp] [....192.168.1.7][53153] -> [..184.25.204.24][...80] [HTTP.NetFlix][Unknown][Video][Fun][tp.akam.nflximg.com] detected: [....29] [ip4][..tcp] [....192.168.1.7][53162] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS @@ -162,7 +162,7 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....29] [ip4][..tcp] [....192.168.1.7][53162] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....30] [ip4][..tcp] [....192.168.1.7][53163] -> [..23.246.11.145][...80] + new: [....30] [ip4][..tcp] [....192.168.1.7][53163] -> [..23.246.11.145][...80] detected: [....30] [ip4][..tcp] [....192.168.1.7][53163] -> [..23.246.11.145][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.145] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....30] [ip4][..tcp] [....192.168.1.7][53163] -> [..23.246.11.145][...80] [HTTP][NetFlix][Download][Acceptable][23.246.11.145] @@ -177,12 +177,12 @@ [IATS(ms)....: 24.8,26.3,3.8,42.5,4.8,43.8,27.2,40.5,69.4,43.9,44.8,78.3,38.8,79.8,102.6,28.8,14.7,354.3,85.0,14.1,12.4,12.7,651.0,22.9,582.5,8.6,27.5,16.4,16.4,14.7,15.1] [PKTLENS.....: 64,60,52,408,567,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,80,1500,1500,1500,1500,64,52,1500,1500,52,1500,52,1500,1500] [ENTROPIES...: 4.6,5.3,5.1,6.4,5.9,3.6,5.2,2.5,2.5,5.1,2.5,5.1,2.5,2.6,2.6,3.8,3.8,3.8,5.3,3.9,3.5,3.5,3.5,5.1,5.2,3.5,3.5,5.2,3.5,5.0,3.6,3.6] - new: [....31] [ip4][..tcp] [....192.168.1.7][53164] -> [..23.246.10.139][...80] + new: [....31] [ip4][..tcp] [....192.168.1.7][53164] -> [..23.246.10.139][...80] detected: [....31] [ip4][..tcp] [....192.168.1.7][53164] -> [..23.246.10.139][...80] [HTTP][NetFlix][Web][Acceptable][23.246.10.139] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....31] [ip4][..tcp] [....192.168.1.7][53164] -> [..23.246.10.139][...80] [HTTP][NetFlix][Download][Acceptable][23.246.10.139] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....32] [ip4][..tcp] [....192.168.1.7][53171] -> [...23.246.3.140][...80] + new: [....32] [ip4][..tcp] [....192.168.1.7][53171] -> [...23.246.3.140][...80] detected: [....32] [ip4][..tcp] [....192.168.1.7][53171] -> [...23.246.3.140][...80] [HTTP][NetFlix][Web][Acceptable][23.246.3.140] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....32] [ip4][..tcp] [....192.168.1.7][53171] -> [...23.246.3.140][...80] [HTTP][NetFlix][Download][Acceptable][23.246.3.140] @@ -197,23 +197,23 @@ [IATS(ms)....: 30.8,32.5,5.5,44.3,2.2,41.1,2.9,12.8,15.6,14.9,15.0,12.8,12.7,26.4,12.8,11.9,13.3,17.2,31.0,13.3,13.6,25.6,14.3,13.9,26.7,13.8,13.3,27.2,13.3,13.3,27.2] [PKTLENS.....: 64,60,52,406,571,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500] [ENTROPIES...: 4.5,5.3,5.1,6.4,5.8,3.6,5.2,2.5,2.6,5.2,2.6,5.0,2.6,2.6,5.2,2.5,5.0,2.6,2.6,5.2,2.5,5.1,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.9,3.5] - new: [....33] [ip4][..tcp] [....192.168.1.7][53172] -> [..23.246.11.133][...80] - new: [....34] [ip4][..tcp] [....192.168.1.7][53173] -> [..23.246.11.133][...80] - new: [....35] [ip4][..tcp] [....192.168.1.7][53174] -> [..23.246.11.141][...80] - new: [....36] [ip4][..tcp] [....192.168.1.7][53175] -> [..23.246.11.141][...80] + new: [....33] [ip4][..tcp] [....192.168.1.7][53172] -> [..23.246.11.133][...80] + new: [....34] [ip4][..tcp] [....192.168.1.7][53173] -> [..23.246.11.133][...80] + new: [....35] [ip4][..tcp] [....192.168.1.7][53174] -> [..23.246.11.141][...80] + new: [....36] [ip4][..tcp] [....192.168.1.7][53175] -> [..23.246.11.141][...80] detected: [....33] [ip4][..tcp] [....192.168.1.7][53172] -> [..23.246.11.133][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.133] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....37] [ip4][..tcp] [....192.168.1.7][53176] -> [..23.246.11.141][...80] - new: [....38] [ip4][..tcp] [....192.168.1.7][53177] -> [..23.246.11.141][...80] - new: [....39] [ip4][..tcp] [....192.168.1.7][53178] -> [..23.246.11.141][...80] - new: [....40] [ip4][..tcp] [....192.168.1.7][53179] -> [..23.246.11.141][...80] - new: [....41] [ip4][..tcp] [....192.168.1.7][53180] -> [..23.246.11.141][...80] + new: [....37] [ip4][..tcp] [....192.168.1.7][53176] -> [..23.246.11.141][...80] + new: [....38] [ip4][..tcp] [....192.168.1.7][53177] -> [..23.246.11.141][...80] + new: [....39] [ip4][..tcp] [....192.168.1.7][53178] -> [..23.246.11.141][...80] + new: [....40] [ip4][..tcp] [....192.168.1.7][53179] -> [..23.246.11.141][...80] + new: [....41] [ip4][..tcp] [....192.168.1.7][53180] -> [..23.246.11.141][...80] detected: [....35] [ip4][..tcp] [....192.168.1.7][53174] -> [..23.246.11.141][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.141] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detected: [....34] [ip4][..tcp] [....192.168.1.7][53173] -> [..23.246.11.133][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.133] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....42] [ip4][..tcp] [....192.168.1.7][53181] -> [..23.246.11.141][...80] - new: [....43] [ip4][..tcp] [....192.168.1.7][53182] -> [..23.246.11.141][...80] + new: [....42] [ip4][..tcp] [....192.168.1.7][53181] -> [..23.246.11.141][...80] + new: [....43] [ip4][..tcp] [....192.168.1.7][53182] -> [..23.246.11.141][...80] detected: [....36] [ip4][..tcp] [....192.168.1.7][53175] -> [..23.246.11.141][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.141] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....33] [ip4][..tcp] [....192.168.1.7][53172] -> [..23.246.11.133][...80] [HTTP][NetFlix][Download][Acceptable][23.246.11.133] @@ -373,22 +373,22 @@ [PKTLENS.....: 64,60,52,281,52,1500,1500,52,215,52,127,58,97,52,103,52,1402,1500,1500,52,1500,337,52,52,52,993,112,52,52,52,83,52] [ENTROPIES...: 4.5,5.3,5.1,5.8,5.1,7.3,7.3,5.1,6.9,5.1,6.1,5.0,6.0,5.2,6.0,5.2,7.9,7.9,7.9,5.2,7.8,7.4,5.1,5.1,5.1,7.8,6.3,5.2,5.1,5.1,5.8,5.1] detection-update: [.....9] [ip4][..tcp] [....192.168.1.7][53118] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ichnaea.netflix.com] - new: [....44] [ip4][..tcp] [....192.168.1.7][53183] -> [...23.246.3.140][...80] - new: [....45] [ip4][..tcp] [....192.168.1.7][53184] -> [..23.246.11.141][...80] + new: [....44] [ip4][..tcp] [....192.168.1.7][53183] -> [...23.246.3.140][...80] + new: [....45] [ip4][..tcp] [....192.168.1.7][53184] -> [..23.246.11.141][...80] detected: [....45] [ip4][..tcp] [....192.168.1.7][53184] -> [..23.246.11.141][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.141] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detected: [....44] [ip4][..tcp] [....192.168.1.7][53183] -> [...23.246.3.140][...80] [HTTP][NetFlix][Web][Acceptable][23.246.3.140] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....45] [ip4][..tcp] [....192.168.1.7][53184] -> [..23.246.11.141][...80] [HTTP][NetFlix][Download][Acceptable][23.246.11.141] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....46] [ip4][..tcp] [....192.168.1.7][53193] -> [...54.191.17.51][..443] - new: [....47] [ip4][..tcp] [....192.168.1.7][53202] -> [...54.191.17.51][..443] - new: [....48] [ip4][..udp] [....192.168.1.7][60962] -> [....192.168.1.1][...53] + new: [....46] [ip4][..tcp] [....192.168.1.7][53193] -> [...54.191.17.51][..443] + new: [....47] [ip4][..tcp] [....192.168.1.7][53202] -> [...54.191.17.51][..443] + new: [....48] [ip4][..udp] [....192.168.1.7][60962] -> [....192.168.1.1][...53] detected: [....48] [ip4][..udp] [....192.168.1.7][60962] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ichnaea.geo.netflix.com] detection-update: [....44] [ip4][..tcp] [....192.168.1.7][53183] -> [...23.246.3.140][...80] [HTTP][NetFlix][Download][Acceptable][23.246.3.140] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....48] [ip4][..udp] [....192.168.1.7][60962] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ichnaea.geo.netflix.com] - new: [....49] [ip4][..tcp] [....192.168.1.7][53203] -> [...52.37.36.252][..443] + new: [....49] [ip4][..tcp] [....192.168.1.7][53203] -> [...52.37.36.252][..443] analyse: [....11] [ip4][..tcp] [....192.168.1.7][53119] -> [..54.69.204.241][..443] [TLS.NetFlix][AmazonAWS][Video][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 30.431| 1.003| 5.373| 28867930.620| 0.200] @@ -448,7 +448,7 @@ [IATS(ms)....: 30.5,31.5,13.2,64.0,5.3,56.4,6.1,68.2,5.4,71.5,109.5,202.7,164.8,560.3,47.3,79.0,279.5,27.7,94.5,26.6,26.1,15.8,70.5,85.9,39.5,39.8,41.6,84.4,730.9,41.5,39.7] [PKTLENS.....: 64,60,52,557,618,951,52,564,628,1500,52,1500,1500,1500,72,64,52,1500,1500,52,1500,52,1500,1500,52,1500,52,1500,64,72,64,52] [ENTROPIES...: 4.5,5.2,5.2,6.2,5.8,3.9,5.1,6.2,5.7,3.2,5.1,7.9,7.8,7.8,5.3,5.2,5.1,7.8,7.8,5.1,7.8,5.0,5.9,7.8,5.1,7.8,5.0,7.8,5.0,5.2,5.1,5.1] - new: [....50] [ip4][..tcp] [....192.168.1.7][53210] -> [..23.246.11.133][...80] + new: [....50] [ip4][..tcp] [....192.168.1.7][53210] -> [..23.246.11.133][...80] detected: [....50] [ip4][..tcp] [....192.168.1.7][53210] -> [..23.246.11.133][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.133] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....50] [ip4][..tcp] [....192.168.1.7][53210] -> [..23.246.11.133][...80] [HTTP][NetFlix][Download][Acceptable][23.246.11.133] @@ -458,7 +458,7 @@ update: [....17] [ip4][..udp] [....192.168.1.7][57719] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun] update: [....13] [ip4][..udp] [....192.168.1.7][51949] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun] update: [.....3] [ip4][..udp] [....192.168.1.7][52116] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun] - new: [....51] [ip4][..tcp] [....192.168.1.7][53217] -> [..23.246.11.141][...80] + new: [....51] [ip4][..tcp] [....192.168.1.7][53217] -> [..23.246.11.141][...80] detected: [....51] [ip4][..tcp] [....192.168.1.7][53217] -> [..23.246.11.141][...80] [HTTP][NetFlix][Web][Acceptable][23.246.11.141] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....51] [ip4][..tcp] [....192.168.1.7][53217] -> [..23.246.11.141][...80] [HTTP][NetFlix][Download][Acceptable][23.246.11.141] @@ -467,23 +467,23 @@ update: [....26] [ip4][..udp] [....192.168.1.7][51728] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....23] [ip4][..udp] [....192.168.1.7][58102] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun] update: [....27] [ip4][..udp] [....192.168.1.7][52347] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun] - new: [....52] [ip4][..udp] [....192.168.1.7][51622] -> [....192.168.1.1][...53] + new: [....52] [ip4][..udp] [....192.168.1.7][51622] -> [....192.168.1.1][...53] detected: [....52] [ip4][..udp] [....192.168.1.7][51622] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] detection-update: [....52] [ip4][..udp] [....192.168.1.7][51622] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] RISK: Unidirectional Traffic detection-update: [....52] [ip4][..udp] [....192.168.1.7][51622] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][ios.nccp.netflix.com] - new: [....53] [ip4][..tcp] [....192.168.1.7][53238] -> [...52.32.22.214][..443] + new: [....53] [ip4][..tcp] [....192.168.1.7][53238] -> [...52.32.22.214][..443] detected: [....53] [ip4][..tcp] [....192.168.1.7][53238] -> [...52.32.22.214][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....53] [ip4][..tcp] [....192.168.1.7][53238] -> [...52.32.22.214][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....53] [ip4][..tcp] [....192.168.1.7][53238] -> [...52.32.22.214][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....54] [ip4][..udp] [....192.168.1.7][52095] -> [....192.168.1.1][...53] + new: [....54] [ip4][..udp] [....192.168.1.7][52095] -> [....192.168.1.1][...53] detected: [....54] [ip4][..udp] [....192.168.1.7][52095] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][api-global.latency.prodaa.netflix.com] detection-update: [....54] [ip4][..udp] [....192.168.1.7][52095] -> [....192.168.1.1][...53] [DNS.NetFlix][Unknown][Network][Fun][api-global.latency.prodaa.netflix.com] - new: [....55] [ip4][..tcp] [....192.168.1.7][53239] -> [.....52.41.30.5][..443] - new: [....56] [ip4][..tcp] [....192.168.1.7][53248] -> [...52.32.22.214][..443] + new: [....55] [ip4][..tcp] [....192.168.1.7][53239] -> [.....52.41.30.5][..443] + new: [....56] [ip4][..tcp] [....192.168.1.7][53248] -> [...52.32.22.214][..443] detected: [....55] [ip4][..tcp] [....192.168.1.7][53239] -> [.....52.41.30.5][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] detected: [....56] [ip4][..tcp] [....192.168.1.7][53248] -> [...52.32.22.214][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS @@ -493,8 +493,8 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....56] [ip4][..tcp] [....192.168.1.7][53248] -> [...52.32.22.214][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][ios.nccp.netflix.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....57] [ip4][..tcp] [....192.168.1.7][53249] -> [.....52.41.30.5][..443] - new: [....58] [ip4][..tcp] [....192.168.1.7][53250] -> [.....52.41.30.5][..443] + new: [....57] [ip4][..tcp] [....192.168.1.7][53249] -> [.....52.41.30.5][..443] + new: [....58] [ip4][..tcp] [....192.168.1.7][53250] -> [.....52.41.30.5][..443] detected: [....57] [ip4][..tcp] [....192.168.1.7][53249] -> [.....52.41.30.5][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....58] [ip4][..tcp] [....192.168.1.7][53250] -> [.....52.41.30.5][..443] [TLS.NetFlix][AmazonAWS][Video][Fun][api-global.netflix.com] @@ -513,11 +513,11 @@ [IATS(ms)....: 52.7,54.2,4.7,50.1,0.9,46.0,1.1,0.4,2.3,0.6,48.9,36.1,58.6,0.1,1.0,141.4,13.3,12.2,4.7,8.7,8.5,4.5,3.7,4.5,12.4,12.8,15.2,13.9,6.1,6.2,6.8] [PKTLENS.....: 64,60,52,260,52,197,52,58,97,1500,550,52,52,1500,213,1500,52,545,52,991,52,425,52,1292,52,1392,52,646,52,794,52,707] [ENTROPIES...: 4.5,5.3,5.1,6.0,5.2,6.5,5.1,5.2,6.0,7.9,7.6,5.1,5.2,7.9,7.0,7.8,5.1,7.6,5.1,7.8,5.2,7.5,5.1,7.8,5.2,7.9,5.1,7.7,5.1,7.8,5.1,7.7] - new: [....59] [ip4][..udp] [....192.168.1.7][57093] -> [....192.168.1.1][...53] + new: [....59] [ip4][..udp] [....192.168.1.7][57093] -> [....192.168.1.1][...53] detected: [....59] [ip4][..udp] [....192.168.1.7][57093] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][a1907.dscg.akamai.net] detection-update: [....59] [ip4][..udp] [....192.168.1.7][57093] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][a1907.dscg.akamai.net] - new: [....60] [ip4][..tcp] [....192.168.1.7][53251] -> [..184.25.204.10][...80] - new: [....61] [ip4][..tcp] [....192.168.1.7][53252] -> [..184.25.204.10][...80] + new: [....60] [ip4][..tcp] [....192.168.1.7][53251] -> [..184.25.204.10][...80] + new: [....61] [ip4][..tcp] [....192.168.1.7][53252] -> [..184.25.204.10][...80] detected: [....60] [ip4][..tcp] [....192.168.1.7][53251] -> [..184.25.204.10][...80] [HTTP.NetFlix][Unknown][Video][Fun][art-1.nflximg.net] detected: [....61] [ip4][..tcp] [....192.168.1.7][53252] -> [..184.25.204.10][...80] [HTTP.NetFlix][Unknown][Video][Fun][art-1.nflximg.net] analyse: [....55] [ip4][..tcp] [....192.168.1.7][53239] -> [.....52.41.30.5][..443] [TLS.NetFlix][AmazonAWS][Video][Fun] @@ -561,7 +561,7 @@ RISK: TLS (probably) Not Carrying HTTPS guessed: [.....1] [ip4][..tcp] [....192.168.1.7][52929] -> [.....52.24.87.6][..443] [TLS][AmazonAWS][Web][Safe] RISK: Unidirectional Traffic - end: [.....1] [ip4][..tcp] [....192.168.1.7][52929] -> [.....52.24.87.6][..443] + end: [.....1] [ip4][..tcp] [....192.168.1.7][52929] -> [.....52.24.87.6][..443] idle: [....46] [ip4][..tcp] [....192.168.1.7][53193] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun] RISK: TLS (probably) Not Carrying HTTPS end: [....47] [ip4][..tcp] [....192.168.1.7][53202] -> [...54.191.17.51][..443] [TLS.NetFlix][AmazonAWS][Video][Fun] diff --git a/test/results/flow-info/default/netflow-fritz.pcap.out b/test/results/flow-info/default/netflow-fritz.pcap.out index 1b8254f41..8ddbc31ec 100644 --- a/test/results/flow-info/default/netflow-fritz.pcap.out +++ b/test/results/flow-info/default/netflow-fritz.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.0.1][23384] -> [....192.168.1.1][.2055] + new: [.....1] [ip4][..udp] [....192.168.0.1][23384] -> [....192.168.1.1][.2055] detected: [.....1] [ip4][..udp] [....192.168.0.1][23384] -> [....192.168.1.1][.2055] [NetFlow][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [....192.168.0.1][23384] -> [....192.168.1.1][.2055] [NetFlow][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/netflowv9.pcap.out b/test/results/flow-info/default/netflowv9.pcap.out index 0da83c46e..64c9d9ec4 100644 --- a/test/results/flow-info/default/netflowv9.pcap.out +++ b/test/results/flow-info/default/netflowv9.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.134][48629] -> [..192.168.2.222][.2057] + new: [.....1] [ip4][..udp] [..192.168.2.134][48629] -> [..192.168.2.222][.2057] detected: [.....1] [ip4][..udp] [..192.168.2.134][48629] -> [..192.168.2.222][.2057] [NetFlow][Unknown][Network][Acceptable] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..udp] [..192.168.2.134][48629] -> [..192.168.2.222][.2057] [NetFlow][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/nfsv2.pcap.out b/test/results/flow-info/default/nfsv2.pcap.out index 944409d07..b86aac8f5 100644 --- a/test/results/flow-info/default/nfsv2.pcap.out +++ b/test/results/flow-info/default/nfsv2.pcap.out @@ -1,18 +1,18 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....139.25.22.2][.3289] -> [..139.25.22.102][..111] + new: [.....1] [ip4][..udp] [....139.25.22.2][.3289] -> [..139.25.22.102][..111] detected: [.....1] [ip4][..udp] [....139.25.22.2][.3289] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [....139.25.22.2][..671] -> [..139.25.22.102][.1048] + new: [.....2] [ip4][..udp] [....139.25.22.2][..671] -> [..139.25.22.102][.1048] detected: [.....2] [ip4][..udp] [....139.25.22.2][..671] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..udp] [....139.25.22.2][.3291] -> [..139.25.22.102][..111] + new: [.....3] [ip4][..udp] [....139.25.22.2][.3291] -> [..139.25.22.102][..111] detected: [.....3] [ip4][..udp] [....139.25.22.2][.3291] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][..udp] [....139.25.22.2][.3292] -> [..139.25.22.102][.2049] + new: [.....4] [ip4][..udp] [....139.25.22.2][.3292] -> [..139.25.22.102][.2049] detected: [.....4] [ip4][..udp] [....139.25.22.2][.3292] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] - new: [.....5] [ip4][..udp] [....139.25.22.2][.1023] -> [..139.25.22.102][.2049] + new: [.....5] [ip4][..udp] [....139.25.22.2][.1023] -> [..139.25.22.102][.2049] detected: [.....5] [ip4][..udp] [....139.25.22.2][.1023] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] analyse: [.....5] [ip4][..udp] [....139.25.22.2][.1023] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] min| max| avg| stddev| variance| entropy @@ -24,10 +24,10 @@ [IATS(ms)....: 0.0,0.0,0.0,40.0,40.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0,0.0,0.0,0.0,10.0,10.0,10.0,10.0,0.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0,0.0,0.0,10.0,10.0] [PKTLENS.....: 152,124,152,76,160,56,160,56,192,156,152,124,152,124,160,156,184,124,160,156,160,56,160,56,160,156,160,56,200,56,152,124] [ENTROPIES...: 3.4,3.5,3.4,3.5,3.3,3.3,3.3,3.3,3.3,3.3,3.4,3.3,3.4,3.5,3.3,3.3,3.7,3.4,3.3,3.4,3.4,3.3,3.4,3.2,3.3,3.4,3.4,3.3,3.2,3.2,3.4,3.5] - new: [.....6] [ip4][..udp] [....139.25.22.2][.3293] -> [..139.25.22.102][..111] + new: [.....6] [ip4][..udp] [....139.25.22.2][.3293] -> [..139.25.22.102][..111] detected: [.....6] [ip4][..udp] [....139.25.22.2][.3293] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....7] [ip4][..udp] [....139.25.22.2][..686] -> [..139.25.22.102][.1048] + new: [.....7] [ip4][..udp] [....139.25.22.2][..686] -> [..139.25.22.102][.1048] detected: [.....7] [ip4][..udp] [....139.25.22.2][..686] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port idle: [.....4] [ip4][..udp] [....139.25.22.2][.3292] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] diff --git a/test/results/flow-info/default/nfsv3.pcap.out b/test/results/flow-info/default/nfsv3.pcap.out index 06e420b1b..e7116be3c 100644 --- a/test/results/flow-info/default/nfsv3.pcap.out +++ b/test/results/flow-info/default/nfsv3.pcap.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....139.25.22.2][.3295] -> [..139.25.22.102][..111] + new: [.....1] [ip4][..udp] [....139.25.22.2][.3295] -> [..139.25.22.102][..111] detected: [.....1] [ip4][..udp] [....139.25.22.2][.3295] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [....139.25.22.2][.3296] -> [..139.25.22.102][.1048] + new: [.....2] [ip4][..udp] [....139.25.22.2][.3296] -> [..139.25.22.102][.1048] detected: [.....2] [ip4][..udp] [....139.25.22.2][.3296] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..udp] [....139.25.22.2][..706] -> [..139.25.22.102][.1048] + new: [.....3] [ip4][..udp] [....139.25.22.2][..706] -> [..139.25.22.102][.1048] detected: [.....3] [ip4][..udp] [....139.25.22.2][..706] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][..udp] [....139.25.22.2][.3297] -> [..139.25.22.102][..111] + new: [.....4] [ip4][..udp] [....139.25.22.2][.3297] -> [..139.25.22.102][..111] detected: [.....4] [ip4][..udp] [....139.25.22.2][.3297] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....5] [ip4][..udp] [....139.25.22.2][.3298] -> [..139.25.22.102][.2049] + new: [.....5] [ip4][..udp] [....139.25.22.2][.3298] -> [..139.25.22.102][.2049] detected: [.....5] [ip4][..udp] [....139.25.22.2][.3298] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] - new: [.....6] [ip4][..udp] [....139.25.22.2][.1022] -> [..139.25.22.102][.2049] + new: [.....6] [ip4][..udp] [....139.25.22.2][.1022] -> [..139.25.22.102][.2049] detected: [.....6] [ip4][..udp] [....139.25.22.2][.1022] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] analyse: [.....6] [ip4][..udp] [....139.25.22.2][.1022] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] min| max| avg| stddev| variance| entropy @@ -27,10 +27,10 @@ [IATS(ms)....: 0.0,0.0,10.0,10.0,0.0,0.0,0.0,50.0,50.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0,0.0,10.0,10.0,0.0,0.0] [PKTLENS.....: 156,140,156,192,156,196,156,168,164,60,164,60,212,300,156,140,192,172,164,60,164,60,164,268,164,60,208,288,164,268,164,60] [ENTROPIES...: 3.3,3.3,3.3,3.2,3.3,3.2,3.3,3.1,3.3,3.2,3.3,3.1,2.9,3.3,3.3,3.1,3.2,3.3,3.3,3.1,3.3,3.1,3.3,3.2,3.3,3.2,3.2,3.3,3.3,3.4,3.5,3.2] - new: [.....7] [ip4][..udp] [....139.25.22.2][.3299] -> [..139.25.22.102][..111] + new: [.....7] [ip4][..udp] [....139.25.22.2][.3299] -> [..139.25.22.102][..111] detected: [.....7] [ip4][..udp] [....139.25.22.2][.3299] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port - new: [.....8] [ip4][..udp] [....139.25.22.2][..722] -> [..139.25.22.102][.1048] + new: [.....8] [ip4][..udp] [....139.25.22.2][..722] -> [..139.25.22.102][.1048] detected: [.....8] [ip4][..udp] [....139.25.22.2][..722] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port idle: [.....5] [ip4][..udp] [....139.25.22.2][.3298] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] diff --git a/test/results/flow-info/default/nintendo.pcap.out b/test/results/flow-info/default/nintendo.pcap.out index c4d124427..d48b2c74b 100644 --- a/test/results/flow-info/default/nintendo.pcap.out +++ b/test/results/flow-info/default/nintendo.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] + new: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] detected: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] [Nintendo][Unknown][Game][Fun] - new: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955] + new: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955] detected: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955] [Nintendo][Unknown][Game][Fun] - new: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251] + new: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251] detected: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251] [Nintendo][Unknown][Game][Fun] - new: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [TLS][AmazonAWS][Web][Safe] - new: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] + new: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] detected: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] [Nintendo][AmazonAWS][Game][Fun] analyse: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] [Nintendo][Unknown][Game][Fun] min| max| avg| stddev| variance| entropy @@ -21,31 +21,31 @@ [IATS(ms)....: 87.9,239.6,335.4,89.8,30.6,131.2,103.3,500.0,507.3,130.9,234.8,19.3,15.8,5.2,16.9,12.6,53.5,8.8,0.2,60.8,14.2,505.6,501.5,5.1,514.4,94.6,0.2,1729.7,0.1,52.6,0.1] [PKTLENS.....: 88,88,184,216,104,88,136,104,88,104,136,120,104,104,104,840,104,840,88,88,104,88,88,88,88,88,104,104,104,104,104,104] [ENTROPIES...: 6.1,6.1,6.8,6.9,6.2,6.1,6.7,6.2,6.1,6.3,6.6,6.4,6.2,6.2,6.2,6.3,6.3,5.9,5.8,5.9,6.2,5.9,6.1,6.2,6.0,6.0,6.1,6.1,6.0,6.2,6.2,6.2] - new: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] - new: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] + new: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] + new: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] detected: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] detection-update: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] - new: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] + new: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] detected: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] [MIDSTREAM] - new: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] - new: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] - new: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] - new: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] + new: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] [MIDSTREAM] + new: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] + new: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] + new: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] + new: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] detected: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net] detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net] detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net] detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net] - new: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] - new: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] + new: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] + new: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] detected: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] detection-update: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] - new: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] + new: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] detected: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com] @@ -62,15 +62,15 @@ [IATS(ms)....: 6.3,307.1,3508.7,3481.6,0.2,0.0,276.4,18.5,55.2,0.1,35.7,210.9,214.2,255.3,13944.5,14019.1,0.8,0.1,5.3,332.5,29.9,280.4,254.2,215.7,3.4,13.6,231.1,4.3,259.0,453.5,730.8] [PKTLENS.....: 152,103,52,119,52,110,99,52,103,152,152,52,52,103,52,457,52,99,386,152,52,103,52,368,52,109,99,52,103,52,152,103] [ENTROPIES...: 6.5,5.8,5.0,6.0,5.0,6.0,6.0,5.0,5.7,6.6,6.6,5.0,5.1,5.7,5.0,7.5,5.1,6.1,7.4,6.5,5.0,5.8,5.1,7.3,5.1,6.2,6.0,5.1,5.8,5.1,6.7,5.7] - new: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] + new: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] detected: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] [Nintendo][Unknown][Game][Fun] - new: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114] + new: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114] detected: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable] - new: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] + new: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] detected: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] [Nintendo][Unknown][Game][Fun] - new: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] + new: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] detected: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] [Nintendo][Unknown][Game][Fun] - new: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114] + new: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114] detected: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable] analyse: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] [Nintendo][Unknown][Game][Fun] min| max| avg| stddev| variance| entropy @@ -103,28 +103,28 @@ [PKTLENS.....: 104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,104,104,88,104,104,872,88,872,88,104,104,88] [ENTROPIES...: 6.1,6.1,6.1,6.0,6.2,6.2,6.2,6.2,6.1,6.0,6.1,6.1,6.1,6.1,6.1,6.7,6.0,6.1,6.2,6.8,6.2,6.2,5.9,6.2,6.2,5.5,5.9,5.6,6.0,6.2,6.1,6.0] guessed: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] [AmazonAWS][AmazonAWS][Cloud][Acceptable] - idle: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] + idle: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] idle: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun] idle: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun] guessed: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] [TLS][AmazonAWS][Web][Safe] - idle: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] + idle: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] idle: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [TLS][AmazonAWS][Web][Safe] idle: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] [Nintendo][Unknown][Game][Fun] idle: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun] guessed: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] [AmazonAWS][AmazonAWS][Cloud][Acceptable] RISK: Unidirectional Traffic - idle: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] + idle: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] guessed: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] [AmazonAWS][AmazonAWS][Cloud][Acceptable] RISK: Unidirectional Traffic - idle: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] + idle: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] guessed: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] [AmazonAWS][AmazonAWS][Cloud][Acceptable] RISK: Unidirectional Traffic - idle: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] + idle: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] idle: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] [Nintendo][Unknown][Game][Fun] idle: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] [Nintendo][AmazonAWS][Game][Fun] guessed: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] [AmazonAWS][AmazonAWS][Cloud][Acceptable] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] + idle: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] end: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun] RISK: TLS (probably) Not Carrying HTTPS end: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun] diff --git a/test/results/flow-info/default/nntp.pcap.out b/test/results/flow-info/default/nntp.pcap.out index c02818525..2144fb147 100644 --- a/test/results/flow-info/default/nntp.pcap.out +++ b/test/results/flow-info/default/nntp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] + new: [.....1] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] detected: [.....1] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] analyse: [.....1] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/no_sni.pcap.out b/test/results/flow-info/default/no_sni.pcap.out index b3048997e..47176edfa 100644 --- a/test/results/flow-info/default/no_sni.pcap.out +++ b/test/results/flow-info/default/no_sni.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe] detection-update: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe] RISK: Unidirectional Traffic - new: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] detection-update: [.....1] [ip4][..tcp] [..192.168.1.119][51331] -> [.104.16.249.249][..443] [TLS][Cloudflare][Web][Safe] detected: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com] detection-update: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable][mozilla.cloudflare-dns.com] - new: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.119][51612] -> [..104.16.124.96][..443] analyse: [.....2] [ip4][..tcp] [..192.168.1.119][51606] -> [.104.16.249.249][..443] [TLS.DoH_DoT][Cloudflare][Network][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.180| 0.028| 0.054| 2913.211| 3.000] @@ -32,11 +32,11 @@ [IATS(ms)....: 121.2,121.3,5.4,100.4,0.4,95.3,1.0,4.8,0.1,77.1,0.5,71.8,0.2,0.4,0.6,0.2,76.9,15.5,380.4,472.6,2.8,2.8,2.1,2.1,1.6,1.6,1.4,0.3,1.6,0.6,0.6] [PKTLENS.....: 64,52,40,987,46,272,40,104,210,903,46,552,40,46,71,40,71,46,46,1078,40,830,40,1431,40,1431,40,1500,393,40,1164,40] [ENTROPIES...: 4.5,4.9,4.4,7.5,4.5,6.8,4.6,6.0,6.9,7.8,4.5,7.6,4.6,4.5,5.7,4.6,5.6,4.5,4.5,7.8,4.6,7.8,4.6,7.9,4.6,7.9,4.6,7.9,7.4,4.6,7.8,4.6] - new: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] - new: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] - new: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] - new: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] - new: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.119][51638] -> [..104.22.72.170][..443] + new: [.....8] [ip4][..tcp] [..192.168.1.119][51639] -> [..104.22.72.170][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.119][51635] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-cf.help.every1dns.net] detected: [.....5] [ip4][..tcp] [..192.168.1.119][51636] -> [..104.17.198.37][..443] [TLS][Cloudflare][Web][Safe][951c558a-5e07-47ca-a0c0-225da1b33163.is-doh.help.every1dns.net] detected: [.....6] [ip4][..tcp] [..192.168.1.119][51637] -> [..104.22.72.170][..443] [TLS][Cloudflare][Web][Safe][] diff --git a/test/results/flow-info/default/ocs.pcap.out b/test/results/flow-info/default/ocs.pcap.out index d3f8c5885..8bc55e4d6 100644 --- a/test/results/flow-info/default/ocs.pcap.out +++ b/test/results/flow-info/default/ocs.pcap.out @@ -1,39 +1,39 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] - new: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] + new: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] + new: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] detected: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][ocu03.labgency.ws] - new: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] + new: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] detected: [.....3] [ip4][..udp] [..192.168.180.2][40097] -> [........8.8.8.8][...53] [DNS.Crashlytics][Google][Network][Acceptable][settings.crashlytics.com] - new: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] + new: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] detected: [.....4] [ip4][..udp] [..192.168.180.2][.1291] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][api.eu01.capptain.com] - new: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] - new: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] - new: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] + new: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] + new: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] + new: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] detected: [.....5] [ip4][..tcp] [..192.168.180.2][48250] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws] RISK: Unidirectional Traffic detected: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com] RISK: HTTP Susp User-Agent, Unidirectional Traffic - new: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] + new: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] detected: [.....8] [ip4][..tcp] [..192.168.180.2][44959] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable][api.eu01.capptain.com] RISK: HTTP Susp User-Agent, Unidirectional Traffic - new: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] + new: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] detected: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] [DNS.PlayStore][Google][Network][Safe][android.clients.google.com] - new: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] + new: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] detected: [....10] [ip4][..tcp] [..192.168.180.2][41223] -> [..216.58.208.46][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic detected: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable][settings.crashlytics.com] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic - new: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] + new: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] detected: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][xmpp.device06.eu01.capptain.com] - new: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] - new: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] - new: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] + new: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] + new: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] + new: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] detected: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][ocs.labgency.ws] detected: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun][ocu03.labgency.ws] RISK: Unidirectional Traffic - new: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] + new: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] detected: [....15] [ip4][..tcp] [..192.168.180.2][36680] -> [.178.248.208.54][..443] [TLS.OCS][OCS][Media][Fun][ocs.labgency.ws] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic analyse: [....13] [ip4][..tcp] [..192.168.180.2][49881] -> [.178.248.208.54][...80] [HTTP.OCS][OCS][Media][Fun] @@ -46,12 +46,12 @@ [IATS(ms)....: 83.8,14.3,246.9,0.6,0.5,68.4,1.8,71.5,0.5,5.4,4.1,41.7,146.0,90.8,71.1,77.4,63.4,3.7,80.5,1.7,86.1,0.6,67.3,32.6,43.3,386.6,73.7,2.5,928.6,31.7,2.1] [PKTLENS.....: 60,52,715,64,72,72,80,72,72,72,72,72,64,52,64,64,64,52,52,52,52,64,64,64,64,52,52,64,64,52,64,64] [ENTROPIES...: 4.5,5.1,6.0,5.1,5.2,5.2,5.2,5.2,5.3,5.2,5.2,5.2,5.2,5.1,5.2,5.2,5.1,5.2,5.1,5.1,5.0,5.1,5.2,5.1,5.2,5.1,5.2,5.2,5.2,5.0,5.1,5.1] - new: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] + new: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] detected: [....16] [ip4][..tcp] [..192.168.180.2][32946] -> [.64.233.184.188][..443] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: TLS (probably) Not Carrying HTTPS, Unidirectional Traffic - new: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] + new: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] detected: [....17] [ip4][..udp] [..192.168.180.2][11793] -> [........8.8.8.8][...53] [DNS.GoogleServices][Google][Network][Acceptable][play.googleapis.com] - new: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] + new: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] detected: [....18] [ip4][..tcp] [..192.168.180.2][47803] -> [..64.233.166.95][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic update: [....14] [ip4][..udp] [..192.168.180.2][.2589] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun] @@ -60,9 +60,9 @@ update: [....11] [ip4][..udp] [..192.168.180.2][.3621] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable] update: [.....2] [ip4][..udp] [..192.168.180.2][38472] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun] update: [.....9] [ip4][..udp] [..192.168.180.2][48770] -> [........8.8.8.8][...53] [DNS.PlayStore][Google][Network][Safe] - new: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] + new: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] detected: [....19] [ip4][..udp] [..192.168.180.2][24245] -> [........8.8.8.8][...53] [DNS.OCS][Google][Network][Fun][www.ocs.fr] - new: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] + new: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] detected: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun][www.ocs.fr] RISK: HTTP Susp User-Agent, Unidirectional Traffic analyse: [....20] [ip4][..tcp] [..192.168.180.2][42590] -> [178.248.208.210][...80] [HTTP.OCS][OCS][Media][Fun] @@ -82,10 +82,10 @@ RISK: HTTP Susp User-Agent, Unidirectional Traffic guessed: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] [Azure][Azure][Cloud][Acceptable] RISK: Unidirectional Traffic - idle: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] + idle: [....12] [ip4][..tcp] [..192.168.180.2][46166] -> [.137.135.131.52][.5122] guessed: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] [Google][Google][Web][Acceptable] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] + idle: [.....1] [ip4][..tcp] [..192.168.180.2][47699] -> [.64.233.184.188][.5228] end: [.....6] [ip4][..tcp] [..192.168.180.2][39263] -> [..23.21.230.199][..443] [TLS.Crashlytics][AmazonAWS][DataTransfer][Acceptable] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic end: [.....7] [ip4][..tcp] [..192.168.180.2][53356] -> [137.135.129.206][...80] [HTTP][Azure][Web][Acceptable] diff --git a/test/results/flow-info/default/ocsp.pcapng.out b/test/results/flow-info/default/ocsp.pcapng.out index 3707facb1..721691795 100644 --- a/test/results/flow-info/default/ocsp.pcapng.out +++ b/test/results/flow-info/default/ocsp.pcapng.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.227][49813] -> [.109.70.240.130][...80] + new: [.....1] [ip4][..tcp] [..192.168.1.227][49813] -> [.109.70.240.130][...80] detected: [.....1] [ip4][..tcp] [..192.168.1.227][49813] -> [.109.70.240.130][...80] [HTTP][Unknown][Web][Acceptable][ocsp07.actalis.it] DAEMON-EVENT: [Processed: 23 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.1.128][54154] -> [.142.250.184.99][...80] + new: [.....2] [ip4][..tcp] [..192.168.1.128][54154] -> [.142.250.184.99][...80] detected: [.....2] [ip4][..tcp] [..192.168.1.128][54154] -> [.142.250.184.99][...80] [HTTP.OCSP][Google][Network][Safe][ocsp.pki.goog] end: [.....1] [ip4][..tcp] [..192.168.1.227][49813] -> [.109.70.240.130][...80] [HTTP.OCSP][Unknown][Web][Safe] - new: [.....3] [ip4][..tcp] [..192.168.1.128][43728] -> [..92.122.95.235][...80] + new: [.....3] [ip4][..tcp] [..192.168.1.128][43728] -> [..92.122.95.235][...80] detected: [.....3] [ip4][..tcp] [..192.168.1.128][43728] -> [..92.122.95.235][...80] [HTTP.OCSP][Unknown][Network][Safe][r3.o.lencr.org] analyse: [.....2] [ip4][..tcp] [..192.168.1.128][54154] -> [.142.250.184.99][...80] [HTTP.OCSP][Google][Network][Safe] min| max| avg| stddev| variance| entropy @@ -30,15 +30,15 @@ [IATS(ms)....: 12.0,16.1,0.3,19.6,157.1,176.9,7779.8,7796.1,1.3,16.6,10045.9,10060.7,10239.9,10239.7,10239.8,10240.0,10244.0,10243.9,10239.9,10240.0,10236.0,10236.1,10243.9,10244.0,10236.0,10235.9,10240.0,10239.8,10240.0,10240.0,10239.9] [PKTLENS.....: 112,112,104,490,104,993,104,490,104,993,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104] [ENTROPIES...: 3.9,4.2,4.1,6.3,4.3,7.0,4.4,6.3,4.4,7.0,4.4,4.4,4.4,4.4,4.4,4.4,4.4,4.4,4.3,4.4,4.3,4.4,4.3,4.4,4.4,4.4,4.3,4.4,4.4,4.4,4.4,4.3] - new: [.....4] [ip4][..tcp] [..192.168.1.128][34320] -> [.151.139.128.14][...80] + new: [.....4] [ip4][..tcp] [..192.168.1.128][34320] -> [.151.139.128.14][...80] detected: [.....4] [ip4][..tcp] [..192.168.1.128][34320] -> [.151.139.128.14][...80] [HTTP.OCSP][Unknown][Network][Safe][geant.ocsp.sectigo.com] - new: [.....5] [ip4][..tcp] [..192.168.1.128][34340] -> [.151.139.128.14][...80] + new: [.....5] [ip4][..tcp] [..192.168.1.128][34340] -> [.151.139.128.14][...80] detected: [.....5] [ip4][..tcp] [..192.168.1.128][34340] -> [.151.139.128.14][...80] [HTTP.OCSP][Unknown][Network][Safe][ocsp.usertrust.com] end: [.....3] [ip4][..tcp] [..192.168.1.128][43728] -> [..92.122.95.235][...80] [HTTP.OCSP][Unknown][Network][Safe] end: [.....2] [ip4][..tcp] [..192.168.1.128][54154] -> [.142.250.184.99][...80] [HTTP.OCSP][Google][Network][Safe] DAEMON-EVENT: [Processed: 157 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.1.128][47904] -> [..93.184.220.29][...80] + new: [.....6] [ip4][..tcp] [..192.168.1.128][47904] -> [..93.184.220.29][...80] detected: [.....6] [ip4][..tcp] [..192.168.1.128][47904] -> [..93.184.220.29][...80] [HTTP.OCSP][Edgecast][Network][Safe][ocsp.digicert.com] end: [.....4] [ip4][..tcp] [..192.168.1.128][34320] -> [.151.139.128.14][...80] [HTTP.OCSP][Unknown][Network][Safe] end: [.....5] [ip4][..tcp] [..192.168.1.128][34340] -> [.151.139.128.14][...80] [HTTP.OCSP][Unknown][Network][Safe] @@ -54,9 +54,9 @@ [ENTROPIES...: 3.9,4.3,4.0,6.3,4.3,7.0,4.4,4.4,4.3,4.4,4.4,4.4,4.4,4.4,4.3,4.4,4.3,6.3,7.0,4.4,6.3,7.0,4.3,4.4,4.3,4.3,4.3,4.4,4.3,4.4,4.3,4.4] DAEMON-EVENT: [Processed: 207 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.1.128][49382] -> [....52.85.15.92][...80] + new: [.....7] [ip4][..tcp] [..192.168.1.128][49382] -> [....52.85.15.92][...80] detected: [.....7] [ip4][..tcp] [..192.168.1.128][49382] -> [....52.85.15.92][...80] [HTTP.OCSP][AmazonAWS][Network][Safe][ocsp.sca1b.amazontrust.com] - new: [.....8] [ip4][..tcp] [..192.168.1.128][59922] -> [..151.101.2.133][...80] + new: [.....8] [ip4][..tcp] [..192.168.1.128][59922] -> [..151.101.2.133][...80] detected: [.....8] [ip4][..tcp] [..192.168.1.128][59922] -> [..151.101.2.133][...80] [HTTP.OCSP][Unknown][Network][Safe][ocsp.globalsign.com] end: [.....6] [ip4][..tcp] [..192.168.1.128][47904] -> [..93.184.220.29][...80] [HTTP.OCSP][Edgecast][Network][Safe] analyse: [.....8] [ip4][..tcp] [..192.168.1.128][59922] -> [..151.101.2.133][...80] [HTTP.OCSP][Unknown][Network][Safe] @@ -81,11 +81,11 @@ [ENTROPIES...: 3.9,4.3,4.0,6.3,4.3,7.0,4.4,4.4,4.3,4.4,4.3,4.4,4.3,4.4,4.3,4.3,4.3,4.4,4.3,4.4,4.3,4.4,4.3,4.3,4.3,4.3,4.3,4.4,4.3,4.3,4.3,4.4] DAEMON-EVENT: [Processed: 274 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.1.128][45514] -> [.109.70.240.114][...80] + new: [.....9] [ip4][..tcp] [..192.168.1.128][45514] -> [.109.70.240.114][...80] detected: [.....9] [ip4][..tcp] [..192.168.1.128][45514] -> [.109.70.240.114][...80] [HTTP.OCSP][Unknown][Network][Safe][ocsp09.actalis.it] end: [.....8] [ip4][..tcp] [..192.168.1.128][59922] -> [..151.101.2.133][...80] [HTTP.OCSP][Unknown][Network][Safe] end: [.....7] [ip4][..tcp] [..192.168.1.128][49382] -> [....52.85.15.92][...80] [HTTP.OCSP][AmazonAWS][Network][Safe] - new: [....10] [ip4][..tcp] [..192.168.1.128][49034] -> [...23.12.96.145][...80] + new: [....10] [ip4][..tcp] [..192.168.1.128][49034] -> [...23.12.96.145][...80] detected: [....10] [ip4][..tcp] [..192.168.1.128][49034] -> [...23.12.96.145][...80] [HTTP.OCSP][Unknown][Network][Safe][ocsp.entrust.net] end: [.....9] [ip4][..tcp] [..192.168.1.128][45514] -> [.109.70.240.114][...80] [HTTP.OCSP][Unknown][Network][Safe] analyse: [....10] [ip4][..tcp] [..192.168.1.128][49034] -> [...23.12.96.145][...80] [HTTP.OCSP][Unknown][Network][Safe] diff --git a/test/results/flow-info/default/oicq.pcap.out b/test/results/flow-info/default/oicq.pcap.out index 4de161a8f..5536b8809 100644 --- a/test/results/flow-info/default/oicq.pcap.out +++ b/test/results/flow-info/default/oicq.pcap.out @@ -1,128 +1,128 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..90.147.69.210][60213] -> [....58.60.10.45][.8000] + new: [.....1] [ip4][..udp] [..90.147.69.210][60213] -> [....58.60.10.45][.8000] detected: [.....1] [ip4][..udp] [..90.147.69.210][60213] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [.....2] [ip4][..udp] [..90.147.69.210][51884] -> [....58.60.10.45][.8000] + new: [.....2] [ip4][..udp] [..90.147.69.210][51884] -> [....58.60.10.45][.8000] detected: [.....2] [ip4][..udp] [..90.147.69.210][51884] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....1] [ip4][..udp] [..90.147.69.210][60213] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..90.147.69.210][52991] -> [....58.60.10.45][.8000] + new: [.....3] [ip4][..udp] [..90.147.69.210][52991] -> [....58.60.10.45][.8000] detected: [.....3] [ip4][..udp] [..90.147.69.210][52991] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....2] [ip4][..udp] [..90.147.69.210][51884] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 3 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [..90.147.69.210][60288] -> [....58.60.10.45][.8000] + new: [.....4] [ip4][..udp] [..90.147.69.210][60288] -> [....58.60.10.45][.8000] detected: [.....4] [ip4][..udp] [..90.147.69.210][60288] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....3] [ip4][..udp] [..90.147.69.210][52991] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [.....5] [ip4][..udp] [..90.147.69.210][56476] -> [....58.60.10.45][.8000] + new: [.....5] [ip4][..udp] [..90.147.69.210][56476] -> [....58.60.10.45][.8000] detected: [.....5] [ip4][..udp] [..90.147.69.210][56476] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....4] [ip4][..udp] [..90.147.69.210][60288] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..udp] [..90.147.69.210][63120] -> [....58.60.10.45][.8000] + new: [.....6] [ip4][..udp] [..90.147.69.210][63120] -> [....58.60.10.45][.8000] detected: [.....6] [ip4][..udp] [..90.147.69.210][63120] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....5] [ip4][..udp] [..90.147.69.210][56476] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..udp] [..90.147.69.210][65276] -> [....58.60.10.45][.8000] + new: [.....7] [ip4][..udp] [..90.147.69.210][65276] -> [....58.60.10.45][.8000] detected: [.....7] [ip4][..udp] [..90.147.69.210][65276] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....6] [ip4][..udp] [..90.147.69.210][63120] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [.....8] [ip4][..udp] [..90.147.69.210][64916] -> [....58.60.10.45][.8000] + new: [.....8] [ip4][..udp] [..90.147.69.210][64916] -> [....58.60.10.45][.8000] detected: [.....8] [ip4][..udp] [..90.147.69.210][64916] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....7] [ip4][..udp] [..90.147.69.210][65276] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..udp] [..90.147.69.210][49340] -> [....58.60.10.45][.8000] + new: [.....9] [ip4][..udp] [..90.147.69.210][49340] -> [....58.60.10.45][.8000] detected: [.....9] [ip4][..udp] [..90.147.69.210][49340] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....8] [ip4][..udp] [..90.147.69.210][64916] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 9 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..udp] [..90.147.69.210][58434] -> [....58.60.10.45][.8000] + new: [....10] [ip4][..udp] [..90.147.69.210][58434] -> [....58.60.10.45][.8000] detected: [....10] [ip4][..udp] [..90.147.69.210][58434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [.....9] [ip4][..udp] [..90.147.69.210][49340] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....11] [ip4][..udp] [..90.147.69.210][55338] -> [....58.60.10.45][.8000] + new: [....11] [ip4][..udp] [..90.147.69.210][55338] -> [....58.60.10.45][.8000] detected: [....11] [ip4][..udp] [..90.147.69.210][55338] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....10] [ip4][..udp] [..90.147.69.210][58434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 11 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....12] [ip4][..udp] [..90.147.69.210][54233] -> [....58.60.10.45][.8000] + new: [....12] [ip4][..udp] [..90.147.69.210][54233] -> [....58.60.10.45][.8000] detected: [....12] [ip4][..udp] [..90.147.69.210][54233] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....11] [ip4][..udp] [..90.147.69.210][55338] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....13] [ip4][..udp] [..90.147.69.210][55774] -> [....58.60.10.45][.8000] + new: [....13] [ip4][..udp] [..90.147.69.210][55774] -> [....58.60.10.45][.8000] detected: [....13] [ip4][..udp] [..90.147.69.210][55774] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....12] [ip4][..udp] [..90.147.69.210][54233] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....14] [ip4][..udp] [..90.147.69.210][52663] -> [....58.60.10.45][.8000] + new: [....14] [ip4][..udp] [..90.147.69.210][52663] -> [....58.60.10.45][.8000] detected: [....14] [ip4][..udp] [..90.147.69.210][52663] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....13] [ip4][..udp] [..90.147.69.210][55774] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 14 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 14|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....15] [ip4][..udp] [..90.147.69.210][58797] -> [....58.60.10.45][.8000] + new: [....15] [ip4][..udp] [..90.147.69.210][58797] -> [....58.60.10.45][.8000] detected: [....15] [ip4][..udp] [..90.147.69.210][58797] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....14] [ip4][..udp] [..90.147.69.210][52663] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 15|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....16] [ip4][..udp] [..90.147.69.210][50315] -> [....58.60.10.45][.8000] + new: [....16] [ip4][..udp] [..90.147.69.210][50315] -> [....58.60.10.45][.8000] detected: [....16] [ip4][..udp] [..90.147.69.210][50315] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....15] [ip4][..udp] [..90.147.69.210][58797] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....17] [ip4][..udp] [..90.147.69.210][65163] -> [....58.60.10.45][.8000] + new: [....17] [ip4][..udp] [..90.147.69.210][65163] -> [....58.60.10.45][.8000] detected: [....17] [ip4][..udp] [..90.147.69.210][65163] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....16] [ip4][..udp] [..90.147.69.210][50315] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 17|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....18] [ip4][..udp] [..90.147.69.210][59802] -> [....58.60.10.45][.8000] + new: [....18] [ip4][..udp] [..90.147.69.210][59802] -> [....58.60.10.45][.8000] detected: [....18] [ip4][..udp] [..90.147.69.210][59802] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....17] [ip4][..udp] [..90.147.69.210][65163] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] + new: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] detected: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....18] [ip4][..udp] [..90.147.69.210][59802] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 19|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] + new: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] detected: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] + new: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] detected: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....22] [ip4][..udp] [..90.147.69.210][61686] -> [....58.60.10.45][.8000] + new: [....22] [ip4][..udp] [..90.147.69.210][61686] -> [....58.60.10.45][.8000] detected: [....22] [ip4][..udp] [..90.147.69.210][61686] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....19] [ip4][..udp] [..90.147.69.210][60434] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....23] [ip4][..udp] [..90.147.69.210][54462] -> [....58.60.10.45][.8000] + new: [....23] [ip4][..udp] [..90.147.69.210][54462] -> [....58.60.10.45][.8000] detected: [....23] [ip4][..udp] [..90.147.69.210][54462] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....20] [ip4][..udp] [..90.147.69.210][60436] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....22] [ip4][..udp] [..90.147.69.210][61686] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....24] [ip4][..udp] [..90.147.69.210][64415] -> [....58.60.10.45][.8000] + new: [....24] [ip4][..udp] [..90.147.69.210][64415] -> [....58.60.10.45][.8000] detected: [....24] [ip4][..udp] [..90.147.69.210][64415] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....21] [ip4][..udp] [..90.147.69.210][57677] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....22] [ip4][..udp] [..90.147.69.210][61686] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....23] [ip4][..udp] [..90.147.69.210][54462] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] + new: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] detected: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....23] [ip4][..udp] [..90.147.69.210][54462] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....24] [ip4][..udp] [..90.147.69.210][64415] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....26] [ip4][..udp] [..90.147.69.210][59394] -> [....58.60.10.45][.8000] + new: [....26] [ip4][..udp] [..90.147.69.210][59394] -> [....58.60.10.45][.8000] detected: [....26] [ip4][..udp] [..90.147.69.210][59394] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....24] [ip4][..udp] [..90.147.69.210][64415] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....27] [ip4][..udp] [..90.147.69.210][49199] -> [....58.60.10.45][.8000] + new: [....27] [ip4][..udp] [..90.147.69.210][49199] -> [....58.60.10.45][.8000] detected: [....27] [ip4][..udp] [..90.147.69.210][49199] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....26] [ip4][..udp] [..90.147.69.210][59394] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] DAEMON-EVENT: [Processed: 27 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 27|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 12] - new: [....28] [ip4][..udp] [..90.147.69.210][61163] -> [....58.60.10.45][.8000] + new: [....28] [ip4][..udp] [..90.147.69.210][61163] -> [....58.60.10.45][.8000] detected: [....28] [ip4][..udp] [..90.147.69.210][61163] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....25] [ip4][..udp] [..90.147.69.210][57872] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....26] [ip4][..udp] [..90.147.69.210][59394] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] update: [....27] [ip4][..udp] [..90.147.69.210][49199] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] - new: [....29] [ip4][..udp] [..90.147.69.210][64420] -> [....58.60.10.45][.8000] + new: [....29] [ip4][..udp] [..90.147.69.210][64420] -> [....58.60.10.45][.8000] detected: [....29] [ip4][..udp] [..90.147.69.210][64420] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....29] [ip4][..udp] [..90.147.69.210][64420] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] idle: [....28] [ip4][..udp] [..90.147.69.210][61163] -> [....58.60.10.45][.8000] [OICQ][Unknown][Chat][Acceptable] diff --git a/test/results/flow-info/default/ookla.pcap.out b/test/results/flow-info/default/ookla.pcap.out index deae2b3f6..d441591d7 100644 --- a/test/results/flow-info/default/ookla.pcap.out +++ b/test/results/flow-info/default/ookla.pcap.out @@ -1,27 +1,27 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] + new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] detected: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] - new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] + new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] detected: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] detection-update: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] RISK: HTTP Obsolete Server - new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] + new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] detected: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] guessed: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] [Ookla][Unknown][Network][Safe] - idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] idle: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 1|detection-updates: 1|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] detection-update: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] idle: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] end: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe] RISK: HTTP Obsolete Server - new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] + new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] detected: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] RISK: Known Proto on Non Std Port detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] diff --git a/test/results/flow-info/default/openvpn.pcap.out b/test/results/flow-info/default/openvpn.pcap.out index c336c5bcd..4d32222f8 100644 --- a/test/results/flow-info/default/openvpn.pcap.out +++ b/test/results/flow-info/default/openvpn.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.77][60140] -> [.46.101.231.218][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.77][60140] -> [.46.101.231.218][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.77][60140] -> [.46.101.231.218][..443] [OpenVPN][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....1] [ip4][..tcp] [...192.168.1.77][60140] -> [.46.101.231.218][..443] [OpenVPN][Unknown][VPN][Acceptable] @@ -16,7 +16,7 @@ [ENTROPIES...: 4.6,5.1,4.9,5.5,5.1,5.6,4.9,5.8,5.1,5.7,5.1,6.0,6.1,5.7,6.5,6.7,5.0,6.6,6.2,6.4,5.7,6.7,6.7,4.8,6.1,6.1,6.4,5.8,6.6,6.8,5.0,6.4] DAEMON-EVENT: [Processed: 95 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.43.12][41507] -> [.139.59.151.137][13680] + new: [.....2] [ip4][..udp] [..192.168.43.12][41507] -> [.139.59.151.137][13680] detected: [.....2] [ip4][..udp] [..192.168.43.12][41507] -> [.139.59.151.137][13680] [OpenVPN][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....2] [ip4][..udp] [..192.168.43.12][41507] -> [.139.59.151.137][13680] [OpenVPN][Unknown][VPN][Acceptable] @@ -33,7 +33,7 @@ RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 178 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.43.18][13680] -> [.139.59.151.137][13680] + new: [.....3] [ip4][..udp] [..192.168.43.18][13680] -> [.139.59.151.137][13680] detected: [.....3] [ip4][..udp] [..192.168.43.18][13680] -> [.139.59.151.137][13680] [OpenVPN][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....3] [ip4][..udp] [..192.168.43.18][13680] -> [.139.59.151.137][13680] [OpenVPN][Unknown][VPN][Acceptable] diff --git a/test/results/flow-info/default/opera-vpn.pcapng.out b/test/results/flow-info/default/opera-vpn.pcapng.out index 926a88d93..a4fbafa35 100644 --- a/test/results/flow-info/default/opera-vpn.pcapng.out +++ b/test/results/flow-info/default/opera-vpn.pcapng.out @@ -1,32 +1,32 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] - new: [.....2] [ip4][..tcp] [...192.168.1.29][51399] -> [..77.111.247.69][..443] - new: [.....3] [ip4][..tcp] [...192.168.1.29][51400] -> [..77.111.247.69][..443] - new: [.....4] [ip4][..tcp] [...192.168.1.29][51401] -> [..77.111.247.69][..443] - new: [.....5] [ip4][..tcp] [...192.168.1.29][51402] -> [..77.111.247.69][..443] - new: [.....6] [ip4][..tcp] [...192.168.1.29][51403] -> [..77.111.247.69][..443] - new: [.....7] [ip4][..tcp] [...192.168.1.29][51404] -> [..77.111.247.69][..443] - new: [.....8] [ip4][..tcp] [...192.168.1.29][51405] -> [..77.111.247.69][..443] - new: [.....9] [ip4][..tcp] [...192.168.1.29][51406] -> [..77.111.247.69][..443] - new: [....10] [ip4][..tcp] [...192.168.1.29][51407] -> [..77.111.247.69][..443] - new: [....11] [ip4][..tcp] [...192.168.1.29][51408] -> [..77.111.247.69][..443] - new: [....12] [ip4][..tcp] [...192.168.1.29][51409] -> [..77.111.247.69][..443] - new: [....13] [ip4][..tcp] [...192.168.1.29][51410] -> [..77.111.247.69][..443] - new: [....14] [ip4][..tcp] [...192.168.1.29][51411] -> [..77.111.247.69][..443] - new: [....15] [ip4][..tcp] [...192.168.1.29][51412] -> [..77.111.247.69][..443] - new: [....16] [ip4][..tcp] [...192.168.1.29][51413] -> [..77.111.247.69][..443] - new: [....17] [ip4][..tcp] [...192.168.1.29][51414] -> [..77.111.247.69][..443] - new: [....18] [ip4][..tcp] [...192.168.1.29][51415] -> [..77.111.247.69][..443] - new: [....19] [ip4][..tcp] [...192.168.1.29][51416] -> [..77.111.247.69][..443] - new: [....20] [ip4][..tcp] [...192.168.1.29][51417] -> [..77.111.247.69][..443] - new: [....21] [ip4][..tcp] [...192.168.1.29][51418] -> [..77.111.247.69][..443] - new: [....22] [ip4][..tcp] [...192.168.1.29][51419] -> [..77.111.247.69][..443] - new: [....23] [ip4][..tcp] [...192.168.1.29][51420] -> [..77.111.247.69][..443] - new: [....24] [ip4][..tcp] [...192.168.1.29][51421] -> [..77.111.247.69][..443] - new: [....25] [ip4][..tcp] [...192.168.1.29][51422] -> [..77.111.247.69][..443] - new: [....26] [ip4][..tcp] [...192.168.1.29][51423] -> [..77.111.247.69][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] + new: [.....2] [ip4][..tcp] [...192.168.1.29][51399] -> [..77.111.247.69][..443] + new: [.....3] [ip4][..tcp] [...192.168.1.29][51400] -> [..77.111.247.69][..443] + new: [.....4] [ip4][..tcp] [...192.168.1.29][51401] -> [..77.111.247.69][..443] + new: [.....5] [ip4][..tcp] [...192.168.1.29][51402] -> [..77.111.247.69][..443] + new: [.....6] [ip4][..tcp] [...192.168.1.29][51403] -> [..77.111.247.69][..443] + new: [.....7] [ip4][..tcp] [...192.168.1.29][51404] -> [..77.111.247.69][..443] + new: [.....8] [ip4][..tcp] [...192.168.1.29][51405] -> [..77.111.247.69][..443] + new: [.....9] [ip4][..tcp] [...192.168.1.29][51406] -> [..77.111.247.69][..443] + new: [....10] [ip4][..tcp] [...192.168.1.29][51407] -> [..77.111.247.69][..443] + new: [....11] [ip4][..tcp] [...192.168.1.29][51408] -> [..77.111.247.69][..443] + new: [....12] [ip4][..tcp] [...192.168.1.29][51409] -> [..77.111.247.69][..443] + new: [....13] [ip4][..tcp] [...192.168.1.29][51410] -> [..77.111.247.69][..443] + new: [....14] [ip4][..tcp] [...192.168.1.29][51411] -> [..77.111.247.69][..443] + new: [....15] [ip4][..tcp] [...192.168.1.29][51412] -> [..77.111.247.69][..443] + new: [....16] [ip4][..tcp] [...192.168.1.29][51413] -> [..77.111.247.69][..443] + new: [....17] [ip4][..tcp] [...192.168.1.29][51414] -> [..77.111.247.69][..443] + new: [....18] [ip4][..tcp] [...192.168.1.29][51415] -> [..77.111.247.69][..443] + new: [....19] [ip4][..tcp] [...192.168.1.29][51416] -> [..77.111.247.69][..443] + new: [....20] [ip4][..tcp] [...192.168.1.29][51417] -> [..77.111.247.69][..443] + new: [....21] [ip4][..tcp] [...192.168.1.29][51418] -> [..77.111.247.69][..443] + new: [....22] [ip4][..tcp] [...192.168.1.29][51419] -> [..77.111.247.69][..443] + new: [....23] [ip4][..tcp] [...192.168.1.29][51420] -> [..77.111.247.69][..443] + new: [....24] [ip4][..tcp] [...192.168.1.29][51421] -> [..77.111.247.69][..443] + new: [....25] [ip4][..tcp] [...192.168.1.29][51422] -> [..77.111.247.69][..443] + new: [....26] [ip4][..tcp] [...192.168.1.29][51423] -> [..77.111.247.69][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [.....2] [ip4][..tcp] [...192.168.1.29][51399] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [.....3] [ip4][..tcp] [...192.168.1.29][51400] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -38,7 +38,7 @@ detected: [.....5] [ip4][..tcp] [...192.168.1.29][51402] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....11] [ip4][..tcp] [...192.168.1.29][51408] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....14] [ip4][..tcp] [...192.168.1.29][51411] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....27] [ip4][..tcp] [...192.168.1.29][51424] -> [..77.111.247.69][..443] + new: [....27] [ip4][..tcp] [...192.168.1.29][51424] -> [..77.111.247.69][..443] detected: [....15] [ip4][..tcp] [...192.168.1.29][51412] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....12] [ip4][..tcp] [...192.168.1.29][51409] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....17] [ip4][..tcp] [...192.168.1.29][51414] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -54,7 +54,7 @@ detected: [....26] [ip4][..tcp] [...192.168.1.29][51423] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....25] [ip4][..tcp] [...192.168.1.29][51422] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....28] [ip4][..tcp] [...192.168.1.29][51425] -> [..77.111.247.69][..443] + new: [....28] [ip4][..tcp] [...192.168.1.29][51425] -> [..77.111.247.69][..443] detection-update: [.....2] [ip4][..tcp] [...192.168.1.29][51399] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [.....3] [ip4][..tcp] [...192.168.1.29][51400] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [.....4] [ip4][..tcp] [...192.168.1.29][51401] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -65,7 +65,7 @@ detection-update: [....11] [ip4][..tcp] [...192.168.1.29][51408] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....14] [ip4][..tcp] [...192.168.1.29][51411] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....27] [ip4][..tcp] [...192.168.1.29][51424] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....29] [ip4][..tcp] [...192.168.1.29][51426] -> [..77.111.247.69][..443] + new: [....29] [ip4][..tcp] [...192.168.1.29][51426] -> [..77.111.247.69][..443] detection-update: [....17] [ip4][..tcp] [...192.168.1.29][51414] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....15] [ip4][..tcp] [...192.168.1.29][51412] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [.....5] [ip4][..tcp] [...192.168.1.29][51402] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -82,10 +82,10 @@ detection-update: [....25] [ip4][..tcp] [...192.168.1.29][51422] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....10] [ip4][..tcp] [...192.168.1.29][51407] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....28] [ip4][..tcp] [...192.168.1.29][51425] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....30] [ip4][..tcp] [...192.168.1.29][51427] -> [..77.111.247.69][..443] + new: [....30] [ip4][..tcp] [...192.168.1.29][51427] -> [..77.111.247.69][..443] detection-update: [....27] [ip4][..tcp] [...192.168.1.29][51424] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....29] [ip4][..tcp] [...192.168.1.29][51426] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....31] [ip4][..tcp] [...192.168.1.29][51428] -> [..77.111.247.69][..443] + new: [....31] [ip4][..tcp] [...192.168.1.29][51428] -> [..77.111.247.69][..443] detection-update: [....28] [ip4][..tcp] [...192.168.1.29][51425] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy @@ -322,7 +322,7 @@ [IATS(ms)....: 27.2,27.2,0.1,29.0,0.4,29.3,0.2,0.2,0.2,0.0,27.4,0.2,22.9,0.0,0.1,50.3,0.1,0.1,27.2,1.1,28.1,0.2,0.0,0.2,1.1,1.1,0.1,0.1,0.1,0.7,0.1] [PKTLENS.....: 64,60,52,569,52,1492,52,1129,52,116,1471,52,52,91,93,76,52,52,591,52,1098,52,1492,704,52,1492,52,1318,751,52,138,172] [ENTROPIES...: 4.2,5.2,4.7,4.4,5.0,7.8,4.8,7.8,4.7,6.0,7.9,5.0,5.0,5.9,5.9,5.6,4.6,4.7,7.6,5.0,7.8,4.7,7.9,7.7,4.7,7.9,4.7,7.8,7.7,4.8,6.2,6.5] - new: [....32] [ip4][..tcp] [...192.168.1.29][51429] -> [..77.111.247.69][..443] + new: [....32] [ip4][..tcp] [...192.168.1.29][51429] -> [..77.111.247.69][..443] analyse: [....24] [ip4][..tcp] [...192.168.1.29][51421] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.044| 0.012| 0.015| 228.764| 3.700] @@ -367,7 +367,7 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....32] [ip4][..tcp] [...192.168.1.29][51429] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....33] [ip4][..tcp] [...192.168.1.29][51430] -> [..77.111.247.69][..443] + new: [....33] [ip4][..tcp] [...192.168.1.29][51430] -> [..77.111.247.69][..443] detected: [....33] [ip4][..tcp] [...192.168.1.29][51430] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....21] [ip4][..tcp] [...192.168.1.29][51418] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy @@ -412,10 +412,10 @@ [ENTROPIES...: 4.2,5.2,4.8,4.4,5.1,7.9,4.8,7.8,4.8,5.9,7.9,5.0,5.1,5.8,4.8,6.0,5.6,4.8,7.7,5.1,7.8,4.8,7.9,7.7,4.8,7.8,4.8,7.9,7.7,4.8,7.9,4.7] detected: [....13] [ip4][..tcp] [...192.168.1.29][51410] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....13] [ip4][..tcp] [...192.168.1.29][51410] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....34] [ip4][..tcp] [...192.168.1.29][51432] -> [..77.111.247.69][..443] - new: [....35] [ip4][..tcp] [...192.168.1.29][51433] -> [..77.111.247.69][..443] + new: [....34] [ip4][..tcp] [...192.168.1.29][51432] -> [..77.111.247.69][..443] + new: [....35] [ip4][..tcp] [...192.168.1.29][51433] -> [..77.111.247.69][..443] detected: [....34] [ip4][..tcp] [...192.168.1.29][51432] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....36] [ip4][..tcp] [...192.168.1.29][51435] -> [..77.111.247.69][..443] + new: [....36] [ip4][..tcp] [...192.168.1.29][51435] -> [..77.111.247.69][..443] detected: [....35] [ip4][..tcp] [...192.168.1.29][51433] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....34] [ip4][..tcp] [...192.168.1.29][51432] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....36] [ip4][..tcp] [...192.168.1.29][51435] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -430,10 +430,10 @@ [IATS(ms)....: 1000.7,1028.3,27.7,0.3,28.6,0.6,28.8,0.7,0.7,1.1,0.3,27.1,1.2,8.9,0.0,35.8,0.0,0.1,0.1,0.6,27.3,2.9,29.6,1.3,0.0,1.3,0.1,0.1,0.8,27.3,0.9] [PKTLENS.....: 64,64,60,52,569,52,1492,52,1129,52,116,1459,52,52,91,93,52,52,76,52,591,52,1098,52,1492,528,52,1067,52,167,52,348] [ENTROPIES...: 4.1,4.2,5.2,4.8,4.4,5.1,7.9,4.8,7.8,4.7,5.9,7.9,5.1,5.0,5.8,6.0,4.7,4.7,5.7,4.7,7.6,4.9,7.8,4.8,7.9,7.6,4.8,7.8,4.7,6.6,5.1,7.3] - new: [....37] [ip4][..tcp] [...192.168.1.29][51436] -> [..77.111.247.69][..443] + new: [....37] [ip4][..tcp] [...192.168.1.29][51436] -> [..77.111.247.69][..443] detection-update: [....36] [ip4][..tcp] [...192.168.1.29][51435] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....38] [ip4][..tcp] [...192.168.1.29][51437] -> [..77.111.247.69][..443] - new: [....39] [ip4][..tcp] [...192.168.1.29][51438] -> [..77.111.247.69][..443] + new: [....38] [ip4][..tcp] [...192.168.1.29][51437] -> [..77.111.247.69][..443] + new: [....39] [ip4][..tcp] [...192.168.1.29][51438] -> [..77.111.247.69][..443] detected: [....37] [ip4][..tcp] [...192.168.1.29][51436] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....39] [ip4][..tcp] [...192.168.1.29][51438] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....38] [ip4][..tcp] [...192.168.1.29][51437] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -470,7 +470,7 @@ [IATS(ms)....: 27.4,27.5,0.2,27.2,1.4,28.3,0.1,0.1,0.2,0.1,25.7,1.2,12.6,39.1,0.1,0.1,0.1,0.1,26.5,1.3,27.7,0.9,0.9,0.3,0.3,0.4,0.4,0.1,0.0,0.1,0.5] [PKTLENS.....: 64,60,52,569,52,1492,52,1129,52,116,1469,52,52,91,52,93,76,52,591,52,1098,52,478,52,1098,52,1492,52,1492,520,52,480] [ENTROPIES...: 4.2,5.3,4.8,4.5,5.1,7.9,4.8,7.9,4.8,5.9,7.9,5.0,5.1,5.9,4.8,6.0,5.7,4.8,7.6,5.1,7.8,4.8,7.5,4.8,7.8,4.8,7.9,4.8,7.9,7.6,4.8,7.5] - new: [....40] [ip4][..tcp] [...192.168.1.29][51440] -> [..77.111.247.69][..443] + new: [....40] [ip4][..tcp] [...192.168.1.29][51440] -> [..77.111.247.69][..443] detected: [....40] [ip4][..tcp] [...192.168.1.29][51440] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....40] [ip4][..tcp] [...192.168.1.29][51440] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....37] [ip4][..tcp] [...192.168.1.29][51436] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -513,7 +513,7 @@ [IATS(ms)....: 31.8,31.9,0.1,31.0,1.6,32.5,1.0,1.0,0.3,0.0,0.0,31.0,1.1,93.8,0.0,125.7,0.0,0.1,0.1,0.1,31.1,87.8,0.0,118.8,0.0,0.3,0.3,0.2,0.0,0.2,0.8] [PKTLENS.....: 64,60,52,569,52,1492,52,1129,52,116,1492,55,52,52,91,93,52,52,76,52,591,52,1098,498,52,52,1098,52,1492,528,52,1098] [ENTROPIES...: 4.2,5.2,4.7,4.5,5.0,7.9,4.7,7.8,4.8,6.0,7.9,4.8,5.0,5.0,5.9,5.9,4.8,4.8,5.6,4.8,7.6,5.0,7.8,7.6,4.8,4.8,7.8,4.7,7.9,7.5,4.8,7.8] - new: [....41] [ip4][..tcp] [...192.168.1.29][51441] -> [..77.111.247.69][..443] + new: [....41] [ip4][..tcp] [...192.168.1.29][51441] -> [..77.111.247.69][..443] detected: [....41] [ip4][..tcp] [...192.168.1.29][51441] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....41] [ip4][..tcp] [...192.168.1.29][51441] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....41] [ip4][..tcp] [...192.168.1.29][51441] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -526,10 +526,10 @@ [IATS(ms)....: 27.0,27.1,0.2,27.1,0.5,0.1,27.4,0.1,0.6,0.1,26.6,0.0,98.7,124.6,1.2,1.2,0.1,0.1,0.1,26.2,91.4,117.4,0.2,0.1,0.3,0.0,0.0,0.3,0.2,0.0,0.2] [PKTLENS.....: 64,60,52,569,52,1492,1129,52,52,116,1465,52,52,91,52,93,52,76,52,591,52,1098,52,1098,52,1492,704,262,52,1098,271,52] [ENTROPIES...: 4.1,5.2,4.7,4.4,5.0,7.8,7.8,4.7,4.7,5.9,7.9,4.9,4.9,5.9,4.7,5.8,4.7,5.5,4.7,7.6,5.0,7.8,4.8,7.8,4.8,7.9,7.7,7.2,4.7,7.8,7.2,4.7] - new: [....42] [ip4][..tcp] [...192.168.1.29][51442] -> [..77.111.247.69][..443] + new: [....42] [ip4][..tcp] [...192.168.1.29][51442] -> [..77.111.247.69][..443] detected: [....42] [ip4][..tcp] [...192.168.1.29][51442] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....43] [ip4][..tcp] [...192.168.1.29][51443] -> [..77.111.247.69][..443] - new: [....44] [ip4][..tcp] [...192.168.1.29][51444] -> [..77.111.247.69][..443] + new: [....43] [ip4][..tcp] [...192.168.1.29][51443] -> [..77.111.247.69][..443] + new: [....44] [ip4][..tcp] [...192.168.1.29][51444] -> [..77.111.247.69][..443] detection-update: [....42] [ip4][..tcp] [...192.168.1.29][51442] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....43] [ip4][..tcp] [...192.168.1.29][51443] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....44] [ip4][..tcp] [...192.168.1.29][51444] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -555,9 +555,9 @@ [IATS(ms)....: 29.8,29.9,0.1,27.6,1.3,0.0,28.8,0.1,0.3,0.0,26.9,0.1,14.1,0.1,40.8,0.1,0.1,0.1,27.1,1.2,28.3,0.7,27.4,96.8,0.1,98.7,0.0,1.2,29.7,0.1,2.9] [PKTLENS.....: 64,60,52,569,52,1492,1128,52,52,116,1461,52,52,91,93,52,76,52,608,52,527,52,138,52,172,583,52,52,133,52,105,1098] [ENTROPIES...: 4.1,5.2,4.7,4.5,5.0,7.9,7.8,4.7,4.6,6.0,7.8,4.9,5.0,5.8,5.9,4.8,5.6,4.8,7.5,5.1,7.6,4.8,6.3,5.0,6.6,7.7,5.0,5.1,6.3,4.7,5.8,7.8] - new: [....45] [ip4][..tcp] [...192.168.1.29][51449] -> [..77.111.247.69][..443] - new: [....46] [ip4][..tcp] [...192.168.1.29][51450] -> [..77.111.247.69][..443] - new: [....47] [ip4][..tcp] [...192.168.1.29][51451] -> [..77.111.247.69][..443] + new: [....45] [ip4][..tcp] [...192.168.1.29][51449] -> [..77.111.247.69][..443] + new: [....46] [ip4][..tcp] [...192.168.1.29][51450] -> [..77.111.247.69][..443] + new: [....47] [ip4][..tcp] [...192.168.1.29][51451] -> [..77.111.247.69][..443] analyse: [....42] [ip4][..tcp] [...192.168.1.29][51442] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.207| 0.028| 0.058| 3307.776| 2.900] @@ -570,9 +570,9 @@ [ENTROPIES...: 4.2,5.2,4.7,4.4,5.1,7.9,4.8,7.8,4.8,5.9,7.9,5.1,5.1,6.0,5.8,5.6,4.8,7.6,5.1,7.8,4.8,7.6,4.8,7.8,4.8,7.9,4.8,7.9,4.8,7.8,4.8,7.9] detected: [....45] [ip4][..tcp] [...192.168.1.29][51449] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....46] [ip4][..tcp] [...192.168.1.29][51450] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....48] [ip4][..tcp] [...192.168.1.29][51452] -> [..77.111.247.69][..443] + new: [....48] [ip4][..tcp] [...192.168.1.29][51452] -> [..77.111.247.69][..443] detected: [....47] [ip4][..tcp] [...192.168.1.29][51451] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....49] [ip4][..tcp] [...192.168.1.29][51453] -> [..77.111.247.69][..443] + new: [....49] [ip4][..tcp] [...192.168.1.29][51453] -> [..77.111.247.69][..443] detection-update: [....45] [ip4][..tcp] [...192.168.1.29][51449] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....46] [ip4][..tcp] [...192.168.1.29][51450] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....48] [ip4][..tcp] [...192.168.1.29][51452] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -610,7 +610,7 @@ [IATS(ms)....: 27.4,27.4,0.1,27.3,0.5,27.6,0.1,0.1,0.2,0.1,26.1,0.5,7.6,0.0,33.8,0.1,1.2,1.1,0.1,27.5,0.4,27.8,0.3,0.1,0.1,26.2,0.0,0.8,0.1,26.6,0.1] [PKTLENS.....: 64,60,52,569,52,1492,52,1129,52,116,1469,52,52,91,93,52,52,76,52,612,52,527,52,138,172,537,52,52,52,133,52,105] [ENTROPIES...: 4.2,5.3,4.8,4.4,5.0,7.8,4.8,7.8,4.8,5.9,7.9,5.1,5.0,6.1,5.9,4.7,4.7,5.6,4.8,7.6,5.1,7.6,4.8,6.3,6.6,7.5,5.1,5.0,5.1,6.5,4.8,5.9] - new: [....50] [ip4][..tcp] [...192.168.1.29][51454] -> [..77.111.247.69][..443] + new: [....50] [ip4][..tcp] [...192.168.1.29][51454] -> [..77.111.247.69][..443] detected: [....50] [ip4][..tcp] [...192.168.1.29][51454] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....50] [ip4][..tcp] [...192.168.1.29][51454] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....47] [ip4][..tcp] [...192.168.1.29][51451] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -623,14 +623,14 @@ [IATS(ms)....: 26.8,26.8,0.1,27.0,1.6,0.0,28.5,0.1,0.2,0.1,25.7,0.0,152.5,0.0,0.1,177.9,0.0,0.1,0.1,26.1,149.1,175.0,1.3,1.3,0.2,0.0,0.2,0.3,0.2,0.1,0.1] [PKTLENS.....: 64,60,52,569,52,1492,1128,52,52,116,1471,52,52,91,93,76,52,52,52,591,52,1098,52,1098,52,1492,704,52,1492,52,1492,52] [ENTROPIES...: 4.1,5.2,4.7,4.4,4.9,7.9,7.8,4.6,4.6,5.9,7.9,5.1,5.0,5.8,5.8,5.6,4.7,4.7,4.7,7.6,5.1,7.8,4.7,7.8,4.7,7.9,7.7,4.7,7.9,4.7,7.9,4.7] - new: [....51] [ip4][..tcp] [...192.168.1.29][51455] -> [..77.111.247.69][..443] - new: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] + new: [....51] [ip4][..tcp] [...192.168.1.29][51455] -> [..77.111.247.69][..443] + new: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] detected: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....51] [ip4][..tcp] [...192.168.1.29][51455] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....51] [ip4][..tcp] [...192.168.1.29][51455] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....53] [ip4][..tcp] [...192.168.1.29][51457] -> [..77.111.247.69][..443] - new: [....54] [ip4][..tcp] [...192.168.1.29][51458] -> [..77.111.247.69][..443] + new: [....53] [ip4][..tcp] [...192.168.1.29][51457] -> [..77.111.247.69][..443] + new: [....54] [ip4][..tcp] [...192.168.1.29][51458] -> [..77.111.247.69][..443] analyse: [.....8] [ip4][..tcp] [...192.168.1.29][51405] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 3.028| 0.204| 0.738| 545057.276| 1.400] @@ -641,7 +641,7 @@ [IATS(ms)....: 33.0,33.0,0.3,26.6,1.1,27.4,0.1,0.1,0.3,0.1,26.0,1.1,8.9,0.1,35.6,0.1,0.1,0.0,26.2,2.1,28.2,0.1,0.0,0.1,0.5,28.2,27.7,0.1,0.1,3002.0,3028.4] [PKTLENS.....: 64,60,52,569,52,1492,52,1128,52,116,1477,52,52,91,93,52,76,52,591,52,1098,52,1098,453,52,138,253,52,148,52,52,76] [ENTROPIES...: 4.2,5.2,4.8,4.4,5.0,7.8,4.8,7.8,4.8,6.0,7.9,5.0,4.9,5.9,5.9,4.8,5.7,4.8,7.6,5.0,7.8,4.7,7.8,7.6,4.7,6.3,7.1,4.8,6.6,4.7,4.6,5.6] - new: [....55] [ip4][..tcp] [...192.168.1.29][51459] -> [..77.111.247.69][..443] + new: [....55] [ip4][..tcp] [...192.168.1.29][51459] -> [..77.111.247.69][..443] analyse: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.029| 0.007| 0.012| 139.021| 3.300] @@ -706,7 +706,7 @@ [IATS(ms)....: 28.6,28.6,0.1,27.3,1.5,0.1,28.7,0.1,0.2,0.1,27.0,0.0,1.1,153.8,0.0,181.6,0.0,0.1,0.1,0.1,27.4,146.5,0.0,173.7,0.1,603.7,0.0,603.8,141.3,141.3,0.3] [PKTLENS.....: 64,60,52,569,52,1492,1127,52,52,116,1469,52,52,52,91,93,52,52,76,52,591,52,1098,498,52,52,1098,498,52,1098,52,1492] [ENTROPIES...: 4.2,5.3,4.8,4.4,5.1,7.9,7.8,4.8,4.8,6.0,7.9,5.1,5.1,5.1,5.9,5.9,4.7,4.8,5.6,4.8,7.6,5.1,7.8,7.6,4.8,4.8,7.8,7.6,4.7,7.8,4.7,7.9] - new: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] + new: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] detected: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -719,7 +719,7 @@ [IATS(ms)....: 27.3,27.4,0.1,27.0,0.6,27.4,0.7,0.7,0.4,0.1,25.9,1.2,11.4,0.0,38.1,0.1,0.0,0.1,0.1,26.0,2.8,28.7,0.2,0.0,0.2,0.1,0.1,0.1,188.2,188.4,5.4] [PKTLENS.....: 64,60,52,569,52,1492,52,1128,52,116,1463,52,52,91,93,52,76,52,52,591,52,1098,52,1492,704,52,1098,52,52,366,52,138] [ENTROPIES...: 4.1,5.2,4.6,4.4,5.0,7.8,4.7,7.8,4.7,5.9,7.9,4.9,5.0,5.9,5.7,4.6,5.6,4.6,4.6,7.6,5.0,7.8,4.7,7.9,7.7,4.6,7.8,4.6,4.7,7.3,4.6,6.2] - new: [....57] [ip4][..tcp] [...192.168.1.29][51461] -> [..77.111.247.69][..443] + new: [....57] [ip4][..tcp] [...192.168.1.29][51461] -> [..77.111.247.69][..443] detected: [....57] [ip4][..tcp] [...192.168.1.29][51461] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....57] [ip4][..tcp] [...192.168.1.29][51461] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....57] [ip4][..tcp] [...192.168.1.29][51461] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -732,7 +732,7 @@ [IATS(ms)....: 27.0,27.1,0.5,27.3,1.5,28.3,0.1,0.1,1.2,0.3,27.0,1.2,7.6,0.1,0.0,34.3,0.1,0.5,26.1,2.9,0.1,28.4,0.0,0.1,0.1,0.2,0.0,0.2,4.5,0.1,4.6] [PKTLENS.....: 64,60,52,569,52,1492,52,1127,52,116,1459,52,52,91,93,76,52,52,591,52,1098,1098,52,52,922,52,1098,250,52,1098,682,52] [ENTROPIES...: 4.2,5.1,4.7,4.4,5.0,7.8,4.8,7.8,4.8,6.0,7.9,5.1,5.1,5.9,6.0,5.7,4.8,4.8,7.7,5.0,7.8,7.8,4.8,4.8,7.8,4.6,7.8,7.2,4.8,7.9,7.7,4.8] - new: [....58] [ip4][..tcp] [...192.168.1.29][51462] -> [..77.111.247.69][..443] + new: [....58] [ip4][..tcp] [...192.168.1.29][51462] -> [..77.111.247.69][..443] detected: [....58] [ip4][..tcp] [...192.168.1.29][51462] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....58] [ip4][..tcp] [...192.168.1.29][51462] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] analyse: [....58] [ip4][..tcp] [...192.168.1.29][51462] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -745,11 +745,11 @@ [IATS(ms)....: 27.2,27.3,0.3,27.3,1.5,28.5,0.1,0.1,0.4,0.1,27.0,0.0,6.2,0.1,32.7,0.0,0.1,0.1,26.1,2.8,28.8,1.2,1.1,0.3,0.3,0.2,0.0,0.0,0.2,0.1,1.1] [PKTLENS.....: 64,60,52,569,52,1492,52,1129,52,116,1491,52,52,91,93,52,76,52,591,52,1098,52,258,52,1098,52,1492,704,610,52,52,148] [ENTROPIES...: 4.2,5.2,4.6,4.4,4.9,7.8,4.7,7.8,4.7,5.8,7.9,4.9,4.9,5.9,5.9,4.7,5.6,4.7,7.6,4.9,7.8,4.7,7.2,4.7,7.8,4.7,7.9,7.7,7.7,4.7,4.7,6.4] - new: [....59] [ip4][..tcp] [...192.168.1.29][51463] -> [..77.111.247.69][..443] - new: [....60] [ip4][..tcp] [...192.168.1.29][51464] -> [..77.111.247.69][..443] + new: [....59] [ip4][..tcp] [...192.168.1.29][51463] -> [..77.111.247.69][..443] + new: [....60] [ip4][..tcp] [...192.168.1.29][51464] -> [..77.111.247.69][..443] detected: [....59] [ip4][..tcp] [...192.168.1.29][51463] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....60] [ip4][..tcp] [...192.168.1.29][51464] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] - new: [....61] [ip4][..tcp] [...192.168.1.29][51465] -> [..77.111.247.69][..443] + new: [....61] [ip4][..tcp] [...192.168.1.29][51465] -> [..77.111.247.69][..443] detection-update: [....59] [ip4][..tcp] [...192.168.1.29][51463] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detected: [....61] [ip4][..tcp] [...192.168.1.29][51465] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....60] [ip4][..tcp] [...192.168.1.29][51464] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] @@ -784,7 +784,7 @@ [IATS(ms)....: 26.5,26.7,0.1,27.2,0.5,27.5,0.1,0.1,0.2,0.1,25.3,1.2,5.0,31.3,0.1,0.1,0.1,0.1,26.1,1.5,27.5,0.1,0.1,0.2,0.2,0.3,0.1,25.6,0.1,2.4,27.8] [PKTLENS.....: 64,60,52,569,52,1492,52,1127,52,116,1459,52,52,91,52,93,76,52,591,52,1098,52,1098,52,1184,52,154,659,52,52,274,52] [ENTROPIES...: 4.2,5.3,4.7,4.4,5.1,7.8,4.8,7.8,4.8,6.0,7.9,5.1,5.1,5.9,4.8,5.9,5.6,4.8,7.6,5.1,7.8,4.8,7.8,4.8,7.8,4.8,6.4,7.6,4.9,5.0,7.2,4.7] - new: [....62] [ip4][..tcp] [...192.168.1.29][51466] -> [..77.111.247.69][..443] + new: [....62] [ip4][..tcp] [...192.168.1.29][51466] -> [..77.111.247.69][..443] detected: [....62] [ip4][..tcp] [...192.168.1.29][51466] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] detection-update: [....62] [ip4][..tcp] [...192.168.1.29][51466] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable][eu0.sec-tunnel.com] idle: [.....1] [ip4][..tcp] [...192.168.1.29][51398] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] @@ -842,7 +842,7 @@ idle: [....52] [ip4][..tcp] [...192.168.1.29][51456] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] guessed: [....53] [ip4][..tcp] [...192.168.1.29][51457] -> [..77.111.247.69][..443] [TLS][Unknown][Web][Safe] RISK: TCP Connection Issues - end: [....53] [ip4][..tcp] [...192.168.1.29][51457] -> [..77.111.247.69][..443] + end: [....53] [ip4][..tcp] [...192.168.1.29][51457] -> [..77.111.247.69][..443] end: [....54] [ip4][..tcp] [...192.168.1.29][51458] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] idle: [....55] [ip4][..tcp] [...192.168.1.29][51459] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] idle: [....56] [ip4][..tcp] [...192.168.1.29][51460] -> [..77.111.247.69][..443] [TLS.OperaVPN][Unknown][VPN][Acceptable] diff --git a/test/results/flow-info/default/oracle12.pcapng.out b/test/results/flow-info/default/oracle12.pcapng.out index 9054ee68a..261b644a8 100644 --- a/test/results/flow-info/default/oracle12.pcapng.out +++ b/test/results/flow-info/default/oracle12.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......10.0.2.15][40226] -> [....10.0.72.139][.1521] + new: [.....1] [ip4][..tcp] [......10.0.2.15][40226] -> [....10.0.72.139][.1521] guessed: [.....1] [ip4][..tcp] [......10.0.2.15][40226] -> [....10.0.72.139][.1521] [Oracle][Unknown][Database][Acceptable] - idle: [.....1] [ip4][..tcp] [......10.0.2.15][40226] -> [....10.0.72.139][.1521] + idle: [.....1] [ip4][..tcp] [......10.0.2.15][40226] -> [....10.0.72.139][.1521] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/os_detected.pcapng.out b/test/results/flow-info/default/os_detected.pcapng.out index f78a15fb3..9c29ed3d9 100644 --- a/test/results/flow-info/default/os_detected.pcapng.out +++ b/test/results/flow-info/default/os_detected.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.128][39821] -> [........8.8.8.8][..443] + new: [.....1] [ip4][..udp] [..192.168.1.128][39821] -> [........8.8.8.8][..443] detected: [.....1] [ip4][..udp] [..192.168.1.128][39821] -> [........8.8.8.8][..443] [QUIC][Google][Web][Acceptable][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch idle: [.....1] [ip4][..udp] [..192.168.1.128][39821] -> [........8.8.8.8][..443] [QUIC][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/ospfv2_add_new_prefix.pcap.out b/test/results/flow-info/default/ospfv2_add_new_prefix.pcap.out index 6bc1cb4c4..617739bac 100644 --- a/test/results/flow-info/default/ospfv2_add_new_prefix.pcap.out +++ b/test/results/flow-info/default/ospfv2_add_new_prefix.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][...89] [.....10.1.10.10] -> [......10.1.10.1] + new: [.....1] [ip4][...89] [.....10.1.10.10] -> [......10.1.10.1] detected: [.....1] [ip4][...89] [.....10.1.10.10] -> [......10.1.10.1] [OSPF][Unknown][Network][Acceptable] idle: [.....1] [ip4][...89] [.....10.1.10.10] -> [......10.1.10.1] [OSPF][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/ossfuzz_seed_fake_traces_1.pcapng.out b/test/results/flow-info/default/ossfuzz_seed_fake_traces_1.pcapng.out index df63cf0a1..328856df4 100644 --- a/test/results/flow-info/default/ossfuzz_seed_fake_traces_1.pcapng.out +++ b/test/results/flow-info/default/ossfuzz_seed_fake_traces_1.pcapng.out @@ -1,41 +1,41 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][....1] -> [......127.0.0.1][....2] + new: [.....1] [ip4][..udp] [......127.0.0.1][....1] -> [......127.0.0.1][....2] detected: [.....1] [ip4][..udp] [......127.0.0.1][....1] -> [......127.0.0.1][....2] [HalfLife2][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] + new: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] idle: [.....1] [ip4][..udp] [......127.0.0.1][....1] -> [......127.0.0.1][....2] [HalfLife2][Unknown][Game][Fun] - update: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] + update: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] detected: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] [Protobuf][Unknown][Network][Safe] RISK: Unidirectional Traffic update: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] [Protobuf][Unknown][Network][Safe] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 10 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....3] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.206.130][.1119] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.206.130][.1119] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.206.130][.1119] [Starcraft][Unknown][Game][Fun] RISK: TCP Connection Issues idle: [.....2] [ip4][..udp] [......127.0.0.1][.1119] -> [......127.0.0.1][.1120] [Protobuf][Unknown][Network][Safe] RISK: Unidirectional Traffic - new: [.....4] [ip4][..tcp] [..192.168.1.128][....1] -> [121.254.200.130][.1119] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.1.128][....1] -> [121.254.200.130][.1119] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.1.128][....1] -> [121.254.200.130][.1119] [Starcraft][Unknown][Game][Fun] RISK: TCP Connection Issues - new: [.....5] [ip4][..tcp] [..192.168.1.128][....1] -> [....202.9.66.76][.1119] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..192.168.1.128][....1] -> [....202.9.66.76][.1119] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..192.168.1.128][....1] -> [....202.9.66.76][.1119] [Starcraft][Starcraft][Game][Fun] RISK: TCP Connection Issues - new: [.....6] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.236.254][.1119] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.236.254][.1119] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..192.168.1.128][....1] -> [.12.129.236.254][.1119] [Starcraft][Unknown][Game][Fun] RISK: TCP Connection Issues DAEMON-EVENT: [Processed: 14 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....7] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] + new: [.....7] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] detected: [.....7] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] [Steam][Unknown][Game][Fun] update: [.....7] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] [Steam][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....8] [ip4][..udp] [......127.0.0.1][17788] -> [......127.0.0.1][17788] + new: [.....8] [ip4][..udp] [......127.0.0.1][17788] -> [......127.0.0.1][17788] detected: [.....8] [ip4][..udp] [......127.0.0.1][17788] -> [......127.0.0.1][17788] [PPStream][Unknown][Streaming][Fun] idle: [.....7] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] [Steam][Unknown][Game][Fun] idle: [.....4] [ip4][..tcp] [..192.168.1.128][....1] -> [121.254.200.130][.1119] [Starcraft][Unknown][Game][Fun] @@ -48,11 +48,11 @@ RISK: TCP Connection Issues DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....9] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...10] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...10] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...10] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol, Unidirectional Traffic, TCP Connection Issues idle: [.....8] [ip4][..udp] [......127.0.0.1][17788] -> [......127.0.0.1][17788] [PPStream][Unknown][Streaming][Fun] - new: [....10] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...11] [MIDSTREAM] + new: [....10] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...11] [MIDSTREAM] detected: [....10] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...11] [Gnutella][Unknown][Download][Potentially Dangerous] RISK: Unsafe Protocol, Unidirectional Traffic, TCP Connection Issues idle: [.....9] [ip4][..tcp] [..192.168.1.128][....1] -> [........1.2.3.4][...10] [Gnutella][Unknown][Download][Potentially Dangerous] diff --git a/test/results/flow-info/default/ossfuzz_seed_fake_traces_2.pcapng.out b/test/results/flow-info/default/ossfuzz_seed_fake_traces_2.pcapng.out index cf4ab63c7..7bbf48be7 100644 --- a/test/results/flow-info/default/ossfuzz_seed_fake_traces_2.pcapng.out +++ b/test/results/flow-info/default/ossfuzz_seed_fake_traces_2.pcapng.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] - new: [.....2] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] + new: [.....1] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] + new: [.....2] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] detected: [.....1] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] [Usenet][Unknown][Web][Acceptable] detected: [.....2] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] - new: [.....4] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] + new: [.....3] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] + new: [.....4] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] detected: [.....4] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] idle: [.....1] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] [Usenet][Unknown][Web][Acceptable] idle: [.....2] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] + new: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] detected: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] guessed: [.....3] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] [WireGuard][Unknown][VPN][Acceptable] - idle: [.....3] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] + idle: [.....3] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] end: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] idle: [.....4] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/ossfuzz_seed_fake_traces_3.pcapng.out b/test/results/flow-info/default/ossfuzz_seed_fake_traces_3.pcapng.out index f7b87506d..64f2c66a0 100644 --- a/test/results/flow-info/default/ossfuzz_seed_fake_traces_3.pcapng.out +++ b/test/results/flow-info/default/ossfuzz_seed_fake_traces_3.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.16.173][60546] -> [..93.184.216.34][...80] + new: [.....1] [ip4][..tcp] [.192.168.16.173][60546] -> [..93.184.216.34][...80] detected: [.....1] [ip4][..tcp] [.192.168.16.173][60546] -> [..93.184.216.34][...80] [MapleStory][Edgecast][Game][Fun] idle: [.....1] [ip4][..tcp] [.192.168.16.173][60546] -> [..93.184.216.34][...80] [MapleStory][Edgecast][Game][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/ossfuzz_seed_fake_traces_4.pcapng.out b/test/results/flow-info/default/ossfuzz_seed_fake_traces_4.pcapng.out index fbe3a06c5..ac6a349ec 100644 --- a/test/results/flow-info/default/ossfuzz_seed_fake_traces_4.pcapng.out +++ b/test/results/flow-info/default/ossfuzz_seed_fake_traces_4.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] + new: [.....1] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] not-detected: [.....1] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] [Unknown][Unknown][Unrated] - idle: [.....1] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] + idle: [.....1] [ip4][..udp] [......127.0.0.1][..100] -> [......127.0.0.1][..200] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/pgm.pcap.out b/test/results/flow-info/default/pgm.pcap.out index cf260a764..9baed44bd 100644 --- a/test/results/flow-info/default/pgm.pcap.out +++ b/test/results/flow-info/default/pgm.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..113] [..10.244.64.154] -> [.....235.0.1.47] + new: [.....1] [ip4][..113] [..10.244.64.154] -> [.....235.0.1.47] detected: [.....1] [ip4][..113] [..10.244.64.154] -> [.....235.0.1.47] [PGM][Unknown][Network][Acceptable] analyse: [.....1] [ip4][..113] [..10.244.64.154] -> [.....235.0.1.47] [PGM][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/pgsql.pcap.out b/test/results/flow-info/default/pgsql.pcap.out index a3a6c4476..75eb2e033 100644 --- a/test/results/flow-info/default/pgsql.pcap.out +++ b/test/results/flow-info/default/pgsql.pcap.out @@ -1,19 +1,19 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][45930] -> [......127.0.0.1][.5432] - new: [.....2] [ip4][..tcp] [......127.0.0.1][45931] -> [......127.0.0.1][.5432] + new: [.....1] [ip4][..tcp] [......127.0.0.1][45930] -> [......127.0.0.1][.5432] + new: [.....2] [ip4][..tcp] [......127.0.0.1][45931] -> [......127.0.0.1][.5432] detected: [.....1] [ip4][..tcp] [......127.0.0.1][45930] -> [......127.0.0.1][.5432] [PostgreSQL][Unknown][Database][Acceptable] detected: [.....2] [ip4][..tcp] [......127.0.0.1][45931] -> [......127.0.0.1][.5432] [PostgreSQL][Unknown][Database][Acceptable] DAEMON-EVENT: [Processed: 39 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..172.16.20.244][59036] -> [...172.16.20.75][.5432] + new: [.....3] [ip4][..tcp] [..172.16.20.244][59036] -> [...172.16.20.75][.5432] detected: [.....3] [ip4][..tcp] [..172.16.20.244][59036] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] - new: [.....4] [ip4][..tcp] [..172.16.20.244][59037] -> [...172.16.20.75][.5432] + new: [.....4] [ip4][..tcp] [..172.16.20.244][59037] -> [...172.16.20.75][.5432] detected: [.....4] [ip4][..tcp] [..172.16.20.244][59037] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] - new: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] + new: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] detected: [.....5] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] - new: [.....6] [ip4][..tcp] [..172.16.20.244][59039] -> [...172.16.20.75][.5432] + new: [.....6] [ip4][..tcp] [..172.16.20.244][59039] -> [...172.16.20.75][.5432] detected: [.....6] [ip4][..tcp] [..172.16.20.244][59039] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] idle: [.....1] [ip4][..tcp] [......127.0.0.1][45930] -> [......127.0.0.1][.5432] [PostgreSQL][Unknown][Database][Acceptable] idle: [.....2] [ip4][..tcp] [......127.0.0.1][45931] -> [......127.0.0.1][.5432] [PostgreSQL][Unknown][Database][Acceptable] diff --git a/test/results/flow-info/default/pim.pcap.out b/test/results/flow-info/default/pim.pcap.out index fea5d9444..08db2145f 100644 --- a/test/results/flow-info/default/pim.pcap.out +++ b/test/results/flow-info/default/pim.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..103] [192.168.203.234] -> [.....224.0.0.13] + new: [.....1] [ip4][..103] [192.168.203.234] -> [.....224.0.0.13] detected: [.....1] [ip4][..103] [192.168.203.234] -> [.....224.0.0.13] [IP_PIM][Unknown][Network][Acceptable] idle: [.....1] [ip4][..103] [192.168.203.234] -> [.....224.0.0.13] [IP_PIM][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/pinterest.pcap.out b/test/results/flow-info/default/pinterest.pcap.out index be6db57e2..f10804089 100644 --- a/test/results/flow-info/default/pinterest.pcap.out +++ b/test/results/flow-info/default/pinterest.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33164] -> [.....................64:ff9b::9765:7854][..443] [MIDSTREAM] - new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] [MIDSTREAM] - new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] + new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33164] -> [.....................64:ff9b::9765:7854][..443] [MIDSTREAM] + new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] [MIDSTREAM] + new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] detected: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][www.pinterest.fr] detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][www.pinterest.fr] detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][www.pinterest.fr] @@ -18,12 +18,12 @@ [PKTLENS.....: 80,80,72,589,72,1120,1120,1120,72,72,72,1120,1120,154,72,72,72,165,171,437,72,72,330,72,138,72,72,110,72,1120,1120,549] [ENTROPIES...: 4.8,5.2,5.2,4.5,5.0,6.8,4.5,6.6,5.2,5.2,5.3,7.1,7.6,6.3,5.2,5.2,5.1,6.1,6.4,7.4,5.1,5.0,7.1,5.3,6.2,5.1,5.2,5.6,5.1,7.8,7.8,7.6] detection-update: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][www.pinterest.fr] - new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] - new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38514] -> [.......................2a04:4e42:1d::84][..443] - new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38516] -> [.......................2a04:4e42:1d::84][..443] - new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38518] -> [.......................2a04:4e42:1d::84][..443] - new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38520] -> [.......................2a04:4e42:1d::84][..443] - new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38522] -> [.......................2a04:4e42:1d::84][..443] + new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] + new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38514] -> [.......................2a04:4e42:1d::84][..443] + new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38516] -> [.......................2a04:4e42:1d::84][..443] + new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38518] -> [.......................2a04:4e42:1d::84][..443] + new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38520] -> [.......................2a04:4e42:1d::84][..443] + new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38522] -> [.......................2a04:4e42:1d::84][..443] detected: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] detected: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38518] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] detected: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38516] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] @@ -42,9 +42,9 @@ detection-update: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38514] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] detection-update: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38520] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] detection-update: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38520] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][s.pinimg.com] - new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33156] -> [.....................64:ff9b::9765:7854][..443] [MIDSTREAM] - new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] [MIDSTREAM] - new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] [MIDSTREAM] + new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33156] -> [.....................64:ff9b::9765:7854][..443] [MIDSTREAM] + new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] [MIDSTREAM] + new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] [MIDSTREAM] analyse: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.054| 0.008| 0.015| 217.895| 3.000] @@ -55,12 +55,12 @@ [IATS(ms)....: 29.2,29.3,0.5,30.6,2.1,0.0,0.0,0.0,32.2,0.0,0.0,0.0,7.2,0.3,2.0,0.2,0.1,0.3,0.4,53.9,0.0,0.2,0.0,43.6,1.3,0.0,0.0,1.3,0.2,0.8,0.5] [PKTLENS.....: 80,80,72,589,72,1460,1460,1460,1230,72,72,72,72,165,171,363,383,350,1026,328,72,72,72,330,72,138,72,72,72,110,1460,72] [ENTROPIES...: 4.6,5.1,5.1,4.4,4.9,6.4,5.2,7.3,7.6,5.1,5.0,5.1,5.1,6.0,6.2,7.2,7.1,6.9,7.4,6.9,4.9,4.9,4.9,7.1,5.1,6.1,4.9,5.0,5.1,5.6,7.9,5.1] - new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] + new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] detected: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][GoogleCloud][Web][Safe][sessions.bugsnag.com] - new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] + new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] detection-update: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][GoogleCloud][Web][Safe][sessions.bugsnag.com] detected: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] - new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] + new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] detection-update: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] detected: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][accounts.pinterest.com] analyse: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Google][Web][Acceptable] @@ -75,7 +75,7 @@ [ENTROPIES...: 4.8,5.3,5.2,4.5,5.1,7.8,7.8,5.3,5.3,7.1,5.3,6.2,6.6,7.4,5.1,5.1,5.1,7.7,5.2,5.8,5.8,5.2,7.5,7.8,7.0,5.2,5.3,5.3,5.9,5.3,5.9,5.1] detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][accounts.pinterest.com] detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][accounts.pinterest.com] - new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] + new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] analyse: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][GoogleCloud][Web][Safe] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.133| 0.015| 0.030| 874.849| 3.100] @@ -111,11 +111,11 @@ [PKTLENS.....: 80,80,72,589,72,1460,1460,72,72,1460,72,1460,1205,72,72,165,171,440,72,72,72,330,138,72,72,1460,1460,1460,72,72,72,1460] [ENTROPIES...: 4.7,5.1,5.1,4.5,5.0,6.7,4.9,5.1,5.1,7.4,5.1,7.3,7.6,5.1,5.2,5.9,6.3,7.4,5.0,5.0,5.0,7.1,6.2,5.2,5.1,7.9,7.9,7.9,5.1,5.1,5.1,7.8] detection-update: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Unknown][Media][Safe][images.unsplash.com] - new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] + new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] detected: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] [TLS.Google][Google][Web][Acceptable][www.gstatic.com] - new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] + new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] detected: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] [TLS.Google][Google][Web][Acceptable][apis.google.com] - new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] + new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] detection-update: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] [TLS.Google][Google][Web][Acceptable][www.gstatic.com] detected: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][connect.facebook.net] detection-update: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] [TLS.Google][Google][Web][Acceptable][apis.google.com] @@ -130,13 +130,13 @@ [IATS(ms)....: 27.0,27.1,0.2,32.3,0.0,0.0,32.0,0.0,3.9,0.4,0.1,64.7,93.2,0.0,0.0,0.3,0.0,0.0,0.0,24.3,0.0,0.0,0.0,0.2,0.0,0.0,0.1,0.0,0.0,4.4,39.9] [PKTLENS.....: 80,80,72,589,72,1452,979,72,72,136,164,330,330,72,72,72,251,152,116,653,72,72,72,72,483,1452,114,72,72,72,103,199] [ENTROPIES...: 5.1,5.4,5.4,4.6,5.3,7.8,7.8,5.5,5.5,6.2,6.5,7.3,7.3,5.3,5.2,5.3,7.0,6.4,5.9,7.6,5.4,5.4,5.4,5.4,7.5,7.9,6.1,5.4,5.4,5.4,5.9,6.7] - new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] + new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] detected: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] + new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] detection-update: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] detected: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable][content-autofill.googleapis.com] detection-update: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable][content-autofill.googleapis.com] - new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [MIDSTREAM] + new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [MIDSTREAM] detected: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Google][Web][Safe] detection-update: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic @@ -151,7 +151,7 @@ [IATS(ms)....: 0.2,23.5,0.2,5.1,0.0,28.6,0.3,0.0,0.0,0.0,0.2,0.0,0.0,0.0,0.0,0.4,0.0,0.0,0.0,0.4,0.0,1.3,0.0,0.0,0.0,0.0,1.3,0.1,0.0,0.0,0.0] [PKTLENS.....: 230,195,72,72,263,1280,72,1280,1280,1280,1280,72,72,1280,1280,72,1280,1280,1280,1280,72,72,1280,1280,237,111,199,72,1280,1280,1280,1280] [ENTROPIES...: 6.9,6.7,5.1,5.1,7.0,7.9,5.2,7.8,7.8,7.8,7.8,5.1,5.1,7.8,7.8,5.2,7.9,7.8,7.8,7.9,5.2,5.2,7.8,7.8,6.9,5.8,6.7,5.1,7.8,7.8,7.8,7.8] - new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] + new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] detected: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] detection-update: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Google][Web][Acceptable][accounts.google.com] analyse: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable] @@ -174,19 +174,19 @@ [IATS(ms)....: 23.4,23.6,0.6,27.8,5.3,0.0,0.0,32.3,0.0,0.0,3.2,0.2,0.2,43.0,0.9,0.0,0.2,40.4,0.9,3.4,2.5,21.4,0.0,21.3,0.0,7.8,0.0,0.0,0.0,7.8,0.0] [PKTLENS.....: 80,80,72,589,72,1280,1280,322,72,72,72,136,164,327,72,72,72,652,72,103,103,72,876,1280,72,72,1280,1280,1280,1280,72,72] [ENTROPIES...: 4.9,5.4,5.2,4.6,5.1,7.8,7.8,7.2,5.2,5.3,5.3,6.2,6.4,7.2,5.1,5.1,5.1,7.6,5.2,5.8,5.8,5.2,7.8,7.8,5.3,5.3,7.8,7.8,7.9,7.8,5.2,5.2] - new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] [MIDSTREAM] - new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] [MIDSTREAM] - new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] [MIDSTREAM] - new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57130] -> [...............2a00:1450:4007:80c::200a][..443] [MIDSTREAM] - new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38402] -> [.......................2a04:4e42:1d::84][..443] [MIDSTREAM] - new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46918] -> [......................2600:1901::7a0b::][..443] [MIDSTREAM] - new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38406] -> [.......................2a04:4e42:1d::84][..443] [MIDSTREAM] - new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51446] -> [...............2a00:1450:4007:816::2003][..443] [MIDSTREAM] - new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47682] -> [...............2a00:1450:4007:816::200a][..443] [MIDSTREAM] - new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48890] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] - new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40560] -> [...............2a00:1450:4007:816::2004][..443] [MIDSTREAM] - new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] - new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] + new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] [MIDSTREAM] + new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] [MIDSTREAM] + new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] [MIDSTREAM] + new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57130] -> [...............2a00:1450:4007:80c::200a][..443] [MIDSTREAM] + new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38402] -> [.......................2a04:4e42:1d::84][..443] [MIDSTREAM] + new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46918] -> [......................2600:1901::7a0b::][..443] [MIDSTREAM] + new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38406] -> [.......................2a04:4e42:1d::84][..443] [MIDSTREAM] + new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51446] -> [...............2a00:1450:4007:816::2003][..443] [MIDSTREAM] + new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47682] -> [...............2a00:1450:4007:816::200a][..443] [MIDSTREAM] + new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48890] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] + new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40560] -> [...............2a00:1450:4007:816::2004][..443] [MIDSTREAM] + new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] + new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] detected: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][assets.pinterest.com] detected: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] [TLS.Google][Google][Advertisement][Acceptable][www.google-analytics.com] detection-update: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][assets.pinterest.com] @@ -213,7 +213,7 @@ [PKTLENS.....: 80,80,72,589,72,1460,1460,72,72,1460,1230,72,72,165,171,338,72,72,330,138,72,570,72,72,72,110,72,210,72,1460,1460,1460] [ENTROPIES...: 4.7,5.1,5.1,4.5,5.0,6.4,5.2,5.2,5.2,7.3,7.6,5.2,5.1,6.1,6.3,7.2,5.0,5.0,7.1,6.1,4.9,7.5,5.2,5.1,5.2,5.6,5.0,6.7,5.0,7.9,7.8,7.8] detection-update: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38546] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun][assets.pinterest.com] - new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] + new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] detected: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][js-agent.newrelic.com] detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][js-agent.newrelic.com] detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][js-agent.newrelic.com] @@ -229,26 +229,26 @@ [ENTROPIES...: 4.8,5.1,5.2,4.5,5.1,6.9,5.1,5.2,5.2,6.7,7.2,7.3,7.6,5.2,5.1,5.2,5.2,5.6,5.2,6.0,6.4,7.1,5.1,5.1,7.0,6.2,5.2,5.2,5.7,5.0,7.8,7.8] detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][js-agent.newrelic.com] guessed: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] [TLS][Google][Web][Safe] - idle: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] + idle: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40876] -> [...............2a00:1450:4007:807::200a][..443] idle: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47032] -> [......................2600:1901::7a0b::][..443] [TLS][GoogleCloud][Web][Safe] idle: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40894] -> [...............2a00:1450:4007:816::200d][..443] [TLS.Google][Google][Web][Acceptable] idle: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45126] -> [...............2a00:1450:4007:80a::200e][..443] [TLS.Google][Google][Advertisement][Acceptable] idle: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40114] -> [.....................64:ff9b::9765:7a6e][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] guessed: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51446] -> [...............2a00:1450:4007:816::2003][..443] [TLS][Google][Web][Safe] - idle: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51446] -> [...............2a00:1450:4007:816::2003][..443] + idle: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51446] -> [...............2a00:1450:4007:816::2003][..443] guessed: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] [TLS][Google][Web][Safe] - idle: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] + idle: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51472] -> [...............2a00:1450:4007:816::2003][..443] idle: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51582] -> [...............2a00:1450:4007:816::2003][..443] [TLS.Google][Google][Web][Acceptable] guessed: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38402] -> [.......................2a04:4e42:1d::84][..443] [TLS][Unknown][Web][Safe] - idle: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38402] -> [.......................2a04:4e42:1d::84][..443] + idle: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38402] -> [.......................2a04:4e42:1d::84][..443] guessed: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38406] -> [.......................2a04:4e42:1d::84][..443] [TLS][Unknown][Web][Safe] - idle: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38406] -> [.......................2a04:4e42:1d::84][..443] + idle: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38406] -> [.......................2a04:4e42:1d::84][..443] idle: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43562] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Google][Web][Safe] guessed: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47682] -> [...............2a00:1450:4007:816::200a][..443] [TLS][Google][Web][Safe] - idle: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47682] -> [...............2a00:1450:4007:816::200a][..443] + idle: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47682] -> [...............2a00:1450:4007:816::200a][..443] idle: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51292] -> [.........2a03:2880:f030:13:face:b00c::3][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] guessed: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] [TLS][Unknown][Web][Safe] - idle: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] + idle: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56940] -> [......................2a04:4e42:1d::720][..443] idle: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38512] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] end: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38514] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] end: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38516] -> [.......................2a04:4e42:1d::84][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] @@ -259,26 +259,26 @@ idle: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47790] -> [...............2a00:1450:4007:816::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable] idle: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57050] -> [......................2a04:4e42:1d::720][..443] [TLS][Unknown][Media][Safe] guessed: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] [TLS][Unknown][Web][Safe] - idle: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] + idle: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][34626] -> [.....................64:ff9b::acd9:13e2][..443] guessed: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] [TLS][Google][Web][Safe] - idle: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] + idle: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54308] -> [...............2a00:1450:4007:806::200e][..443] idle: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54416] -> [...............2a00:1450:4007:806::200e][..443] [TLS.Google][Google][Web][Acceptable] guessed: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33156] -> [.....................64:ff9b::9765:7854][..443] [TLS][Unknown][Web][Safe] - idle: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33156] -> [.....................64:ff9b::9765:7854][..443] + idle: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33156] -> [.....................64:ff9b::9765:7854][..443] guessed: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33164] -> [.....................64:ff9b::9765:7854][..443] [TLS][Unknown][Web][Safe] - idle: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33164] -> [.....................64:ff9b::9765:7854][..443] + idle: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33164] -> [.....................64:ff9b::9765:7854][..443] guessed: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] [TLS][Google][Web][Safe] - idle: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] + idle: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58726] -> [...............2a00:1450:4007:80b::2002][..443] idle: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][60340] -> [......2a03:2880:f11f:83:face:b00c::25de][..443] [TLS.Facebook][Facebook][SocialNetwork][Fun] idle: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33262] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] idle: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][33280] -> [.....................64:ff9b::9765:7854][..443] [TLS.Pinterest][Unknown][SocialNetwork][Fun] guessed: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40560] -> [...............2a00:1450:4007:816::2004][..443] [TLS][Google][Web][Safe] - idle: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40560] -> [...............2a00:1450:4007:816::2004][..443] + idle: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40560] -> [...............2a00:1450:4007:816::2004][..443] idle: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40694] -> [...............2a00:1450:4007:816::2004][..443] [TLS.Google][Google][Web][Acceptable] guessed: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48890] -> [...............2a00:1450:4007:815::2003][..443] [TLS][Google][Web][Safe] - idle: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48890] -> [...............2a00:1450:4007:815::2003][..443] + idle: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48890] -> [...............2a00:1450:4007:815::2003][..443] guessed: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57130] -> [...............2a00:1450:4007:80c::200a][..443] [TLS][Google][Web][Safe] - idle: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57130] -> [...............2a00:1450:4007:80c::200a][..443] + idle: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57130] -> [...............2a00:1450:4007:80c::200a][..443] guessed: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46918] -> [......................2600:1901::7a0b::][..443] [TLS][GoogleCloud][Web][Safe] - idle: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46918] -> [......................2600:1901::7a0b::][..443] + idle: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46918] -> [......................2600:1901::7a0b::][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/pluralsight.pcap.out b/test/results/flow-info/default/pluralsight.pcap.out index 345e38927..740dd4d01 100644 --- a/test/results/flow-info/default/pluralsight.pcap.out +++ b/test/results/flow-info/default/pluralsight.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] - new: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] - new: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detected: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] detection-update: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detection-update: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detection-update: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] detection-update: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] - new: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] detection-update: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] detection-update: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] - new: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][www.pluralsight.com] detection-update: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][www.pluralsight.com] - new: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] detected: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][zn6qzq6caaucudesr-pluralsight.siteintercept.qualtrics.com] detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][zn6qzq6caaucudesr-pluralsight.siteintercept.qualtrics.com] idle: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun] diff --git a/test/results/flow-info/default/pop3.pcap.out b/test/results/flow-info/default/pop3.pcap.out index 9846f9324..edd53540c 100644 --- a/test/results/flow-info/default/pop3.pcap.out +++ b/test/results/flow-info/default/pop3.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [143.225.229.181][35287] -> [....74.208.5.28][..110] + new: [.....1] [ip4][..tcp] [143.225.229.181][35287] -> [....74.208.5.28][..110] detected: [.....1] [ip4][..tcp] [143.225.229.181][35287] -> [....74.208.5.28][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials DAEMON-EVENT: [Processed: 31 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [....192.168.0.4][26272] -> [.212.227.15.166][..110] + new: [.....2] [ip4][..tcp] [....192.168.0.4][26272] -> [.212.227.15.166][..110] detected: [.....2] [ip4][..tcp] [....192.168.0.4][26272] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol end: [.....1] [ip4][..tcp] [143.225.229.181][35287] -> [....74.208.5.28][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials - new: [.....3] [ip4][..tcp] [....192.168.0.4][26284] -> [.212.227.15.166][..110] + new: [.....3] [ip4][..tcp] [....192.168.0.4][26284] -> [.212.227.15.166][..110] detected: [.....3] [ip4][..tcp] [....192.168.0.4][26284] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol - new: [.....4] [ip4][..tcp] [....192.168.0.4][26304] -> [.212.227.15.166][..110] + new: [.....4] [ip4][..tcp] [....192.168.0.4][26304] -> [.212.227.15.166][..110] detected: [.....4] [ip4][..tcp] [....192.168.0.4][26304] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol - new: [.....5] [ip4][..tcp] [....192.168.0.4][26308] -> [.212.227.15.166][..110] + new: [.....5] [ip4][..tcp] [....192.168.0.4][26308] -> [.212.227.15.166][..110] detected: [.....5] [ip4][..tcp] [....192.168.0.4][26308] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol - new: [.....6] [ip4][..tcp] [....192.168.0.4][26383] -> [.212.227.15.166][..110] + new: [.....6] [ip4][..tcp] [....192.168.0.4][26383] -> [.212.227.15.166][..110] detected: [.....6] [ip4][..tcp] [....192.168.0.4][26383] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol analyse: [.....6] [ip4][..tcp] [....192.168.0.4][26383] -> [.212.227.15.166][..110] [POP3][Unknown][Email][Unsafe] diff --git a/test/results/flow-info/default/pop3_stls.pcap.out b/test/results/flow-info/default/pop3_stls.pcap.out index 42a6f89c7..7a9c4d6be 100644 --- a/test/results/flow-info/default/pop3_stls.pcap.out +++ b/test/results/flow-info/default/pop3_stls.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.20.18][50583] -> [...72.249.41.52][..110] + new: [.....1] [ip4][..tcp] [..192.168.20.18][50583] -> [...72.249.41.52][..110] detected: [.....1] [ip4][..tcp] [..192.168.20.18][50583] -> [...72.249.41.52][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol detection-update: [.....1] [ip4][..tcp] [..192.168.20.18][50583] -> [...72.249.41.52][..110] [POPS][Unknown][Email][Safe] diff --git a/test/results/flow-info/default/pops.pcapng.out b/test/results/flow-info/default/pops.pcapng.out index 02d8663db..c80184e03 100644 --- a/test/results/flow-info/default/pops.pcapng.out +++ b/test/results/flow-info/default/pops.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.0.1][55077] -> [.....10.10.10.1][..995] + new: [.....1] [ip4][..tcp] [....192.168.0.1][55077] -> [.....10.10.10.1][..995] detected: [.....1] [ip4][..tcp] [....192.168.0.1][55077] -> [.....10.10.10.1][..995] [POPS][Unknown][Email][Safe] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [....192.168.0.1][55077] -> [.....10.10.10.1][..995] [POPS][Unknown][Email][Safe] diff --git a/test/results/flow-info/default/pps.pcap.out b/test/results/flow-info/default/pps.pcap.out index 58eb84497..25b7e09fc 100644 --- a/test/results/flow-info/default/pps.pcap.out +++ b/test/results/flow-info/default/pps.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] - new: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] - new: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] - new: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] - new: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] - new: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] - new: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] - analyse: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] + new: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] + new: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] + new: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] + new: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] + new: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] + new: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] + new: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] + analyse: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.014| 0.003| 0.004| 16.289| 3.700] [PKTLEN......: 65.000| 1093.000| 386.200| 476.500| 227043.400| 4.000] @@ -18,7 +18,7 @@ [IATS(ms)....: 0.3,0.3,3.0,2.0,4.7,0.3,0.1,0.0,0.6,0.6,2.0,0.9,0.2,1.9,1.1,0.1,11.9,11.8,0.1,13.6,13.5,0.1,2.8,2.6,0.2,1.3,1.0,0.1,1.6,1.9,0.3] [PKTLENS.....: 1093,65,65,1093,1093,65,65,65,65,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65] [ENTROPIES...: 7.8,5.1,5.1,7.8,7.8,5.2,5.1,5.2,5.1,5.2,5.2,7.8,5.1,5.1,7.8,5.2,5.2,7.8,5.1,5.1,7.8,5.2,5.2,7.8,5.1,5.1,7.6,5.2,5.2,7.8,5.2,5.2] - analyse: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] + analyse: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.013| 0.002| 0.004| 13.731| 3.800] [PKTLEN......: 65.000| 1093.000| 386.200| 476.500| 227043.400| 4.000] @@ -28,8 +28,8 @@ [IATS(ms)....: 0.3,12.6,12.6,0.2,1.1,0.9,0.1,1.6,1.5,0.2,2.1,1.8,0.3,0.7,0.6,0.3,1.7,1.1,0.1,3.6,5.8,0.4,11.9,9.1,0.1,1.2,1.4,0.1,1.5,1.1,0.1] [PKTLENS.....: 65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65] [ENTROPIES...: 5.1,5.1,7.8,5.2,5.2,7.7,5.0,5.0,7.8,5.2,5.2,7.8,5.1,5.1,7.8,5.1,5.1,7.8,5.1,5.1,7.8,5.1,5.1,7.8,5.1,5.1,7.8,5.2,5.2,7.8,5.2,5.2] - new: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] - analyse: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] + new: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] + analyse: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.027| 0.009| 0.008| 71.240| 4.100] [PKTLEN......: 65.000| 1093.000| 386.200| 476.500| 227043.400| 4.000] @@ -39,9 +39,9 @@ [IATS(ms)....: 0.4,0.2,4.9,0.2,24.3,18.9,0.1,5.4,6.9,0.2,19.1,17.6,0.1,13.8,13.8,0.1,13.1,15.4,0.1,27.0,24.4,0.2,9.0,11.0,0.4,2.0,0.9,14.1,8.3,0.1,12.1] [PKTLENS.....: 1093,65,65,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093] [ENTROPIES...: 7.7,5.1,5.1,5.1,5.1,7.8,5.1,5.1,7.8,5.2,5.2,7.8,5.1,5.1,7.8,5.0,5.0,7.8,5.1,5.1,7.8,5.2,5.2,7.8,5.1,5.1,5.0,5.0,7.8,5.1,5.1,7.8] - new: [.....9] [ip4][..tcp] [..192.168.115.8][50462] -> [.202.108.14.236][...80] [MIDSTREAM] - new: [....10] [ip4][..tcp] [...192.168.5.15][65125] -> [.68.233.253.133][...80] [MIDSTREAM] - analyse: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] + new: [.....9] [ip4][..tcp] [..192.168.115.8][50462] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....10] [ip4][..tcp] [...192.168.5.15][65125] -> [.68.233.253.133][...80] [MIDSTREAM] + analyse: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.070| 0.024| 0.021| 457.568| 4.200] [PKTLEN......: 65.000| 1093.000| 322.000| 445.100| 198147.000| 3.900] @@ -51,38 +51,38 @@ [IATS(ms)....: 0.4,29.9,29.7,0.1,32.0,32.8,0.3,45.7,0.3,69.6,23.0,0.1,42.0,41.6,0.1,36.0,0.3,59.5,23.0,0.1,31.8,32.2,0.3,44.4,0.3,68.3,22.7,0.2,30.9,30.8,0.2] [PKTLENS.....: 65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65] [ENTROPIES...: 5.1,5.1,7.8,5.2,5.2,7.8,5.2,5.2,5.2,5.2,7.8,5.3,5.3,7.8,5.1,5.1,5.1,5.1,7.8,5.2,5.2,7.8,5.2,5.2,5.2,5.2,7.8,5.1,5.1,7.8,4.9,4.9] - new: [....11] [ip4][..udp] [..192.168.115.8][22793] -> [..218.61.39.103][17788] + new: [....11] [ip4][..udp] [..192.168.115.8][22793] -> [..218.61.39.103][17788] detected: [....11] [ip4][..udp] [..192.168.115.8][22793] -> [..218.61.39.103][17788] [PPStream][Unknown][Streaming][Fun] - new: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] - new: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] - new: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] - new: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] - new: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] - new: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] - new: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] - new: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] - new: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] - new: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] - new: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] - new: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] - new: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] - new: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] - new: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] - new: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] - new: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] - new: [....29] [ip4][..udp] [..192.168.115.8][22793] -> [..183.61.167.82][17788] + new: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] + new: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] + new: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] + new: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] + new: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] + new: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] + new: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] + new: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] + new: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] + new: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] + new: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] + new: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] + new: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] + new: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] + new: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] + new: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] + new: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] + new: [....29] [ip4][..udp] [..192.168.115.8][22793] -> [..183.61.167.82][17788] detected: [....29] [ip4][..udp] [..192.168.115.8][22793] -> [..183.61.167.82][17788] [PPStream][Unknown][Streaming][Fun] - new: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] - new: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] - new: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] - new: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] - new: [....34] [ip4][..udp] [..192.168.115.8][22793] -> [...218.61.39.87][17788] + new: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] + new: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] + new: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] + new: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] + new: [....34] [ip4][..udp] [..192.168.115.8][22793] -> [...218.61.39.87][17788] detected: [....34] [ip4][..udp] [..192.168.115.8][22793] -> [...218.61.39.87][17788] [PPStream][Unknown][Streaming][Fun] - new: [....35] [ip4][..udp] [..192.168.115.8][22793] -> [119.188.133.182][17788] + new: [....35] [ip4][..udp] [..192.168.115.8][22793] -> [119.188.133.182][17788] detected: [....35] [ip4][..udp] [..192.168.115.8][22793] -> [119.188.133.182][17788] [PPStream][Unknown][Streaming][Fun] - new: [....36] [ip4][..udp] [..192.168.115.8][22793] -> [.183.61.167.104][17788] + new: [....36] [ip4][..udp] [..192.168.115.8][22793] -> [.183.61.167.104][17788] detected: [....36] [ip4][..udp] [..192.168.115.8][22793] -> [.183.61.167.104][17788] [PPStream][Unknown][Streaming][Fun] - analyse: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] + analyse: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.108| 0.029| 0.031| 941.853| 4.000] [PKTLEN......: 47.000| 1093.000| 289.300| 425.300| 180865.500| 3.800] @@ -92,104 +92,104 @@ [IATS(ms)....: 0.9,52.8,52.3,0.3,55.5,0.1,77.7,22.0,0.2,78.3,79.3,0.5,0.4,0.1,46.5,44.4,0.1,18.4,18.5,0.3,36.0,0.1,108.0,71.5,0.7,28.3,0.5,45.9,16.1,0.4,33.5] [PKTLENS.....: 65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,1093,65,65,65,65,1093,65,65,65,65,1093,65,65,47] [ENTROPIES...: 5.3,5.3,7.8,5.3,5.3,5.3,5.3,7.8,5.2,5.2,7.8,5.0,5.0,5.1,5.1,7.8,5.2,5.2,7.7,5.1,5.1,5.1,5.1,7.8,5.1,5.1,5.1,5.1,7.8,5.1,5.1,4.9] - new: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [MIDSTREAM] + new: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [MIDSTREAM] detected: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] detection-update: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] RISK: Unidirectional Traffic detection-update: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] RISK: HTTP Obsolete Server - new: [....38] [ip4][..tcp] [..192.168.115.8][50464] -> [.123.125.112.49][...80] [MIDSTREAM] + new: [....38] [ip4][..tcp] [..192.168.115.8][50464] -> [.123.125.112.49][...80] [MIDSTREAM] detected: [....38] [ip4][..tcp] [..192.168.115.8][50464] -> [.123.125.112.49][...80] [HTTP][Unknown][Web][Acceptable][click.hm.baidu.com] - new: [....39] [ip4][..tcp] [..192.168.115.8][50466] -> [..203.66.182.24][...80] [MIDSTREAM] + new: [....39] [ip4][..tcp] [..192.168.115.8][50466] -> [..203.66.182.24][...80] [MIDSTREAM] detected: [....39] [ip4][..tcp] [..192.168.115.8][50466] -> [..203.66.182.24][...80] [HTTP.Google][Unknown][Web][Acceptable][clients1.google.com] - new: [....40] [ip4][..tcp] [..192.168.115.8][50467] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....40] [ip4][..tcp] [..192.168.115.8][50467] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....40] [ip4][..tcp] [..192.168.115.8][50467] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....40] [ip4][..tcp] [..192.168.115.8][50467] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....41] [ip4][..tcp] [..192.168.115.8][50469] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....41] [ip4][..tcp] [..192.168.115.8][50469] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....41] [ip4][..tcp] [..192.168.115.8][50469] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] - new: [....42] [ip4][..tcp] [..192.168.115.8][50470] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....42] [ip4][..tcp] [..192.168.115.8][50470] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....42] [ip4][..tcp] [..192.168.115.8][50470] -> [.202.108.14.236][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] detection-update: [....42] [ip4][..tcp] [..192.168.115.8][50470] -> [.202.108.14.236][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server detection-update: [....41] [ip4][..tcp] [..192.168.115.8][50469] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....43] [ip4][..tcp] [..192.168.115.8][50471] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....43] [ip4][..tcp] [..192.168.115.8][50471] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....43] [ip4][..tcp] [..192.168.115.8][50471] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....43] [ip4][..tcp] [..192.168.115.8][50471] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....44] [ip4][..tcp] [..192.168.115.8][50474] -> [.202.108.14.221][...80] [MIDSTREAM] + new: [....44] [ip4][..tcp] [..192.168.115.8][50474] -> [.202.108.14.221][...80] [MIDSTREAM] detected: [....44] [ip4][..tcp] [..192.168.115.8][50474] -> [.202.108.14.221][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] - new: [....45] [ip4][..tcp] [..192.168.115.8][50475] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....45] [ip4][..tcp] [..192.168.115.8][50475] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....45] [ip4][..tcp] [..192.168.115.8][50475] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....44] [ip4][..tcp] [..192.168.115.8][50474] -> [.202.108.14.221][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server - new: [....46] [ip4][..tcp] [..192.168.115.8][50473] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....46] [ip4][..tcp] [..192.168.115.8][50473] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....46] [ip4][..tcp] [..192.168.115.8][50473] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....45] [ip4][..tcp] [..192.168.115.8][50475] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....47] [ip4][..tcp] [..192.168.115.8][50476] -> [..101.227.32.39][...80] [MIDSTREAM] + new: [....47] [ip4][..tcp] [..192.168.115.8][50476] -> [..101.227.32.39][...80] [MIDSTREAM] detected: [....47] [ip4][..tcp] [..192.168.115.8][50476] -> [..101.227.32.39][...80] [HTTP.PPStream][Unknown][Streaming][Fun][cache.video.iqiyi.com] RISK: HTTP Susp User-Agent detection-update: [....46] [ip4][..tcp] [..192.168.115.8][50473] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....48] [ip4][..tcp] [..192.168.115.8][50477] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....48] [ip4][..tcp] [..192.168.115.8][50477] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....48] [ip4][..tcp] [..192.168.115.8][50477] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....48] [ip4][..tcp] [..192.168.115.8][50477] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....49] [ip4][..tcp] [..117.79.81.135][...80] -> [..192.168.115.8][50443] [MIDSTREAM] + new: [....49] [ip4][..tcp] [..117.79.81.135][...80] -> [..192.168.115.8][50443] [MIDSTREAM] detected: [....49] [ip4][..tcp] [..117.79.81.135][...80] -> [..192.168.115.8][50443] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent - new: [....50] [ip4][..tcp] [..192.168.115.8][50482] -> [.140.205.243.64][...80] [MIDSTREAM] + new: [....50] [ip4][..tcp] [..192.168.115.8][50482] -> [.140.205.243.64][...80] [MIDSTREAM] detected: [....50] [ip4][..tcp] [..192.168.115.8][50482] -> [.140.205.243.64][...80] [HTTP][Alibaba][Web][Acceptable][cmc.tanx.com] - new: [....51] [ip4][..tcp] [..192.168.115.8][50483] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....51] [ip4][..tcp] [..192.168.115.8][50483] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....51] [ip4][..tcp] [..192.168.115.8][50483] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....51] [ip4][..tcp] [..192.168.115.8][50483] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....52] [ip4][..tcp] [..192.168.115.8][50484] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....52] [ip4][..tcp] [..192.168.115.8][50484] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....52] [ip4][..tcp] [..192.168.115.8][50484] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....52] [ip4][..tcp] [..192.168.115.8][50484] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....53] [ip4][..tcp] [..192.168.115.8][50485] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....53] [ip4][..tcp] [..192.168.115.8][50485] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....53] [ip4][..tcp] [..192.168.115.8][50485] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....53] [ip4][..tcp] [..192.168.115.8][50485] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [MIDSTREAM] + new: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [MIDSTREAM] detected: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [HTTP.Cybersec][AVAST][Cybersecurity][Safe][bcu.ff.avast.com] RISK: HTTP Susp User-Agent detection-update: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [HTTP.Cybersec][AVAST][Cybersecurity][Safe][bcu.ff.avast.com] RISK: HTTP Susp User-Agent, Unidirectional Traffic - new: [....55] [ip4][..udp] [...192.168.5.57][59648] -> [239.255.255.250][.1900] + new: [....55] [ip4][..udp] [...192.168.5.57][59648] -> [239.255.255.250][.1900] detected: [....55] [ip4][..udp] [...192.168.5.57][59648] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] detection-update: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [HTTP.Cybersec][AVAST][Download][Safe][bcu.ff.avast.com] RISK: Binary App Transfer, HTTP Susp User-Agent, HTTP Obsolete Server - new: [....56] [ip4][..tcp] [..192.168.115.8][50487] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....56] [ip4][..tcp] [..192.168.115.8][50487] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....56] [ip4][..tcp] [..192.168.115.8][50487] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] - new: [....57] [ip4][..tcp] [..192.168.115.8][50488] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [....57] [ip4][..tcp] [..192.168.115.8][50488] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [....57] [ip4][..tcp] [..192.168.115.8][50488] -> [..223.26.106.20][...80] [HTTP][Unknown][Web][Acceptable][meta.video.qiyi.com] - new: [....58] [ip4][..tcp] [..192.168.115.8][50489] -> [.119.188.13.188][...80] [MIDSTREAM] + new: [....58] [ip4][..tcp] [..192.168.115.8][50489] -> [.119.188.13.188][...80] [MIDSTREAM] detected: [....58] [ip4][..tcp] [..192.168.115.8][50489] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] detection-update: [....58] [ip4][..tcp] [..192.168.115.8][50489] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] RISK: HTTP Obsolete Server - new: [....59] [ip4][..tcp] [..192.168.115.8][50490] -> [.119.188.13.188][...80] [MIDSTREAM] + new: [....59] [ip4][..tcp] [..192.168.115.8][50490] -> [.119.188.13.188][...80] [MIDSTREAM] detected: [....59] [ip4][..tcp] [..192.168.115.8][50490] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] detection-update: [....59] [ip4][..tcp] [..192.168.115.8][50490] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] RISK: HTTP Obsolete Server - new: [....60] [ip4][..tcp] [..192.168.115.8][50491] -> [..223.26.106.66][...80] [MIDSTREAM] + new: [....60] [ip4][..tcp] [..192.168.115.8][50491] -> [..223.26.106.66][...80] [MIDSTREAM] detected: [....60] [ip4][..tcp] [..192.168.115.8][50491] -> [..223.26.106.66][...80] [HTTP][Unknown][Web][Acceptable][223.26.106.66] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....61] [ip4][..tcp] [..192.168.115.8][50492] -> [...111.206.13.3][...80] [MIDSTREAM] + new: [....61] [ip4][..tcp] [..192.168.115.8][50492] -> [...111.206.13.3][...80] [MIDSTREAM] detected: [....61] [ip4][..tcp] [..192.168.115.8][50492] -> [...111.206.13.3][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] - new: [....62] [ip4][..tcp] [..192.168.115.8][50493] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....62] [ip4][..tcp] [..192.168.115.8][50493] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....62] [ip4][..tcp] [..192.168.115.8][50493] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....61] [ip4][..tcp] [..192.168.115.8][50492] -> [...111.206.13.3][...80] [HTTP][Unknown][Web][Acceptable][pdata.video.qiyi.com] RISK: HTTP Obsolete Server - new: [....63] [ip4][..tcp] [..192.168.115.8][50494] -> [..223.26.106.66][...80] [MIDSTREAM] + new: [....63] [ip4][..tcp] [..192.168.115.8][50494] -> [..223.26.106.66][...80] [MIDSTREAM] detected: [....63] [ip4][..tcp] [..192.168.115.8][50494] -> [..223.26.106.66][...80] [HTTP][Unknown][Web][Acceptable][223.26.106.66] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....62] [ip4][..tcp] [..192.168.115.8][50493] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....64] [ip4][..tcp] [...192.168.5.15][65127] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [....64] [ip4][..tcp] [...192.168.5.15][65127] -> [.68.233.253.133][...80] [MIDSTREAM] detected: [....64] [ip4][..tcp] [...192.168.5.15][65127] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] detection-update: [....64] [ip4][..tcp] [...192.168.5.15][65127] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] RISK: Error Code @@ -197,178 +197,178 @@ RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, Unidirectional Traffic detection-update: [....63] [ip4][..tcp] [..192.168.115.8][50494] -> [..223.26.106.66][...80] [HTTP][Unknown][Download][Acceptable][223.26.106.66] RISK: Binary App Transfer, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....65] [ip4][..udp] [...192.168.5.48][63930] -> [239.255.255.250][.1900] + new: [....65] [ip4][..udp] [...192.168.5.48][63930] -> [239.255.255.250][.1900] detected: [....65] [ip4][..udp] [...192.168.5.48][63930] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....66] [ip4][..tcp] [..192.168.115.8][50495] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....66] [ip4][..tcp] [..192.168.115.8][50495] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....66] [ip4][..tcp] [..192.168.115.8][50495] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....66] [ip4][..tcp] [..192.168.115.8][50495] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....67] [ip4][..tcp] [..192.168.115.8][50496] -> [.101.227.200.11][...80] [MIDSTREAM] + new: [....67] [ip4][..tcp] [..192.168.115.8][50496] -> [.101.227.200.11][...80] [MIDSTREAM] detected: [....67] [ip4][..tcp] [..192.168.115.8][50496] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] detection-update: [....67] [ip4][..tcp] [..192.168.115.8][50496] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] RISK: Unidirectional Traffic detection-update: [....67] [ip4][..tcp] [..192.168.115.8][50496] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] RISK: HTTP Obsolete Server - new: [....68] [ip4][..tcp] [..192.168.115.8][50497] -> [.123.125.112.49][...80] [MIDSTREAM] + new: [....68] [ip4][..tcp] [..192.168.115.8][50497] -> [.123.125.112.49][...80] [MIDSTREAM] detected: [....68] [ip4][..tcp] [..192.168.115.8][50497] -> [.123.125.112.49][...80] [HTTP][Unknown][Web][Acceptable][click.hm.baidu.com] - new: [....69] [ip4][..udp] [...192.168.5.63][39383] -> [239.255.255.250][.1900] + new: [....69] [ip4][..udp] [...192.168.5.63][39383] -> [239.255.255.250][.1900] detected: [....69] [ip4][..udp] [...192.168.5.63][39383] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....70] [ip4][..udp] [...192.168.5.63][60976] -> [239.255.255.250][.1900] + new: [....70] [ip4][..udp] [...192.168.5.63][60976] -> [239.255.255.250][.1900] detected: [....70] [ip4][..udp] [...192.168.5.63][60976] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....71] [ip4][..tcp] [..192.168.115.8][50498] -> [..36.110.220.15][...80] [MIDSTREAM] + new: [....71] [ip4][..tcp] [..192.168.115.8][50498] -> [..36.110.220.15][...80] [MIDSTREAM] detected: [....71] [ip4][..tcp] [..192.168.115.8][50498] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable][msg.video.qiyi.com] detection-update: [....71] [ip4][..tcp] [..192.168.115.8][50498] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable][msg.video.qiyi.com] RISK: HTTP Obsolete Server - new: [....72] [ip4][..tcp] [..192.168.115.8][50499] -> [..111.206.22.76][...80] [MIDSTREAM] + new: [....72] [ip4][..tcp] [..192.168.115.8][50499] -> [..111.206.22.76][...80] [MIDSTREAM] detected: [....72] [ip4][..tcp] [..192.168.115.8][50499] -> [..111.206.22.76][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] detection-update: [....72] [ip4][..tcp] [..192.168.115.8][50499] -> [..111.206.22.76][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server - new: [....73] [ip4][..tcp] [..192.168.115.8][50500] -> [..23.41.133.163][...80] [MIDSTREAM] + new: [....73] [ip4][..tcp] [..192.168.115.8][50500] -> [..23.41.133.163][...80] [MIDSTREAM] detected: [....73] [ip4][..tcp] [..192.168.115.8][50500] -> [..23.41.133.163][...80] [HTTP][Unknown][Web][Acceptable][s1.symcb.com] - new: [....74] [ip4][..tcp] [..192.168.115.8][50501] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....74] [ip4][..tcp] [..192.168.115.8][50501] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....74] [ip4][..tcp] [..192.168.115.8][50501] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....74] [ip4][..tcp] [..192.168.115.8][50501] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....75] [ip4][..udp] [...192.168.5.38][58897] -> [239.255.255.250][.1900] + new: [....75] [ip4][..udp] [...192.168.5.38][58897] -> [239.255.255.250][.1900] detected: [....75] [ip4][..udp] [...192.168.5.38][58897] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....76] [ip4][..tcp] [..192.168.115.8][50502] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....76] [ip4][..tcp] [..192.168.115.8][50502] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....76] [ip4][..tcp] [..192.168.115.8][50502] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....76] [ip4][..tcp] [..192.168.115.8][50502] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....77] [ip4][..udp] [...192.168.5.50][52529] -> [239.255.255.250][.1900] + new: [....77] [ip4][..udp] [...192.168.5.50][52529] -> [239.255.255.250][.1900] detected: [....77] [ip4][..udp] [...192.168.5.50][52529] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....78] [ip4][..tcp] [...192.168.5.15][65128] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [....78] [ip4][..tcp] [...192.168.5.15][65128] -> [.68.233.253.133][...80] [MIDSTREAM] detected: [....78] [ip4][..tcp] [...192.168.5.15][65128] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] detection-update: [....78] [ip4][..tcp] [...192.168.5.15][65128] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] RISK: Error Code - new: [....79] [ip4][..tcp] [..192.168.115.8][50503] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....79] [ip4][..tcp] [..192.168.115.8][50503] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....79] [ip4][..tcp] [..192.168.115.8][50503] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....79] [ip4][..tcp] [..192.168.115.8][50503] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....80] [ip4][..udp] [...192.168.5.28][60023] -> [239.255.255.250][.1900] + new: [....80] [ip4][..udp] [...192.168.5.28][60023] -> [239.255.255.250][.1900] detected: [....80] [ip4][..udp] [...192.168.5.28][60023] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - update: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] - update: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] - update: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] - update: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] - update: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] - update: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] - update: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] - update: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] - update: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] - update: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] - update: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] - update: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] - update: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] - update: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] - update: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] - update: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] + update: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] + update: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] + update: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] + update: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] + update: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] + update: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] + update: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] + update: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] + update: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] + update: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] + update: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] + update: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] + update: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] + update: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] + update: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] + update: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] update: [....35] [ip4][..udp] [..192.168.115.8][22793] -> [119.188.133.182][17788] [PPStream][Unknown][Streaming][Fun] - update: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] - update: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] - update: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] - update: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] - update: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] - update: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] + update: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] + update: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] + update: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] + update: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] + update: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] + update: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] update: [....29] [ip4][..udp] [..192.168.115.8][22793] -> [..183.61.167.82][17788] [PPStream][Unknown][Streaming][Fun] update: [....36] [ip4][..udp] [..192.168.115.8][22793] -> [.183.61.167.104][17788] [PPStream][Unknown][Streaming][Fun] - update: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] + update: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] update: [....11] [ip4][..udp] [..192.168.115.8][22793] -> [..218.61.39.103][17788] [PPStream][Unknown][Streaming][Fun] update: [....34] [ip4][..udp] [..192.168.115.8][22793] -> [...218.61.39.87][17788] [PPStream][Unknown][Streaming][Fun] - update: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] - update: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] - update: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] - update: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] - update: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] - update: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] - new: [....81] [ip4][..tcp] [..192.168.115.8][50505] -> [..223.26.106.19][...80] [MIDSTREAM] + update: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] + update: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] + update: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] + update: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] + update: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] + update: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] + new: [....81] [ip4][..tcp] [..192.168.115.8][50505] -> [..223.26.106.19][...80] [MIDSTREAM] detected: [....81] [ip4][..tcp] [..192.168.115.8][50505] -> [..223.26.106.19][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....81] [ip4][..tcp] [..192.168.115.8][50505] -> [..223.26.106.19][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....82] [ip4][..tcp] [..192.168.115.8][50504] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....82] [ip4][..tcp] [..192.168.115.8][50504] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....82] [ip4][..tcp] [..192.168.115.8][50504] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] - new: [....83] [ip4][..udp] [...192.168.5.38][.1900] -> [239.255.255.250][.1900] + new: [....83] [ip4][..udp] [...192.168.5.38][.1900] -> [239.255.255.250][.1900] detected: [....83] [ip4][..udp] [...192.168.5.38][.1900] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....84] [ip4][..udp] [...192.168.5.41][50374] -> [239.255.255.250][.1900] + new: [....84] [ip4][..udp] [...192.168.5.41][50374] -> [239.255.255.250][.1900] detected: [....84] [ip4][..udp] [...192.168.5.41][50374] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....85] [ip4][..tcp] [..192.168.115.8][50507] -> [..223.26.106.19][...80] [MIDSTREAM] + new: [....85] [ip4][..tcp] [..192.168.115.8][50507] -> [..223.26.106.19][...80] [MIDSTREAM] detected: [....85] [ip4][..tcp] [..192.168.115.8][50507] -> [..223.26.106.19][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....85] [ip4][..tcp] [..192.168.115.8][50507] -> [..223.26.106.19][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....86] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50506] [MIDSTREAM] + new: [....86] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50506] [MIDSTREAM] detected: [....86] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50506] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent, HTTP Obsolete Server - new: [....87] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50295] [MIDSTREAM] + new: [....87] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50295] [MIDSTREAM] detected: [....87] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50295] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent, HTTP Obsolete Server detection-update: [....87] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50295] [HTTP][Unknown][Web][Acceptable][] RISK: HTTP Susp User-Agent, Unidirectional Traffic, HTTP Obsolete Server - new: [....88] [ip4][..tcp] [..192.168.115.8][50508] -> [..223.26.106.19][...80] [MIDSTREAM] + new: [....88] [ip4][..tcp] [..192.168.115.8][50508] -> [..223.26.106.19][...80] [MIDSTREAM] detected: [....88] [ip4][..tcp] [..192.168.115.8][50508] -> [..223.26.106.19][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....88] [ip4][..tcp] [..192.168.115.8][50508] -> [..223.26.106.19][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....89] [ip4][..tcp] [..192.168.115.8][50509] -> [.106.38.219.107][...80] [MIDSTREAM] + new: [....89] [ip4][..tcp] [..192.168.115.8][50509] -> [.106.38.219.107][...80] [MIDSTREAM] detected: [....89] [ip4][..tcp] [..192.168.115.8][50509] -> [.106.38.219.107][...80] [HTTP][Unknown][Web][Acceptable][iplocation.geo.qiyi.com] - new: [....90] [ip4][..tcp] [..192.168.115.8][50766] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [....90] [ip4][..tcp] [..192.168.115.8][50766] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [....90] [ip4][..tcp] [..192.168.115.8][50766] -> [..223.26.106.20][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....90] [ip4][..tcp] [..192.168.115.8][50766] -> [..223.26.106.20][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....91] [ip4][..tcp] [..192.168.115.8][50767] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [....91] [ip4][..tcp] [..192.168.115.8][50767] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [....91] [ip4][..tcp] [..192.168.115.8][50767] -> [..223.26.106.20][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....91] [ip4][..tcp] [..192.168.115.8][50767] -> [..223.26.106.20][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....92] [ip4][..tcp] [..192.168.115.8][50765] -> [..36.110.220.15][...80] [MIDSTREAM] + new: [....92] [ip4][..tcp] [..192.168.115.8][50765] -> [..36.110.220.15][...80] [MIDSTREAM] detected: [....92] [ip4][..tcp] [..192.168.115.8][50765] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable][msg.video.qiyi.com] - new: [....93] [ip4][..tcp] [..192.168.115.8][50768] -> [..223.26.106.19][...80] [MIDSTREAM] + new: [....93] [ip4][..tcp] [..192.168.115.8][50768] -> [..223.26.106.19][...80] [MIDSTREAM] detected: [....93] [ip4][..tcp] [..192.168.115.8][50768] -> [..223.26.106.19][...80] [HTTP][Unknown][Web][Acceptable][static.qiyi.com] detection-update: [....92] [ip4][..tcp] [..192.168.115.8][50765] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable][msg.video.qiyi.com] RISK: HTTP Obsolete Server detection-update: [....93] [ip4][..tcp] [..192.168.115.8][50768] -> [..223.26.106.19][...80] [HTTP][Unknown][Download][Acceptable][static.qiyi.com] RISK: Binary App Transfer - new: [....94] [ip4][..tcp] [..192.168.115.8][50769] -> [.101.227.200.11][...80] [MIDSTREAM] + new: [....94] [ip4][..tcp] [..192.168.115.8][50769] -> [.101.227.200.11][...80] [MIDSTREAM] detected: [....94] [ip4][..tcp] [..192.168.115.8][50769] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] detection-update: [....94] [ip4][..tcp] [..192.168.115.8][50769] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun][api.cupid.iqiyi.com] RISK: HTTP Obsolete Server - new: [....95] [ip4][..tcp] [..192.168.115.8][50771] -> [.202.108.14.236][...80] [MIDSTREAM] + new: [....95] [ip4][..tcp] [..192.168.115.8][50771] -> [.202.108.14.236][...80] [MIDSTREAM] detected: [....95] [ip4][..tcp] [..192.168.115.8][50771] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] - new: [....96] [ip4][..tcp] [..192.168.115.8][50772] -> [.123.125.111.70][...80] [MIDSTREAM] + new: [....96] [ip4][..tcp] [..192.168.115.8][50772] -> [.123.125.111.70][...80] [MIDSTREAM] detected: [....96] [ip4][..tcp] [..192.168.115.8][50772] -> [.123.125.111.70][...80] [HTTP.PPStream][Unknown][Streaming][Fun][nl.rcd.iqiyi.com] detection-update: [....95] [ip4][..tcp] [..192.168.115.8][50771] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....97] [ip4][..tcp] [..192.168.115.8][50773] -> [.202.108.14.221][...80] [MIDSTREAM] + new: [....97] [ip4][..tcp] [..192.168.115.8][50773] -> [.202.108.14.221][...80] [MIDSTREAM] detected: [....97] [ip4][..tcp] [..192.168.115.8][50773] -> [.202.108.14.221][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] detection-update: [....97] [ip4][..tcp] [..192.168.115.8][50773] -> [.202.108.14.221][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server - new: [....98] [ip4][..tcp] [..192.168.115.8][50775] -> [.123.125.111.70][...80] [MIDSTREAM] + new: [....98] [ip4][..tcp] [..192.168.115.8][50775] -> [.123.125.111.70][...80] [MIDSTREAM] detected: [....98] [ip4][..tcp] [..192.168.115.8][50775] -> [.123.125.111.70][...80] [HTTP.PPStream][Unknown][Streaming][Fun][nl.rcd.iqiyi.com] - new: [....99] [ip4][..tcp] [..192.168.115.8][50774] -> [.202.108.14.219][...80] [MIDSTREAM] + new: [....99] [ip4][..tcp] [..192.168.115.8][50774] -> [.202.108.14.219][...80] [MIDSTREAM] detected: [....99] [ip4][..tcp] [..192.168.115.8][50774] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] - new: [...100] [ip4][..tcp] [..192.168.115.8][50776] -> [..111.206.22.77][...80] [MIDSTREAM] + new: [...100] [ip4][..tcp] [..192.168.115.8][50776] -> [..111.206.22.77][...80] [MIDSTREAM] detected: [...100] [ip4][..tcp] [..192.168.115.8][50776] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] detection-update: [....99] [ip4][..tcp] [..192.168.115.8][50774] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable][msg.71.am] RISK: HTTP Obsolete Server detection-update: [...100] [ip4][..tcp] [..192.168.115.8][50776] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server - new: [...101] [ip4][..tcp] [..192.168.115.8][50777] -> [..111.206.22.77][...80] [MIDSTREAM] + new: [...101] [ip4][..tcp] [..192.168.115.8][50777] -> [..111.206.22.77][...80] [MIDSTREAM] detected: [...101] [ip4][..tcp] [..192.168.115.8][50777] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] detection-update: [...101] [ip4][..tcp] [..192.168.115.8][50777] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server - new: [...102] [ip4][..tcp] [..192.168.115.8][50778] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [...102] [ip4][..tcp] [..192.168.115.8][50778] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [...102] [ip4][..tcp] [..192.168.115.8][50778] -> [..223.26.106.20][...80] [HTTP.PPStream][Unknown][Streaming][Fun][preimage1.qiyipic.com] - new: [...103] [ip4][..udp] [..192.168.115.1][50945] -> [239.255.255.250][.1900] + new: [...103] [ip4][..udp] [..192.168.115.1][50945] -> [239.255.255.250][.1900] detected: [...103] [ip4][..udp] [..192.168.115.1][50945] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...104] [ip4][..tcp] [..192.168.115.8][50779] -> [..111.206.22.77][...80] [MIDSTREAM] + new: [...104] [ip4][..tcp] [..192.168.115.8][50779] -> [..111.206.22.77][...80] [MIDSTREAM] detected: [...104] [ip4][..tcp] [..192.168.115.8][50779] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] detection-update: [...104] [ip4][..tcp] [..192.168.115.8][50779] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: Unidirectional Traffic detection-update: [...104] [ip4][..tcp] [..192.168.115.8][50779] -> [..111.206.22.77][...80] [HTTP.PPStream][Unknown][Streaming][Fun][msg.iqiyi.com] RISK: HTTP Obsolete Server - new: [...105] [ip4][..tcp] [..192.168.115.8][50780] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [...105] [ip4][..tcp] [..192.168.115.8][50780] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [...105] [ip4][..tcp] [..192.168.115.8][50780] -> [..223.26.106.20][...80] [HTTP.PPStream][Unknown][Streaming][Fun][preimage1.qiyipic.com] update: [....55] [ip4][..udp] [...192.168.5.57][59648] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - new: [...106] [ip4][..tcp] [..192.168.115.8][50781] -> [..223.26.106.20][...80] [MIDSTREAM] + new: [...106] [ip4][..tcp] [..192.168.115.8][50781] -> [..223.26.106.20][...80] [MIDSTREAM] detected: [...106] [ip4][..tcp] [..192.168.115.8][50781] -> [..223.26.106.20][...80] [HTTP.PPStream][Unknown][Streaming][Fun][preimage1.qiyipic.com] - new: [...107] [ip4][..tcp] [...77.234.41.35][...80] -> [..192.168.115.8][49174] [MIDSTREAM] + new: [...107] [ip4][..tcp] [...77.234.41.35][...80] -> [..192.168.115.8][49174] [MIDSTREAM] detected: [...107] [ip4][..tcp] [...77.234.41.35][...80] -> [..192.168.115.8][49174] [HTTP][AVAST][Download][Acceptable][] RISK: Binary App Transfer, HTTP Susp User-Agent detection-update: [...107] [ip4][..tcp] [...77.234.41.35][...80] -> [..192.168.115.8][49174] [HTTP][AVAST][Download][Acceptable][] @@ -377,35 +377,35 @@ RISK: HTTP Susp User-Agent not-detected: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] + idle: [....22] [ip4][..udp] [..192.168.115.8][22793] -> [.222.26.193.119][.7133] idle: [....54] [ip4][..tcp] [..192.168.115.8][50486] -> [...77.234.40.96][...80] [HTTP.Cybersec][AVAST][Download][Safe] RISK: Binary App Transfer, HTTP Susp User-Agent, HTTP Obsolete Server not-detected: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] + idle: [....25] [ip4][..udp] [..192.168.115.8][22793] -> [.115.157.62.243][29006] not-detected: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] + idle: [....13] [ip4][..udp] [..192.168.115.8][22793] -> [.111.250.102.66][.1107] guessed: [....10] [ip4][..tcp] [...192.168.5.15][65125] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....10] [ip4][..tcp] [...192.168.5.15][65125] -> [.68.233.253.133][...80] + end: [....10] [ip4][..tcp] [...192.168.5.15][65125] -> [.68.233.253.133][...80] idle: [....64] [ip4][..tcp] [...192.168.5.15][65127] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable] RISK: Error Code idle: [....78] [ip4][..tcp] [...192.168.5.15][65128] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable] RISK: Error Code not-detected: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] + idle: [....24] [ip4][..udp] [..192.168.115.8][22793] -> [..222.26.74.190][.1037] not-detected: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] + idle: [....26] [ip4][..udp] [..192.168.115.8][22793] -> [.210.44.232.243][21044] not-detected: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] + idle: [....27] [ip4][..udp] [..192.168.115.8][22793] -> [..1.169.136.116][17951] idle: [....39] [ip4][..tcp] [..192.168.115.8][50466] -> [..203.66.182.24][...80] [HTTP.OCSP][Unknown][Web][Safe] not-detected: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] + idle: [....33] [ip4][..udp] [..192.168.115.8][22793] -> [.220.130.154.23][35941] idle: [....55] [ip4][..udp] [...192.168.5.57][59648] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....57] [ip4][..tcp] [..192.168.115.8][50488] -> [..223.26.106.20][...80] [HTTP][Unknown][Web][Acceptable] idle: [....60] [ip4][..tcp] [..192.168.115.8][50491] -> [..223.26.106.66][...80] [HTTP][Unknown][Web][Acceptable] @@ -420,7 +420,7 @@ RISK: Binary App Transfer not-detected: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] + idle: [....32] [ip4][..udp] [..192.168.115.8][22793] -> [..114.47.91.129][22576] idle: [....37] [ip4][..tcp] [..192.168.115.8][50463] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun] RISK: HTTP Obsolete Server idle: [....47] [ip4][..tcp] [..192.168.115.8][50476] -> [..101.227.32.39][...80] [HTTP.PPStream][Unknown][Streaming][Fun] @@ -431,7 +431,7 @@ idle: [....69] [ip4][..udp] [...192.168.5.63][39383] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] + idle: [.....6] [ip4][..udp] [..192.168.115.8][22793] -> [.111.249.53.196][32443] idle: [....90] [ip4][..tcp] [..192.168.115.8][50766] -> [..223.26.106.20][...80] [HTTP][Unknown][Download][Acceptable] RISK: Binary App Transfer idle: [....91] [ip4][..tcp] [..192.168.115.8][50767] -> [..223.26.106.20][...80] [HTTP][Unknown][Download][Acceptable] @@ -444,11 +444,11 @@ idle: [....87] [ip4][..tcp] [.202.108.14.219][...80] -> [..192.168.115.8][50295] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent, Unidirectional Traffic, HTTP Obsolete Server not-detected: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] [Unknown][Unknown][Unrated] - idle: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] + idle: [.....3] [ip4][..udp] [..192.168.115.8][22793] -> [...114.42.0.158][.7716] idle: [....80] [ip4][..udp] [...192.168.5.28][60023] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] + idle: [....12] [ip4][..udp] [..192.168.115.8][22793] -> [...210.44.171.1][29702] idle: [....58] [ip4][..tcp] [..192.168.115.8][50489] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Obsolete Server idle: [....59] [ip4][..tcp] [..192.168.115.8][50490] -> [.119.188.13.188][...80] [HTTP][Unknown][Web][Acceptable] @@ -456,12 +456,12 @@ idle: [....94] [ip4][..tcp] [..192.168.115.8][50769] -> [.101.227.200.11][...80] [HTTP.PPStream][Unknown][Streaming][Fun] RISK: HTTP Obsolete Server not-detected: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] [Unknown][Unknown][Unrated] - idle: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] + idle: [.....4] [ip4][..udp] [..192.168.115.8][22793] -> [.222.197.138.12][.6956] not-detected: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] [Unknown][Unknown][Unrated] - idle: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] + idle: [.....2] [ip4][..udp] [..118.171.15.56][.5544] -> [..192.168.115.8][22793] guessed: [.....9] [ip4][..tcp] [..192.168.115.8][50462] -> [.202.108.14.236][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [.....9] [ip4][..tcp] [..192.168.115.8][50462] -> [.202.108.14.236][...80] + idle: [.....9] [ip4][..tcp] [..192.168.115.8][50462] -> [.202.108.14.236][...80] idle: [....40] [ip4][..tcp] [..192.168.115.8][50467] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable] RISK: HTTP Obsolete Server idle: [....41] [ip4][..tcp] [..192.168.115.8][50469] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable] @@ -502,37 +502,37 @@ RISK: HTTP Susp User-Agent not-detected: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] + idle: [....23] [ip4][..udp] [..192.168.115.8][22793] -> [.114.37.142.173][.1074] not-detected: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] [Unknown][Unknown][Unrated] - idle: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] + idle: [.....7] [ip4][..udp] [..192.168.115.8][22793] -> [219.228.107.156][.1250] not-detected: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] + idle: [....16] [ip4][..udp] [..192.168.115.8][22793] -> [...36.233.39.81][18590] idle: [....38] [ip4][..tcp] [..192.168.115.8][50464] -> [.123.125.112.49][...80] [HTTP][Unknown][Web][Acceptable] idle: [....35] [ip4][..udp] [..192.168.115.8][22793] -> [119.188.133.182][17788] [PPStream][Unknown][Streaming][Fun] end: [....68] [ip4][..tcp] [..192.168.115.8][50497] -> [.123.125.112.49][...80] [HTTP][Unknown][Web][Acceptable] idle: [....50] [ip4][..tcp] [..192.168.115.8][50482] -> [.140.205.243.64][...80] [HTTP][Alibaba][Web][Acceptable] not-detected: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] + idle: [....18] [ip4][..udp] [..192.168.115.8][22793] -> [..61.227.170.88][20227] not-detected: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] + idle: [....20] [ip4][..udp] [..192.168.115.8][22793] -> [.121.248.133.93][12757] idle: [....95] [ip4][..tcp] [..192.168.115.8][50771] -> [.202.108.14.236][...80] [HTTP][Unknown][Streaming][Acceptable] RISK: HTTP Obsolete Server not-detected: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] + idle: [....19] [ip4][..udp] [..192.168.115.8][22793] -> [..202.112.31.89][29072] idle: [....97] [ip4][..tcp] [..192.168.115.8][50773] -> [.202.108.14.221][...80] [HTTP][Unknown][Streaming][Acceptable] RISK: HTTP Obsolete Server idle: [....99] [ip4][..tcp] [..192.168.115.8][50774] -> [.202.108.14.219][...80] [HTTP][Unknown][Streaming][Acceptable] RISK: HTTP Obsolete Server not-detected: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] + idle: [....28] [ip4][..udp] [..192.168.115.8][22793] -> [.114.41.144.153][10492] not-detected: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] + idle: [....14] [ip4][..udp] [..192.168.115.8][22793] -> [..61.223.204.67][11102] idle: [....71] [ip4][..tcp] [..192.168.115.8][50498] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Obsolete Server idle: [....61] [ip4][..tcp] [..192.168.115.8][50492] -> [...111.206.13.3][...80] [HTTP][Unknown][Web][Acceptable] @@ -543,22 +543,22 @@ idle: [....96] [ip4][..tcp] [..192.168.115.8][50772] -> [.123.125.111.70][...80] [HTTP.PPStream][Unknown][Streaming][Fun] idle: [....98] [ip4][..tcp] [..192.168.115.8][50775] -> [.123.125.111.70][...80] [HTTP.PPStream][Unknown][Streaming][Fun] not-detected: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] [Unknown][Unknown][Unrated] - idle: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] + idle: [.....8] [ip4][..udp] [.183.228.182.44][13913] -> [..192.168.115.8][22793] idle: [....84] [ip4][..udp] [...192.168.5.41][50374] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....36] [ip4][..udp] [..192.168.115.8][22793] -> [.183.61.167.104][17788] [PPStream][Unknown][Streaming][Fun] idle: [....29] [ip4][..udp] [..192.168.115.8][22793] -> [..183.61.167.82][17788] [PPStream][Unknown][Streaming][Fun] not-detected: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] + idle: [....21] [ip4][..udp] [..192.168.115.8][22793] -> [..1.175.128.104][.5185] idle: [....34] [ip4][..udp] [..192.168.115.8][22793] -> [...218.61.39.87][17788] [PPStream][Unknown][Streaming][Fun] idle: [....11] [ip4][..udp] [..192.168.115.8][22793] -> [..218.61.39.103][17788] [PPStream][Unknown][Streaming][Fun] idle: [....77] [ip4][..udp] [...192.168.5.50][52529] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] + idle: [....31] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.20][33738] not-detected: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] + idle: [....30] [ip4][..udp] [..192.168.115.8][22793] -> [...210.47.12.19][33738] idle: [....92] [ip4][..tcp] [..192.168.115.8][50765] -> [..36.110.220.15][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Obsolete Server idle: [....49] [ip4][..tcp] [..117.79.81.135][...80] -> [..192.168.115.8][50443] [HTTP][Unknown][Web][Acceptable] @@ -573,15 +573,15 @@ idle: [....70] [ip4][..udp] [...192.168.5.63][60976] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] + idle: [....17] [ip4][..udp] [..192.168.115.8][22793] -> [.111.117.101.81][10162] idle: [...103] [ip4][..udp] [..192.168.115.1][50945] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] [Unknown][Unknown][Unrated] - idle: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] + idle: [.....1] [ip4][..udp] [....1.173.5.226][22636] -> [..192.168.115.8][22793] not-detected: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] [Unknown][Unknown][Unrated] - idle: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] + idle: [.....5] [ip4][..udp] [..192.168.115.8][22793] -> [...202.198.7.89][16039] idle: [....73] [ip4][..tcp] [..192.168.115.8][50500] -> [..23.41.133.163][...80] [HTTP][Unknown][Web][Acceptable] idle: [....83] [ip4][..udp] [...192.168.5.38][.1900] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] + idle: [....15] [ip4][..udp] [..192.168.115.8][22793] -> [..36.237.154.69][.4316] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/pptp.pcap.out b/test/results/flow-info/default/pptp.pcap.out index 2432dcdd8..bda2b487e 100644 --- a/test/results/flow-info/default/pptp.pcap.out +++ b/test/results/flow-info/default/pptp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.43.22][41366] -> [...191.101.61.1][.1723] + new: [.....1] [ip4][..tcp] [..192.168.43.22][41366] -> [...191.101.61.1][.1723] detected: [.....1] [ip4][..tcp] [..192.168.43.22][41366] -> [...191.101.61.1][.1723] [PPTP][Unknown][VPN][Acceptable] end: [.....1] [ip4][..tcp] [..192.168.43.22][41366] -> [...191.101.61.1][.1723] [PPTP][Unknown][VPN][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/protobuf.pcap.out b/test/results/flow-info/default/protobuf.pcap.out index 82561fbe3..72f03114f 100644 --- a/test/results/flow-info/default/protobuf.pcap.out +++ b/test/results/flow-info/default/protobuf.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][52392] -> [......127.0.0.1][12345] + new: [.....1] [ip4][..tcp] [......127.0.0.1][52392] -> [......127.0.0.1][12345] detected: [.....1] [ip4][..tcp] [......127.0.0.1][52392] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [......127.0.0.1][51680] -> [......127.0.0.1][12345] + new: [.....2] [ip4][..tcp] [......127.0.0.1][51680] -> [......127.0.0.1][12345] end: [.....1] [ip4][..tcp] [......127.0.0.1][52392] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] detected: [.....2] [ip4][..tcp] [......127.0.0.1][51680] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 36 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [......127.0.0.1][39786] -> [......127.0.0.1][12345] + new: [.....3] [ip4][..tcp] [......127.0.0.1][39786] -> [......127.0.0.1][12345] detected: [.....3] [ip4][..tcp] [......127.0.0.1][39786] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] end: [.....2] [ip4][..tcp] [......127.0.0.1][51680] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 44 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [......127.0.0.1][42358] -> [......127.0.0.1][12345] + new: [.....4] [ip4][..tcp] [......127.0.0.1][42358] -> [......127.0.0.1][12345] detected: [.....4] [ip4][..tcp] [......127.0.0.1][42358] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] end: [.....3] [ip4][..tcp] [......127.0.0.1][39786] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 52 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [......127.0.0.1][59030] -> [......127.0.0.1][12345] + new: [.....5] [ip4][..tcp] [......127.0.0.1][59030] -> [......127.0.0.1][12345] detected: [.....5] [ip4][..tcp] [......127.0.0.1][59030] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] end: [.....4] [ip4][..tcp] [......127.0.0.1][42358] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] end: [.....5] [ip4][..tcp] [......127.0.0.1][59030] -> [......127.0.0.1][12345] [Protobuf][Unknown][Network][Safe] diff --git a/test/results/flow-info/default/protonvpn.pcap.out b/test/results/flow-info/default/protonvpn.pcap.out index 32001b75a..bcbf7d8af 100644 --- a/test/results/flow-info/default/protonvpn.pcap.out +++ b/test/results/flow-info/default/protonvpn.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] + new: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] detected: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] [TLS.ProtonVPN][Unknown][VPN][Acceptable][vpn-api.proton.me] detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] [TLS.ProtonVPN][Unknown][VPN][Acceptable][vpn-api.proton.me] detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] [TLS.ProtonVPN][Unknown][VPN][Acceptable][vpn-api.proton.me] RISK: TLS Cert Expired - new: [.....2] [ip4][..udp] [......10.0.2.15][57701] -> [....217.23.3.76][..443] + new: [.....2] [ip4][..udp] [......10.0.2.15][57701] -> [....217.23.3.76][..443] detected: [.....2] [ip4][..udp] [......10.0.2.15][57701] -> [....217.23.3.76][..443] [WireGuard][ProtonVPN][VPN][Acceptable] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 40 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....3] [ip4][..tcp] [....2.58.241.67][37710] -> [........8.8.8.8][..443] + new: [.....3] [ip4][..tcp] [....2.58.241.67][37710] -> [........8.8.8.8][..443] idle: [.....2] [ip4][..udp] [......10.0.2.15][57701] -> [....217.23.3.76][..443] [WireGuard][ProtonVPN][VPN][Acceptable] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..tcp] [......10.0.2.15][37810] -> [185.159.159.148][..443] [TLS.ProtonVPN][Unknown][VPN][Acceptable] RISK: TLS Cert Expired guessed: [.....3] [ip4][..tcp] [....2.58.241.67][37710] -> [........8.8.8.8][..443] [TLS][Google][Web][Safe] RISK: Anonymous Subscriber, Unidirectional Traffic - idle: [.....3] [ip4][..tcp] [....2.58.241.67][37710] -> [........8.8.8.8][..443] + idle: [.....3] [ip4][..tcp] [....2.58.241.67][37710] -> [........8.8.8.8][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/psiphon3.pcap.out b/test/results/flow-info/default/psiphon3.pcap.out index e6e965629..73dfb710f 100644 --- a/test/results/flow-info/default/psiphon3.pcap.out +++ b/test/results/flow-info/default/psiphon3.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.0.103][40557] -> [.104.18.151.190][..443] + new: [.....1] [ip4][..tcp] [..192.168.0.103][40557] -> [.104.18.151.190][..443] detected: [.....1] [ip4][..tcp] [..192.168.0.103][40557] -> [.104.18.151.190][..443] [TLS][Cloudflare][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....1] [ip4][..tcp] [..192.168.0.103][40557] -> [.104.18.151.190][..443] [TLS][Cloudflare][Web][Safe][] diff --git a/test/results/flow-info/default/punycode-idn.pcap.out b/test/results/flow-info/default/punycode-idn.pcap.out index f33c8c9a0..62f5e1c2e 100644 --- a/test/results/flow-info/default/punycode-idn.pcap.out +++ b/test/results/flow-info/default/punycode-idn.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.140][45520] -> [....192.168.2.1][...53] + new: [.....1] [ip4][..udp] [..192.168.2.140][45520] -> [....192.168.2.1][...53] detected: [.....1] [ip4][..udp] [..192.168.2.140][45520] -> [....192.168.2.1][...53] [DNS.Spotify][Unknown][Network][Fun][i.scdn.co] detection-update: [.....1] [ip4][..udp] [..192.168.2.140][45520] -> [....192.168.2.1][...53] [DNS.Spotify][Unknown][Network][Fun][i.scdn.co] - new: [.....2] [ip4][..udp] [..192.168.2.140][60156] -> [....192.168.2.1][...53] + new: [.....2] [ip4][..udp] [..192.168.2.140][60156] -> [....192.168.2.1][...53] detected: [.....2] [ip4][..udp] [..192.168.2.140][60156] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][www.xn--mnich-kva.com] RISK: IDN Domain Name detection-update: [.....2] [ip4][..udp] [..192.168.2.140][60156] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][www.xn--mnich-kva.com] RISK: IDN Domain Name, Error Code - new: [.....3] [ip4][..tcp] [..192.168.2.140][56011] -> [...170.33.9.230][...80] + new: [.....3] [ip4][..tcp] [..192.168.2.140][56011] -> [...170.33.9.230][...80] detected: [.....3] [ip4][..tcp] [..192.168.2.140][56011] -> [...170.33.9.230][...80] [HTTP][Alibaba][Web][Acceptable][www.love.xn--55qx5d] RISK: IDN Domain Name detection-update: [.....3] [ip4][..tcp] [..192.168.2.140][56011] -> [...170.33.9.230][...80] [HTTP][Alibaba][Web][Acceptable][www.love.xn--55qx5d] diff --git a/test/results/flow-info/default/quic-23.pcap.out b/test/results/flow-info/default/quic-23.pcap.out index 94058c828..e4dbc9ff3 100644 --- a/test/results/flow-info/default/quic-23.pcap.out +++ b/test/results/flow-info/default/quic-23.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [2e4a:774d:26fd:7f9b:785b:2d1b:4f8a:63c7][50339] -> [3bcc:9991:faba:bae1:cd2a:e2fd:b3be:c5ab][..443] + new: [.....1] [ip6][..udp] [2e4a:774d:26fd:7f9b:785b:2d1b:4f8a:63c7][50339] -> [3bcc:9991:faba:bae1:cd2a:e2fd:b3be:c5ab][..443] detected: [.....1] [ip6][..udp] [2e4a:774d:26fd:7f9b:785b:2d1b:4f8a:63c7][50339] -> [3bcc:9991:faba:bae1:cd2a:e2fd:b3be:c5ab][..443] [QUIC][Unknown][Web][Acceptable][quic.aiortc.org] idle: [.....1] [ip6][..udp] [2e4a:774d:26fd:7f9b:785b:2d1b:4f8a:63c7][50339] -> [3bcc:9991:faba:bae1:cd2a:e2fd:b3be:c5ab][..443] [QUIC][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-24.pcap.out b/test/results/flow-info/default/quic-24.pcap.out index c8d525960..9610c7809 100644 --- a/test/results/flow-info/default/quic-24.pcap.out +++ b/test/results/flow-info/default/quic-24.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.9.0.1][41436] -> [.......10.9.0.2][..443] + new: [.....1] [ip4][..udp] [.......10.9.0.1][41436] -> [.......10.9.0.2][..443] detected: [.....1] [ip4][..udp] [.......10.9.0.1][41436] -> [.......10.9.0.2][..443] [QUIC][Unknown][Web][Acceptable][localhost] idle: [.....1] [ip4][..udp] [.......10.9.0.1][41436] -> [.......10.9.0.2][..443] [QUIC][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-27.pcap.out b/test/results/flow-info/default/quic-27.pcap.out index 4cc28dd37..23051ebc4 100644 --- a/test/results/flow-info/default/quic-27.pcap.out +++ b/test/results/flow-info/default/quic-27.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [...3ef4:2194:f4a6:3503:40cd:714:57:c4e4][64229] -> [..............2f3d:64d1:9d59:549b::200e][..443] + new: [.....1] [ip6][..udp] [...3ef4:2194:f4a6:3503:40cd:714:57:c4e4][64229] -> [..............2f3d:64d1:9d59:549b::200e][..443] detected: [.....1] [ip6][..udp] [...3ef4:2194:f4a6:3503:40cd:714:57:c4e4][64229] -> [..............2f3d:64d1:9d59:549b::200e][..443] [QUIC.Google][Unknown][Web][Acceptable][play.google.com] idle: [.....1] [ip6][..udp] [...3ef4:2194:f4a6:3503:40cd:714:57:c4e4][64229] -> [..............2f3d:64d1:9d59:549b::200e][..443] [QUIC.Google][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-28.pcap.out b/test/results/flow-info/default/quic-28.pcap.out index 1b2b989c0..5d01558ba 100644 --- a/test/results/flow-info/default/quic-28.pcap.out +++ b/test/results/flow-info/default/quic-28.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.9.0.2][60106] -> [..104.26.11.240][..443] + new: [.....1] [ip4][..udp] [.......10.9.0.2][60106] -> [..104.26.11.240][..443] detected: [.....1] [ip4][..udp] [.......10.9.0.2][60106] -> [..104.26.11.240][..443] [QUIC][Cloudflare][Web][Acceptable][www.wireshark.org] analyse: [.....1] [ip4][..udp] [.......10.9.0.2][60106] -> [..104.26.11.240][..443] [QUIC][Cloudflare][Web][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/quic-29.pcap.out b/test/results/flow-info/default/quic-29.pcap.out index e12999ea0..5418ae900 100644 --- a/test/results/flow-info/default/quic-29.pcap.out +++ b/test/results/flow-info/default/quic-29.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.9.0.1][36588] -> [.......10.9.0.2][..443] + new: [.....1] [ip4][..udp] [.......10.9.0.1][36588] -> [.......10.9.0.2][..443] detected: [.....1] [ip4][..udp] [.......10.9.0.1][36588] -> [.......10.9.0.2][..443] [QUIC][Unknown][Web][Acceptable][localhost] idle: [.....1] [ip4][..udp] [.......10.9.0.1][36588] -> [.......10.9.0.2][..443] [QUIC][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-33.pcapng.out b/test/results/flow-info/default/quic-33.pcapng.out index bac973961..c2cd4e3c3 100644 --- a/test/results/flow-info/default/quic-33.pcapng.out +++ b/test/results/flow-info/default/quic-33.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....................................::1][51430] -> [....................................::1][.4443] + new: [.....1] [ip6][..udp] [....................................::1][51430] -> [....................................::1][.4443] detected: [.....1] [ip6][..udp] [....................................::1][51430] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch idle: [.....1] [ip6][..udp] [....................................::1][51430] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic-34.pcap.out b/test/results/flow-info/default/quic-34.pcap.out index 1f095ce2f..459943709 100644 --- a/test/results/flow-info/default/quic-34.pcap.out +++ b/test/results/flow-info/default/quic-34.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.56.1][55880] -> [.192.168.56.198][.4443] + new: [.....1] [ip4][..udp] [...192.168.56.1][55880] -> [.192.168.56.198][.4443] detected: [.....1] [ip4][..udp] [...192.168.56.1][55880] -> [.192.168.56.198][.4443] [QUIC][Unknown][Web][Acceptable][] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch idle: [.....1] [ip4][..udp] [...192.168.56.1][55880] -> [.192.168.56.198][.4443] [QUIC][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic-forcing-vn-with-data.pcapng.out b/test/results/flow-info/default/quic-forcing-vn-with-data.pcapng.out index 7f129e550..2566d3784 100644 --- a/test/results/flow-info/default/quic-forcing-vn-with-data.pcapng.out +++ b/test/results/flow-info/default/quic-forcing-vn-with-data.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.56.103][55523] -> [.192.168.56.104][.4433] + new: [.....1] [ip4][..udp] [.192.168.56.103][55523] -> [.192.168.56.104][.4433] detected: [.....1] [ip4][..udp] [.192.168.56.103][55523] -> [.192.168.56.104][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [.192.168.56.103][55523] -> [.192.168.56.104][.4433] [QUIC][Unknown][Web][Acceptable][] diff --git a/test/results/flow-info/default/quic-fuzz-overflow.pcapng.out b/test/results/flow-info/default/quic-fuzz-overflow.pcapng.out index c57f84a5a..515f6dde6 100644 --- a/test/results/flow-info/default/quic-fuzz-overflow.pcapng.out +++ b/test/results/flow-info/default/quic-fuzz-overflow.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [255.255.255.255][.8224] -> [.255.255.255.32][.8224] + new: [.....1] [ip4][..udp] [255.255.255.255][.8224] -> [.255.255.255.32][.8224] detected: [.....1] [ip4][..udp] [255.255.255.255][.8224] -> [.255.255.255.32][.8224] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn idle: [.....1] [ip4][..udp] [255.255.255.255][.8224] -> [.255.255.255.32][.8224] [QUIC][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic-mvfst-22.pcap.out b/test/results/flow-info/default/quic-mvfst-22.pcap.out index aca2f88e1..994ca621d 100644 --- a/test/results/flow-info/default/quic-mvfst-22.pcap.out +++ b/test/results/flow-info/default/quic-mvfst-22.pcap.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..udp] [......10.0.2.15][35601] -> [.....31.13.86.8][..443] + new: [.....1] [ip4][..udp] [......10.0.2.15][35601] -> [.....31.13.86.8][..443] detected: [.....1] [ip4][..udp] [......10.0.2.15][35601] -> [.....31.13.86.8][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] analyse: [.....1] [ip4][..udp] [......10.0.2.15][35601] -> [.....31.13.86.8][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/quic-mvfst-22_decryption_error.pcap.out b/test/results/flow-info/default/quic-mvfst-22_decryption_error.pcap.out index b105ad58b..94e013830 100644 --- a/test/results/flow-info/default/quic-mvfst-22_decryption_error.pcap.out +++ b/test/results/flow-info/default/quic-mvfst-22_decryption_error.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..10.230.40.168][62196] -> [..94.97.225.146][..443] + new: [.....1] [ip4][..udp] [..10.230.40.168][62196] -> [..94.97.225.146][..443] detected: [.....1] [ip4][..udp] [..10.230.40.168][62196] -> [..94.97.225.146][..443] [QUIC][Unknown][Web][Acceptable] idle: [.....1] [ip4][..udp] [..10.230.40.168][62196] -> [..94.97.225.146][..443] [QUIC][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-mvfst-27.pcapng.out b/test/results/flow-info/default/quic-mvfst-27.pcapng.out index 47aa89e61..ffd1d5b83 100644 --- a/test/results/flow-info/default/quic-mvfst-27.pcapng.out +++ b/test/results/flow-info/default/quic-mvfst-27.pcapng.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] + new: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] detected: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] idle: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-mvfst-exp.pcap.out b/test/results/flow-info/default/quic-mvfst-exp.pcap.out index 20fe34f3c..1e1fed520 100644 --- a/test/results/flow-info/default/quic-mvfst-exp.pcap.out +++ b/test/results/flow-info/default/quic-mvfst-exp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [.2aac:cdf7:d506:7807:9092:75f:a963:f4ab][57587] -> [....3f65:ece9:fe71:6e2a:face:b00c::358e][..443] + new: [.....1] [ip6][..udp] [.2aac:cdf7:d506:7807:9092:75f:a963:f4ab][57587] -> [....3f65:ece9:fe71:6e2a:face:b00c::358e][..443] detected: [.....1] [ip6][..udp] [.2aac:cdf7:d506:7807:9092:75f:a963:f4ab][57587] -> [....3f65:ece9:fe71:6e2a:face:b00c::358e][..443] [QUIC.FbookReelStory][Unknown][SocialNetwork][Fun][video.fmct2-3.fna.fbcdn.net] idle: [.....1] [ip6][..udp] [.2aac:cdf7:d506:7807:9092:75f:a963:f4ab][57587] -> [....3f65:ece9:fe71:6e2a:face:b00c::358e][..443] [QUIC.FbookReelStory][Unknown][SocialNetwork][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic-v2.pcapng.out b/test/results/flow-info/default/quic-v2.pcapng.out index d6b453226..122c43ae1 100644 --- a/test/results/flow-info/default/quic-v2.pcapng.out +++ b/test/results/flow-info/default/quic-v2.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....................................::1][42086] -> [....................................::1][.4443] + new: [.....1] [ip6][..udp] [....................................::1][42086] -> [....................................::1][.4443] detected: [.....1] [ip6][..udp] [....................................::1][42086] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable][test] RISK: Known Proto on Non Std Port idle: [.....1] [ip6][..udp] [....................................::1][42086] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic.pcap.out b/test/results/flow-info/default/quic.pcap.out index 0a18f1a43..723f9b860 100644 --- a/test/results/flow-info/default/quic.pcap.out +++ b/test/results/flow-info/default/quic.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.109][57833] -> [.216.58.212.101][..443] + new: [.....1] [ip4][..udp] [..192.168.1.109][57833] -> [.216.58.212.101][..443] detected: [.....1] [ip4][..udp] [..192.168.1.109][57833] -> [.216.58.212.101][..443] [QUIC.GMail][Google][Email][Acceptable][mail.google.com] analyse: [.....1] [ip4][..udp] [..192.168.1.109][57833] -> [.216.58.212.101][..443] [QUIC.GMail][Google][Email][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,30 +15,30 @@ [ENTROPIES...: 4.8,7.5,7.8,5.7,5.5,7.7,5.7,7.7,5.7,6.9,7.5,5.4,5.8,6.9,6.6,5.4,6.0,5.7,5.6,7.1,6.6,5.5,5.4,7.0,5.1,5.8,6.9,5.6,7.9,5.4,7.8,7.6] DAEMON-EVENT: [Processed: 413 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.......10.0.0.4][40134] -> [.......10.0.0.3][.6121] + new: [.....2] [ip4][..udp] [.......10.0.0.4][40134] -> [.......10.0.0.3][.6121] detected: [.....2] [ip4][..udp] [.......10.0.0.4][40134] -> [.......10.0.0.3][.6121] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn idle: [.....1] [ip4][..udp] [..192.168.1.109][57833] -> [.216.58.212.101][..443] [QUIC.GMail][Google][Email][Acceptable] DAEMON-EVENT: [Processed: 419 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.1.105][45669] -> [...172.217.16.4][..443] + new: [.....3] [ip4][..udp] [..192.168.1.105][45669] -> [...172.217.16.4][..443] detected: [.....3] [ip4][..udp] [..192.168.1.105][45669] -> [...172.217.16.4][..443] [QUIC.Google][Google][Web][Acceptable][www.google.com] - new: [.....4] [ip4][..udp] [..192.168.1.105][40461] -> [...172.217.16.3][..443] - new: [.....5] [ip4][..udp] [..192.168.1.105][34438] -> [.216.58.210.238][..443] + new: [.....4] [ip4][..udp] [..192.168.1.105][40461] -> [...172.217.16.3][..443] + new: [.....5] [ip4][..udp] [..192.168.1.105][34438] -> [.216.58.210.238][..443] detected: [.....5] [ip4][..udp] [..192.168.1.105][34438] -> [.216.58.210.238][..443] [QUIC.YouTube][Google][Media][Fun][www.youtube.com] - new: [.....6] [ip4][..udp] [..192.168.1.105][48445] -> [.216.58.214.110][..443] + new: [.....6] [ip4][..udp] [..192.168.1.105][48445] -> [.216.58.214.110][..443] detected: [.....6] [ip4][..udp] [..192.168.1.105][48445] -> [.216.58.214.110][..443] [QUIC.YouTube][Google][Media][Fun][i.ytimg.com] - new: [.....7] [ip4][..udp] [..192.168.1.105][40030] -> [.216.58.201.227][..443] + new: [.....7] [ip4][..udp] [..192.168.1.105][40030] -> [.216.58.201.227][..443] detected: [.....7] [ip4][..udp] [..192.168.1.105][40030] -> [.216.58.201.227][..443] [QUIC.Google][Google][Web][Acceptable][fonts.gstatic.com] - new: [.....8] [ip4][..udp] [..192.168.1.105][55934] -> [.216.58.201.238][..443] + new: [.....8] [ip4][..udp] [..192.168.1.105][55934] -> [.216.58.201.238][..443] detected: [.....8] [ip4][..udp] [..192.168.1.105][55934] -> [.216.58.201.238][..443] [QUIC.YouTube][Google][Media][Fun][s.ytimg.com] - new: [.....9] [ip4][..udp] [..192.168.1.105][53817] -> [.216.58.210.225][..443] + new: [.....9] [ip4][..udp] [..192.168.1.105][53817] -> [.216.58.210.225][..443] detected: [.....9] [ip4][..udp] [..192.168.1.105][53817] -> [.216.58.210.225][..443] [QUIC.YouTube][Google][Media][Fun][yt3.ggpht.com] idle: [.....2] [ip4][..udp] [.......10.0.0.4][40134] -> [.......10.0.0.3][.6121] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn DAEMON-EVENT: [Processed: 449 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..udp] [..192.168.1.109][35236] -> [.216.58.210.206][..443] + new: [....10] [ip4][..udp] [..192.168.1.109][35236] -> [.216.58.210.206][..443] detected: [....10] [ip4][..udp] [..192.168.1.109][35236] -> [.216.58.210.206][..443] [QUIC.YouTube][Google][Media][Fun][www.youtube.com] analyse: [....10] [ip4][..udp] [..192.168.1.109][35236] -> [.216.58.210.206][..443] [QUIC.YouTube][Google][Media][Fun] min| max| avg| stddev| variance| entropy @@ -52,7 +52,7 @@ [ENTROPIES...: 5.1,7.4,7.6,2.6,5.4,7.4,5.3,5.5,7.9,5.5,5.5,5.7,7.9,7.9,7.8,5.6,5.6,7.9,7.9,5.7,7.9,7.9,7.9,5.6,7.9,5.7,7.9,7.8,7.9,5.6,7.9,7.9] idle: [.....7] [ip4][..udp] [..192.168.1.105][40030] -> [.216.58.201.227][..443] [QUIC.Google][Google][Web][Acceptable] guessed: [.....4] [ip4][..udp] [..192.168.1.105][40461] -> [...172.217.16.3][..443] [QUIC][Google][Web][Acceptable] - idle: [.....4] [ip4][..udp] [..192.168.1.105][40461] -> [...172.217.16.3][..443] + idle: [.....4] [ip4][..udp] [..192.168.1.105][40461] -> [...172.217.16.3][..443] idle: [.....6] [ip4][..udp] [..192.168.1.105][48445] -> [.216.58.214.110][..443] [QUIC.YouTube][Google][Media][Fun] idle: [.....5] [ip4][..udp] [..192.168.1.105][34438] -> [.216.58.210.238][..443] [QUIC.YouTube][Google][Media][Fun] idle: [.....3] [ip4][..udp] [..192.168.1.105][45669] -> [...172.217.16.4][..443] [QUIC.Google][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/quic046.pcap.out b/test/results/flow-info/default/quic046.pcap.out index 6d88815a5..7d45d30c4 100644 --- a/test/results/flow-info/default/quic046.pcap.out +++ b/test/results/flow-info/default/quic046.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.236][50587] -> [..216.58.206.86][..443] + new: [.....1] [ip4][..udp] [..192.168.1.236][50587] -> [..216.58.206.86][..443] detected: [.....1] [ip4][..udp] [..192.168.1.236][50587] -> [..216.58.206.86][..443] [QUIC.YouTube][Google][Media][Fun][i.ytimg.com] analyse: [.....1] [ip4][..udp] [..192.168.1.236][50587] -> [..216.58.206.86][..443] [QUIC.YouTube][Google][Media][Fun] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/quic_0RTT.pcap.out b/test/results/flow-info/default/quic_0RTT.pcap.out index 71486eab3..efa9a79a6 100644 --- a/test/results/flow-info/default/quic_0RTT.pcap.out +++ b/test/results/flow-info/default/quic_0RTT.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....................................::1][60459] -> [....................................::1][.4443] + new: [.....1] [ip6][..udp] [....................................::1][60459] -> [....................................::1][.4443] detected: [.....1] [ip6][..udp] [....................................::1][60459] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable][abcd] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][51972] -> [142.250.181.227][..443] + new: [.....2] [ip4][..udp] [..192.168.2.100][51972] -> [142.250.181.227][..443] detected: [.....2] [ip4][..udp] [..192.168.2.100][51972] -> [142.250.181.227][..443] [QUIC.Google][Google][Web][Acceptable][ssl.gstatic.com] RISK: Unidirectional Traffic idle: [.....2] [ip4][..udp] [..192.168.2.100][51972] -> [142.250.181.227][..443] [QUIC.Google][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/quic_cc_ack.pcapng.out b/test/results/flow-info/default/quic_cc_ack.pcapng.out index 8f6aa69b9..8877f86b8 100644 --- a/test/results/flow-info/default/quic_cc_ack.pcapng.out +++ b/test/results/flow-info/default/quic_cc_ack.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.152.14.223.145][57113] -> [...71.98.228.93][..443] + new: [.....1] [ip4][..udp] [.152.14.223.145][57113] -> [...71.98.228.93][..443] detected: [.....1] [ip4][..udp] [.152.14.223.145][57113] -> [...71.98.228.93][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....2] [ip4][..udp] [.183.23.159.144][37787] -> [.108.140.147.22][..443] + new: [.....2] [ip4][..udp] [.183.23.159.144][37787] -> [.108.140.147.22][..443] detected: [.....2] [ip4][..udp] [.183.23.159.144][37787] -> [.108.140.147.22][..443] [QUIC][Azure][Web][Acceptable] idle: [.....2] [ip4][..udp] [.183.23.159.144][37787] -> [.108.140.147.22][..443] [QUIC][Azure][Web][Acceptable] idle: [.....1] [ip4][..udp] [.152.14.223.145][57113] -> [...71.98.228.93][..443] [QUIC][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic_crypto_aes_auth_size.pcap.out b/test/results/flow-info/default/quic_crypto_aes_auth_size.pcap.out index 50ffc1c6a..75117b536 100644 --- a/test/results/flow-info/default/quic_crypto_aes_auth_size.pcap.out +++ b/test/results/flow-info/default/quic_crypto_aes_auth_size.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...134.53.36.43][34917] -> [..142.104.38.30][..443] + new: [.....1] [ip4][..udp] [...134.53.36.43][34917] -> [..142.104.38.30][..443] detected: [.....1] [ip4][..udp] [...134.53.36.43][34917] -> [..142.104.38.30][..443] [QUIC.Snapchat][Unknown][SocialNetwork][Fun][app-analytics-v2.snapchat.com] - new: [.....2] [ip4][..udp] [245.161.134.177][27636] -> [..77.242.114.14][..443] + new: [.....2] [ip4][..udp] [245.161.134.177][27636] -> [..77.242.114.14][..443] detected: [.....2] [ip4][..udp] [245.161.134.177][27636] -> [..77.242.114.14][..443] [QUIC.Snapchat][Unknown][SocialNetwork][Fun][gcp.api.snapchat.com] idle: [.....1] [ip4][..udp] [...134.53.36.43][34917] -> [..142.104.38.30][..443] [QUIC.Snapchat][Unknown][SocialNetwork][Fun] idle: [.....2] [ip4][..udp] [245.161.134.177][27636] -> [..77.242.114.14][..443] [QUIC.Snapchat][Unknown][SocialNetwork][Fun] diff --git a/test/results/flow-info/default/quic_frags_ch_in_multiple_packets.pcapng.out b/test/results/flow-info/default/quic_frags_ch_in_multiple_packets.pcapng.out index deed65941..6d37529eb 100644 --- a/test/results/flow-info/default/quic_frags_ch_in_multiple_packets.pcapng.out +++ b/test/results/flow-info/default/quic_frags_ch_in_multiple_packets.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....................................::1][58822] -> [....................................::1][.4443] + new: [.....1] [ip6][..udp] [....................................::1][58822] -> [....................................::1][.4443] detected: [.....1] [ip6][..udp] [....................................::1][58822] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip6][..udp] [....................................::1][58822] -> [....................................::1][.4443] [QUIC][Unknown][Web][Acceptable][] diff --git a/test/results/flow-info/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out b/test/results/flow-info/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out index 522e72496..7866ffc31 100644 --- a/test/results/flow-info/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out +++ b/test/results/flow-info/default/quic_frags_ch_out_of_order_same_packet_craziness.pcapng.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.133.205.75.230][56528] -> [.208.229.157.81][..443] + new: [.....1] [ip4][..udp] [.133.205.75.230][56528] -> [.208.229.157.81][..443] detected: [.....1] [ip4][..udp] [.133.205.75.230][56528] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][update.googleapis.com] - new: [.....2] [ip4][..udp] [..147.196.90.42][61647] -> [..177.86.46.206][..443] + new: [.....2] [ip4][..udp] [..147.196.90.42][61647] -> [..177.86.46.206][..443] detected: [.....2] [ip4][..udp] [..147.196.90.42][61647] -> [..177.86.46.206][..443] [QUIC.Google][Unknown][Web][Acceptable][sb-ssl.google.com] idle: [.....1] [ip4][..udp] [.133.205.75.230][56528] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [...168.144.64.5][55376] -> [.212.22.246.243][..443] + new: [.....3] [ip4][..udp] [...168.144.64.5][55376] -> [.212.22.246.243][..443] detected: [.....3] [ip4][..udp] [...168.144.64.5][55376] -> [.212.22.246.243][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] - new: [.....4] [ip4][..udp] [...168.144.64.5][64964] -> [.133.202.76.105][..443] + new: [.....4] [ip4][..udp] [...168.144.64.5][64964] -> [.133.202.76.105][..443] detected: [.....4] [ip4][..udp] [...168.144.64.5][64964] -> [.133.202.76.105][..443] [QUIC.Google][Unknown][Web][Acceptable][accounts.google.com] - new: [.....5] [ip4][..udp] [...168.144.64.5][55844] -> [..112.1.105.138][..443] + new: [.....5] [ip4][..udp] [...168.144.64.5][55844] -> [..112.1.105.138][..443] detected: [.....5] [ip4][..udp] [...168.144.64.5][55844] -> [..112.1.105.138][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe][android.clients.google.com] - new: [.....6] [ip4][..udp] [...168.144.64.5][59827] -> [..37.47.218.224][..443] + new: [.....6] [ip4][..udp] [...168.144.64.5][59827] -> [..37.47.218.224][..443] detected: [.....6] [ip4][..udp] [...168.144.64.5][59827] -> [..37.47.218.224][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][www.googleadservices.com] idle: [.....2] [ip4][..udp] [..147.196.90.42][61647] -> [..177.86.46.206][..443] [QUIC.Google][Unknown][Web][Acceptable] - new: [.....7] [ip4][..udp] [...168.144.64.5][51053] -> [241.138.147.133][..443] + new: [.....7] [ip4][..udp] [...168.144.64.5][51053] -> [241.138.147.133][..443] detected: [.....7] [ip4][..udp] [...168.144.64.5][51053] -> [241.138.147.133][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][content-autofill.googleapis.com] update: [.....3] [ip4][..udp] [...168.144.64.5][55376] -> [.212.22.246.243][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [.....4] [ip4][..udp] [...168.144.64.5][64964] -> [.133.202.76.105][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -25,43 +25,43 @@ update: [.....5] [ip4][..udp] [...168.144.64.5][55844] -> [..112.1.105.138][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe] DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 4] - new: [.....8] [ip4][..udp] [..10.117.78.100][44252] -> [.251.236.18.198][..443] + new: [.....8] [ip4][..udp] [..10.117.78.100][44252] -> [.251.236.18.198][..443] detected: [.....8] [ip4][..udp] [..10.117.78.100][44252] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable][accounts.google.com] idle: [.....3] [ip4][..udp] [...168.144.64.5][55376] -> [.212.22.246.243][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [.....4] [ip4][..udp] [...168.144.64.5][64964] -> [.133.202.76.105][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [.....6] [ip4][..udp] [...168.144.64.5][59827] -> [..37.47.218.224][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] idle: [.....7] [ip4][..udp] [...168.144.64.5][51053] -> [241.138.147.133][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] idle: [.....5] [ip4][..udp] [...168.144.64.5][55844] -> [..112.1.105.138][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe] - new: [.....9] [ip4][..udp] [..10.117.78.100][55273] -> [202.152.155.121][..443] + new: [.....9] [ip4][..udp] [..10.117.78.100][55273] -> [202.152.155.121][..443] detected: [.....9] [ip4][..udp] [..10.117.78.100][55273] -> [202.152.155.121][..443] [QUIC.Google][Unknown][Web][Acceptable][clients4.google.com] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 4] - new: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] + new: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] detected: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][update.googleapis.com] - new: [....11] [ip4][..udp] [...168.144.64.5][53431] -> [...128.248.24.1][..443] + new: [....11] [ip4][..udp] [...168.144.64.5][53431] -> [...128.248.24.1][..443] detected: [....11] [ip4][..udp] [...168.144.64.5][53431] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][fonts.gstatic.com] - new: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] + new: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] detected: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] [QUIC.YouTube][Unknown][Media][Fun][yt3.ggpht.com] - new: [....13] [ip4][..udp] [...168.144.64.5][62652] -> [.158.146.215.30][..443] + new: [....13] [ip4][..udp] [...168.144.64.5][62652] -> [.158.146.215.30][..443] detected: [....13] [ip4][..udp] [...168.144.64.5][62652] -> [.158.146.215.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][static.doubleclick.net] - new: [....14] [ip4][..udp] [...168.144.64.5][63136] -> [...9.65.169.252][..443] + new: [....14] [ip4][..udp] [...168.144.64.5][63136] -> [...9.65.169.252][..443] detected: [....14] [ip4][..udp] [...168.144.64.5][63136] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun][suggestqueries-clients6.youtube.com] idle: [.....8] [ip4][..udp] [..10.117.78.100][44252] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [.....9] [ip4][..udp] [..10.117.78.100][55273] -> [202.152.155.121][..443] [QUIC.Google][Unknown][Web][Acceptable] - new: [....15] [ip4][..udp] [...168.144.64.5][51456] -> [102.194.207.179][..443] + new: [....15] [ip4][..udp] [...168.144.64.5][51456] -> [102.194.207.179][..443] detected: [....15] [ip4][..udp] [...168.144.64.5][51456] -> [102.194.207.179][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][clientservices.googleapis.com] update: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....13] [ip4][..udp] [...168.144.64.5][62652] -> [.158.146.215.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] update: [....14] [ip4][..udp] [...168.144.64.5][63136] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....11] [ip4][..udp] [...168.144.64.5][53431] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....16] [ip4][..udp] [...168.144.64.5][63163] -> [113.250.137.243][..443] + new: [....16] [ip4][..udp] [...168.144.64.5][63163] -> [113.250.137.243][..443] detected: [....16] [ip4][..udp] [...168.144.64.5][63163] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][update.googleapis.com] - new: [....17] [ip4][..udp] [...168.144.64.5][54016] -> [...153.98.28.78][..443] + new: [....17] [ip4][..udp] [...168.144.64.5][54016] -> [...153.98.28.78][..443] detected: [....17] [ip4][..udp] [...168.144.64.5][54016] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] - new: [....18] [ip4][..udp] [...168.144.64.5][51248] -> [..99.42.133.245][..443] + new: [....18] [ip4][..udp] [...168.144.64.5][51248] -> [..99.42.133.245][..443] detected: [....18] [ip4][..udp] [...168.144.64.5][51248] -> [..99.42.133.245][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gcp.gvt2.com] - new: [....19] [ip4][..udp] [...168.144.64.5][60896] -> [.45.228.175.189][..443] + new: [....19] [ip4][..udp] [...168.144.64.5][60896] -> [.45.228.175.189][..443] detected: [....19] [ip4][..udp] [...168.144.64.5][60896] -> [.45.228.175.189][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] update: [....17] [ip4][..udp] [...168.144.64.5][54016] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] [QUIC.YouTube][Unknown][Media][Fun] @@ -72,9 +72,9 @@ update: [....18] [ip4][..udp] [...168.144.64.5][51248] -> [..99.42.133.245][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] update: [....15] [ip4][..udp] [...168.144.64.5][51456] -> [102.194.207.179][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] + new: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] detected: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gvt2.com] - new: [....21] [ip4][..udp] [...168.144.64.5][56488] -> [..177.86.46.206][..443] + new: [....21] [ip4][..udp] [...168.144.64.5][56488] -> [..177.86.46.206][..443] detected: [....21] [ip4][..udp] [...168.144.64.5][56488] -> [..177.86.46.206][..443] [QUIC.YouTube][Unknown][Media][Fun][www.youtube.com] idle: [....11] [ip4][..udp] [...168.144.64.5][53431] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....10] [ip4][..udp] [...168.144.64.5][53404] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -86,13 +86,13 @@ update: [....19] [ip4][..udp] [...168.144.64.5][60896] -> [.45.228.175.189][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....18] [ip4][..udp] [...168.144.64.5][51248] -> [..99.42.133.245][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....15] [ip4][..udp] [...168.144.64.5][51456] -> [102.194.207.179][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....22] [ip4][..udp] [...168.144.64.5][49153] -> [...153.98.28.78][..443] + new: [....22] [ip4][..udp] [...168.144.64.5][49153] -> [...153.98.28.78][..443] detected: [....22] [ip4][..udp] [...168.144.64.5][49153] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] idle: [....12] [ip4][..udp] [...168.144.64.5][50482] -> [121.209.126.161][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....13] [ip4][..udp] [...168.144.64.5][62652] -> [.158.146.215.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] idle: [....14] [ip4][..udp] [...168.144.64.5][63136] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] - new: [....23] [ip4][..udp] [...168.144.64.5][51296] -> [...128.248.24.1][..443] + new: [....23] [ip4][..udp] [...168.144.64.5][51296] -> [...128.248.24.1][..443] detected: [....23] [ip4][..udp] [...168.144.64.5][51296] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gcp.gvt2.com] idle: [....17] [ip4][..udp] [...168.144.64.5][54016] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] idle: [....16] [ip4][..udp] [...168.144.64.5][63163] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -102,77 +102,77 @@ update: [....22] [ip4][..udp] [...168.144.64.5][49153] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....21] [ip4][..udp] [...168.144.64.5][56488] -> [..177.86.46.206][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] - new: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] + new: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] detected: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] [QUIC.YouTube][Unknown][Media][Fun][r11---sn-vh5ouxa-hjuk.googlevideo.com] idle: [....23] [ip4][..udp] [...168.144.64.5][51296] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....19] [ip4][..udp] [...168.144.64.5][60896] -> [.45.228.175.189][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....22] [ip4][..udp] [...168.144.64.5][49153] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] idle: [....21] [ip4][..udp] [...168.144.64.5][56488] -> [..177.86.46.206][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....20] [ip4][..udp] [...168.144.64.5][60551] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] - new: [....25] [ip4][..udp] [...168.144.64.5][63736] -> [.213.188.47.247][..443] + new: [....25] [ip4][..udp] [...168.144.64.5][63736] -> [.213.188.47.247][..443] detected: [....25] [ip4][..udp] [...168.144.64.5][63736] -> [.213.188.47.247][..443] [QUIC.YouTube][Unknown][Media][Fun][r4---sn-vh5ouxa-hjud.googlevideo.com] - new: [....26] [ip4][..udp] [...168.144.64.5][52273] -> [244.214.160.219][..443] + new: [....26] [ip4][..udp] [...168.144.64.5][52273] -> [244.214.160.219][..443] detected: [....26] [ip4][..udp] [...168.144.64.5][52273] -> [244.214.160.219][..443] [QUIC.YouTube][Unknown][Media][Fun][r3---sn-vh5ouxa-hju6.googlevideo.com] - new: [....27] [ip4][..udp] [...168.144.64.5][49324] -> [..35.194.157.47][..443] + new: [....27] [ip4][..udp] [...168.144.64.5][49324] -> [..35.194.157.47][..443] detected: [....27] [ip4][..udp] [...168.144.64.5][49324] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable][pagead2.googlesyndication.com] update: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] [QUIC.YouTube][Unknown][Media][Fun] DAEMON-EVENT: [Processed: 38 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 27|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [....28] [ip4][..udp] [...168.144.64.5][62047] -> [..136.125.67.96][..443] + new: [....28] [ip4][..udp] [...168.144.64.5][62047] -> [..136.125.67.96][..443] detected: [....28] [ip4][..udp] [...168.144.64.5][62047] -> [..136.125.67.96][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons4.gvt2.com] update: [....25] [ip4][..udp] [...168.144.64.5][63736] -> [.213.188.47.247][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....27] [ip4][..udp] [...168.144.64.5][49324] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] update: [....26] [ip4][..udp] [...168.144.64.5][52273] -> [244.214.160.219][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] + new: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] detected: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] [QUIC.YouTube][Unknown][Media][Fun][r1---sn-hju7enel.googlevideo.com] idle: [....25] [ip4][..udp] [...168.144.64.5][63736] -> [.213.188.47.247][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....28] [ip4][..udp] [...168.144.64.5][62047] -> [..136.125.67.96][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....27] [ip4][..udp] [...168.144.64.5][49324] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] idle: [....26] [ip4][..udp] [...168.144.64.5][52273] -> [244.214.160.219][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....24] [ip4][..udp] [...168.144.64.5][57767] -> [....76.83.40.87][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] + new: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] detected: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable][www.googleadservices.com] - new: [....31] [ip4][..udp] [...168.144.64.5][50540] -> [...99.45.60.254][..443] + new: [....31] [ip4][..udp] [...168.144.64.5][50540] -> [...99.45.60.254][..443] detected: [....31] [ip4][..udp] [...168.144.64.5][50540] -> [...99.45.60.254][..443] [QUIC.YouTube][Unknown][Media][Fun][i.ytimg.com] update: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] DAEMON-EVENT: [Processed: 42 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 31|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 38] - new: [....32] [ip4][..udp] [...168.144.64.5][60809] -> [...9.65.169.252][..443] + new: [....32] [ip4][..udp] [...168.144.64.5][60809] -> [...9.65.169.252][..443] detected: [....32] [ip4][..udp] [...168.144.64.5][60809] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun][suggestqueries-clients6.youtube.com] update: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] update: [....31] [ip4][..udp] [...168.144.64.5][50540] -> [...99.45.60.254][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....33] [ip4][..udp] [...168.144.64.5][55637] -> [.169.81.163.225][..443] + new: [....33] [ip4][..udp] [...168.144.64.5][55637] -> [.169.81.163.225][..443] detected: [....33] [ip4][..udp] [...168.144.64.5][55637] -> [.169.81.163.225][..443] [QUIC.YouTube][Unknown][Media][Fun][r3---sn-hju7enel.googlevideo.com] - new: [....34] [ip4][..udp] [...168.144.64.5][53127] -> [113.250.137.243][..443] + new: [....34] [ip4][..udp] [...168.144.64.5][53127] -> [113.250.137.243][..443] detected: [....34] [ip4][..udp] [...168.144.64.5][53127] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable][b1.nel.goog] idle: [....29] [ip4][..udp] [...168.144.64.5][64976] -> [..220.80.126.73][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....30] [ip4][..udp] [...168.144.64.5][61209] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] idle: [....31] [ip4][..udp] [...168.144.64.5][50540] -> [...99.45.60.254][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....32] [ip4][..udp] [...168.144.64.5][60809] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....33] [ip4][..udp] [...168.144.64.5][55637] -> [.169.81.163.225][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] + new: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] detected: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] [QUIC.YouTube][Unknown][Media][Fun][r3---sn-vh5ouxa-hjud.googlevideo.com] idle: [....32] [ip4][..udp] [...168.144.64.5][60809] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....33] [ip4][..udp] [...168.144.64.5][55637] -> [.169.81.163.225][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....34] [ip4][..udp] [...168.144.64.5][53127] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] - new: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] + new: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] detected: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable][accounts.google.com] idle: [....34] [ip4][..udp] [...168.144.64.5][53127] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] update: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....37] [ip4][..udp] [.192.168.254.11][38331] -> [.93.100.151.221][..443] + new: [....37] [ip4][..udp] [.192.168.254.11][38331] -> [.93.100.151.221][..443] detected: [....37] [ip4][..udp] [.192.168.254.11][38331] -> [.93.100.151.221][..443] [QUIC.DataSaver][Unknown][Web][Fun][litepages.googlezip.net] - new: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] + new: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] detected: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][content-autofill.googleapis.com] - new: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] + new: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] detected: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][optimizationguide-pa.googleapis.com] - new: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] + new: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] detected: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] [QUIC][Unknown][Web][Acceptable][www.freearabianporn.com] update: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....41] [ip4][..udp] [.192.168.254.11][35124] -> [..168.78.153.39][..443] + new: [....41] [ip4][..udp] [.192.168.254.11][35124] -> [..168.78.153.39][..443] detected: [....41] [ip4][..udp] [.192.168.254.11][35124] -> [..168.78.153.39][..443] [QUIC][Unknown][Web][Acceptable][s-img.adskeeper.co.uk] idle: [....35] [ip4][..udp] [...168.144.64.5][50073] -> [.152.128.87.238][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -180,9 +180,9 @@ update: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] [QUIC][Unknown][Web][Acceptable] update: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....42] [ip4][..udp] [.192.168.254.11][51075] -> [.117.148.117.30][..443] + new: [....42] [ip4][..udp] [.192.168.254.11][51075] -> [.117.148.117.30][..443] detected: [....42] [ip4][..udp] [.192.168.254.11][51075] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][pagead2.googlesyndication.com] - new: [....43] [ip4][..udp] [.192.168.254.11][49689] -> [.87.179.155.149][..443] + new: [....43] [ip4][..udp] [.192.168.254.11][49689] -> [.87.179.155.149][..443] detected: [....43] [ip4][..udp] [.192.168.254.11][49689] -> [.87.179.155.149][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] idle: [....36] [ip4][..udp] [.192.168.254.11][59048] -> [.251.236.18.198][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -190,42 +190,42 @@ update: [....37] [ip4][..udp] [.192.168.254.11][38331] -> [.93.100.151.221][..443] [QUIC.DataSaver][Unknown][Web][Fun] update: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] [QUIC][Unknown][Web][Acceptable] update: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....44] [ip4][..udp] [...168.144.64.5][62818] -> [113.250.137.243][..443] + new: [....44] [ip4][..udp] [...168.144.64.5][62818] -> [113.250.137.243][..443] detected: [....44] [ip4][..udp] [...168.144.64.5][62818] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][clientservices.googleapis.com] idle: [....38] [ip4][..udp] [.192.168.254.11][45652] -> [.170.196.90.126][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] idle: [....37] [ip4][..udp] [.192.168.254.11][38331] -> [.93.100.151.221][..443] [QUIC.DataSaver][Unknown][Web][Fun] idle: [....39] [ip4][..udp] [.192.168.254.11][43427] -> [..98.251.203.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....45] [ip4][..udp] [...168.144.64.5][56425] -> [..125.136.204.4][..443] + new: [....45] [ip4][..udp] [...168.144.64.5][56425] -> [..125.136.204.4][..443] detected: [....45] [ip4][..udp] [...168.144.64.5][56425] -> [..125.136.204.4][..443] [QUIC.YouTube][Unknown][Media][Fun][r1---sn-vh5ouxa-hjuk.googlevideo.com] idle: [....40] [ip4][..udp] [.192.168.254.11][54692] -> [.171.182.169.23][..443] [QUIC][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 57 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 45|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [....46] [ip4][..udp] [...168.144.64.5][59622] -> [...153.98.28.78][..443] + new: [....46] [ip4][..udp] [...168.144.64.5][59622] -> [...153.98.28.78][..443] detected: [....46] [ip4][..udp] [...168.144.64.5][59622] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] idle: [....44] [ip4][..udp] [...168.144.64.5][62818] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] idle: [....41] [ip4][..udp] [.192.168.254.11][35124] -> [..168.78.153.39][..443] [QUIC][Unknown][Web][Acceptable] idle: [....42] [ip4][..udp] [.192.168.254.11][51075] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] idle: [....43] [ip4][..udp] [.192.168.254.11][49689] -> [.87.179.155.149][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....45] [ip4][..udp] [...168.144.64.5][56425] -> [..125.136.204.4][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] + new: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] detected: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gvt2.com] idle: [....45] [ip4][..udp] [...168.144.64.5][56425] -> [..125.136.204.4][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] + new: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] detected: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable][b1.nel.goog] - new: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] + new: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] detected: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] update: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] update: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....46] [ip4][..udp] [...168.144.64.5][59622] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] - new: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] + new: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] detected: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun][r9---sn-vh5ouxa-hjuk.googlevideo.com] - new: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] + new: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] detected: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable][b1.nel.goog] update: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] update: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....46] [ip4][..udp] [...168.144.64.5][59622] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] - new: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] + new: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] detected: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun][r9---sn-vh5ouxa-hjuk.googlevideo.com] idle: [....48] [ip4][..udp] [...168.144.64.5][56844] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] idle: [....47] [ip4][..udp] [...168.144.64.5][50552] -> [108.171.138.182][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -233,46 +233,46 @@ update: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] - new: [....53] [ip4][..udp] [...168.144.64.5][60936] -> [...9.65.169.252][..443] + new: [....53] [ip4][..udp] [...168.144.64.5][60936] -> [...9.65.169.252][..443] detected: [....53] [ip4][..udp] [...168.144.64.5][60936] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun][suggestqueries-clients6.youtube.com] update: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] update: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....54] [ip4][..udp] [...168.144.64.5][59965] -> [..22.12.150.194][..443] + new: [....54] [ip4][..udp] [...168.144.64.5][59965] -> [..22.12.150.194][..443] detected: [....54] [ip4][..udp] [...168.144.64.5][59965] -> [..22.12.150.194][..443] [QUIC.YouTube][Unknown][Media][Fun][r1---sn-vh5ouxa-hju6.googlevideo.com] idle: [....49] [ip4][..udp] [...168.144.64.5][58414] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] - new: [....55] [ip4][..udp] [...168.144.64.5][64693] -> [113.250.137.243][..443] + new: [....55] [ip4][..udp] [...168.144.64.5][64693] -> [113.250.137.243][..443] detected: [....55] [ip4][..udp] [...168.144.64.5][64693] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable][b1.nel.goog] idle: [....50] [ip4][..udp] [...168.144.64.5][61341] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....51] [ip4][..udp] [...168.144.64.5][56683] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] update: [....54] [ip4][..udp] [...168.144.64.5][59965] -> [..22.12.150.194][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....53] [ip4][..udp] [...168.144.64.5][60936] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] + new: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] detected: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][googleads.g.doubleclick.net] idle: [....54] [ip4][..udp] [...168.144.64.5][59965] -> [..22.12.150.194][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....53] [ip4][..udp] [...168.144.64.5][60936] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....55] [ip4][..udp] [...168.144.64.5][64693] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] idle: [....52] [ip4][..udp] [...168.144.64.5][64700] -> [.16.232.218.117][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] + new: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] detected: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] [QUIC.YouTube][Unknown][Media][Fun][r2---sn-vh5ouxa-hjuk.googlevideo.com] - new: [....58] [ip4][..udp] [...168.144.64.5][52387] -> [..143.52.137.18][..443] + new: [....58] [ip4][..udp] [...168.144.64.5][52387] -> [..143.52.137.18][..443] detected: [....58] [ip4][..udp] [...168.144.64.5][52387] -> [..143.52.137.18][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][pagead2.googlesyndication.com] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 58|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 75] - new: [....59] [ip4][..udp] [...168.144.64.5][49860] -> [113.250.137.243][..443] + new: [....59] [ip4][..udp] [...168.144.64.5][49860] -> [113.250.137.243][..443] detected: [....59] [ip4][..udp] [...168.144.64.5][49860] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable][b1.nel.goog] update: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] update: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....58] [ip4][..udp] [...168.144.64.5][52387] -> [..143.52.137.18][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....60] [ip4][..udp] [...168.144.64.5][60949] -> [185.186.183.185][..443] + new: [....60] [ip4][..udp] [...168.144.64.5][60949] -> [185.186.183.185][..443] detected: [....60] [ip4][..udp] [...168.144.64.5][60949] -> [185.186.183.185][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][content-autofill.googleapis.com] update: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] update: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] [QUIC.YouTube][Unknown][Media][Fun] update: [....58] [ip4][..udp] [...168.144.64.5][52387] -> [..143.52.137.18][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] update: [....59] [ip4][..udp] [...168.144.64.5][49860] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] - new: [....61] [ip4][..udp] [...168.144.64.5][57735] -> [..137.238.249.2][..443] + new: [....61] [ip4][..udp] [...168.144.64.5][57735] -> [..137.238.249.2][..443] detected: [....61] [ip4][..udp] [...168.144.64.5][57735] -> [..137.238.249.2][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][ade.googlesyndication.com] idle: [....56] [ip4][..udp] [...168.144.64.5][59680] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] idle: [....57] [ip4][..udp] [...168.144.64.5][57565] -> [217.254.108.174][..443] [QUIC.YouTube][Unknown][Media][Fun] @@ -281,65 +281,65 @@ idle: [....59] [ip4][..udp] [...168.144.64.5][49860] -> [113.250.137.243][..443] [QUIC.Google][Unknown][Cloud][Acceptable] DAEMON-EVENT: [Processed: 73 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 61|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 82] - new: [....62] [ip4][..udp] [..52.187.20.175][50588] -> [.208.229.157.81][..443] + new: [....62] [ip4][..udp] [..52.187.20.175][50588] -> [.208.229.157.81][..443] detected: [....62] [ip4][..udp] [..52.187.20.175][50588] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][update.googleapis.com] idle: [....61] [ip4][..udp] [...168.144.64.5][57735] -> [..137.238.249.2][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....63] [ip4][..udp] [..52.187.20.175][61089] -> [..99.42.133.245][..443] + new: [....63] [ip4][..udp] [..52.187.20.175][61089] -> [..99.42.133.245][..443] detected: [....63] [ip4][..udp] [..52.187.20.175][61089] -> [..99.42.133.245][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][clientservices.googleapis.com] update: [....62] [ip4][..udp] [..52.187.20.175][50588] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [....64] [ip4][..udp] [..52.187.20.175][49880] -> [.208.229.157.81][..443] + new: [....64] [ip4][..udp] [..52.187.20.175][49880] -> [.208.229.157.81][..443] detected: [....64] [ip4][..udp] [..52.187.20.175][49880] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][update.googleapis.com] DAEMON-EVENT: [Processed: 85 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 64|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 83] - new: [....65] [ip4][..udp] [159.117.176.124][58337] -> [.208.229.157.81][..443] + new: [....65] [ip4][..udp] [159.117.176.124][58337] -> [.208.229.157.81][..443] detected: [....65] [ip4][..udp] [159.117.176.124][58337] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][clientservices.googleapis.com] idle: [....62] [ip4][..udp] [..52.187.20.175][50588] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] idle: [....64] [ip4][..udp] [..52.187.20.175][49880] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] idle: [....63] [ip4][..udp] [..52.187.20.175][61089] -> [..99.42.133.245][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] DAEMON-EVENT: [Processed: 89 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 65|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 83] - new: [....66] [ip4][..udp] [159.117.176.124][49867] -> [...198.74.29.79][..443] + new: [....66] [ip4][..udp] [159.117.176.124][49867] -> [...198.74.29.79][..443] detected: [....66] [ip4][..udp] [159.117.176.124][49867] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][content-autofill.googleapis.com] idle: [....65] [ip4][..udp] [159.117.176.124][58337] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 93 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 66|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 83] - new: [....67] [ip4][..udp] [..52.187.20.175][58123] -> [..118.89.218.46][..443] + new: [....67] [ip4][..udp] [..52.187.20.175][58123] -> [..118.89.218.46][..443] detected: [....67] [ip4][..udp] [..52.187.20.175][58123] -> [..118.89.218.46][..443] [QUIC.Google][Tencent][Web][Acceptable][accounts.google.com] - new: [....68] [ip4][..udp] [..52.187.20.175][63507] -> [121.209.126.161][..443] + new: [....68] [ip4][..udp] [..52.187.20.175][63507] -> [121.209.126.161][..443] detected: [....68] [ip4][..udp] [..52.187.20.175][63507] -> [121.209.126.161][..443] [QUIC.Google][Azure][Web][Acceptable][clients2.googleusercontent.com] idle: [....66] [ip4][..udp] [159.117.176.124][49867] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....69] [ip4][..udp] [..52.187.20.175][57066] -> [108.171.138.182][..443] + new: [....69] [ip4][..udp] [..52.187.20.175][57066] -> [108.171.138.182][..443] detected: [....69] [ip4][..udp] [..52.187.20.175][57066] -> [108.171.138.182][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][clientservices.googleapis.com] update: [....67] [ip4][..udp] [..52.187.20.175][58123] -> [..118.89.218.46][..443] [QUIC.Google][Tencent][Web][Acceptable] update: [....68] [ip4][..udp] [..52.187.20.175][63507] -> [121.209.126.161][..443] [QUIC.Google][Azure][Web][Acceptable] DAEMON-EVENT: [Processed: 102 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 69|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 85] - new: [....70] [ip4][..udp] [..52.187.20.175][52512] -> [..196.245.61.64][..443] + new: [....70] [ip4][..udp] [..52.187.20.175][52512] -> [..196.245.61.64][..443] detected: [....70] [ip4][..udp] [..52.187.20.175][52512] -> [..196.245.61.64][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][safebrowsing.googleapis.com] idle: [....67] [ip4][..udp] [..52.187.20.175][58123] -> [..118.89.218.46][..443] [QUIC.Google][Tencent][Web][Acceptable] idle: [....68] [ip4][..udp] [..52.187.20.175][63507] -> [121.209.126.161][..443] [QUIC.Google][Azure][Web][Acceptable] idle: [....69] [ip4][..udp] [..52.187.20.175][57066] -> [108.171.138.182][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] DAEMON-EVENT: [Processed: 106 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 70|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 85] - new: [....71] [ip4][..udp] [..52.187.20.175][51619] -> [.208.229.157.81][..443] + new: [....71] [ip4][..udp] [..52.187.20.175][51619] -> [.208.229.157.81][..443] detected: [....71] [ip4][..udp] [..52.187.20.175][51619] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][clientservices.googleapis.com] idle: [....70] [ip4][..udp] [..52.187.20.175][52512] -> [..196.245.61.64][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] DAEMON-EVENT: [Processed: 110 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 71|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 85] - new: [....72] [ip4][..udp] [...168.144.64.5][58703] -> [.93.100.151.221][..443] + new: [....72] [ip4][..udp] [...168.144.64.5][58703] -> [.93.100.151.221][..443] detected: [....72] [ip4][..udp] [...168.144.64.5][58703] -> [.93.100.151.221][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe][android.clients.google.com] - new: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] + new: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] detected: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][fonts.gstatic.com] - new: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] + new: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] detected: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Web][Acceptable][adservice.google.com] - new: [....75] [ip4][..udp] [...168.144.64.5][65391] -> [...128.248.24.1][..443] + new: [....75] [ip4][..udp] [...168.144.64.5][65391] -> [...128.248.24.1][..443] detected: [....75] [ip4][..udp] [...168.144.64.5][65391] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][fonts.gstatic.com] - new: [....76] [ip4][..udp] [...168.144.64.5][58832] -> [.117.148.117.30][..443] + new: [....76] [ip4][..udp] [...168.144.64.5][58832] -> [.117.148.117.30][..443] detected: [....76] [ip4][..udp] [...168.144.64.5][58832] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][googleads.g.doubleclick.net] - new: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] + new: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] detected: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][static.doubleclick.net] idle: [....71] [ip4][..udp] [..52.187.20.175][51619] -> [.208.229.157.81][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] + new: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] detected: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][clientservices.googleapis.com] update: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....75] [ip4][..udp] [...168.144.64.5][65391] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -347,13 +347,13 @@ update: [....76] [ip4][..udp] [...168.144.64.5][58832] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] update: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] + new: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] detected: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gcp.gvt2.com] - new: [....80] [ip4][..udp] [...168.144.64.5][59785] -> [...128.248.24.1][..443] + new: [....80] [ip4][..udp] [...168.144.64.5][59785] -> [...128.248.24.1][..443] detected: [....80] [ip4][..udp] [...168.144.64.5][59785] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gcp.gvt2.com] - new: [....81] [ip4][..udp] [...168.144.64.5][59327] -> [...153.98.28.78][..443] + new: [....81] [ip4][..udp] [...168.144.64.5][59327] -> [...153.98.28.78][..443] detected: [....81] [ip4][..udp] [...168.144.64.5][59327] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] - new: [....82] [ip4][..udp] [...168.144.64.5][63925] -> [...39.227.72.32][..443] + new: [....82] [ip4][..udp] [...168.144.64.5][63925] -> [...39.227.72.32][..443] detected: [....82] [ip4][..udp] [...168.144.64.5][63925] -> [...39.227.72.32][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons2.gvt2.com] update: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -363,11 +363,11 @@ update: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] update: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....83] [ip4][..udp] [...168.144.64.5][49926] -> [.103.179.40.184][..443] + new: [....83] [ip4][..udp] [...168.144.64.5][49926] -> [.103.179.40.184][..443] detected: [....83] [ip4][..udp] [...168.144.64.5][49926] -> [.103.179.40.184][..443] [QUIC.YouTube][Unknown][Media][Fun][r5---sn-vh5ouxa-hju6.googlevideo.com] - new: [....84] [ip4][..udp] [...168.144.64.5][56384] -> [.117.148.117.30][..443] + new: [....84] [ip4][..udp] [...168.144.64.5][56384] -> [.117.148.117.30][..443] detected: [....84] [ip4][..udp] [...168.144.64.5][56384] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][pagead2.googlesyndication.com] - new: [....85] [ip4][..udp] [...168.144.64.5][57398] -> [..137.238.249.2][..443] + new: [....85] [ip4][..udp] [...168.144.64.5][57398] -> [..137.238.249.2][..443] detected: [....85] [ip4][..udp] [...168.144.64.5][57398] -> [..137.238.249.2][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][www.googleadservices.com] update: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -380,7 +380,7 @@ update: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] update: [....82] [ip4][..udp] [...168.144.64.5][63925] -> [...39.227.72.32][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....86] [ip4][..udp] [...168.144.64.5][64497] -> [102.194.207.179][..443] + new: [....86] [ip4][..udp] [...168.144.64.5][64497] -> [102.194.207.179][..443] detected: [....86] [ip4][..udp] [...168.144.64.5][64497] -> [102.194.207.179][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gvt2.com] idle: [....73] [ip4][..udp] [...168.144.64.5][55066] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....75] [ip4][..udp] [...168.144.64.5][65391] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] @@ -388,11 +388,11 @@ idle: [....76] [ip4][..udp] [...168.144.64.5][58832] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] idle: [....74] [ip4][..udp] [...168.144.64.5][61886] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....77] [ip4][..udp] [...168.144.64.5][58429] -> [....38.57.8.121][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....87] [ip4][..udp] [...168.144.64.5][55572] -> [.117.148.117.30][..443] + new: [....87] [ip4][..udp] [...168.144.64.5][55572] -> [.117.148.117.30][..443] detected: [....87] [ip4][..udp] [...168.144.64.5][55572] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][googleads.g.doubleclick.net] - new: [....88] [ip4][..udp] [...168.144.64.5][58956] -> [...128.248.24.1][..443] + new: [....88] [ip4][..udp] [...168.144.64.5][58956] -> [...128.248.24.1][..443] detected: [....88] [ip4][..udp] [...168.144.64.5][58956] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons.gcp.gvt2.com] - new: [....89] [ip4][..udp] [...168.144.64.5][54449] -> [102.194.207.179][..443] + new: [....89] [ip4][..udp] [...168.144.64.5][54449] -> [102.194.207.179][..443] detected: [....89] [ip4][..udp] [...168.144.64.5][54449] -> [102.194.207.179][..443] [QUIC.Google][Unknown][Web][Acceptable][beacons3.gvt2.com] idle: [....79] [ip4][..udp] [...168.144.64.5][60934] -> [...128.248.24.1][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....78] [ip4][..udp] [...168.144.64.5][55479] -> [113.250.137.243][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -405,7 +405,7 @@ update: [....81] [ip4][..udp] [...168.144.64.5][59327] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] update: [....82] [ip4][..udp] [...168.144.64.5][63925] -> [...39.227.72.32][..443] [QUIC.Google][Unknown][Web][Acceptable] update: [....87] [ip4][..udp] [...168.144.64.5][55572] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [....90] [ip4][..udp] [...168.144.64.5][60342] -> [.93.100.151.221][..443] + new: [....90] [ip4][..udp] [...168.144.64.5][60342] -> [.93.100.151.221][..443] detected: [....90] [ip4][..udp] [...168.144.64.5][60342] -> [.93.100.151.221][..443] [QUIC.YouTube][Unknown][Media][Fun][suggestqueries-clients6.youtube.com] idle: [....86] [ip4][..udp] [...168.144.64.5][64497] -> [102.194.207.179][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [....83] [ip4][..udp] [...168.144.64.5][49926] -> [.103.179.40.184][..443] [QUIC.YouTube][Unknown][Media][Fun] @@ -419,84 +419,84 @@ idle: [....87] [ip4][..udp] [...168.144.64.5][55572] -> [.117.148.117.30][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] DAEMON-EVENT: [Processed: 129 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 90|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 119] - new: [....91] [ip4][..udp] [...168.144.64.5][65186] -> [...9.65.169.252][..443] + new: [....91] [ip4][..udp] [...168.144.64.5][65186] -> [...9.65.169.252][..443] detected: [....91] [ip4][..udp] [...168.144.64.5][65186] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun][www.youtube.com] idle: [....90] [ip4][..udp] [...168.144.64.5][60342] -> [.93.100.151.221][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....92] [ip4][..udp] [...168.144.64.5][52942] -> [.93.100.151.221][..443] + new: [....92] [ip4][..udp] [...168.144.64.5][52942] -> [.93.100.151.221][..443] detected: [....92] [ip4][..udp] [...168.144.64.5][52942] -> [.93.100.151.221][..443] [QUIC.Google][Unknown][Web][Acceptable][clients2.google.com] idle: [....91] [ip4][..udp] [...168.144.64.5][65186] -> [...9.65.169.252][..443] [QUIC.YouTube][Unknown][Media][Fun] - new: [....93] [ip4][..udp] [..52.187.20.175][62114] -> [...198.74.29.79][..443] + new: [....93] [ip4][..udp] [..52.187.20.175][62114] -> [...198.74.29.79][..443] detected: [....93] [ip4][..udp] [..52.187.20.175][62114] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][safebrowsing.googleapis.com] idle: [....92] [ip4][..udp] [...168.144.64.5][52942] -> [.93.100.151.221][..443] [QUIC.Google][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 135 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 93|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 119] - new: [....94] [ip4][..udp] [...168.144.64.5][55561] -> [..35.194.157.47][..443] + new: [....94] [ip4][..udp] [...168.144.64.5][55561] -> [..35.194.157.47][..443] detected: [....94] [ip4][..udp] [...168.144.64.5][55561] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable][googleads.g.doubleclick.net] idle: [....93] [ip4][..udp] [..52.187.20.175][62114] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [....95] [ip4][..udp] [159.117.176.124][61202] -> [...198.74.29.79][..443] + new: [....95] [ip4][..udp] [159.117.176.124][61202] -> [...198.74.29.79][..443] detected: [....95] [ip4][..udp] [159.117.176.124][61202] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][safebrowsing.googleapis.com] idle: [....94] [ip4][..udp] [...168.144.64.5][55561] -> [..35.194.157.47][..443] [QUIC.GoogleCloud][GoogleCloud][Advertisement][Acceptable] DAEMON-EVENT: [Processed: 140 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 95|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 119] - new: [....96] [ip4][..udp] [159.117.176.124][49521] -> [...128.248.24.1][..443] + new: [....96] [ip4][..udp] [159.117.176.124][49521] -> [...128.248.24.1][..443] detected: [....96] [ip4][..udp] [159.117.176.124][49521] -> [...128.248.24.1][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][clientservices.googleapis.com] update: [....95] [ip4][..udp] [159.117.176.124][61202] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 144 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 96|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 120] - new: [....97] [ip4][..udp] [...168.144.64.5][49217] -> [185.186.183.185][..443] + new: [....97] [ip4][..udp] [...168.144.64.5][49217] -> [185.186.183.185][..443] detected: [....97] [ip4][..udp] [...168.144.64.5][49217] -> [185.186.183.185][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][safebrowsing.googleapis.com] idle: [....95] [ip4][..udp] [159.117.176.124][61202] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] idle: [....96] [ip4][..udp] [159.117.176.124][49521] -> [...128.248.24.1][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] - new: [....98] [ip4][..udp] [..52.187.20.175][61286] -> [...198.74.29.79][..443] + new: [....98] [ip4][..udp] [..52.187.20.175][61286] -> [...198.74.29.79][..443] detected: [....98] [ip4][..udp] [..52.187.20.175][61286] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][safebrowsing.googleapis.com] update: [....97] [ip4][..udp] [...168.144.64.5][49217] -> [185.186.183.185][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 149 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 98|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 121] - new: [....99] [ip4][..udp] [..52.187.20.175][53260] -> [102.194.207.179][..443] + new: [....99] [ip4][..udp] [..52.187.20.175][53260] -> [102.194.207.179][..443] detected: [....99] [ip4][..udp] [..52.187.20.175][53260] -> [102.194.207.179][..443] [QUIC.GoogleServices][Azure][Web][Acceptable][clientservices.googleapis.com] idle: [....97] [ip4][..udp] [...168.144.64.5][49217] -> [185.186.183.185][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] idle: [....98] [ip4][..udp] [..52.187.20.175][61286] -> [...198.74.29.79][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [...100] [ip4][..udp] [...168.144.64.5][50023] -> [..76.231.104.92][..443] + new: [...100] [ip4][..udp] [...168.144.64.5][50023] -> [..76.231.104.92][..443] detected: [...100] [ip4][..udp] [...168.144.64.5][50023] -> [..76.231.104.92][..443] [QUIC.YouTube][Unknown][Media][Fun][www.youtube.com] update: [....99] [ip4][..udp] [..52.187.20.175][53260] -> [102.194.207.179][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [...101] [ip4][..udp] [...168.144.64.5][65360] -> [....65.33.51.74][..443] + new: [...101] [ip4][..udp] [...168.144.64.5][65360] -> [....65.33.51.74][..443] detected: [...101] [ip4][..udp] [...168.144.64.5][65360] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Advertisement][Acceptable][googleads.g.doubleclick.net] idle: [...100] [ip4][..udp] [...168.144.64.5][50023] -> [..76.231.104.92][..443] [QUIC.YouTube][Unknown][Media][Fun] idle: [....99] [ip4][..udp] [..52.187.20.175][53260] -> [102.194.207.179][..443] [QUIC.GoogleServices][Azure][Web][Acceptable] - new: [...102] [ip4][..udp] [159.117.176.124][64134] -> [..207.121.63.92][..443] + new: [...102] [ip4][..udp] [159.117.176.124][64134] -> [..207.121.63.92][..443] detected: [...102] [ip4][..udp] [159.117.176.124][64134] -> [..207.121.63.92][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] - new: [...103] [ip4][..udp] [..52.187.20.175][61484] -> [202.152.155.121][..443] + new: [...103] [ip4][..udp] [..52.187.20.175][61484] -> [202.152.155.121][..443] detected: [...103] [ip4][..udp] [..52.187.20.175][61484] -> [202.152.155.121][..443] [QUIC.Google][Azure][Web][Acceptable][ogs.google.com] update: [...101] [ip4][..udp] [...168.144.64.5][65360] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] - new: [...104] [ip4][..udp] [159.117.176.124][51856] -> [.16.205.123.234][..443] + new: [...104] [ip4][..udp] [159.117.176.124][51856] -> [.16.205.123.234][..443] detected: [...104] [ip4][..udp] [159.117.176.124][51856] -> [.16.205.123.234][..443] [QUIC.WhatsAppFiles][Unknown][Download][Acceptable][media.fmct2-1.fna.whatsapp.net] idle: [...101] [ip4][..udp] [...168.144.64.5][65360] -> [....65.33.51.74][..443] [QUIC.Google][Unknown][Advertisement][Acceptable] DAEMON-EVENT: [Processed: 164 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 104|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 123] - new: [...105] [ip4][..udp] [...168.144.64.5][54120] -> [...153.98.28.78][..443] + new: [...105] [ip4][..udp] [...168.144.64.5][54120] -> [...153.98.28.78][..443] detected: [...105] [ip4][..udp] [...168.144.64.5][54120] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] idle: [...102] [ip4][..udp] [159.117.176.124][64134] -> [..207.121.63.92][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [...103] [ip4][..udp] [..52.187.20.175][61484] -> [202.152.155.121][..443] [QUIC.Google][Azure][Web][Acceptable] idle: [...104] [ip4][..udp] [159.117.176.124][51856] -> [.16.205.123.234][..443] [QUIC.WhatsAppFiles][Unknown][Download][Acceptable] DAEMON-EVENT: [Processed: 165 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 105|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 123] - new: [...106] [ip4][..udp] [...168.144.64.5][52396] -> [...153.98.28.78][..443] + new: [...106] [ip4][..udp] [...168.144.64.5][52396] -> [...153.98.28.78][..443] detected: [...106] [ip4][..udp] [...168.144.64.5][52396] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable][dns.google] idle: [...105] [ip4][..udp] [...168.144.64.5][54120] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 166 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 106|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 123] - new: [...107] [ip4][..udp] [...168.144.64.5][50224] -> [....126.3.93.89][..443] + new: [...107] [ip4][..udp] [...168.144.64.5][50224] -> [....126.3.93.89][..443] detected: [...107] [ip4][..udp] [...168.144.64.5][50224] -> [....126.3.93.89][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][www.googleapis.com] - new: [...108] [ip4][..udp] [...168.144.64.5][62719] -> [..31.219.210.96][..443] + new: [...108] [ip4][..udp] [...168.144.64.5][62719] -> [..31.219.210.96][..443] detected: [...108] [ip4][..udp] [...168.144.64.5][62719] -> [..31.219.210.96][..443] [QUIC.Google][Unknown][Web][Acceptable][lh4.googleusercontent.com] idle: [...106] [ip4][..udp] [...168.144.64.5][52396] -> [...153.98.28.78][..443] [QUIC.DoH_DoT][Unknown][Network][Acceptable] - new: [...109] [ip4][..udp] [...168.144.64.5][58351] -> [.193.68.169.100][..443] + new: [...109] [ip4][..udp] [...168.144.64.5][58351] -> [.193.68.169.100][..443] detected: [...109] [ip4][..udp] [...168.144.64.5][58351] -> [.193.68.169.100][..443] [QUIC.Google][Unknown][Web][Acceptable][www.gstatic.com] - new: [...110] [ip4][..udp] [...168.144.64.5][57319] -> [....7.71.118.27][..443] + new: [...110] [ip4][..udp] [...168.144.64.5][57319] -> [....7.71.118.27][..443] detected: [...110] [ip4][..udp] [...168.144.64.5][57319] -> [....7.71.118.27][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe][android.clients.google.com] - new: [...111] [ip4][..udp] [...168.144.64.5][60919] -> [.53.101.228.200][..443] + new: [...111] [ip4][..udp] [...168.144.64.5][60919] -> [.53.101.228.200][..443] detected: [...111] [ip4][..udp] [...168.144.64.5][60919] -> [.53.101.228.200][..443] [QUIC.Google][Unknown][Web][Acceptable][adservice.google.com] - new: [...112] [ip4][..udp] [...168.144.64.5][50423] -> [.144.237.113.58][..443] + new: [...112] [ip4][..udp] [...168.144.64.5][50423] -> [.144.237.113.58][..443] detected: [...112] [ip4][..udp] [...168.144.64.5][50423] -> [.144.237.113.58][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] idle: [...110] [ip4][..udp] [...168.144.64.5][57319] -> [....7.71.118.27][..443] [QUIC.PlayStore][Unknown][SoftwareUpdate][Safe] idle: [...107] [ip4][..udp] [...168.144.64.5][50224] -> [....126.3.93.89][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] @@ -505,7 +505,7 @@ idle: [...111] [ip4][..udp] [...168.144.64.5][60919] -> [.53.101.228.200][..443] [QUIC.Google][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 178 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 112|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 123] - new: [...113] [ip4][..udp] [...168.144.64.5][59206] -> [..76.231.104.92][..443] + new: [...113] [ip4][..udp] [...168.144.64.5][59206] -> [..76.231.104.92][..443] detected: [...113] [ip4][..udp] [...168.144.64.5][59206] -> [..76.231.104.92][..443] [QUIC.Google][Unknown][Web][Acceptable][ogs.google.com] idle: [...113] [ip4][..udp] [...168.144.64.5][59206] -> [..76.231.104.92][..443] [QUIC.Google][Unknown][Web][Acceptable] idle: [...112] [ip4][..udp] [...168.144.64.5][50423] -> [.144.237.113.58][..443] [QUIC.Google][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/quic_interop_V.pcapng.out b/test/results/flow-info/default/quic_interop_V.pcapng.out index 03d43313f..f63a5f7e4 100644 --- a/test/results/flow-info/default/quic_interop_V.pcapng.out +++ b/test/results/flow-info/default/quic_interop_V.pcapng.out @@ -1,226 +1,226 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38077] -> [.........2400:8902::f03c:91ff:fe69:a454][..443] + new: [.....1] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38077] -> [.........2400:8902::f03c:91ff:fe69:a454][..443] detected: [.....1] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38077] -> [.........2400:8902::f03c:91ff:fe69:a454][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....2] [ip4][..udp] [..192.168.1.128][37643] -> [..71.202.41.169][..443] + new: [.....2] [ip4][..udp] [..192.168.1.128][37643] -> [..71.202.41.169][..443] detected: [.....2] [ip4][..udp] [..192.168.1.128][37643] -> [..71.202.41.169][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....3] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][37876] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][..443] + new: [.....3] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][37876] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][..443] detected: [.....3] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][37876] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][..443] [QUIC][AmazonAWS][Web][Acceptable] - new: [.....4] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][34442] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][..443] + new: [.....4] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][34442] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][..443] detected: [.....4] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][34442] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....5] [ip4][..udp] [..192.168.1.128][47010] -> [...3.121.242.54][..443] + new: [.....5] [ip4][..udp] [..192.168.1.128][47010] -> [...3.121.242.54][..443] detected: [.....5] [ip4][..udp] [..192.168.1.128][47010] -> [...3.121.242.54][..443] [QUIC][AmazonAWS][Web][Acceptable] - new: [.....6] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][48707] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][..443] + new: [.....6] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][48707] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][..443] detected: [.....6] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][48707] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....7] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60346] -> [..................2001:bc8:47a4:1c25::1][..443] + new: [.....7] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60346] -> [..................2001:bc8:47a4:1c25::1][..443] detected: [.....7] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60346] -> [..................2001:bc8:47a4:1c25::1][..443] [QUIC][Unknown][Web][Acceptable] - new: [.....8] [ip4][..udp] [..192.168.1.128][46576] -> [..40.112.191.60][.4433] + new: [.....8] [ip4][..udp] [..192.168.1.128][46576] -> [..40.112.191.60][.4433] detected: [.....8] [ip4][..udp] [..192.168.1.128][46576] -> [..40.112.191.60][.4433] [QUIC][Azure][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [.....9] [ip4][..udp] [..192.168.1.128][46334] -> [..40.112.191.60][..443] + new: [.....9] [ip4][..udp] [..192.168.1.128][46334] -> [..40.112.191.60][..443] detected: [.....9] [ip4][..udp] [..192.168.1.128][46334] -> [..40.112.191.60][..443] [QUIC][Azure][Web][Acceptable] - new: [....10] [ip4][..udp] [..192.168.1.128][38366] -> [.202.238.220.92][.4433] + new: [....10] [ip4][..udp] [..192.168.1.128][38366] -> [.202.238.220.92][.4433] detected: [....10] [ip4][..udp] [..192.168.1.128][38366] -> [.202.238.220.92][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....11] [ip4][.icmp] [...3.121.242.54] -> [..192.168.1.128] + new: [....11] [ip4][.icmp] [...3.121.242.54] -> [..192.168.1.128] detected: [....11] [ip4][.icmp] [...3.121.242.54] -> [..192.168.1.128] [ICMP][AmazonAWS][Network][Acceptable] RISK: Susp Entropy - new: [....12] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][32957] -> [.................2606:4700:10::6816:826][.4433] + new: [....12] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][32957] -> [.................2606:4700:10::6816:826][.4433] detected: [....12] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][32957] -> [.................2606:4700:10::6816:826][.4433] [QUIC][Cloudflare][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....13] [ip4][..udp] [..192.168.1.128][60784] -> [...3.121.242.54][.4433] + new: [....13] [ip4][..udp] [..192.168.1.128][60784] -> [...3.121.242.54][.4433] detected: [....13] [ip4][..udp] [..192.168.1.128][60784] -> [...3.121.242.54][.4433] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....14] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51185] -> [..................2001:bc8:47a4:1c25::1][.4433] + new: [....14] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51185] -> [..................2001:bc8:47a4:1c25::1][.4433] detected: [....14] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51185] -> [..................2001:bc8:47a4:1c25::1][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....15] [ip4][..udp] [..192.168.1.128][34511] -> [.131.159.24.198][..443] + new: [....15] [ip4][..udp] [..192.168.1.128][34511] -> [.131.159.24.198][..443] detected: [....15] [ip4][..udp] [..192.168.1.128][34511] -> [.131.159.24.198][..443] [QUIC][Unknown][Web][Acceptable] - new: [....16] [ip4][..udp] [..192.168.1.128][51887] -> [..51.158.105.98][..443] + new: [....16] [ip4][..udp] [..192.168.1.128][51887] -> [..51.158.105.98][..443] detected: [....16] [ip4][..udp] [..192.168.1.128][51887] -> [..51.158.105.98][..443] [QUIC][Unknown][Web][Acceptable] - new: [....17] [ip4][..udp] [..192.168.1.128][43475] -> [..18.189.84.245][.4433] + new: [....17] [ip4][..udp] [..192.168.1.128][43475] -> [..18.189.84.245][.4433] detected: [....17] [ip4][..udp] [..192.168.1.128][43475] -> [..18.189.84.245][.4433] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....18] [ip4][..udp] [..192.168.1.128][49151] -> [133.242.206.244][.4433] + new: [....18] [ip4][..udp] [..192.168.1.128][49151] -> [133.242.206.244][.4433] detected: [....18] [ip4][..udp] [..192.168.1.128][49151] -> [133.242.206.244][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....19] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39945] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4433] + new: [....19] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39945] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4433] detected: [....19] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39945] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4433] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....20] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39624] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][..443] + new: [....20] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39624] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][..443] detected: [....20] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][39624] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][..443] [QUIC][Unknown][Web][Acceptable] - new: [....21] [ip4][..udp] [..192.168.1.128][59171] -> [..193.190.10.98][.4433] + new: [....21] [ip4][..udp] [..192.168.1.128][59171] -> [..193.190.10.98][.4433] detected: [....21] [ip4][..udp] [..192.168.1.128][59171] -> [..193.190.10.98][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....22] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][35643] -> [......................2001:19f0:4:34::1][.4433] + new: [....22] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][35643] -> [......................2001:19f0:4:34::1][.4433] detected: [....22] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][35643] -> [......................2001:19f0:4:34::1][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....23] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56213] -> [.........2400:8902::f03c:91ff:fe69:a454][.4433] + new: [....23] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56213] -> [.........2400:8902::f03c:91ff:fe69:a454][.4433] detected: [....23] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56213] -> [.........2400:8902::f03c:91ff:fe69:a454][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....24] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52080] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4434] + new: [....24] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52080] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4434] detected: [....24] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52080] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4434] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....25] [ip4][..udp] [..192.168.1.128][37661] -> [..71.202.41.169][.4433] + new: [....25] [ip4][..udp] [..192.168.1.128][37661] -> [..71.202.41.169][.4433] detected: [....25] [ip4][..udp] [..192.168.1.128][37661] -> [..71.202.41.169][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....26] [ip4][..udp] [..192.168.1.128][37784] -> [..140.227.52.92][..443] + new: [....26] [ip4][..udp] [..192.168.1.128][37784] -> [..140.227.52.92][..443] detected: [....26] [ip4][..udp] [..192.168.1.128][37784] -> [..140.227.52.92][..443] [QUIC][Unknown][Web][Acceptable] - new: [....27] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60983] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4433] + new: [....27] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60983] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4433] detected: [....27] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][60983] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....28] [ip4][..udp] [..192.168.1.128][49658] -> [..193.190.10.98][..443] + new: [....28] [ip4][..udp] [..192.168.1.128][49658] -> [..193.190.10.98][..443] detected: [....28] [ip4][..udp] [..192.168.1.128][49658] -> [..193.190.10.98][..443] [QUIC][Unknown][Web][Acceptable] - new: [....29] [ip4][..udp] [..192.168.1.128][41587] -> [.131.159.24.198][.4433] + new: [....29] [ip4][..udp] [..192.168.1.128][41587] -> [.131.159.24.198][.4433] detected: [....29] [ip4][..udp] [..192.168.1.128][41587] -> [.131.159.24.198][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....30] [ip4][.icmp] [..51.158.105.98] -> [..192.168.1.128] + new: [....30] [ip4][.icmp] [..51.158.105.98] -> [..192.168.1.128] detected: [....30] [ip4][.icmp] [..51.158.105.98] -> [..192.168.1.128] [ICMP][Unknown][Network][Acceptable] RISK: Susp Entropy - new: [....31] [ip4][..udp] [..192.168.1.128][38933] -> [.202.238.220.92][..443] + new: [....31] [ip4][..udp] [..192.168.1.128][38933] -> [.202.238.220.92][..443] detected: [....31] [ip4][..udp] [..192.168.1.128][38933] -> [.202.238.220.92][..443] [QUIC][Unknown][Web][Acceptable] - new: [....32] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52271] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4434] + new: [....32] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52271] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4434] detected: [....32] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][52271] -> [..2a00:ac00:4000:400:2e0:4cff:fe68:199d][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....33] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51040] -> [............2604:a880:800:a1::1279:3001][.4433] + new: [....33] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51040] -> [............2604:a880:800:a1::1279:3001][.4433] detected: [....33] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][51040] -> [............2604:a880:800:a1::1279:3001][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....34] [ip4][.icmp] [.131.159.24.198] -> [..192.168.1.128] + new: [....34] [ip4][.icmp] [.131.159.24.198] -> [..192.168.1.128] detected: [....34] [ip4][.icmp] [.131.159.24.198] -> [..192.168.1.128] [ICMP][Unknown][Network][Acceptable] RISK: Susp Entropy - new: [....35] [ip4][..udp] [..192.168.1.128][45250] -> [..51.158.105.98][.4433] + new: [....35] [ip4][..udp] [..192.168.1.128][45250] -> [..51.158.105.98][.4433] detected: [....35] [ip4][..udp] [..192.168.1.128][45250] -> [..51.158.105.98][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....36] [ip4][..udp] [..192.168.1.128][42456] -> [133.242.206.244][..443] + new: [....36] [ip4][..udp] [..192.168.1.128][42456] -> [133.242.206.244][..443] detected: [....36] [ip4][..udp] [..192.168.1.128][42456] -> [133.242.206.244][..443] [QUIC][Unknown][Web][Acceptable] - new: [....37] [ip6][icmp6] [.2001:4800:7817:101:be76:4eff:fe04:631d] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] + new: [....37] [ip6][icmp6] [.2001:4800:7817:101:be76:4eff:fe04:631d] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] detected: [....37] [ip6][icmp6] [.2001:4800:7817:101:be76:4eff:fe04:631d] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] [ICMPV6][Unknown][Network][Acceptable] - new: [....38] [ip4][..udp] [..192.168.1.128][50289] -> [..71.202.41.169][.4434] + new: [....38] [ip4][..udp] [..192.168.1.128][50289] -> [..71.202.41.169][.4434] detected: [....38] [ip4][..udp] [..192.168.1.128][50289] -> [..71.202.41.169][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....39] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49270] -> [..................2001:bc8:47a4:1c25::1][.4434] + new: [....39] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49270] -> [..................2001:bc8:47a4:1c25::1][.4434] detected: [....39] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49270] -> [..................2001:bc8:47a4:1c25::1][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....40] [ip4][..udp] [..192.168.1.128][34903] -> [..18.189.84.245][..443] + new: [....40] [ip4][..udp] [..192.168.1.128][34903] -> [..18.189.84.245][..443] detected: [....40] [ip4][..udp] [..192.168.1.128][34903] -> [..18.189.84.245][..443] [QUIC][AmazonAWS][Web][Acceptable] - new: [....41] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][45852] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4433] + new: [....41] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][45852] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4433] detected: [....41] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][45852] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....42] [ip4][..udp] [..192.168.1.128][45855] -> [133.242.206.244][.4434] + new: [....42] [ip4][..udp] [..192.168.1.128][45855] -> [133.242.206.244][.4434] detected: [....42] [ip4][..udp] [..192.168.1.128][45855] -> [133.242.206.244][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38077] -> [.........2400:8902::f03c:91ff:fe69:a454][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - new: [....43] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46353] -> [.................2606:4700:10::6816:826][..443] + new: [....43] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46353] -> [.................2606:4700:10::6816:826][..443] detected: [....43] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46353] -> [.................2606:4700:10::6816:826][..443] [QUIC][Cloudflare][Web][Acceptable] - new: [....44] [ip4][..udp] [..192.168.1.128][53791] -> [..40.112.191.60][.4434] + new: [....44] [ip4][..udp] [..192.168.1.128][53791] -> [..40.112.191.60][.4434] detected: [....44] [ip4][..udp] [..192.168.1.128][53791] -> [..40.112.191.60][.4434] [QUIC][Azure][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....45] [ip4][..udp] [..192.168.1.128][59515] -> [..193.190.10.98][.4434] + new: [....45] [ip4][..udp] [..192.168.1.128][59515] -> [..193.190.10.98][.4434] detected: [....45] [ip4][..udp] [..192.168.1.128][59515] -> [..193.190.10.98][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....46] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49788] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4434] + new: [....46] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49788] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4434] detected: [....46] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][49788] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....47] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46242] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][..443] + new: [....47] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46242] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][..443] detected: [....47] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46242] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][..443] [QUIC][AmazonAWS][Web][Acceptable] - new: [....48] [ip4][..udp] [..192.168.1.128][44619] -> [..140.227.52.92][.4433] + new: [....48] [ip4][..udp] [..192.168.1.128][44619] -> [..140.227.52.92][.4433] detected: [....48] [ip4][..udp] [..192.168.1.128][44619] -> [..140.227.52.92][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....8] [ip4][..udp] [..192.168.1.128][46576] -> [..40.112.191.60][.4433] [QUIC][Azure][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....49] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44243] -> [......................2001:19f0:4:34::1][.4434] + new: [....49] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44243] -> [......................2001:19f0:4:34::1][.4434] detected: [....49] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44243] -> [......................2001:19f0:4:34::1][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....50] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38394] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4433] + new: [....50] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38394] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4433] detected: [....50] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38394] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][.4433] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....10] [ip4][..udp] [..192.168.1.128][38366] -> [.202.238.220.92][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....51] [ip6][icmp6] [.....2001:19f0:5:c21:5400:1ff:fe33:3b96] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] + new: [....51] [ip6][icmp6] [.....2001:19f0:5:c21:5400:1ff:fe33:3b96] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] detected: [....51] [ip6][icmp6] [.....2001:19f0:5:c21:5400:1ff:fe33:3b96] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] [ICMPV6][Unknown][Network][Acceptable] - new: [....52] [ip4][..udp] [..192.168.1.128][35263] -> [.202.238.220.92][.4434] + new: [....52] [ip4][..udp] [..192.168.1.128][35263] -> [.202.238.220.92][.4434] detected: [....52] [ip4][..udp] [..192.168.1.128][35263] -> [.202.238.220.92][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....12] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][32957] -> [.................2606:4700:10::6816:826][.4433] [QUIC][Cloudflare][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....53] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53760] -> [............2604:a880:800:a1::1279:3001][.4434] + new: [....53] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53760] -> [............2604:a880:800:a1::1279:3001][.4434] detected: [....53] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53760] -> [............2604:a880:800:a1::1279:3001][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....13] [ip4][..udp] [..192.168.1.128][60784] -> [...3.121.242.54][.4433] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....54] [ip4][..udp] [..192.168.1.128][54570] -> [..18.189.84.245][.4434] + new: [....54] [ip4][..udp] [..192.168.1.128][54570] -> [..18.189.84.245][.4434] detected: [....54] [ip4][..udp] [..192.168.1.128][54570] -> [..18.189.84.245][.4434] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....55] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44924] -> [.........2400:8902::f03c:91ff:fe69:a454][.4434] + new: [....55] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44924] -> [.........2400:8902::f03c:91ff:fe69:a454][.4434] detected: [....55] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44924] -> [.........2400:8902::f03c:91ff:fe69:a454][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....15] [ip4][..udp] [..192.168.1.128][34511] -> [.131.159.24.198][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - new: [....56] [ip4][..udp] [..192.168.1.128][39975] -> [.138.91.188.147][..443] + new: [....56] [ip4][..udp] [..192.168.1.128][39975] -> [.138.91.188.147][..443] detected: [....56] [ip4][..udp] [..192.168.1.128][39975] -> [.138.91.188.147][..443] [QUIC][Azure][Web][Acceptable] - new: [....57] [ip4][..udp] [..192.168.1.128][50705] -> [.138.91.188.147][.4434] + new: [....57] [ip4][..udp] [..192.168.1.128][50705] -> [.138.91.188.147][.4434] detected: [....57] [ip4][..udp] [..192.168.1.128][50705] -> [.138.91.188.147][.4434] [QUIC][Azure][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....58] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][41857] -> [.................2606:4700:10::6816:826][.4434] + new: [....58] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][41857] -> [.................2606:4700:10::6816:826][.4434] detected: [....58] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][41857] -> [.................2606:4700:10::6816:826][.4434] [QUIC][Cloudflare][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....59] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56073] -> [............2604:a880:800:a1::1279:3001][..443] + new: [....59] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56073] -> [............2604:a880:800:a1::1279:3001][..443] detected: [....59] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56073] -> [............2604:a880:800:a1::1279:3001][..443] [QUIC][Unknown][Web][Acceptable] - new: [....60] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][43645] -> [......................2001:19f0:4:34::1][..443] + new: [....60] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][43645] -> [......................2001:19f0:4:34::1][..443] detected: [....60] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][43645] -> [......................2001:19f0:4:34::1][..443] [QUIC][Unknown][Web][Acceptable] detection-update: [....21] [ip4][..udp] [..192.168.1.128][59171] -> [..193.190.10.98][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....61] [ip4][..udp] [..192.168.1.128][48644] -> [.131.159.24.198][.4434] + new: [....61] [ip4][..udp] [..192.168.1.128][48644] -> [.131.159.24.198][.4434] detected: [....61] [ip4][..udp] [..192.168.1.128][48644] -> [.131.159.24.198][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....62] [ip4][..udp] [..192.168.1.128][42468] -> [.138.91.188.147][.4433] + new: [....62] [ip4][..udp] [..192.168.1.128][42468] -> [.138.91.188.147][.4433] detected: [....62] [ip4][..udp] [..192.168.1.128][42468] -> [.138.91.188.147][.4433] [QUIC][Azure][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....23] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][56213] -> [.........2400:8902::f03c:91ff:fe69:a454][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....25] [ip4][..udp] [..192.168.1.128][37661] -> [..71.202.41.169][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....63] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38689] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4434] + new: [....63] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38689] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4434] detected: [....63] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][38689] -> [.....2001:19f0:5:c21:5400:1ff:fe33:3b96][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....2] [ip4][..udp] [..192.168.1.128][37643] -> [..71.202.41.169][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic detection-update: [....26] [ip4][..udp] [..192.168.1.128][37784] -> [..140.227.52.92][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - new: [....64] [ip4][..udp] [..192.168.1.128][53402] -> [...3.121.242.54][.4434] + new: [....64] [ip4][..udp] [..192.168.1.128][53402] -> [...3.121.242.54][.4434] detected: [....64] [ip4][..udp] [..192.168.1.128][53402] -> [...3.121.242.54][.4434] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....28] [ip4][..udp] [..192.168.1.128][49658] -> [..193.190.10.98][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - new: [....65] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53140] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4433] + new: [....65] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53140] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4433] detected: [....65] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][53140] -> [.2001:4800:7817:101:be76:4eff:fe04:631d][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port - new: [....66] [ip4][..udp] [..192.168.1.128][57926] -> [..140.227.52.92][.4434] + new: [....66] [ip4][..udp] [..192.168.1.128][57926] -> [..140.227.52.92][.4434] detected: [....66] [ip4][..udp] [..192.168.1.128][57926] -> [..140.227.52.92][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [.....9] [ip4][..udp] [..192.168.1.128][46334] -> [..40.112.191.60][..443] [QUIC][Azure][Web][Acceptable] RISK: Unidirectional Traffic detection-update: [....18] [ip4][..udp] [..192.168.1.128][49151] -> [133.242.206.244][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....67] [ip6][icmp6] [.........2400:8902::f03c:91ff:fe69:a454] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] + new: [....67] [ip6][icmp6] [.........2400:8902::f03c:91ff:fe69:a454] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] detected: [....67] [ip6][icmp6] [.........2400:8902::f03c:91ff:fe69:a454] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] [ICMPV6][Unknown][Network][Acceptable] - new: [....68] [ip6][icmp6] [......................2001:19f0:4:34::1] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] + new: [....68] [ip6][icmp6] [......................2001:19f0:4:34::1] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] detected: [....68] [ip6][icmp6] [......................2001:19f0:4:34::1] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] [ICMPV6][Unknown][Network][Acceptable] - new: [....69] [ip4][..udp] [..192.168.1.128][43735] -> [..51.158.105.98][.4434] + new: [....69] [ip4][..udp] [..192.168.1.128][43735] -> [..51.158.105.98][.4434] detected: [....69] [ip4][..udp] [..192.168.1.128][43735] -> [..51.158.105.98][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....31] [ip4][..udp] [..192.168.1.128][38933] -> [.202.238.220.92][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - new: [....70] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44605] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4434] + new: [....70] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44605] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4434] detected: [....70] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44605] -> [.2a05:d018:ce9:8100:cd2a:e2fd:b3be:c5ab][.4434] [QUIC][AmazonAWS][Web][Acceptable] RISK: Known Proto on Non Std Port detection-update: [....36] [ip4][..udp] [..192.168.1.128][42456] -> [133.242.206.244][..443] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic detection-update: [....38] [ip4][..udp] [..192.168.1.128][50289] -> [..71.202.41.169][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....71] [ip4][.icmp] [.202.238.220.92] -> [..192.168.1.128] + new: [....71] [ip4][.icmp] [.202.238.220.92] -> [..192.168.1.128] detected: [....71] [ip4][.icmp] [.202.238.220.92] -> [..192.168.1.128] [ICMP][Unknown][Network][Acceptable] RISK: Susp Entropy detection-update: [....42] [ip4][..udp] [..192.168.1.128][45855] -> [133.242.206.244][.4434] [QUIC][Unknown][Web][Acceptable] @@ -229,18 +229,18 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....45] [ip4][..udp] [..192.168.1.128][59515] -> [..193.190.10.98][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....72] [ip4][.icmp] [..18.189.84.245] -> [..192.168.1.128] + new: [....72] [ip4][.icmp] [..18.189.84.245] -> [..192.168.1.128] detected: [....72] [ip4][.icmp] [..18.189.84.245] -> [..192.168.1.128] [ICMP][AmazonAWS][Network][Acceptable] RISK: Susp Entropy detection-update: [....48] [ip4][..udp] [..192.168.1.128][44619] -> [..140.227.52.92][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....47] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][46242] -> [2600:1f18:2310:d230:5103:7d9e:7d75:374f][..443] [QUIC][AmazonAWS][Web][Acceptable] RISK: Unidirectional Traffic - new: [....73] [ip6][icmp6] [............2604:a880:800:a1::1279:3001] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] + new: [....73] [ip6][icmp6] [............2604:a880:800:a1::1279:3001] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] detected: [....73] [ip6][icmp6] [............2604:a880:800:a1::1279:3001] -> [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d] [ICMPV6][Unknown][Network][Acceptable] detection-update: [....52] [ip4][..udp] [..192.168.1.128][35263] -> [.202.238.220.92][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....74] [ip4][.icmp] [..192.168.1.128] -> [..40.112.191.60] + new: [....74] [ip4][.icmp] [..192.168.1.128] -> [..40.112.191.60] detected: [....74] [ip4][.icmp] [..192.168.1.128] -> [..40.112.191.60] [ICMP][Azure][Network][Acceptable] detection-update: [....55] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][44924] -> [.........2400:8902::f03c:91ff:fe69:a454][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic @@ -250,7 +250,7 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....58] [ip6][..udp] [..2001:b07:ac9:d5ae:a4d3:fe47:691e:807d][41857] -> [.................2606:4700:10::6816:826][.4434] [QUIC][Cloudflare][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....75] [ip4][.icmp] [133.242.206.244] -> [..192.168.1.128] + new: [....75] [ip4][.icmp] [133.242.206.244] -> [..192.168.1.128] detected: [....75] [ip4][.icmp] [133.242.206.244] -> [..192.168.1.128] [ICMP][Unknown][Network][Acceptable] RISK: Susp Entropy detection-update: [....62] [ip4][..udp] [..192.168.1.128][42468] -> [.138.91.188.147][.4433] [QUIC][Azure][Web][Acceptable] @@ -259,9 +259,9 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....66] [ip4][..udp] [..192.168.1.128][57926] -> [..140.227.52.92][.4434] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....76] [ip4][.icmp] [..192.168.1.128] -> [..140.227.52.92] + new: [....76] [ip4][.icmp] [..192.168.1.128] -> [..140.227.52.92] detected: [....76] [ip4][.icmp] [..192.168.1.128] -> [..140.227.52.92] [ICMP][Unknown][Network][Acceptable] - new: [....77] [ip4][.icmp] [..192.168.1.128] -> [.138.91.188.147] + new: [....77] [ip4][.icmp] [..192.168.1.128] -> [.138.91.188.147] detected: [....77] [ip4][.icmp] [..192.168.1.128] -> [.138.91.188.147] [ICMP][Azure][Network][Acceptable] idle: [....21] [ip4][..udp] [..192.168.1.128][59171] -> [..193.190.10.98][.4433] [QUIC][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic diff --git a/test/results/flow-info/default/quic_q39.pcap.out b/test/results/flow-info/default/quic_q39.pcap.out index 7ae575ecf..d0585a941 100644 --- a/test/results/flow-info/default/quic_q39.pcap.out +++ b/test/results/flow-info/default/quic_q39.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.170.216.16.209][38620] -> [.21.157.183.227][..443] + new: [.....1] [ip4][..udp] [.170.216.16.209][38620] -> [.21.157.183.227][..443] detected: [.....1] [ip4][..udp] [.170.216.16.209][38620] -> [.21.157.183.227][..443] [QUIC.YouTube][Unknown][Media][Fun][s.youtube.com] analyse: [.....1] [ip4][..udp] [.170.216.16.209][38620] -> [.21.157.183.227][..443] [QUIC.YouTube][Unknown][Media][Fun] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/quic_q43.pcap.out b/test/results/flow-info/default/quic_q43.pcap.out index 06bd013a5..309b28fad 100644 --- a/test/results/flow-info/default/quic_q43.pcap.out +++ b/test/results/flow-info/default/quic_q43.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..51.120.20.202][49241] -> [..72.119.217.29][..443] + new: [.....1] [ip4][..udp] [..51.120.20.202][49241] -> [..72.119.217.29][..443] detected: [.....1] [ip4][..udp] [..51.120.20.202][49241] -> [..72.119.217.29][..443] [QUIC.DoH_DoT][Azure][Network][Acceptable][dns.google.com] idle: [.....1] [ip4][..udp] [..51.120.20.202][49241] -> [..72.119.217.29][..443] [QUIC.DoH_DoT][Azure][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic_q46.pcap.out b/test/results/flow-info/default/quic_q46.pcap.out index b373260ee..74c7938a1 100644 --- a/test/results/flow-info/default/quic_q46.pcap.out +++ b/test/results/flow-info/default/quic_q46.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..172.29.42.236][38292] -> [.153.20.183.203][..443] + new: [.....1] [ip4][..udp] [..172.29.42.236][38292] -> [.153.20.183.203][..443] detected: [.....1] [ip4][..udp] [..172.29.42.236][38292] -> [.153.20.183.203][..443] [QUIC.Google][Unknown][Web][Acceptable][play.google.com] idle: [.....1] [ip4][..udp] [..172.29.42.236][38292] -> [.153.20.183.203][..443] [QUIC.Google][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic_q46_b.pcap.out b/test/results/flow-info/default/quic_q46_b.pcap.out index cec0f2b61..cae52f781 100644 --- a/test/results/flow-info/default/quic_q46_b.pcap.out +++ b/test/results/flow-info/default/quic_q46_b.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..172.27.69.216][45530] -> [.110.231.134.35][..443] + new: [.....1] [ip4][..udp] [..172.27.69.216][45530] -> [.110.231.134.35][..443] detected: [.....1] [ip4][..udp] [..172.27.69.216][45530] -> [.110.231.134.35][..443] [QUIC.YouTubeUpload][Unknown][Media][Fun][upload.youtube.com] idle: [.....1] [ip4][..udp] [..172.27.69.216][45530] -> [.110.231.134.35][..443] [QUIC.YouTubeUpload][Unknown][Media][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic_q50.pcap.out b/test/results/flow-info/default/quic_q50.pcap.out index 5afd952e3..ac8514cf7 100644 --- a/test/results/flow-info/default/quic_q50.pcap.out +++ b/test/results/flow-info/default/quic_q50.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [248.144.129.147][39203] -> [184.151.193.237][..443] + new: [.....1] [ip4][..udp] [248.144.129.147][39203] -> [184.151.193.237][..443] detected: [.....1] [ip4][..udp] [248.144.129.147][39203] -> [184.151.193.237][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][www.googletagmanager.com] idle: [.....1] [ip4][..udp] [248.144.129.147][39203] -> [184.151.193.237][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic_t50.pcap.out b/test/results/flow-info/default/quic_t50.pcap.out index 4983054af..523730fac 100644 --- a/test/results/flow-info/default/quic_t50.pcap.out +++ b/test/results/flow-info/default/quic_t50.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.40.154.127.200][49836] -> [166.240.188.209][..443] + new: [.....1] [ip4][..udp] [.40.154.127.200][49836] -> [166.240.188.209][..443] detected: [.....1] [ip4][..udp] [.40.154.127.200][49836] -> [166.240.188.209][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable][fonts.googleapis.com] idle: [.....1] [ip4][..udp] [.40.154.127.200][49836] -> [166.240.188.209][..443] [QUIC.GoogleServices][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quic_t51.pcap.out b/test/results/flow-info/default/quic_t51.pcap.out index 3eed957fd..dbdf04c0e 100644 --- a/test/results/flow-info/default/quic_t51.pcap.out +++ b/test/results/flow-info/default/quic_t51.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [187.227.136.152][55356] -> [.211.247.147.90][..443] + new: [.....1] [ip4][..udp] [187.227.136.152][55356] -> [.211.247.147.90][..443] detected: [.....1] [ip4][..udp] [187.227.136.152][55356] -> [.211.247.147.90][..443] [QUIC.Google][Unknown][Web][Acceptable][www.google.com] idle: [.....1] [ip4][..udp] [187.227.136.152][55356] -> [.211.247.147.90][..443] [QUIC.Google][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/quickplay.pcap.out b/test/results/flow-info/default/quickplay.pcap.out index 6468f968e..7870da8e6 100644 --- a/test/results/flow-info/default/quickplay.pcap.out +++ b/test/results/flow-info/default/quickplay.pcap.out @@ -1,30 +1,30 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..10.54.169.250][50668] -> [...120.28.35.41][...80] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..10.54.169.250][50668] -> [...120.28.35.41][...80] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..10.54.169.250][50668] -> [...120.28.35.41][...80] [HTTP][Unknown][Streaming][Acceptable][api-singtelhawk.quickplay.com] - new: [.....2] [ip4][..tcp] [..10.54.169.250][50669] -> [...120.28.35.41][...80] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..10.54.169.250][50669] -> [...120.28.35.41][...80] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..10.54.169.250][50669] -> [...120.28.35.41][...80] [HTTP][Unknown][Streaming][Acceptable][api-singtelhawk.quickplay.com] - new: [.....3] [ip4][..tcp] [..10.54.169.250][33064] -> [....120.28.5.18][...80] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..10.54.169.250][33064] -> [....120.28.5.18][...80] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..10.54.169.250][33064] -> [....120.28.5.18][...80] [HTTP][Unknown][Streaming][Acceptable][api-singtelhawk.quickplay.com] - new: [.....4] [ip4][..tcp] [..10.54.169.250][52285] -> [..173.252.74.22][...80] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..10.54.169.250][52285] -> [..173.252.74.22][...80] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..10.54.169.250][52285] -> [..173.252.74.22][...80] [HTTP.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [.....5] [ip4][..tcp] [..10.54.169.250][52288] -> [..173.252.74.22][...80] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..10.54.169.250][52288] -> [..173.252.74.22][...80] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..10.54.169.250][52288] -> [..173.252.74.22][...80] [HTTP.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [.....6] [ip4][..tcp] [..10.54.169.250][33277] -> [..120.28.26.231][...80] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..10.54.169.250][33277] -> [..120.28.26.231][...80] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..10.54.169.250][33277] -> [..120.28.26.231][...80] [HTTP.Google][Unknown][Web][Acceptable][clients3.google.com] - new: [.....7] [ip4][..tcp] [..10.54.169.250][44793] -> [....31.13.68.49][...80] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..10.54.169.250][44793] -> [....31.13.68.49][...80] [MIDSTREAM] detected: [.....7] [ip4][..tcp] [..10.54.169.250][44793] -> [....31.13.68.49][...80] [HTTP.Facebook][Facebook][SocialNetwork][Fun][www.facebook.com] - new: [.....8] [ip4][..tcp] [..10.54.169.250][44256] -> [....120.28.5.41][...80] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [..10.54.169.250][44256] -> [....120.28.5.41][...80] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [..10.54.169.250][44256] -> [....120.28.5.41][...80] [HTTP][Unknown][Streaming][Acceptable][play-singtelhawk.quickplay.com] detection-update: [.....8] [ip4][..tcp] [..10.54.169.250][44256] -> [....120.28.5.41][...80] [HTTP][Unknown][Streaming][Acceptable][play-singtelhawk.quickplay.com] RISK: Unidirectional Traffic detection-update: [.....8] [ip4][..tcp] [..10.54.169.250][44256] -> [....120.28.5.41][...80] [HTTP][Unknown][Streaming][Acceptable][play-singtelhawk.quickplay.com] - new: [.....9] [ip4][..tcp] [..10.54.169.250][52007] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..10.54.169.250][52007] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..10.54.169.250][52007] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] detection-update: [.....9] [ip4][..tcp] [..10.54.169.250][52007] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] RISK: Unidirectional Traffic - new: [....10] [ip4][..tcp] [..10.54.169.250][54883] -> [203.205.151.160][...80] [MIDSTREAM] + new: [....10] [ip4][..tcp] [..10.54.169.250][54883] -> [203.205.151.160][...80] [MIDSTREAM] detected: [....10] [ip4][..tcp] [..10.54.169.250][54883] -> [203.205.151.160][...80] [HTTP_Proxy.QQ][Unknown][Chat][Fun][hkextshort.weixin.qq.com] RISK: Known Proto on Non Std Port detection-update: [.....9] [ip4][..tcp] [..10.54.169.250][52007] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] @@ -32,19 +32,19 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [....10] [ip4][..tcp] [..10.54.169.250][54883] -> [203.205.151.160][...80] [HTTP_Proxy.QQ][Unknown][Chat][Fun][hkextshort.weixin.qq.com] RISK: Known Proto on Non Std Port - new: [....11] [ip4][..tcp] [..10.54.169.250][52009] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....11] [ip4][..tcp] [..10.54.169.250][52009] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....11] [ip4][..tcp] [..10.54.169.250][52009] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] - new: [....12] [ip4][..tcp] [..10.54.169.250][42761] -> [203.205.129.101][...80] [MIDSTREAM] + new: [....12] [ip4][..tcp] [..10.54.169.250][42761] -> [203.205.129.101][...80] [MIDSTREAM] detected: [....12] [ip4][..tcp] [..10.54.169.250][42761] -> [203.205.129.101][...80] [HTTP_Proxy.QQ][Tencent][Chat][Fun][hkextshort.weixin.qq.com] RISK: Known Proto on Non Std Port - new: [....13] [ip4][..tcp] [..10.54.169.250][54885] -> [203.205.151.160][...80] [MIDSTREAM] + new: [....13] [ip4][..tcp] [..10.54.169.250][54885] -> [203.205.151.160][...80] [MIDSTREAM] detected: [....13] [ip4][..tcp] [..10.54.169.250][54885] -> [203.205.151.160][...80] [HTTP_Proxy.QQ][Unknown][Chat][Fun][hkextshort.weixin.qq.com] RISK: Known Proto on Non Std Port detection-update: [....12] [ip4][..tcp] [..10.54.169.250][42761] -> [203.205.129.101][...80] [HTTP_Proxy.QQ][Tencent][Download][Fun][hkextshort.weixin.qq.com] RISK: Binary App Transfer, Known Proto on Non Std Port detection-update: [....13] [ip4][..tcp] [..10.54.169.250][54885] -> [203.205.151.160][...80] [HTTP_Proxy.QQ][Unknown][Download][Fun][hkextshort.weixin.qq.com] RISK: Binary App Transfer, Known Proto on Non Std Port - new: [....14] [ip4][..tcp] [..10.54.169.250][42762] -> [203.205.129.101][...80] [MIDSTREAM] + new: [....14] [ip4][..tcp] [..10.54.169.250][42762] -> [203.205.129.101][...80] [MIDSTREAM] detected: [....14] [ip4][..tcp] [..10.54.169.250][42762] -> [203.205.129.101][...80] [HTTP_Proxy.QQ][Tencent][Chat][Fun][hkextshort.weixin.qq.com] RISK: Known Proto on Non Std Port detection-update: [....14] [ip4][..tcp] [..10.54.169.250][42762] -> [203.205.129.101][...80] [HTTP_Proxy.QQ][Tencent][Download][Fun][hkextshort.weixin.qq.com] @@ -59,24 +59,24 @@ [IATS(ms)....: 2337.9,2470.8,5776.6,5871.2,324.6,2084.5,1689.1,182.6,2170.3,2013.3,645.6,519.6,2223.7,2353.5,480.9,4401.9,3911.8,3909.7,3936.6,2356.5,2338.3,2620.0,2626.5,2264.1,2270.5,2391.5,2349.5,2604.5,2642.0,2224.9,2252.1] [PKTLENS.....: 484,1440,484,224,569,486,1232,569,486,838,571,60,488,1252,569,486,142,486,642,486,1108,486,1192,486,332,486,1440,486,946,486,564,486] [ENTROPIES...: 5.9,7.9,6.0,7.1,5.9,5.9,7.8,5.9,5.9,7.7,6.0,5.0,6.0,7.8,6.0,5.9,6.6,5.9,7.7,6.0,7.8,5.9,7.8,6.0,7.3,5.9,7.9,5.9,7.8,5.9,7.6,5.9] - new: [....15] [ip4][..tcp] [..10.54.169.250][35670] -> [203.205.147.215][...80] [MIDSTREAM] + new: [....15] [ip4][..tcp] [..10.54.169.250][35670] -> [203.205.147.215][...80] [MIDSTREAM] detected: [....15] [ip4][..tcp] [..10.54.169.250][35670] -> [203.205.147.215][...80] [HTTP_Proxy.QQ][Tencent][Chat][Fun][hkminorshort.weixin.qq.com] RISK: Known Proto on Non Std Port detection-update: [....15] [ip4][..tcp] [..10.54.169.250][35670] -> [203.205.147.215][...80] [HTTP_Proxy.QQ][Tencent][Download][Fun][hkminorshort.weixin.qq.com] RISK: Binary App Transfer, Known Proto on Non Std Port - new: [....16] [ip4][..tcp] [..10.54.169.250][56381] -> [..54.179.140.65][...80] [MIDSTREAM] + new: [....16] [ip4][..tcp] [..10.54.169.250][56381] -> [..54.179.140.65][...80] [MIDSTREAM] detected: [....16] [ip4][..tcp] [..10.54.169.250][56381] -> [..54.179.140.65][...80] [HTTP.Xiaomi][AmazonAWS][Web][Acceptable][api.account.xiaomi.com] - new: [....17] [ip4][..tcp] [..10.54.169.250][52017] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....17] [ip4][..tcp] [..10.54.169.250][52017] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....17] [ip4][..tcp] [..10.54.169.250][52017] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] end: [....13] [ip4][..tcp] [..10.54.169.250][54885] -> [203.205.151.160][...80] [HTTP_Proxy.QQ][Unknown][Download][Fun] RISK: Binary App Transfer, Known Proto on Non Std Port - new: [....18] [ip4][..tcp] [..10.54.169.250][52018] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....18] [ip4][..tcp] [..10.54.169.250][52018] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....18] [ip4][..tcp] [..10.54.169.250][52018] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] - new: [....19] [ip4][..tcp] [..10.54.169.250][52019] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....19] [ip4][..tcp] [..10.54.169.250][52019] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....19] [ip4][..tcp] [..10.54.169.250][52019] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] - new: [....20] [ip4][..tcp] [..10.54.169.250][52021] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....20] [ip4][..tcp] [..10.54.169.250][52021] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....20] [ip4][..tcp] [..10.54.169.250][52021] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] - new: [....21] [ip4][..tcp] [..10.54.169.250][52022] -> [...120.28.35.40][...80] [MIDSTREAM] + new: [....21] [ip4][..tcp] [..10.54.169.250][52022] -> [...120.28.35.40][...80] [MIDSTREAM] detected: [....21] [ip4][..tcp] [..10.54.169.250][52022] -> [...120.28.35.40][...80] [HTTP][Unknown][Streaming][Acceptable][vod-singtelhawk.quickplay.com] idle: [.....1] [ip4][..tcp] [..10.54.169.250][50668] -> [...120.28.35.41][...80] [HTTP][Unknown][Streaming][Acceptable] idle: [.....2] [ip4][..tcp] [..10.54.169.250][50669] -> [...120.28.35.41][...80] [HTTP][Unknown][Streaming][Acceptable] diff --git a/test/results/flow-info/default/radius_false_positive.pcapng.out b/test/results/flow-info/default/radius_false_positive.pcapng.out index 6a9217e89..0f37db6f9 100644 --- a/test/results/flow-info/default/radius_false_positive.pcapng.out +++ b/test/results/flow-info/default/radius_false_positive.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [................2bc6:b5ac:cb3b:676b::18][..443] -> [3dba:3762:c186:e122:89b0:5170:a86c:ecff][53129] + new: [.....1] [ip6][..udp] [................2bc6:b5ac:cb3b:676b::18][..443] -> [3dba:3762:c186:e122:89b0:5170:a86c:ecff][53129] guessed: [.....1] [ip6][..udp] [................2bc6:b5ac:cb3b:676b::18][..443] -> [3dba:3762:c186:e122:89b0:5170:a86c:ecff][53129] [QUIC][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [.....1] [ip6][..udp] [................2bc6:b5ac:cb3b:676b::18][..443] -> [3dba:3762:c186:e122:89b0:5170:a86c:ecff][53129] + idle: [.....1] [ip6][..udp] [................2bc6:b5ac:cb3b:676b::18][..443] -> [3dba:3762:c186:e122:89b0:5170:a86c:ecff][53129] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/raknet.pcap.out b/test/results/flow-info/default/raknet.pcap.out index ad33b853c..d2a1e1fb8 100644 --- a/test/results/flow-info/default/raknet.pcap.out +++ b/test/results/flow-info/default/raknet.pcap.out @@ -1,34 +1,34 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60030] + new: [.....1] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60030] detected: [.....1] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60030] [RakNet][Unknown][Game][Fun] - new: [.....2] [ip4][..udp] [..192.168.2.100][60689] -> [.148.153.35.205][60028] + new: [.....2] [ip4][..udp] [..192.168.2.100][60689] -> [.148.153.35.205][60028] detected: [.....2] [ip4][..udp] [..192.168.2.100][60689] -> [.148.153.35.205][60028] [RakNet][Unknown][Game][Fun] update: [.....1] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60030] [RakNet][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 30 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [..192.168.2.100][32951] -> [.148.153.35.205][60021] + new: [.....3] [ip4][..udp] [..192.168.2.100][32951] -> [.148.153.35.205][60021] detected: [.....3] [ip4][..udp] [..192.168.2.100][32951] -> [.148.153.35.205][60021] [RakNet][Unknown][Game][Fun] - new: [.....4] [ip4][..udp] [.148.153.35.205][60022] -> [..192.168.2.100][32951] + new: [.....4] [ip4][..udp] [.148.153.35.205][60022] -> [..192.168.2.100][32951] detected: [.....4] [ip4][..udp] [.148.153.35.205][60022] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] - new: [.....5] [ip4][..udp] [..192.168.2.100][32952] -> [.148.153.35.205][60021] + new: [.....5] [ip4][..udp] [..192.168.2.100][32952] -> [.148.153.35.205][60021] detected: [.....5] [ip4][..udp] [..192.168.2.100][32952] -> [.148.153.35.205][60021] [RakNet][Unknown][Game][Fun] RISK: Unidirectional Traffic - new: [.....6] [ip4][..udp] [.148.153.35.205][60025] -> [..192.168.2.100][32951] + new: [.....6] [ip4][..udp] [.148.153.35.205][60025] -> [..192.168.2.100][32951] detected: [.....6] [ip4][..udp] [.148.153.35.205][60025] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] RISK: Unidirectional Traffic - new: [.....7] [ip4][..udp] [..192.168.2.100][32953] -> [.148.153.35.205][60021] + new: [.....7] [ip4][..udp] [..192.168.2.100][32953] -> [.148.153.35.205][60021] detected: [.....7] [ip4][..udp] [..192.168.2.100][32953] -> [.148.153.35.205][60021] [RakNet][Unknown][Game][Fun] - new: [.....8] [ip4][..udp] [..192.168.2.100][60690] -> [.148.153.35.205][60028] + new: [.....8] [ip4][..udp] [..192.168.2.100][60690] -> [.148.153.35.205][60028] detected: [.....8] [ip4][..udp] [..192.168.2.100][60690] -> [.148.153.35.205][60028] [RakNet][Unknown][Game][Fun] - new: [.....9] [ip4][..udp] [.148.153.35.205][60005] -> [..192.168.2.100][32951] + new: [.....9] [ip4][..udp] [.148.153.35.205][60005] -> [..192.168.2.100][32951] detected: [.....9] [ip4][..udp] [.148.153.35.205][60005] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][60689] -> [.148.153.35.205][60028] [RakNet][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60030] [RakNet][Unknown][Game][Fun] - new: [....10] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60031] + new: [....10] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60031] detected: [....10] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60031] [RakNet][Unknown][Game][Fun] - new: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] + new: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] update: [.....8] [ip4][..udp] [..192.168.2.100][60690] -> [.148.153.35.205][60028] [RakNet][Unknown][Game][Fun] update: [....10] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60031] [RakNet][Unknown][Game][Fun] update: [.....9] [ip4][..udp] [.148.153.35.205][60005] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] @@ -40,7 +40,7 @@ update: [.....6] [ip4][..udp] [.148.153.35.205][60025] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] RISK: Unidirectional Traffic update: [.....8] [ip4][..udp] [..192.168.2.100][60690] -> [.148.153.35.205][60028] [RakNet][Unknown][Game][Fun] - update: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] + update: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] update: [....10] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][60031] [RakNet][Unknown][Game][Fun] update: [.....9] [ip4][..udp] [.148.153.35.205][60005] -> [..192.168.2.100][32951] [RakNet][Unknown][Game][Fun] update: [.....3] [ip4][..udp] [..192.168.2.100][32951] -> [.148.153.35.205][60021] [RakNet][Unknown][Game][Fun] @@ -64,7 +64,7 @@ RISK: Unidirectional Traffic update: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] [RakNet][Unknown][Game][Fun] RISK: Unidirectional Traffic - new: [....12] [ip4][..udp] [.148.153.35.205][43582] -> [..192.168.2.100][44501] + new: [....12] [ip4][..udp] [.148.153.35.205][43582] -> [..192.168.2.100][44501] detected: [....12] [ip4][..udp] [.148.153.35.205][43582] -> [..192.168.2.100][44501] [RakNet][Unknown][Game][Fun] idle: [....11] [ip4][..udp] [..192.168.2.100][44501] -> [.148.153.35.205][59935] [RakNet][Unknown][Game][Fun] RISK: Unidirectional Traffic diff --git a/test/results/flow-info/default/rdp.pcap.out b/test/results/flow-info/default/rdp.pcap.out index c63e3e0dc..572e795ea 100644 --- a/test/results/flow-info/default/rdp.pcap.out +++ b/test/results/flow-info/default/rdp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.16.2.185][52494] -> [..192.168.2.142][.3389] + new: [.....1] [ip4][..tcp] [...172.16.2.185][52494] -> [..192.168.2.142][.3389] detected: [.....1] [ip4][..tcp] [...172.16.2.185][52494] -> [..192.168.2.142][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing idle: [.....1] [ip4][..tcp] [...172.16.2.185][52494] -> [..192.168.2.142][.3389] [RDP][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/rdp2.pcap.out b/test/results/flow-info/default/rdp2.pcap.out index 438e26e87..708c10895 100644 --- a/test/results/flow-info/default/rdp2.pcap.out +++ b/test/results/flow-info/default/rdp2.pcap.out @@ -1,19 +1,19 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [192.168.122.181][54759] -> [..192.168.122.2][.3389] + new: [.....1] [ip4][..udp] [192.168.122.181][54759] -> [..192.168.122.2][.3389] detected: [.....1] [ip4][..udp] [192.168.122.181][54759] -> [..192.168.122.2][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [....10.8.37.100][51652] -> [....10.100.2.87][.3389] + new: [.....2] [ip4][..udp] [....10.8.37.100][51652] -> [....10.100.2.87][.3389] detected: [.....2] [ip4][..udp] [....10.8.37.100][51652] -> [....10.100.2.87][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing idle: [.....1] [ip4][..udp] [192.168.122.181][54759] -> [..192.168.122.2][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing DAEMON-EVENT: [Processed: 32 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..10.50.181.210][60355] -> [....10.50.73.36][.3389] + new: [.....3] [ip4][..udp] [..10.50.181.210][60355] -> [....10.50.73.36][.3389] detected: [.....3] [ip4][..udp] [..10.50.181.210][60355] -> [....10.50.73.36][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing idle: [.....2] [ip4][..udp] [....10.8.37.100][51652] -> [....10.100.2.87][.3389] [RDP][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/reasm_crash_anon.pcapng.out b/test/results/flow-info/default/reasm_crash_anon.pcapng.out index 859cea665..0c0b8bb38 100644 --- a/test/results/flow-info/default/reasm_crash_anon.pcapng.out +++ b/test/results/flow-info/default/reasm_crash_anon.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] [MIDSTREAM] - analyse: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] + new: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] [MIDSTREAM] + analyse: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 30.166| 9.710| 14.065| 197823744.180| 3.300] [PKTLEN......: 52.000| 777.000| 155.000| 234.800| 55144.500| 4.000] @@ -17,5 +17,5 @@ DAEMON-EVENT: [Processed: 169 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] not-detected: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] [Unknown][Unknown][Unrated] - end: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] + end: [.....1] [ip4][..tcp] [192.168.145.147][51218] -> [...10.209.8.148][21999] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/reasm_segv_anon.pcapng.out b/test/results/flow-info/default/reasm_segv_anon.pcapng.out index 436c4129e..4d4635808 100644 --- a/test/results/flow-info/default/reasm_segv_anon.pcapng.out +++ b/test/results/flow-info/default/reasm_segv_anon.pcapng.out @@ -2,7 +2,7 @@ DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] ERROR-EVENT: Captured packet size is smaller than expected packet size [1/16] - new: [.....1] [ip4][..udp] [...145.76.2.236][.2152] -> [...187.96.52.85][.2152] + new: [.....1] [ip4][..udp] [...145.76.2.236][.2152] -> [...187.96.52.85][.2152] detected: [.....1] [ip4][..udp] [...145.76.2.236][.2152] -> [...187.96.52.85][.2152] [GTP.GTP_U][Unknown][Network][Acceptable] ERROR-EVENT: Captured packet size is smaller than expected packet size [2/16] ERROR-EVENT: Captured packet size is smaller than expected packet size [3/16] diff --git a/test/results/flow-info/default/reddit.pcap.out b/test/results/flow-info/default/reddit.pcap.out index fe30eba35..91ed3673a 100644 --- a/test/results/flow-info/default/reddit.pcap.out +++ b/test/results/flow-info/default/reddit.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40028] -> [...............2a00:1450:4007:80a::200a][..443] - new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40030] -> [...............2a00:1450:4007:80a::200a][..443] - new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] + new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40028] -> [...............2a00:1450:4007:80a::200a][..443] + new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40030] -> [...............2a00:1450:4007:80a::200a][..443] + new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] detected: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40028] -> [...............2a00:1450:4007:80a::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable][safebrowsing.googleapis.com] - new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56560] -> [.....................64:ff9b::9765:798c][..443] + new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56560] -> [.....................64:ff9b::9765:798c][..443] detected: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40030] -> [...............2a00:1450:4007:80a::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable][safebrowsing.googleapis.com] detected: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.reddit.com] detection-update: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40028] -> [...............2a00:1450:4007:80a::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable][safebrowsing.googleapis.com] @@ -25,28 +25,28 @@ [IATS(ms)....: 24.9,25.0,0.5,75.6,0.0,0.0,0.0,75.2,0.0,0.0,8.8,5.0,0.6,0.7,37.6,3.5,25.9,1.2,0.5,1.6,1.1,59.9,0.0,0.0,0.0,0.0,0.0,0.0,58.8,0.0,0.0] [PKTLENS.....: 80,80,72,589,72,1280,1280,572,72,72,72,136,164,896,710,72,652,72,72,103,72,103,72,72,384,422,285,111,139,72,72,72] [ENTROPIES...: 4.7,5.2,5.1,4.6,4.9,7.8,7.8,7.5,5.2,5.0,5.1,6.1,6.5,7.8,7.7,5.0,7.6,5.1,5.1,5.7,5.1,5.8,5.1,5.0,7.3,7.4,7.1,6.0,6.2,5.1,5.1,5.1] - new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56562] -> [.....................64:ff9b::9765:798c][..443] - new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] - new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56566] -> [.....................64:ff9b::9765:798c][..443] - new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56568] -> [.....................64:ff9b::9765:798c][..443] - new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56570] -> [.....................64:ff9b::9765:798c][..443] - new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56572] -> [.....................64:ff9b::9765:798c][..443] - new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56574] -> [.....................64:ff9b::9765:798c][..443] - new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56576] -> [.....................64:ff9b::9765:798c][..443] - new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] - new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56580] -> [.....................64:ff9b::9765:798c][..443] - new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] - new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56584] -> [.....................64:ff9b::9765:798c][..443] - new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56586] -> [.....................64:ff9b::9765:798c][..443] - new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56588] -> [.....................64:ff9b::9765:798c][..443] + new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56562] -> [.....................64:ff9b::9765:798c][..443] + new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] + new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56566] -> [.....................64:ff9b::9765:798c][..443] + new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56568] -> [.....................64:ff9b::9765:798c][..443] + new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56570] -> [.....................64:ff9b::9765:798c][..443] + new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56572] -> [.....................64:ff9b::9765:798c][..443] + new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56574] -> [.....................64:ff9b::9765:798c][..443] + new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56576] -> [.....................64:ff9b::9765:798c][..443] + new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] + new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56580] -> [.....................64:ff9b::9765:798c][..443] + new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] + new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56584] -> [.....................64:ff9b::9765:798c][..443] + new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56586] -> [.....................64:ff9b::9765:798c][..443] + new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56588] -> [.....................64:ff9b::9765:798c][..443] detected: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] detected: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56562] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] detected: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56570] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] detected: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56568] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] detected: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56566] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] detected: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56572] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][www.redditstatic.com] - new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56590] -> [.....................64:ff9b::9765:798c][..443] - new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] + new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56590] -> [.....................64:ff9b::9765:798c][..443] + new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] detected: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][styles.redditmedia.com] detected: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56576] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][styles.redditmedia.com] detected: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56574] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][styles.redditmedia.com] @@ -100,7 +100,7 @@ [PKTLENS.....: 80,80,72,589,72,1120,1120,1120,602,72,72,72,72,165,171,389,153,72,330,72,72,72,138,72,1120,1118,72,72,72,1120,72,1120] [ENTROPIES...: 4.9,5.4,5.3,4.6,5.1,6.9,7.3,7.4,7.5,5.2,5.2,5.2,5.3,6.1,6.4,7.3,6.1,5.1,7.1,5.3,5.1,5.0,6.2,5.1,7.8,7.8,5.3,5.2,5.3,7.8,5.2,7.8] detection-update: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][emoji.redditmedia.com] - new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] + new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] detected: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][b.thumbs.redditmedia.com] detection-update: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][b.thumbs.redditmedia.com] detection-update: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][b.thumbs.redditmedia.com] @@ -115,9 +115,9 @@ [PKTLENS.....: 80,80,72,589,72,1120,72,1120,1120,623,72,72,72,165,171,403,72,72,72,346,138,1120,1120,1120,1120,72,72,72,72,72,72,110] [ENTROPIES...: 4.9,5.3,5.3,4.6,5.1,7.0,5.3,7.3,7.3,7.6,5.3,5.3,5.3,6.1,6.5,7.3,5.1,5.2,5.2,7.2,6.2,7.8,7.8,7.8,7.8,5.3,5.3,5.3,5.3,5.3,5.3,5.7] detection-update: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][b.thumbs.redditmedia.com] - new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] - new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43492] -> [......................64:ff9b::df9:21c6][..443] - new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38320] -> [.....................64:ff9b::6853:b3b6][..443] + new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] + new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43492] -> [......................64:ff9b::df9:21c6][..443] + new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38320] -> [.....................64:ff9b::6853:b3b6][..443] detected: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] [TLS.GoogleServices][Google][Web][Acceptable][www.googletagservices.com] detected: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38320] -> [.....................64:ff9b::6853:b3b6][..443] [TLS][Unknown][Web][Safe][c.aaxads.com] detected: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43492] -> [......................64:ff9b::df9:21c6][..443] [TLS.Amazon][Unknown][Web][Acceptable][c.amazon-adsystem.com] @@ -145,17 +145,17 @@ [PKTLENS.....: 80,80,72,589,72,1460,1460,1460,1460,387,72,72,72,72,72,136,164,330,72,72,72,143,72,103,1460,1460,1460,1460,72,72,72,72] [ENTROPIES...: 4.8,5.2,5.2,4.5,5.1,7.8,7.8,7.9,7.8,7.4,5.2,5.2,5.2,5.2,5.1,6.1,6.5,7.3,5.0,5.0,5.1,6.3,5.2,5.9,7.9,7.8,7.9,7.8,5.2,5.2,5.3,5.3] detection-update: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43492] -> [......................64:ff9b::df9:21c6][..443] [TLS.Amazon][Unknown][Web][Acceptable][c.amazon-adsystem.com] - new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51026] -> [.....................64:ff9b::acd9:12c2][..443] + new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51026] -> [.....................64:ff9b::acd9:12c2][..443] detected: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51026] -> [.....................64:ff9b::acd9:12c2][..443] [TLS.Google][Unknown][Advertisement][Acceptable][securepubads.g.doubleclick.net] - new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] + new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] detected: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS.Twitter][Unknown][SocialNetwork][Fun][platform.twitter.com] detection-update: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51026] -> [.....................64:ff9b::acd9:12c2][..443] [TLS.Google][Unknown][Advertisement][Acceptable][securepubads.g.doubleclick.net] detection-update: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS.Twitter][Unknown][SocialNetwork][Fun][platform.twitter.com] detection-update: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS.Twitter][Unknown][SocialNetwork][Fun][platform.twitter.com] - new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39520] -> [...............2a00:1450:4007:816::2008][..443] + new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39520] -> [...............2a00:1450:4007:816::2008][..443] detected: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39520] -> [...............2a00:1450:4007:816::2008][..443] [TLS.GoogleServices][Google][Web][Acceptable][www.googletagmanager.com] detection-update: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39520] -> [...............2a00:1450:4007:816::2008][..443] [TLS.GoogleServices][Google][Web][Acceptable][www.googletagmanager.com] - new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][32970] -> [.....................64:ff9b::6853:b3d1][..443] + new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][32970] -> [.....................64:ff9b::6853:b3d1][..443] analyse: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39520] -> [...............2a00:1450:4007:816::2008][..443] [TLS.GoogleServices][Google][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.044| 0.008| 0.014| 205.550| 3.200] @@ -167,14 +167,14 @@ [PKTLENS.....: 80,80,72,589,72,1280,1280,550,72,72,72,136,164,335,72,72,652,103,72,72,103,72,545,72,1280,1280,72,72,1280,72,1280,1280] [ENTROPIES...: 4.8,5.3,5.1,4.6,5.0,7.8,7.8,7.6,5.2,5.2,5.2,6.0,6.6,7.3,5.0,5.0,7.7,5.7,5.2,5.2,5.8,5.1,7.6,5.2,7.8,7.8,5.2,5.2,7.8,5.2,7.8,7.8] detected: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][32970] -> [.....................64:ff9b::6853:b3d1][..443] [TLS][Unknown][Web][Safe][www.aaxdetect.com] - new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] + new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] detected: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [TLS.Twitter][Unknown][SocialNetwork][Fun][syndication.twitter.com] detection-update: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][32970] -> [.....................64:ff9b::6853:b3d1][..443] [TLS][Unknown][Web][Safe][www.aaxdetect.com] - new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39626] -> [.....................64:ff9b::2278:cf94][..443] - new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54862] -> [...............2a00:1450:4007:806::200e][..443] + new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39626] -> [.....................64:ff9b::2278:cf94][..443] + new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54862] -> [...............2a00:1450:4007:806::200e][..443] detected: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39626] -> [.....................64:ff9b::2278:cf94][..443] [TLS][Unknown][Web][Safe][id.rlcdn.com] - new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48648] -> [...2620:116:800d:21:f916:5049:f87f:108e][..443] - new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44264] -> [.....................64:ff9b::1736:86f1][..443] + new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48648] -> [...2620:116:800d:21:f916:5049:f87f:108e][..443] + new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44264] -> [.....................64:ff9b::1736:86f1][..443] detected: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54862] -> [...............2a00:1450:4007:806::200e][..443] [TLS.YouTube][Google][Media][Fun][www.youtube.com] detected: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48648] -> [...2620:116:800d:21:f916:5049:f87f:108e][..443] [TLS][Unknown][Web][Safe][secure.quantserve.com] detected: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44264] -> [.....................64:ff9b::1736:86f1][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][sb.scorecardresearch.com] @@ -196,9 +196,9 @@ [PKTLENS.....: 80,80,72,589,72,1460,1460,660,72,72,72,198,171,330,330,72,346,141,72,72,110,72,72,110,72,1460,1460,72,72,1460,1460,1460] [ENTROPIES...: 5.3,5.6,5.5,4.7,5.4,6.9,7.4,7.6,5.4,5.4,5.3,6.5,6.4,7.2,7.2,5.4,7.2,6.3,5.5,5.5,5.8,5.4,5.4,6.0,5.4,7.9,7.9,5.5,5.5,7.9,7.9,7.9] detection-update: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48648] -> [...2620:116:800d:21:f916:5049:f87f:108e][..443] [TLS][Unknown][Web][Safe][secure.quantserve.com] - new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51100] -> [.....................64:ff9b::d83a:d1e6][..443] - new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51102] -> [.....................64:ff9b::d83a:d1e6][..443] - new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56186] -> [...2600:9000:219c:ee00:6:44e3:f8c0:93a1][..443] + new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51100] -> [.....................64:ff9b::d83a:d1e6][..443] + new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51102] -> [.....................64:ff9b::d83a:d1e6][..443] + new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56186] -> [...2600:9000:219c:ee00:6:44e3:f8c0:93a1][..443] detected: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51100] -> [.....................64:ff9b::d83a:d1e6][..443] [TLS.Google][Unknown][Advertisement][Acceptable][ad.doubleclick.net] detected: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51102] -> [.....................64:ff9b::d83a:d1e6][..443] [TLS.Google][Unknown][Advertisement][Acceptable][ad.doubleclick.net] detected: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56186] -> [...2600:9000:219c:ee00:6:44e3:f8c0:93a1][..443] [TLS][AmazonAWS][Web][Safe][rules.quantcount.com] @@ -226,11 +226,11 @@ [PKTLENS.....: 80,80,72,589,72,1460,72,1460,735,72,72,198,171,362,362,72,72,72,172,72,314,72,116,72,110,110,72,72,72,531,72,338] [ENTROPIES...: 4.8,5.2,5.2,4.6,5.1,6.8,5.2,7.4,7.6,5.2,5.2,6.4,6.3,7.1,7.1,5.1,5.1,5.1,6.4,5.1,7.0,5.2,5.9,5.2,5.6,5.9,5.2,5.1,5.1,7.5,5.2,7.3] detection-update: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [TLS.Twitter][Unknown][SocialNetwork][Fun][syndication.twitter.com] - new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39736] -> [.....2606:2800:134:1a0d:1429:742:782:b6][..443] + new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39736] -> [.....2606:2800:134:1a0d:1429:742:782:b6][..443] detected: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39736] -> [.....2606:2800:134:1a0d:1429:742:782:b6][..443] [TLS.Twitter][Edgecast][SocialNetwork][Fun][cdn.syndication.twimg.com] detection-update: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39736] -> [.....2606:2800:134:1a0d:1429:742:782:b6][..443] [TLS.Twitter][Edgecast][SocialNetwork][Fun][cdn.syndication.twimg.com] - new: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54726] -> [...............2a00:1450:4007:808::2006][..443] - new: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57282] -> [...............2a00:1450:4007:805::2004][..443] + new: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54726] -> [...............2a00:1450:4007:808::2006][..443] + new: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57282] -> [...............2a00:1450:4007:805::2004][..443] detected: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54726] -> [...............2a00:1450:4007:808::2006][..443] [TLS.Google][Google][Advertisement][Acceptable][static.doubleclick.net] detected: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57282] -> [...............2a00:1450:4007:805::2004][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] analyse: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39736] -> [.....2606:2800:134:1a0d:1429:742:782:b6][..443] [TLS.Twitter][Edgecast][SocialNetwork][Fun] @@ -244,10 +244,10 @@ [PKTLENS.....: 80,80,72,589,72,171,72,595,72,1280,72,1280,1280,72,72,409,72,146,164,459,72,327,327,168,72,72,72,103,72,72,103,1280] [ENTROPIES...: 5.2,5.5,5.4,4.7,5.3,6.2,5.3,5.1,5.3,7.8,5.5,7.8,7.9,5.4,5.4,7.4,5.5,6.4,6.6,7.5,5.4,7.3,7.3,6.5,5.4,5.5,5.4,6.0,5.4,5.4,5.9,7.8] detection-update: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][54726] -> [...............2a00:1450:4007:808::2006][..443] [TLS.Google][Google][Advertisement][Acceptable][static.doubleclick.net] - new: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58122] -> [...............2a00:1450:4007:805::2001][..443] - new: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][52296] -> [...............2a00:1450:4007:815::2016][..443] - new: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47302] -> [...............2a00:1450:4007:80c::2003][..443] - new: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47304] -> [...............2a00:1450:4007:80c::2003][..443] + new: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58122] -> [...............2a00:1450:4007:805::2001][..443] + new: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][52296] -> [...............2a00:1450:4007:815::2016][..443] + new: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47302] -> [...............2a00:1450:4007:80c::2003][..443] + new: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47304] -> [...............2a00:1450:4007:80c::2003][..443] detection-update: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57282] -> [...............2a00:1450:4007:805::2004][..443] [TLS.Google][Google][Web][Acceptable][www.google.com] detected: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47302] -> [...............2a00:1450:4007:80c::2003][..443] [TLS.Google][Google][Web][Acceptable][fonts.gstatic.com] detected: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47304] -> [...............2a00:1450:4007:80c::2003][..443] [TLS.Google][Google][Web][Acceptable][fonts.gstatic.com] @@ -277,7 +277,7 @@ [IATS(ms)....: 63.7,63.8,0.2,68.5,0.7,0.0,0.0,0.0,69.0,0.0,0.0,0.0,0.0,0.0,8.3,2.6,2.5,40.2,1.0,0.0,0.0,27.8,0.2,1.6,0.0,1.4,0.0,0.1,0.0,0.0,0.0] [PKTLENS.....: 80,80,72,589,72,1280,1280,1280,1280,72,72,72,72,469,72,136,164,407,72,652,72,72,72,103,103,503,72,72,1280,1280,328,111] [ENTROPIES...: 4.8,5.2,5.1,4.5,5.1,7.8,7.8,7.8,7.8,5.2,5.2,5.2,5.2,7.4,5.2,6.1,6.6,7.5,5.1,7.6,5.0,5.1,5.1,5.8,5.6,7.6,5.2,5.2,7.8,7.9,7.2,5.9] - new: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] + new: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] detected: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][gateway.reddit.com] detection-update: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][gateway.reddit.com] detection-update: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][gateway.reddit.com] @@ -292,12 +292,12 @@ [PKTLENS.....: 80,80,72,589,72,1120,1120,72,72,1120,587,72,72,165,171,471,72,72,330,138,72,72,72,439,72,110,566,142,72,72,72,114] [ENTROPIES...: 4.9,5.3,5.2,4.5,5.1,6.9,7.4,5.2,5.2,7.3,7.5,5.2,5.2,6.1,6.4,7.4,5.2,5.1,7.1,6.2,5.2,5.3,5.1,7.5,5.3,5.6,7.6,6.2,5.1,5.1,5.1,6.0] detection-update: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun][gateway.reddit.com] - new: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51006] -> [...............2a00:1450:4007:805::2002][..443] - new: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59336] -> [...............2a00:1450:4007:80b::2002][..443] + new: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51006] -> [...............2a00:1450:4007:805::2002][..443] + new: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59336] -> [...............2a00:1450:4007:80b::2002][..443] detected: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51006] -> [...............2a00:1450:4007:805::2002][..443] [TLS.Google][Google][Web][Acceptable][adservice.google.fr] detected: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59336] -> [...............2a00:1450:4007:80b::2002][..443] [TLS.Google][Google][Web][Acceptable][adservice.google.com] - new: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46646] -> [.....................64:ff9b::345f:7ca5][..443] - new: [....48] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59624] -> [...............2a00:1450:4007:80b::2001][..443] + new: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46646] -> [.....................64:ff9b::345f:7ca5][..443] + new: [....48] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59624] -> [...............2a00:1450:4007:80b::2001][..443] detected: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46646] -> [.....................64:ff9b::345f:7ca5][..443] [TLS.Amazon][Unknown][Web][Acceptable][aax-eu.amazon-adsystem.com] detection-update: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51006] -> [...............2a00:1450:4007:805::2002][..443] [TLS.Google][Google][Web][Acceptable][adservice.google.fr] detection-update: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][59336] -> [...............2a00:1450:4007:80b::2002][..443] [TLS.Google][Google][Web][Acceptable][adservice.google.com] @@ -325,16 +325,16 @@ [IATS(ms)....: 28.1,28.1,0.7,33.2,1.6,34.2,0.1,0.0,0.6,0.6,4.6,0.2,0.2,27.0,3.5,25.5,0.2,4.3,1.4,5.5,0.1,6.3,0.0,0.0,6.4,0.0,0.0,0.2,0.0,0.2,0.0] [PKTLENS.....: 80,80,72,589,72,1280,72,1280,72,534,72,136,164,422,72,652,72,103,72,103,72,72,482,1280,1280,72,72,72,704,111,72,72] [ENTROPIES...: 4.8,5.3,5.1,5.0,5.0,7.8,5.2,7.8,5.2,7.6,5.1,6.1,6.6,7.4,5.0,7.7,5.2,5.9,5.0,5.8,5.1,5.1,7.5,7.8,7.8,5.2,5.2,5.1,7.7,5.9,5.2,5.2] - new: [....49] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46806] -> [...............2a00:1450:4007:808::2001][..443] - new: [....50] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46808] -> [...............2a00:1450:4007:808::2001][..443] - new: [....51] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46810] -> [...............2a00:1450:4007:808::2001][..443] - new: [....52] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46812] -> [...............2a00:1450:4007:808::2001][..443] - new: [....53] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46814] -> [...............2a00:1450:4007:808::2001][..443] - new: [....54] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38166] -> [...............2a00:1450:4007:811::200a][..443] - new: [....55] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36964] -> [...............2a00:1450:4007:80f::2001][..443] - new: [....56] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36966] -> [...............2a00:1450:4007:80f::2001][..443] - new: [....57] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36968] -> [...............2a00:1450:4007:80f::2001][..443] - new: [....58] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36970] -> [...............2a00:1450:4007:80f::2001][..443] + new: [....49] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46806] -> [...............2a00:1450:4007:808::2001][..443] + new: [....50] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46808] -> [...............2a00:1450:4007:808::2001][..443] + new: [....51] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46810] -> [...............2a00:1450:4007:808::2001][..443] + new: [....52] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46812] -> [...............2a00:1450:4007:808::2001][..443] + new: [....53] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46814] -> [...............2a00:1450:4007:808::2001][..443] + new: [....54] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38166] -> [...............2a00:1450:4007:811::200a][..443] + new: [....55] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36964] -> [...............2a00:1450:4007:80f::2001][..443] + new: [....56] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36966] -> [...............2a00:1450:4007:80f::2001][..443] + new: [....57] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36968] -> [...............2a00:1450:4007:80f::2001][..443] + new: [....58] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36970] -> [...............2a00:1450:4007:80f::2001][..443] detected: [....49] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46806] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] detected: [....50] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46808] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] detected: [....51] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46810] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] @@ -346,7 +346,7 @@ detected: [....58] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36970] -> [...............2a00:1450:4007:80f::2001][..443] [TLS.Google][Google][Advertisement][Acceptable][tpc.googlesyndication.com] detected: [....57] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36968] -> [...............2a00:1450:4007:80f::2001][..443] [TLS.Google][Google][Advertisement][Acceptable][tpc.googlesyndication.com] detection-update: [....49] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46806] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] - new: [....59] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36972] -> [...............2a00:1450:4007:80f::2001][..443] + new: [....59] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36972] -> [...............2a00:1450:4007:80f::2001][..443] detection-update: [....50] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46808] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] detection-update: [....51] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46810] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] detection-update: [....52] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][46812] -> [...............2a00:1450:4007:808::2001][..443] [TLS.Google][Google][Web][Acceptable][cdn.ampproject.org] @@ -376,7 +376,7 @@ [IATS(ms)....: 28.7,28.7,0.2,37.9,6.1,43.8,0.1,0.0,0.6,0.6,16.4,9.8,0.9,43.8,3.9,20.7,0.6,14.9,1.7,0.0,16.0,10.5,0.0,0.0,0.0,10.5,0.0,0.0,0.0,0.2,0.0] [PKTLENS.....: 80,80,72,589,72,1280,72,1280,72,572,72,136,164,355,72,652,72,103,72,103,72,72,531,897,272,357,72,72,72,72,111,72] [ENTROPIES...: 4.8,5.2,5.1,4.6,5.0,7.8,5.1,7.8,5.0,7.6,5.0,6.0,6.4,7.3,5.0,7.6,5.1,5.8,5.0,5.5,5.0,5.1,7.5,7.7,7.1,7.3,5.1,5.1,5.1,5.1,5.8,5.0] - new: [....60] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47006] -> [.....................64:ff9b::34d3:acec][..443] + new: [....60] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47006] -> [.....................64:ff9b::34d3:acec][..443] detected: [....60] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47006] -> [.....................64:ff9b::34d3:acec][..443] [TLS][Unknown][Web][Safe][d9.flashtalking.com] detection-update: [....60] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47006] -> [.....................64:ff9b::34d3:acec][..443] [TLS][Unknown][Web][Safe][d9.flashtalking.com] detection-update: [....60] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47006] -> [.....................64:ff9b::34d3:acec][..443] [TLS][Unknown][Web][Safe][d9.flashtalking.com] @@ -389,7 +389,7 @@ end: [....58] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36970] -> [...............2a00:1450:4007:80f::2001][..443] [TLS.Google][Google][Advertisement][Acceptable] guessed: [....59] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36972] -> [...............2a00:1450:4007:80f::2001][..443] [TLS][Google][Web][Safe] RISK: TCP Connection Issues - end: [....59] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36972] -> [...............2a00:1450:4007:80f::2001][..443] + end: [....59] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][36972] -> [...............2a00:1450:4007:80f::2001][..443] idle: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44264] -> [.....................64:ff9b::1736:86f1][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] idle: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] [TLS.Reddit][Unknown][SocialNetwork][Fun] idle: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47302] -> [...............2a00:1450:4007:80c::2003][..443] [TLS.Google][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/riot.pcapng.out b/test/results/flow-info/default/riot.pcapng.out index d1d453a01..5386bea30 100644 --- a/test/results/flow-info/default/riot.pcapng.out +++ b/test/results/flow-info/default/riot.pcapng.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..52.41.135.135][..443] -> [..192.168.26.22][51817] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [..35.234.85.218][..443] -> [..192.168.26.22][51949] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..52.41.135.135][..443] -> [..192.168.26.22][51817] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..35.234.85.218][..443] -> [..192.168.26.22][51949] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..35.234.85.218][..443] -> [..192.168.26.22][51949] [TLS][GoogleCloud][Web][Safe][] detection-update: [.....2] [ip4][..tcp] [..35.234.85.218][..443] -> [..192.168.26.22][51949] [TLS][GoogleCloud][Web][Safe][] RISK: Unidirectional Traffic @@ -10,7 +10,7 @@ RISK: Unidirectional Traffic guessed: [.....1] [ip4][..tcp] [..52.41.135.135][..443] -> [..192.168.26.22][51817] [TLS][AmazonAWS][Web][Safe] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [..52.41.135.135][..443] -> [..192.168.26.22][51817] + idle: [.....1] [ip4][..tcp] [..52.41.135.135][..443] -> [..192.168.26.22][51817] idle: [.....2] [ip4][..tcp] [..35.234.85.218][..443] -> [..192.168.26.22][51949] [TLS.RiotGames][GoogleCloud][Game][Fun] RISK: Unidirectional Traffic DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/riotgames.pcap.out b/test/results/flow-info/default/riotgames.pcap.out index 55854aca0..bce3bfa32 100644 --- a/test/results/flow-info/default/riotgames.pcap.out +++ b/test/results/flow-info/default/riotgames.pcap.out @@ -1,46 +1,46 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][59956] -> [...162.249.72.1][.7194] + new: [.....1] [ip4][..udp] [..192.168.2.100][59956] -> [...162.249.72.1][.7194] detected: [.....1] [ip4][..udp] [..192.168.2.100][59956] -> [...162.249.72.1][.7194] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][48526] -> [213.179.216.242][50004] + new: [.....2] [ip4][..udp] [..192.168.2.100][48526] -> [213.179.216.242][50004] detected: [.....2] [ip4][..udp] [..192.168.2.100][48526] -> [213.179.216.242][50004] [Discord][Discord][Collaborative][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][59956] -> [...162.249.72.1][.7194] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.2.100][62854] -> [...162.249.72.1][.8181] + new: [.....3] [ip4][..udp] [..192.168.2.100][62854] -> [...162.249.72.1][.8181] detected: [.....3] [ip4][..udp] [..192.168.2.100][62854] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][48526] -> [213.179.216.242][50004] [Discord][Discord][Collaborative][Fun] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [..192.168.2.100][54231] -> [....43.229.65.1][.7998] + new: [.....4] [ip4][..udp] [..192.168.2.100][54231] -> [....43.229.65.1][.7998] detected: [.....4] [ip4][..udp] [..192.168.2.100][54231] -> [....43.229.65.1][.7998] [RiotGames][RiotGames][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][62854] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 21 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [..192.168.2.100][58106] -> [...162.249.72.1][.8181] + new: [.....5] [ip4][..udp] [..192.168.2.100][58106] -> [...162.249.72.1][.8181] detected: [.....5] [ip4][..udp] [..192.168.2.100][58106] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] idle: [.....4] [ip4][..udp] [..192.168.2.100][54231] -> [....43.229.65.1][.7998] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 23 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..udp] [..192.168.2.100][50004] -> [...162.249.72.1][.8181] + new: [.....6] [ip4][..udp] [..192.168.2.100][50004] -> [...162.249.72.1][.8181] detected: [.....6] [ip4][..udp] [..192.168.2.100][50004] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] idle: [.....5] [ip4][..udp] [..192.168.2.100][58106] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 25 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..udp] [..192.168.2.100][63038] -> [....43.229.65.1][.7998] + new: [.....7] [ip4][..udp] [..192.168.2.100][63038] -> [....43.229.65.1][.7998] detected: [.....7] [ip4][..udp] [..192.168.2.100][63038] -> [....43.229.65.1][.7998] [RiotGames][RiotGames][Game][Fun] idle: [.....6] [ip4][..udp] [..192.168.2.100][50004] -> [...162.249.72.1][.8181] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 27 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..udp] [..192.168.2.100][61099] -> [....66.22.241.8][50004] + new: [.....8] [ip4][..udp] [..192.168.2.100][61099] -> [....66.22.241.8][50004] detected: [.....8] [ip4][..udp] [..192.168.2.100][61099] -> [....66.22.241.8][50004] [Discord][Discord][Collaborative][Fun] idle: [.....7] [ip4][..udp] [..192.168.2.100][63038] -> [....43.229.65.1][.7998] [RiotGames][RiotGames][Game][Fun] DAEMON-EVENT: [Processed: 29 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..udp] [..192.168.2.100][49298] -> [...162.249.72.1][.7194] + new: [.....9] [ip4][..udp] [..192.168.2.100][49298] -> [...162.249.72.1][.7194] detected: [.....9] [ip4][..udp] [..192.168.2.100][49298] -> [...162.249.72.1][.7194] [RiotGames][RiotGames][Game][Fun] idle: [.....8] [ip4][..udp] [..192.168.2.100][61099] -> [....66.22.241.8][50004] [Discord][Discord][Collaborative][Fun] idle: [.....9] [ip4][..udp] [..192.168.2.100][49298] -> [...162.249.72.1][.7194] [RiotGames][RiotGames][Game][Fun] diff --git a/test/results/flow-info/default/rmcp.pcap.out b/test/results/flow-info/default/rmcp.pcap.out index 1c2888e4c..3e33da857 100644 --- a/test/results/flow-info/default/rmcp.pcap.out +++ b/test/results/flow-info/default/rmcp.pcap.out @@ -1,24 +1,24 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.123.212.25.229][49531] -> [..171.47.173.23][..623] + new: [.....1] [ip4][..udp] [.123.212.25.229][49531] -> [..171.47.173.23][..623] detected: [.....1] [ip4][..udp] [.123.212.25.229][49531] -> [..171.47.173.23][..623] [RMCP][Unknown][System][Safe] DAEMON-EVENT: [Processed: 1 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.54.229.154.152][59937] -> [...14.85.79.172][..623] + new: [.....2] [ip4][..udp] [.54.229.154.152][59937] -> [...14.85.79.172][..623] detected: [.....2] [ip4][..udp] [.54.229.154.152][59937] -> [...14.85.79.172][..623] [RMCP][AmazonAWS][System][Safe] - new: [.....3] [ip4][..udp] [..137.141.61.18][59937] -> [...82.132.4.178][..623] + new: [.....3] [ip4][..udp] [..137.141.61.18][59937] -> [...82.132.4.178][..623] detected: [.....3] [ip4][..udp] [..137.141.61.18][59937] -> [...82.132.4.178][..623] [RMCP][Unknown][System][Safe] idle: [.....1] [ip4][..udp] [.123.212.25.229][49531] -> [..171.47.173.23][..623] [RMCP][Unknown][System][Safe] DAEMON-EVENT: [Processed: 3 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [.129.222.153.30][58065] -> [190.219.142.148][..623] + new: [.....4] [ip4][..udp] [.129.222.153.30][58065] -> [190.219.142.148][..623] detected: [.....4] [ip4][..udp] [.129.222.153.30][58065] -> [190.219.142.148][..623] [RMCP][Unknown][System][Safe] idle: [.....3] [ip4][..udp] [..137.141.61.18][59937] -> [...82.132.4.178][..623] [RMCP][Unknown][System][Safe] idle: [.....2] [ip4][..udp] [.54.229.154.152][59937] -> [...14.85.79.172][..623] [RMCP][AmazonAWS][System][Safe] - new: [.....5] [ip4][..udp] [..64.240.55.240][57984] -> [...30.144.16.67][..623] + new: [.....5] [ip4][..udp] [..64.240.55.240][57984] -> [...30.144.16.67][..623] detected: [.....5] [ip4][..udp] [..64.240.55.240][57984] -> [...30.144.16.67][..623] [RMCP][Unknown][System][Safe] - new: [.....6] [ip4][..udp] [..127.36.88.103][34698] -> [.164.114.97.252][..623] + new: [.....6] [ip4][..udp] [..127.36.88.103][34698] -> [.164.114.97.252][..623] detected: [.....6] [ip4][..udp] [..127.36.88.103][34698] -> [.164.114.97.252][..623] [RMCP][Unknown][System][Safe] idle: [.....6] [ip4][..udp] [..127.36.88.103][34698] -> [.164.114.97.252][..623] [RMCP][Unknown][System][Safe] idle: [.....5] [ip4][..udp] [..64.240.55.240][57984] -> [...30.144.16.67][..623] [RMCP][Unknown][System][Safe] diff --git a/test/results/flow-info/default/roblox.pcapng.out b/test/results/flow-info/default/roblox.pcapng.out index 0cd3350fd..c6c89746f 100644 --- a/test/results/flow-info/default/roblox.pcapng.out +++ b/test/results/flow-info/default/roblox.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.156][42965] -> [.128.116.89.113][63862] + new: [.....1] [ip4][..udp] [.192.168.12.156][42965] -> [.128.116.89.113][63862] detected: [.....1] [ip4][..udp] [.192.168.12.156][42965] -> [.128.116.89.113][63862] [RakNet][Roblox][Game][Fun] - new: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] + new: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] detected: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] [TLS.Roblox][Roblox][Game][Fun][assetgame.roblox.com] detection-update: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] [TLS.Roblox][Roblox][Game][Fun][assetgame.roblox.com] analyse: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] [TLS.Roblox][Roblox][Game][Fun] @@ -19,13 +19,13 @@ detection-update: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] [TLS.Roblox][Roblox][Game][Fun][assetgame.roblox.com] DAEMON-EVENT: [Processed: 47 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....3] [ip4][..udp] [.192.168.12.156][45693] -> [..128.116.44.33][53385] + new: [.....3] [ip4][..udp] [.192.168.12.156][45693] -> [..128.116.44.33][53385] detected: [.....3] [ip4][..udp] [.192.168.12.156][45693] -> [..128.116.44.33][53385] [RakNet][Roblox][Game][Fun] idle: [.....1] [ip4][..udp] [.192.168.12.156][42965] -> [.128.116.89.113][63862] [RakNet][Roblox][Game][Fun] end: [.....2] [ip4][..tcp] [.192.168.12.156][39034] -> [..128.116.122.4][..443] [TLS.Roblox][Roblox][Game][Fun] DAEMON-EVENT: [Processed: 64 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....4] [ip4][..udp] [.192.168.12.156][46507] -> [..128.116.44.33][51438] + new: [.....4] [ip4][..udp] [.192.168.12.156][46507] -> [..128.116.44.33][51438] detected: [.....4] [ip4][..udp] [.192.168.12.156][46507] -> [..128.116.44.33][51438] [RakNet][Roblox][Game][Fun] idle: [.....3] [ip4][..udp] [.192.168.12.156][45693] -> [..128.116.44.33][53385] [RakNet][Roblox][Game][Fun] idle: [.....4] [ip4][..udp] [.192.168.12.156][46507] -> [..128.116.44.33][51438] [RakNet][Roblox][Game][Fun] diff --git a/test/results/flow-info/default/rsh-syslog-false-positive.pcap.out b/test/results/flow-info/default/rsh-syslog-false-positive.pcap.out index 703b11c94..582f540cc 100644 --- a/test/results/flow-info/default/rsh-syslog-false-positive.pcap.out +++ b/test/results/flow-info/default/rsh-syslog-false-positive.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..172.31.78.129][.9039] -> [..172.29.43.201][..514] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..172.31.78.129][.9039] -> [..172.29.43.201][..514] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..172.31.78.129][.9039] -> [..172.29.43.201][..514] [Syslog][Unknown][System][Acceptable] ERROR-EVENT: Captured packet size is smaller than expected packet size [1/16] ERROR-EVENT: Captured packet size is smaller than expected packet size [2/16] diff --git a/test/results/flow-info/default/rsh.pcap.out b/test/results/flow-info/default/rsh.pcap.out index dbff3be51..775187f6b 100644 --- a/test/results/flow-info/default/rsh.pcap.out +++ b/test/results/flow-info/default/rsh.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][.1023] -> [......127.0.0.1][..514] + new: [.....1] [ip4][..tcp] [......127.0.0.1][.1023] -> [......127.0.0.1][..514] detected: [.....1] [ip4][..tcp] [......127.0.0.1][.1023] -> [......127.0.0.1][..514] [RSH][Unknown][RemoteAccess][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials - new: [.....2] [ip4][..tcp] [......127.0.0.1][.1021] -> [......127.0.0.1][..514] + new: [.....2] [ip4][..tcp] [......127.0.0.1][.1021] -> [......127.0.0.1][..514] detected: [.....2] [ip4][..tcp] [......127.0.0.1][.1021] -> [......127.0.0.1][..514] [RSH][Unknown][RemoteAccess][Unsafe] RISK: Unsafe Protocol, Clear-Text Credentials end: [.....2] [ip4][..tcp] [......127.0.0.1][.1021] -> [......127.0.0.1][..514] [RSH][Unknown][RemoteAccess][Unsafe] diff --git a/test/results/flow-info/default/rsync.pcap.out b/test/results/flow-info/default/rsync.pcap.out index 914718b2b..21cdd9d35 100644 --- a/test/results/flow-info/default/rsync.pcap.out +++ b/test/results/flow-info/default/rsync.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][54489] -> [......127.0.0.1][..873] + new: [.....1] [ip4][..tcp] [......127.0.0.1][54489] -> [......127.0.0.1][..873] detected: [.....1] [ip4][..tcp] [......127.0.0.1][54489] -> [......127.0.0.1][..873] [RSYNC][Unknown][DataTransfer][Acceptable] end: [.....1] [ip4][..tcp] [......127.0.0.1][54489] -> [......127.0.0.1][..873] [RSYNC][Unknown][DataTransfer][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/rtcp_multiple_pkts_in_the_same_datagram.pcap.out b/test/results/flow-info/default/rtcp_multiple_pkts_in_the_same_datagram.pcap.out index 040b40958..f2d4228ab 100644 --- a/test/results/flow-info/default/rtcp_multiple_pkts_in_the_same_datagram.pcap.out +++ b/test/results/flow-info/default/rtcp_multiple_pkts_in_the_same_datagram.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..217.12.244.34][25963] -> [..217.12.247.98][31601] + new: [.....1] [ip4][..udp] [..217.12.244.34][25963] -> [..217.12.247.98][31601] detected: [.....1] [ip4][..udp] [..217.12.244.34][25963] -> [..217.12.247.98][31601] [RTCP][Unknown][VoIP][Acceptable] idle: [.....1] [ip4][..udp] [..217.12.244.34][25963] -> [..217.12.247.98][31601] [RTCP][Unknown][VoIP][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/rtmp.pcap.out b/test/results/flow-info/default/rtmp.pcap.out index 3f77fc4e9..b4f4d4534 100644 --- a/test/results/flow-info/default/rtmp.pcap.out +++ b/test/results/flow-info/default/rtmp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.43.1][.1177] -> [.192.168.43.128][.1935] + new: [.....1] [ip4][..tcp] [...192.168.43.1][.1177] -> [.192.168.43.128][.1935] detected: [.....1] [ip4][..tcp] [...192.168.43.1][.1177] -> [.192.168.43.128][.1935] [RTMP][Unknown][Media][Acceptable] idle: [.....1] [ip4][..tcp] [...192.168.43.1][.1177] -> [.192.168.43.128][.1935] [RTMP][Unknown][Media][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/rtp.pcapng.out b/test/results/flow-info/default/rtp.pcapng.out index 3cfecd3c2..de9a06c71 100644 --- a/test/results/flow-info/default/rtp.pcapng.out +++ b/test/results/flow-info/default/rtp.pcapng.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..10.204.220.71][.6000] -> [.10.204.220.171][.6000] + new: [.....1] [ip4][..udp] [..10.204.220.71][.6000] -> [.10.204.220.171][.6000] detected: [.....1] [ip4][..udp] [..10.204.220.71][.6000] -> [.10.204.220.171][.6000] [RTP][Unknown][Media][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.150.219.118.19][54234] -> [192.113.193.227][50003] + new: [.....2] [ip4][..udp] [.150.219.118.19][54234] -> [192.113.193.227][50003] detected: [.....2] [ip4][..udp] [.150.219.118.19][54234] -> [192.113.193.227][50003] [Discord][Unknown][Collaborative][Fun] idle: [.....1] [ip4][..udp] [..10.204.220.71][.6000] -> [.10.204.220.171][.6000] [RTP][Unknown][Media][Acceptable] - new: [.....3] [ip4][..udp] [..10.140.67.167][55402] -> [..148.153.85.97][.6008] + new: [.....3] [ip4][..udp] [..10.140.67.167][55402] -> [..148.153.85.97][.6008] detected: [.....3] [ip4][..udp] [..10.140.67.167][55402] -> [..148.153.85.97][.6008] [RTP][Unknown][Media][Acceptable] idle: [.....2] [ip4][..udp] [.150.219.118.19][54234] -> [192.113.193.227][50003] [Discord][Unknown][Collaborative][Fun] idle: [.....3] [ip4][..udp] [..10.140.67.167][55402] -> [..148.153.85.97][.6008] [RTP][Unknown][Media][Acceptable] diff --git a/test/results/flow-info/default/rtsp.pcap.out b/test/results/flow-info/default/rtsp.pcap.out index a16868f98..3d1ac6712 100644 --- a/test/results/flow-info/default/rtsp.pcap.out +++ b/test/results/flow-info/default/rtsp.pcap.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] + new: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] detected: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] @@ -17,7 +17,7 @@ [IATS(ms)....: 0.0,0.0,0.1,0.2,0.1,0.0,0.0,0.2,0.0,0.0,0.1,13.1,0.0,0.0,0.1,13.5,0.0,0.0,0.0,20.6,0.0,0.0,0.0,21.1,0.0,0.0,0.1,0.5,0.0,0.0,0.0] [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,40,46,46,165,165,165,165,182,182,182,182,46,40,46,46] [ENTROPIES...: 4.4,4.4,4.5,4.5,4.7,4.7,4.7,4.7,4.4,4.4,4.7,4.4,5.7,5.7,5.7,5.7,4.3,4.6,4.3,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.3,4.7,4.4,4.3] - new: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] + new: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] detected: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....3] [ip4][..tcp] [......10.1.1.10][52474] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] @@ -30,7 +30,7 @@ [IATS(ms)....: 0.0,0.0,0.1,0.3,0.0,0.0,0.0,0.6,0.0,0.0,0.1,9.3,0.0,0.0,0.1,10.1,0.0,0.0,0.0,20.5,0.0,0.0,0.0,21.2,0.0,0.0,0.4,0.9,0.1,0.0,0.0] [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,40,46,46,165,165,165,165,182,182,182,182,46,46,40,46] [ENTROPIES...: 4.4,4.4,4.4,4.4,4.6,4.7,4.7,4.6,4.4,4.4,4.7,4.4,5.8,5.8,5.8,5.8,4.3,4.7,4.4,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.3,4.3,4.6,4.3] - new: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] + new: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] detected: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....4] [ip4][..tcp] [......10.1.1.10][52476] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] @@ -43,7 +43,7 @@ [IATS(ms)....: 0.0,0.0,0.3,0.3,0.1,0.0,0.1,0.8,0.1,0.0,0.2,4.8,0.0,0.0,0.4,6.2,0.1,0.0,0.1,20.1,0.0,0.1,0.0,21.0,0.0,0.0,0.1,0.9,0.0,0.0,0.1] [PKTLENS.....: 52,52,52,52,52,52,52,52,46,46,40,46,156,156,156,156,46,46,40,46,165,165,165,165,182,182,182,182,46,40,46,46] [ENTROPIES...: 4.3,4.3,4.4,4.4,4.6,4.6,4.6,4.6,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.2,4.5,4.2,4.3] - new: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] + new: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] detected: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....5] [ip4][..tcp] [......10.1.1.10][52478] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] @@ -58,7 +58,7 @@ [ENTROPIES...: 4.4,4.4,4.4,4.4,3.5,3.8,3.5,3.5,4.4,4.4,4.4,4.4,4.6,4.7,4.6,4.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7,4.3,4.3,4.6,4.3,5.7,5.7,5.7,5.7] end: [.....1] [ip4][..tcp] [......10.1.1.10][52470] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port - new: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] + new: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] detected: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....6] [ip4][..tcp] [......10.1.1.10][52480] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] @@ -73,7 +73,7 @@ [ENTROPIES...: 4.3,4.3,4.4,4.4,4.6,4.6,4.6,4.6,4.3,4.3,4.6,4.3,5.7,5.7,5.7,4.2,4.6,5.7,4.2,4.3,5.7,5.7,5.7,5.7,5.8,5.8,5.8,5.8,4.2,4.6,4.2,4.3] end: [.....2] [ip4][..tcp] [......10.1.1.10][52472] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port - new: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] + new: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] detected: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port analyse: [.....7] [ip4][..tcp] [......10.1.1.10][52482] -> [.......10.2.2.2][.8554] [RTSP][Unknown][Media][Fun] diff --git a/test/results/flow-info/default/rtsp_setup_http.pcapng.out b/test/results/flow-info/default/rtsp_setup_http.pcapng.out index 8291bb485..5756d5b35 100644 --- a/test/results/flow-info/default/rtsp_setup_http.pcapng.out +++ b/test/results/flow-info/default/rtsp_setup_http.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.28.5.170][63840] -> [....172.28.4.26][.8554] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...172.28.5.170][63840] -> [....172.28.4.26][.8554] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...172.28.5.170][63840] -> [....172.28.4.26][.8554] [RTSP][Unknown][Media][Fun] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..tcp] [...172.28.5.170][63840] -> [....172.28.4.26][.8554] [RTSP][Unknown][Media][Fun] diff --git a/test/results/flow-info/default/rx.pcap.out b/test/results/flow-info/default/rx.pcap.out index bf56d4d6b..93f040347 100644 --- a/test/results/flow-info/default/rx.pcap.out +++ b/test/results/flow-info/default/rx.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [131.114.219.168][41559] -> [192.167.206.124][.7002] + new: [.....1] [ip4][..udp] [131.114.219.168][41559] -> [192.167.206.124][.7002] detected: [.....1] [ip4][..udp] [131.114.219.168][41559] -> [192.167.206.124][.7002] [RX][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..udp] [131.114.219.168][38331] -> [192.167.206.124][.7002] + new: [.....2] [ip4][..udp] [131.114.219.168][38331] -> [192.167.206.124][.7002] detected: [.....2] [ip4][..udp] [131.114.219.168][38331] -> [192.167.206.124][.7002] [RX][Unknown][RPC][Acceptable] - new: [.....3] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7003] + new: [.....3] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7003] detected: [.....3] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7003] [RX][Unknown][RPC][Acceptable] - new: [.....4] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.241][.7000] + new: [.....4] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.241][.7000] detected: [.....4] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.241][.7000] [RX][Unknown][RPC][Acceptable] - new: [.....5] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7000] + new: [.....5] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7000] detected: [.....5] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.124][.7000] [RX][Unknown][RPC][Acceptable] analyse: [.....4] [ip4][..udp] [131.114.219.168][.7001] -> [192.167.206.241][.7000] [RX][Unknown][RPC][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/s7comm.pcap.out b/test/results/flow-info/default/s7comm.pcap.out index ac0e670d5..44758355b 100644 --- a/test/results/flow-info/default/s7comm.pcap.out +++ b/test/results/flow-info/default/s7comm.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.10][.4185] -> [...192.168.1.40][..102] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...192.168.1.10][.4185] -> [...192.168.1.40][..102] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...192.168.1.10][.4185] -> [...192.168.1.40][..102] [s7comm][Unknown][Network][Acceptable] analyse: [.....1] [ip4][..tcp] [...192.168.1.10][.4185] -> [...192.168.1.40][..102] [s7comm][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/safari.pcap.out b/test/results/flow-info/default/safari.pcap.out index 202a4feab..71fe08b20 100644 --- a/test/results/flow-info/default/safari.pcap.out +++ b/test/results/flow-info/default/safari.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][55262] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] - new: [.....2] [ip4][..tcp] [..192.168.1.178][55265] -> [...146.48.58.18][..443] - new: [.....3] [ip4][..tcp] [..192.168.1.178][55266] -> [...146.48.58.18][..443] - new: [.....4] [ip4][..tcp] [..192.168.1.178][55267] -> [...146.48.58.18][..443] - new: [.....5] [ip4][..tcp] [..192.168.1.178][55268] -> [...146.48.58.18][..443] - new: [.....6] [ip4][..tcp] [..192.168.1.178][55269] -> [...146.48.58.18][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.178][55265] -> [...146.48.58.18][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.178][55266] -> [...146.48.58.18][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.178][55267] -> [...146.48.58.18][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.178][55268] -> [...146.48.58.18][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.178][55269] -> [...146.48.58.18][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.178][55267] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] RISK: TLS (probably) Not Carrying HTTPS detected: [.....2] [ip4][..tcp] [..192.168.1.178][55265] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] @@ -40,7 +40,7 @@ [IATS(ms)....: 29.6,29.7,2.4,30.5,0.0,28.2,51.9,8.9,77.9,8.5,0.6,1.2,27.4,0.1,0.1,0.2,0.1,0.1,0.3,0.1,0.1,0.2,0.5,0.1,0.6,24.0,24.0,84.5,7.8,118.9,0.9] [PKTLENS.....: 64,60,52,263,52,193,52,103,494,52,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1492,1492,52,1029,52,52,483,52,1492] [ENTROPIES...: 4.4,5.2,4.9,5.8,5.0,6.4,4.9,5.5,7.5,5.0,4.8,7.9,7.9,5.0,7.9,7.9,5.0,7.9,7.9,4.9,7.9,7.9,5.0,7.9,7.9,4.9,7.8,5.0,4.8,7.5,5.1,7.9] - new: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] detection-update: [.....7] [ip4][..tcp] [..192.168.1.178][55285] -> [...146.48.58.18][..443] [TLS][Unknown][Web][Safe][www.iit.cnr.it] diff --git a/test/results/flow-info/default/salesforce.pcap.out b/test/results/flow-info/default/salesforce.pcap.out index 92d8bf055..e0fc549ca 100644 --- a/test/results/flow-info/default/salesforce.pcap.out +++ b/test/results/flow-info/default/salesforce.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][54399] -> [...85.222.142.6][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][54399] -> [...85.222.142.6][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][54399] -> [...85.222.142.6][..443] [TLS.Salesforce][Unknown][Cloud][Safe][help.salesforce.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][54399] -> [...85.222.142.6][..443] [TLS.Salesforce][Unknown][Cloud][Safe][help.salesforce.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][54399] -> [...85.222.142.6][..443] [TLS.Salesforce][Unknown][Cloud][Safe][help.salesforce.com] diff --git a/test/results/flow-info/default/sccp_hw_conf_register.pcapng.out b/test/results/flow-info/default/sccp_hw_conf_register.pcapng.out index 3fd89e9c8..22a8ea526 100644 --- a/test/results/flow-info/default/sccp_hw_conf_register.pcapng.out +++ b/test/results/flow-info/default/sccp_hw_conf_register.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..10.180.110.58][46461] -> [..10.180.110.48][.2000] + new: [.....1] [ip4][..tcp] [..10.180.110.58][46461] -> [..10.180.110.48][.2000] detected: [.....1] [ip4][..tcp] [..10.180.110.58][46461] -> [..10.180.110.48][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] idle: [.....1] [ip4][..tcp] [..10.180.110.58][46461] -> [..10.180.110.48][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/sctp.cap.out b/test/results/flow-info/default/sctp.cap.out index 7f23e72bc..6aa8c77d7 100644 --- a/test/results/flow-info/default/sctp.cap.out +++ b/test/results/flow-info/default/sctp.cap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..132] [.....10.28.6.43] -> [.....10.28.6.44] + new: [.....1] [ip4][..132] [.....10.28.6.43] -> [.....10.28.6.44] detected: [.....1] [ip4][..132] [.....10.28.6.43] -> [.....10.28.6.44] [SCTP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..132] [.....10.28.6.42] -> [.....10.28.6.44] + new: [.....2] [ip4][..132] [.....10.28.6.42] -> [.....10.28.6.44] detected: [.....2] [ip4][..132] [.....10.28.6.42] -> [.....10.28.6.44] [SCTP][Unknown][Network][Acceptable] idle: [.....2] [ip4][..132] [.....10.28.6.42] -> [.....10.28.6.44] [SCTP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..132] [.....10.28.6.43] -> [.....10.28.6.44] [SCTP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/selfsigned.pcap.out b/test/results/flow-info/default/selfsigned.pcap.out index 30d00363e..274ba2f53 100644 --- a/test/results/flow-info/default/selfsigned.pcap.out +++ b/test/results/flow-info/default/selfsigned.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][51607] -> [......127.0.0.1][.3001] + new: [.....1] [ip4][..tcp] [......127.0.0.1][51607] -> [......127.0.0.1][.3001] detected: [.....1] [ip4][..tcp] [......127.0.0.1][51607] -> [......127.0.0.1][.3001] [TLS][Unknown][Web][Safe][localhost] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..tcp] [......127.0.0.1][51607] -> [......127.0.0.1][.3001] [TLS.ntop][Unknown][Network][Safe][localhost] diff --git a/test/results/flow-info/default/sflow.pcap.out b/test/results/flow-info/default/sflow.pcap.out index aee44e076..8d3fa614e 100644 --- a/test/results/flow-info/default/sflow.pcap.out +++ b/test/results/flow-info/default/sflow.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...172.21.35.17][.1027] -> [..172.21.35.199][.6343] + new: [.....1] [ip4][..udp] [...172.21.35.17][.1027] -> [..172.21.35.199][.6343] detected: [.....1] [ip4][..udp] [...172.21.35.17][.1027] -> [..172.21.35.199][.6343] [sFlow][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...172.21.35.17][.1027] -> [..172.21.35.199][.6343] [sFlow][Unknown][Network][Acceptable] idle: [.....1] [ip4][..udp] [...172.21.35.17][.1027] -> [..172.21.35.199][.6343] [sFlow][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/shadowsocks.pcap.out b/test/results/flow-info/default/shadowsocks.pcap.out index 72e5cc52f..d314e93c4 100644 --- a/test/results/flow-info/default/shadowsocks.pcap.out +++ b/test/results/flow-info/default/shadowsocks.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......127.0.0.1][37904] -> [......127.0.0.1][.1080] + new: [.....1] [ip4][..tcp] [......127.0.0.1][37904] -> [......127.0.0.1][.1080] detected: [.....1] [ip4][..tcp] [......127.0.0.1][37904] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] - new: [.....2] [ip4][..tcp] [......127.0.0.1][44276] -> [......127.0.0.1][.8388] + new: [.....2] [ip4][..tcp] [......127.0.0.1][44276] -> [......127.0.0.1][.8388] end: [.....1] [ip4][..tcp] [......127.0.0.1][37904] -> [......127.0.0.1][.1080] [SOCKS][Unknown][Web][Acceptable] not-detected: [.....2] [ip4][..tcp] [......127.0.0.1][44276] -> [......127.0.0.1][.8388] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [.....2] [ip4][..tcp] [......127.0.0.1][44276] -> [......127.0.0.1][.8388] + end: [.....2] [ip4][..tcp] [......127.0.0.1][44276] -> [......127.0.0.1][.8388] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/signal.pcap.out b/test/results/flow-info/default/signal.pcap.out index 0a90ae6d8..5c5565465 100644 --- a/test/results/flow-info/default/signal.pcap.out +++ b/test/results/flow-info/default/signal.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....1] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....1] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [.....2] [ip4][..udp] [...192.168.2.17][60793] -> [....192.168.2.1][...53] + new: [.....2] [ip4][..udp] [...192.168.2.17][60793] -> [....192.168.2.1][...53] detected: [.....2] [ip4][..udp] [...192.168.2.17][60793] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][e673.dsce9.akamaiedge.net] - new: [.....3] [ip4][..tcp] [...192.168.2.17][49226] -> [.34.225.240.173][..443] - new: [.....4] [ip4][..tcp] [...192.168.2.17][57018] -> [....23.57.24.16][..443] - new: [.....5] [ip4][..tcp] [...192.168.2.17][57019] -> [.34.225.240.173][..443] - new: [.....6] [ip4][..tcp] [...192.168.2.17][57020] -> [.34.225.240.173][..443] - new: [.....7] [ip4][..tcp] [...192.168.2.17][57021] -> [.34.225.240.173][..443] + new: [.....3] [ip4][..tcp] [...192.168.2.17][49226] -> [.34.225.240.173][..443] + new: [.....4] [ip4][..tcp] [...192.168.2.17][57018] -> [....23.57.24.16][..443] + new: [.....5] [ip4][..tcp] [...192.168.2.17][57019] -> [.34.225.240.173][..443] + new: [.....6] [ip4][..tcp] [...192.168.2.17][57020] -> [.34.225.240.173][..443] + new: [.....7] [ip4][..tcp] [...192.168.2.17][57021] -> [.34.225.240.173][..443] detection-update: [.....2] [ip4][..udp] [...192.168.2.17][60793] -> [....192.168.2.1][...53] [DNS][Unknown][Network][Acceptable][e673.dsce9.akamaiedge.net] detected: [.....4] [ip4][..tcp] [...192.168.2.17][57018] -> [....23.57.24.16][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][itunes.apple.com] detection-update: [.....4] [ip4][..tcp] [...192.168.2.17][57018] -> [....23.57.24.16][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][itunes.apple.com] @@ -38,21 +38,21 @@ detection-update: [.....7] [ip4][..tcp] [...192.168.2.17][57021] -> [.34.225.240.173][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [.....6] [ip4][..tcp] [...192.168.2.17][57020] -> [.34.225.240.173][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [.....6] [ip4][..tcp] [...192.168.2.17][57020] -> [.34.225.240.173][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] - new: [.....8] [ip4][..tcp] [...192.168.2.17][56996] -> [.17.248.146.144][..443] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [...192.168.2.17][56996] -> [.17.248.146.144][..443] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [...192.168.2.17][56996] -> [.17.248.146.144][..443] [TLS][Apple][Web][Safe] detection-update: [.....8] [ip4][..tcp] [...192.168.2.17][56996] -> [.17.248.146.144][..443] [TLS][Apple][Web][Safe] RISK: Unidirectional Traffic - new: [.....9] [ip4][..tcp] [...192.168.2.17][57017] -> [...2.18.232.118][..443] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...192.168.2.17][57017] -> [...2.18.232.118][..443] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...192.168.2.17][57017] -> [...2.18.232.118][..443] [TLS][Unknown][Web][Safe] - new: [....10] [ip4][..tcp] [...192.168.2.17][49227] -> [....35.169.3.40][..443] - new: [....11] [ip4][..tcp] [...192.168.2.17][57022] -> [....23.57.24.16][..443] - new: [....12] [ip4][..udp] [...192.168.2.17][56263] -> [....192.168.2.1][...53] + new: [....10] [ip4][..tcp] [...192.168.2.17][49227] -> [....35.169.3.40][..443] + new: [....11] [ip4][..tcp] [...192.168.2.17][57022] -> [....23.57.24.16][..443] + new: [....12] [ip4][..udp] [...192.168.2.17][56263] -> [....192.168.2.1][...53] detected: [....12] [ip4][..udp] [...192.168.2.17][56263] -> [....192.168.2.1][...53] [DNS.Signal][Unknown][Network][Fun][textsecure-service.whispersystems.org] - new: [....13] [ip4][..tcp] [...192.168.2.17][57023] -> [....35.169.3.40][..443] - new: [....14] [ip4][..tcp] [...192.168.2.17][57024] -> [....35.169.3.40][..443] - new: [....15] [ip4][..tcp] [...192.168.2.17][57025] -> [....35.169.3.40][..443] + new: [....13] [ip4][..tcp] [...192.168.2.17][57023] -> [....35.169.3.40][..443] + new: [....14] [ip4][..tcp] [...192.168.2.17][57024] -> [....35.169.3.40][..443] + new: [....15] [ip4][..tcp] [...192.168.2.17][57025] -> [....35.169.3.40][..443] detection-update: [....12] [ip4][..udp] [...192.168.2.17][56263] -> [....192.168.2.1][...53] [DNS.Signal][Unknown][Network][Fun][textsecure-service.whispersystems.org] - new: [....16] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] + new: [....16] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] detected: [....16] [ip4][.icmp] [...192.168.2.17] -> [....192.168.2.1] [ICMP][Unknown][Network][Acceptable] detected: [....11] [ip4][..tcp] [...192.168.2.17][57022] -> [....23.57.24.16][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][itunes.apple.com] detection-update: [....11] [ip4][..tcp] [...192.168.2.17][57022] -> [....23.57.24.16][..443] [TLS.AppleiTunes][Unknown][Streaming][Fun][itunes.apple.com] @@ -81,7 +81,7 @@ detection-update: [....15] [ip4][..tcp] [...192.168.2.17][57025] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [....14] [ip4][..tcp] [...192.168.2.17][57024] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [....14] [ip4][..tcp] [...192.168.2.17][57024] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] - new: [....17] [ip4][..tcp] [...192.168.2.17][57026] -> [....35.169.3.40][..443] + new: [....17] [ip4][..tcp] [...192.168.2.17][57026] -> [....35.169.3.40][..443] detected: [....17] [ip4][..tcp] [...192.168.2.17][57026] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [....17] [ip4][..tcp] [...192.168.2.17][57026] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] detection-update: [....17] [ip4][..tcp] [...192.168.2.17][57026] -> [....35.169.3.40][..443] [TLS.Signal][AmazonAWS][Chat][Fun][textsecure-service.whispersystems.org] @@ -95,12 +95,12 @@ [IATS(ms)....: 108.9,110.6,0.1,110.4,2.1,0.0,112.4,5.0,114.9,0.0,109.6,1.9,0.0,0.0,0.1,0.8,0.1,0.2,0.1,111.4,0.2,108.4,1.8,0.6,1.7,0.2,0.2,0.3,0.1,109.4,1.5] [PKTLENS.....: 64,60,52,569,52,1492,1090,52,178,103,121,52,105,102,94,298,1492,1492,1492,364,52,90,834,52,52,1492,1492,1492,1492,137,52,52] [ENTROPIES...: 4.4,5.2,5.1,4.6,5.2,7.1,7.7,5.0,6.5,5.8,6.4,5.1,5.7,5.6,5.6,7.1,7.9,7.9,7.9,7.4,5.2,5.9,7.7,5.1,5.1,7.9,7.9,7.9,7.9,6.1,5.2,5.0] - new: [....18] [ip4][..tcp] [....23.57.24.16][..443] -> [...192.168.2.17][57016] [MIDSTREAM] + new: [....18] [ip4][..tcp] [....23.57.24.16][..443] -> [...192.168.2.17][57016] [MIDSTREAM] detected: [....18] [ip4][..tcp] [....23.57.24.16][..443] -> [...192.168.2.17][57016] [TLS][Unknown][Web][Safe] detection-update: [....18] [ip4][..tcp] [....23.57.24.16][..443] -> [...192.168.2.17][57016] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detection-update: [....18] [ip4][..tcp] [....23.57.24.16][..443] -> [...192.168.2.17][57016] [TLS][Unknown][Web][Safe] - new: [....19] [ip4][..tcp] [...192.168.2.17][57027] -> [...13.35.253.42][..443] + new: [....19] [ip4][..tcp] [...192.168.2.17][57027] -> [...13.35.253.42][..443] detected: [....19] [ip4][..tcp] [...192.168.2.17][57027] -> [...13.35.253.42][..443] [TLS.Signal][AmazonAWS][Chat][Fun][cdn.signal.org] detection-update: [....19] [ip4][..tcp] [...192.168.2.17][57027] -> [...13.35.253.42][..443] [TLS.Signal][AmazonAWS][Chat][Fun][cdn.signal.org] detection-update: [....19] [ip4][..tcp] [...192.168.2.17][57027] -> [...13.35.253.42][..443] [TLS.Signal][AmazonAWS][Chat][Fun][cdn.signal.org] diff --git a/test/results/flow-info/default/simple-dnscrypt.pcap.out b/test/results/flow-info/default/simple-dnscrypt.pcap.out index e43bb09bb..00637ed60 100644 --- a/test/results/flow-info/default/simple-dnscrypt.pcap.out +++ b/test/results/flow-info/default/simple-dnscrypt.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] + new: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] detected: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] [TLS][Unknown][Web][Safe][simplednscrypt.org] detection-update: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] [TLS][Unknown][Web][Safe][simplednscrypt.org] detection-update: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] [TLS.DNScrypt][Unknown][Network][Acceptable][simplednscrypt.org] @@ -16,9 +16,9 @@ [PKTLENS.....: 52,52,40,246,40,1350,1350,40,1350,1350,1350,346,40,166,93,96,82,258,298,109,40,78,40,78,40,40,40,401,40,105,1350,1310] [ENTROPIES...: 4.7,5.1,4.9,5.6,4.9,7.3,7.2,4.7,7.6,7.5,7.6,7.3,4.8,6.4,5.7,5.8,5.5,7.1,7.1,6.1,4.9,5.4,4.9,5.8,4.9,4.9,4.9,7.3,4.9,6.0,7.8,7.8] detection-update: [.....1] [ip4][..tcp] [.192.168.43.167][50233] -> [..134.119.26.24][..443] [TLS.DNScrypt][Unknown][Network][Acceptable][simplednscrypt.org] - new: [.....2] [ip4][..tcp] [.192.168.43.167][50253] -> [..134.119.26.24][..443] - new: [.....3] [ip4][..tcp] [.192.168.43.167][50258] -> [..134.119.26.24][..443] - new: [.....4] [ip4][..tcp] [.192.168.43.167][50259] -> [..134.119.26.24][..443] + new: [.....2] [ip4][..tcp] [.192.168.43.167][50253] -> [..134.119.26.24][..443] + new: [.....3] [ip4][..tcp] [.192.168.43.167][50258] -> [..134.119.26.24][..443] + new: [.....4] [ip4][..tcp] [.192.168.43.167][50259] -> [..134.119.26.24][..443] detected: [.....2] [ip4][..tcp] [.192.168.43.167][50253] -> [..134.119.26.24][..443] [TLS.DNScrypt][Unknown][Network][Acceptable][simplednscrypt.org] detected: [.....4] [ip4][..tcp] [.192.168.43.167][50259] -> [..134.119.26.24][..443] [TLS.DNScrypt][Unknown][Network][Acceptable][simplednscrypt.org] detected: [.....3] [ip4][..tcp] [.192.168.43.167][50258] -> [..134.119.26.24][..443] [TLS.DNScrypt][Unknown][Network][Acceptable][simplednscrypt.org] diff --git a/test/results/flow-info/default/sip.pcap.out b/test/results/flow-info/default/sip.pcap.out index 7bde4f3dd..ce8ac34a8 100644 --- a/test/results/flow-info/default/sip.pcap.out +++ b/test/results/flow-info/default/sip.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] + new: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] detected: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [.....2] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] + new: [.....2] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] detected: [.....2] [ip4][..udp] [....192.168.1.2][.5060] -> [..200.68.120.81][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] @@ -41,9 +41,9 @@ update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [.....3] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] + new: [.....3] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] detected: [.....3] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] - new: [.....4] [ip4][..udp] [....192.168.1.2][30001] -> [..212.242.33.36][40393] + new: [.....4] [ip4][..udp] [....192.168.1.2][30001] -> [..212.242.33.36][40393] detected: [.....4] [ip4][..udp] [....192.168.1.2][30001] -> [..212.242.33.36][40393] [RTCP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [....192.168.1.2][.5060] -> [..212.242.33.35][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....3] [ip4][..udp] [....192.168.1.2][30000] -> [..212.242.33.36][40392] [RTP][Unknown][Media][Acceptable] diff --git a/test/results/flow-info/default/sip_hello.pcapng.out b/test/results/flow-info/default/sip_hello.pcapng.out index 8c99d0823..a0b0b4dde 100644 --- a/test/results/flow-info/default/sip_hello.pcapng.out +++ b/test/results/flow-info/default/sip_hello.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] - update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] - update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] - update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] + new: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] + update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] + update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] + update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] detected: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] [SIP][Unknown][VoIP][Acceptable] update: [.....1] [ip4][..udp] [.10.239.156.235][.5060] -> [...172.29.38.91][.5060] [SIP][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/sites.pcapng.out b/test/results/flow-info/default/sites.pcapng.out index 7099f8ccf..9c42fd3d2 100644 --- a/test/results/flow-info/default/sites.pcapng.out +++ b/test/results/flow-info/default/sites.pcapng.out @@ -1,25 +1,25 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.12.169][46160] -> [..69.171.250.20][..443] + new: [.....1] [ip4][..tcp] [.192.168.12.169][46160] -> [..69.171.250.20][..443] detected: [.....1] [ip4][..tcp] [.192.168.12.169][46160] -> [..69.171.250.20][..443] [TLS.Messenger][Facebook][Chat][Acceptable][edge-mqtt.facebook.com] detection-update: [.....1] [ip4][..tcp] [.192.168.12.169][46160] -> [..69.171.250.20][..443] [TLS.Messenger][Facebook][Chat][Acceptable][edge-mqtt.facebook.com] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.1.250][41878] -> [...92.122.95.99][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.250][41878] -> [...92.122.95.99][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.250][41878] -> [...92.122.95.99][..443] [TLS.TikTok][Unknown][SocialNetwork][Fun][vcs-va.tiktokv.com] detection-update: [.....2] [ip4][..tcp] [..192.168.1.250][41878] -> [...92.122.95.99][..443] [TLS.TikTok][Unknown][SocialNetwork][Fun][vcs-va.tiktokv.com] idle: [.....1] [ip4][..tcp] [.192.168.12.169][46160] -> [..69.171.250.20][..443] [TLS.Messenger][Facebook][Chat][Acceptable] DAEMON-EVENT: [Processed: 35 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] detected: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] [TLS.Fuze][AmazonAWS][VoIP][Acceptable][presence.fuze.com] detection-update: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] [TLS.Fuze][AmazonAWS][VoIP][Acceptable][presence.fuze.com] detection-update: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] [TLS.Fuze][AmazonAWS][VoIP][Acceptable][presence.fuze.com] end: [.....2] [ip4][..tcp] [..192.168.1.250][41878] -> [...92.122.95.99][..443] [TLS.TikTok][Unknown][SocialNetwork][Fun] DAEMON-EVENT: [Processed: 66 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] [TLS.Wikipedia][Unknown][Web][Safe][upload.wikimedia.org] detection-update: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] [TLS.Wikipedia][Unknown][Web][Safe][upload.wikimedia.org] analyse: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] [TLS.Wikipedia][Unknown][Web][Safe] @@ -36,7 +36,7 @@ end: [.....3] [ip4][..tcp] [..192.168.1.227][50071] -> [...52.73.71.226][..443] [TLS.Fuze][AmazonAWS][VoIP][Acceptable] DAEMON-EVENT: [Processed: 118 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 6|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.1.250][39890] -> [...45.82.241.51][...80] + new: [.....5] [ip4][..tcp] [..192.168.1.250][39890] -> [...45.82.241.51][...80] detected: [.....5] [ip4][..tcp] [..192.168.1.250][39890] -> [...45.82.241.51][...80] [HTTP.Likee][Unknown][SocialNetwork][Fun][videosnap.like.video] analyse: [.....5] [ip4][..tcp] [..192.168.1.250][39890] -> [...45.82.241.51][...80] [HTTP.Likee][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy @@ -51,129 +51,129 @@ end: [.....4] [ip4][..tcp] [..192.168.1.128][50620] -> [.91.198.174.208][..443] [TLS.Wikipedia][Unknown][Web][Safe] DAEMON-EVENT: [Processed: 230 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 6|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] detected: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] [TLS.Vimeo][Unknown][Streaming][Fun][f.vimeocdn.com] detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] [TLS.Vimeo][Unknown][Streaming][Fun][f.vimeocdn.com] detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] [TLS.Vimeo][Unknown][Streaming][Fun][f.vimeocdn.com] end: [.....5] [ip4][..tcp] [..192.168.1.250][39890] -> [...45.82.241.51][...80] [HTTP.Likee][Unknown][SocialNetwork][Fun] DAEMON-EVENT: [Processed: 255 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 8|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.1.128][48918] -> [...143.204.9.65][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.128][48918] -> [...143.204.9.65][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.128][48918] -> [...143.204.9.65][..443] [TLS.DisneyPlus][AmazonAWS][Streaming][Fun][prod-static.disney-plus.net] detection-update: [.....7] [ip4][..tcp] [..192.168.1.128][48918] -> [...143.204.9.65][..443] [TLS.DisneyPlus][AmazonAWS][Streaming][Fun][prod-static.disney-plus.net] end: [.....6] [ip4][..tcp] [..192.168.1.128][46724] -> [.199.232.82.109][..443] [TLS.Vimeo][Unknown][Streaming][Fun] DAEMON-EVENT: [Processed: 284 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 9|updates: 0] - new: [.....8] [ip4][..tcp] [.192.168.12.169][39248] -> [...23.12.104.83][..443] + new: [.....8] [ip4][..tcp] [.192.168.12.169][39248] -> [...23.12.104.83][..443] detected: [.....8] [ip4][..tcp] [.192.168.12.169][39248] -> [...23.12.104.83][..443] [TLS.AccuWeather][Unknown][Web][Fun][api.accuweather.com] detection-update: [.....8] [ip4][..tcp] [.192.168.12.169][39248] -> [...23.12.104.83][..443] [TLS.AccuWeather][Unknown][Web][Fun][api.accuweather.com] end: [.....7] [ip4][..tcp] [..192.168.1.128][48918] -> [...143.204.9.65][..443] [TLS.DisneyPlus][AmazonAWS][Streaming][Fun] DAEMON-EVENT: [Processed: 314 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 10|updates: 0] - new: [.....9] [ip4][..udp] [..192.168.1.123][59102] -> [..216.58.209.46][..443] + new: [.....9] [ip4][..udp] [..192.168.1.123][59102] -> [..216.58.209.46][..443] detected: [.....9] [ip4][..udp] [..192.168.1.123][59102] -> [..216.58.209.46][..443] [QUIC.GoogleClassroom][Google][Collaborative][Safe][classroom.google.com] end: [.....8] [ip4][..tcp] [.192.168.12.169][39248] -> [...23.12.104.83][..443] [TLS.AccuWeather][Unknown][Web][Fun] DAEMON-EVENT: [Processed: 315 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 10|updates: 0] - new: [....10] [ip4][..tcp] [..192.168.1.128][35054] -> [..31.222.67.112][..443] + new: [....10] [ip4][..tcp] [..192.168.1.128][35054] -> [..31.222.67.112][..443] detected: [....10] [ip4][..tcp] [..192.168.1.128][35054] -> [..31.222.67.112][..443] [TLS.Badoo][Unknown][SocialNetwork][Fun][www.badoo.com] detection-update: [....10] [ip4][..tcp] [..192.168.1.128][35054] -> [..31.222.67.112][..443] [TLS.Badoo][Unknown][SocialNetwork][Fun][www.badoo.com] idle: [.....9] [ip4][..udp] [..192.168.1.123][59102] -> [..216.58.209.46][..443] [QUIC.GoogleClassroom][Google][Collaborative][Safe] - new: [....11] [ip4][..tcp] [..192.168.1.128][53998] -> [..172.65.251.78][..443] + new: [....11] [ip4][..tcp] [..192.168.1.128][53998] -> [..172.65.251.78][..443] detected: [....11] [ip4][..tcp] [..192.168.1.128][53998] -> [..172.65.251.78][..443] [TLS.GitLab][Cloudflare][Collaborative][Fun][www.gitlab.com] detection-update: [....11] [ip4][..tcp] [..192.168.1.128][53998] -> [..172.65.251.78][..443] [TLS.GitLab][Cloudflare][Collaborative][Fun][www.gitlab.com] - new: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] + new: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] detected: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] [TLS.Activision][Unknown][Game][Fun][www.activision.com] detection-update: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] [TLS.Activision][Unknown][Game][Fun][www.activision.com] detection-update: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] [TLS.Activision][Unknown][Game][Fun][www.activision.com] - new: [....13] [ip4][..tcp] [..192.168.1.128][46084] -> [..146.75.62.167][..443] + new: [....13] [ip4][..tcp] [..192.168.1.128][46084] -> [..146.75.62.167][..443] detected: [....13] [ip4][..tcp] [..192.168.1.128][46084] -> [..146.75.62.167][..443] [TLS.Twitch][Unknown][Video][Fun][gql.twitch.tv] detection-update: [....13] [ip4][..tcp] [..192.168.1.128][46084] -> [..146.75.62.167][..443] [TLS.Twitch][Unknown][Video][Fun][gql.twitch.tv] - new: [....14] [ip4][..tcp] [..192.168.1.128][45936] -> [..208.85.40.158][...80] - new: [....15] [ip4][..tcp] [..192.168.1.128][51806] -> [..18.66.196.102][..443] + new: [....14] [ip4][..tcp] [..192.168.1.128][45936] -> [..208.85.40.158][...80] + new: [....15] [ip4][..tcp] [..192.168.1.128][51806] -> [..18.66.196.102][..443] detected: [....15] [ip4][..tcp] [..192.168.1.128][51806] -> [..18.66.196.102][..443] [TLS.SoundCloud][AmazonAWS][Music][Fun][soundcloud.com] detection-update: [....15] [ip4][..tcp] [..192.168.1.128][51806] -> [..18.66.196.102][..443] [TLS.SoundCloud][AmazonAWS][Music][Fun][soundcloud.com] - new: [....16] [ip4][..tcp] [..192.168.1.128][56468] -> [.151.101.192.92][..443] + new: [....16] [ip4][..tcp] [..192.168.1.128][56468] -> [.151.101.192.92][..443] detected: [....16] [ip4][..tcp] [..192.168.1.128][56468] -> [.151.101.192.92][..443] [TLS][Unknown][Web][Safe][vevo.com] detection-update: [....16] [ip4][..tcp] [..192.168.1.128][56468] -> [.151.101.192.92][..443] [TLS][Unknown][Web][Safe][vevo.com] detection-update: [....16] [ip4][..tcp] [..192.168.1.128][56468] -> [.151.101.192.92][..443] [TLS.Vevo][Unknown][Music][Fun][vevo.com] - new: [....17] [ip4][..tcp] [..192.168.1.128][48140] -> [.....23.1.66.79][..443] + new: [....17] [ip4][..tcp] [..192.168.1.128][48140] -> [.....23.1.66.79][..443] detected: [....17] [ip4][..tcp] [..192.168.1.128][48140] -> [.....23.1.66.79][..443] [TLS.CNN][Unknown][Web][Safe][cdn.cnn.com] detection-update: [....17] [ip4][..tcp] [..192.168.1.128][48140] -> [.....23.1.66.79][..443] [TLS.CNN][Unknown][Web][Safe][cdn.cnn.com] - new: [....18] [ip4][..tcp] [..192.168.1.128][40832] -> [....2.17.141.49][..443] + new: [....18] [ip4][..tcp] [..192.168.1.128][40832] -> [....2.17.141.49][..443] detected: [....18] [ip4][..tcp] [..192.168.1.128][40832] -> [....2.17.141.49][..443] [TLS.eBay][Unknown][Shopping][Safe][www.ebay.com] detection-update: [....18] [ip4][..tcp] [..192.168.1.128][40832] -> [....2.17.141.49][..443] [TLS.eBay][Unknown][Shopping][Safe][www.ebay.com] - new: [....19] [ip4][..tcp] [..192.168.1.128][42884] -> [.185.125.190.21][..443] + new: [....19] [ip4][..tcp] [..192.168.1.128][42884] -> [.185.125.190.21][..443] detected: [....19] [ip4][..tcp] [..192.168.1.128][42884] -> [.185.125.190.21][..443] [TLS.UbuntuONE][UbuntuONE][Cloud][Acceptable][assets.ubuntu.com] detection-update: [....19] [ip4][..tcp] [..192.168.1.128][42884] -> [.185.125.190.21][..443] [TLS.UbuntuONE][UbuntuONE][Cloud][Acceptable][assets.ubuntu.com] - new: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] + new: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] detected: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] [TLS][Unknown][Web][Safe][tuenti.com] detection-update: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] [TLS][Unknown][Web][Safe][tuenti.com] detection-update: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable][tuenti.com] - new: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] + new: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] detected: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable][static.tuenti.com] detection-update: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable][static.tuenti.com] detection-update: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable][static.tuenti.com] - new: [....22] [ip4][..tcp] [..192.168.1.128][51432] -> [.95.101.195.214][..443] + new: [....22] [ip4][..tcp] [..192.168.1.128][51432] -> [.95.101.195.214][..443] detected: [....22] [ip4][..tcp] [..192.168.1.128][51432] -> [.95.101.195.214][..443] [TLS.Hulu][Unknown][Streaming][Fun][hulu.com] detection-update: [....22] [ip4][..tcp] [..192.168.1.128][51432] -> [.95.101.195.214][..443] [TLS.Hulu][Unknown][Streaming][Fun][hulu.com] - new: [....23] [ip4][..tcp] [..192.168.1.128][44954] -> [..34.96.123.111][...80] - new: [....24] [ip4][..tcp] [..192.168.1.128][47122] -> [.35.201.112.136][..443] + new: [....23] [ip4][..tcp] [..192.168.1.128][44954] -> [..34.96.123.111][...80] + new: [....24] [ip4][..tcp] [..192.168.1.128][47122] -> [.35.201.112.136][..443] detected: [....24] [ip4][..tcp] [..192.168.1.128][47122] -> [.35.201.112.136][..443] [TLS.LastFM][GoogleCloud][Music][Fun][kerve.last.fm] detection-update: [....24] [ip4][..tcp] [..192.168.1.128][47122] -> [.35.201.112.136][..443] [TLS.LastFM][GoogleCloud][Music][Fun][kerve.last.fm] - new: [....25] [ip4][..tcp] [..192.168.1.128][39036] -> [..69.191.252.15][...80] - new: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] + new: [....25] [ip4][..tcp] [..192.168.1.128][39036] -> [..69.191.252.15][...80] + new: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] detected: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] [TLS.Bloomberg][Unknown][Cloud][Acceptable][www.bloomberg.com] detection-update: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] [TLS.Bloomberg][Unknown][Cloud][Acceptable][www.bloomberg.com] detection-update: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] [TLS.Bloomberg][Unknown][Cloud][Acceptable][www.bloomberg.com] - new: [....27] [ip4][..tcp] [..192.168.1.128][57014] -> [108.139.210.102][..443] + new: [....27] [ip4][..tcp] [..192.168.1.128][57014] -> [108.139.210.102][..443] detected: [....27] [ip4][..tcp] [..192.168.1.128][57014] -> [108.139.210.102][..443] [TLS.Bloomberg][AmazonAWS][Cloud][Acceptable][sourcepointcmp.bloomberg.com] detection-update: [....27] [ip4][..tcp] [..192.168.1.128][57014] -> [108.139.210.102][..443] [TLS.Bloomberg][AmazonAWS][Cloud][Acceptable][sourcepointcmp.bloomberg.com] - new: [....28] [ip4][..tcp] [..192.168.1.128][48654] -> [...13.107.42.14][..443] + new: [....28] [ip4][..tcp] [..192.168.1.128][48654] -> [...13.107.42.14][..443] detected: [....28] [ip4][..tcp] [..192.168.1.128][48654] -> [...13.107.42.14][..443] [TLS.LinkedIn][Azure][SocialNetwork][Fun][www.linkedin.com] detection-update: [....28] [ip4][..tcp] [..192.168.1.128][48654] -> [...13.107.42.14][..443] [TLS.LinkedIn][Azure][SocialNetwork][Fun][www.linkedin.com] - new: [....29] [ip4][..tcp] [..192.168.1.128][39934] -> [..104.23.98.190][..443] + new: [....29] [ip4][..tcp] [..192.168.1.128][39934] -> [..104.23.98.190][..443] detected: [....29] [ip4][..tcp] [..192.168.1.128][39934] -> [..104.23.98.190][..443] [TLS.Pastebin][Cloudflare][Download][Potentially Dangerous][pastebin.com] RISK: Unsafe Protocol detection-update: [....29] [ip4][..tcp] [..192.168.1.128][39934] -> [..104.23.98.190][..443] [TLS.Pastebin][Cloudflare][Download][Potentially Dangerous][pastebin.com] RISK: Unsafe Protocol - new: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] + new: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] detected: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] [TLS.Playstation][Unknown][Game][Fun][www.playstation.com] detection-update: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] [TLS.Playstation][Unknown][Game][Fun][www.playstation.com] detection-update: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] [TLS.Playstation][Unknown][Game][Fun][www.playstation.com] - new: [....31] [ip4][..tcp] [..192.168.1.128][46264] -> [...23.51.246.65][..443] + new: [....31] [ip4][..tcp] [..192.168.1.128][46264] -> [...23.51.246.65][..443] detected: [....31] [ip4][..tcp] [..192.168.1.128][46264] -> [...23.51.246.65][..443] [TLS.Playstation][Unknown][Game][Fun][static.playstation.com] detection-update: [....31] [ip4][..tcp] [..192.168.1.128][46264] -> [...23.51.246.65][..443] [TLS.Playstation][Unknown][Game][Fun][static.playstation.com] - new: [....32] [ip4][..tcp] [..192.168.1.128][43150] -> [.108.138.199.67][..443] + new: [....32] [ip4][..tcp] [..192.168.1.128][43150] -> [.108.138.199.67][..443] detected: [....32] [ip4][..tcp] [..192.168.1.128][43150] -> [.108.138.199.67][..443] [TLS.Deezer][AmazonAWS][Music][Fun][deezer.com] detection-update: [....32] [ip4][..tcp] [..192.168.1.128][43150] -> [.108.138.199.67][..443] [TLS.Deezer][AmazonAWS][Music][Fun][deezer.com] - new: [....33] [ip4][..tcp] [..192.168.1.128][52070] -> [....18.65.82.67][...80] - new: [....34] [ip4][..tcp] [..192.168.1.128][38858] -> [142.250.180.142][..443] + new: [....33] [ip4][..tcp] [..192.168.1.128][52070] -> [....18.65.82.67][...80] + new: [....34] [ip4][..tcp] [..192.168.1.128][38858] -> [142.250.180.142][..443] detected: [....34] [ip4][..tcp] [..192.168.1.128][38858] -> [142.250.180.142][..443] [TLS.GoogleMaps][Google][Web][Safe][maps.google.com] detection-update: [....34] [ip4][..tcp] [..192.168.1.128][38858] -> [142.250.180.142][..443] [TLS.GoogleMaps][Google][Web][Safe][maps.google.com] - new: [....35] [ip4][..tcp] [..192.168.1.128][48902] -> [....2.17.140.63][..443] + new: [....35] [ip4][..tcp] [..192.168.1.128][48902] -> [....2.17.140.63][..443] detected: [....35] [ip4][..tcp] [..192.168.1.128][48902] -> [....2.17.140.63][..443] [TLS.Xbox][Unknown][Game][Fun][account.xbox.com] detection-update: [....35] [ip4][..tcp] [..192.168.1.128][48902] -> [....2.17.140.63][..443] [TLS.Xbox][Unknown][Game][Fun][account.xbox.com] - new: [....36] [ip4][..tcp] [..192.168.1.128][39828] -> [....40.97.160.2][..443] + new: [....36] [ip4][..tcp] [..192.168.1.128][39828] -> [....40.97.160.2][..443] detected: [....36] [ip4][..tcp] [..192.168.1.128][39828] -> [....40.97.160.2][..443] [TLS.Outlook][Outlook][Email][Acceptable][outlook.com] detection-update: [....36] [ip4][..tcp] [..192.168.1.128][39828] -> [....40.97.160.2][..443] [TLS.Outlook][Outlook][Email][Acceptable][outlook.com] DAEMON-EVENT: [Processed: 457 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 27 / 36|skipped: 0|!detected: 0|guessed: 0|detection-updates: 39|updates: 0] - new: [....37] [ip4][..tcp] [..192.168.1.128][45898] -> [..15.160.39.187][..443] + new: [....37] [ip4][..tcp] [..192.168.1.128][45898] -> [..15.160.39.187][..443] detected: [....37] [ip4][..tcp] [..192.168.1.128][45898] -> [..15.160.39.187][..443] [TLS.AppleSiri][AmazonAWS][VirtAssistant][Acceptable][guzzoni.apple.com] detection-update: [....37] [ip4][..tcp] [..192.168.1.128][45898] -> [..15.160.39.187][..443] [TLS.AppleSiri][AmazonAWS][VirtAssistant][Acceptable][guzzoni.apple.com] idle: [....22] [ip4][..tcp] [..192.168.1.128][51432] -> [.95.101.195.214][..443] [TLS.Hulu][Unknown][Streaming][Fun] guessed: [....23] [ip4][..tcp] [..192.168.1.128][44954] -> [..34.96.123.111][...80] [HTTP][GoogleCloud][Web][Acceptable][] - idle: [....23] [ip4][..tcp] [..192.168.1.128][44954] -> [..34.96.123.111][...80] + idle: [....23] [ip4][..tcp] [..192.168.1.128][44954] -> [..34.96.123.111][...80] guessed: [....25] [ip4][..tcp] [..192.168.1.128][39036] -> [..69.191.252.15][...80] [HTTP][Bloomberg][Web][Acceptable][] - idle: [....25] [ip4][..tcp] [..192.168.1.128][39036] -> [..69.191.252.15][...80] + idle: [....25] [ip4][..tcp] [..192.168.1.128][39036] -> [..69.191.252.15][...80] idle: [....10] [ip4][..tcp] [..192.168.1.128][35054] -> [..31.222.67.112][..443] [TLS.Badoo][Unknown][SocialNetwork][Fun] idle: [....26] [ip4][..tcp] [..192.168.1.128][43412] -> [.151.101.193.73][..443] [TLS.Bloomberg][Unknown][Cloud][Acceptable] idle: [....12] [ip4][..tcp] [..192.168.1.128][42580] -> [...2.17.141.128][..443] [TLS.Activision][Unknown][Game][Fun] idle: [....13] [ip4][..tcp] [..192.168.1.128][46084] -> [..146.75.62.167][..443] [TLS.Twitch][Unknown][Video][Fun] idle: [....31] [ip4][..tcp] [..192.168.1.128][46264] -> [...23.51.246.65][..443] [TLS.Playstation][Unknown][Game][Fun] guessed: [....14] [ip4][..tcp] [..192.168.1.128][45936] -> [..208.85.40.158][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [....14] [ip4][..tcp] [..192.168.1.128][45936] -> [..208.85.40.158][...80] + idle: [....14] [ip4][..tcp] [..192.168.1.128][45936] -> [..208.85.40.158][...80] idle: [....35] [ip4][..tcp] [..192.168.1.128][48902] -> [....2.17.140.63][..443] [TLS.Xbox][Unknown][Game][Fun] idle: [....18] [ip4][..tcp] [..192.168.1.128][40832] -> [....2.17.141.49][..443] [TLS.eBay][Unknown][Shopping][Safe] idle: [....30] [ip4][..tcp] [..192.168.1.128][57336] -> [....23.1.68.189][..443] [TLS.Playstation][Unknown][Game][Fun] @@ -184,7 +184,7 @@ idle: [....34] [ip4][..tcp] [..192.168.1.128][38858] -> [142.250.180.142][..443] [TLS.GoogleMaps][Google][Web][Safe] idle: [....32] [ip4][..tcp] [..192.168.1.128][43150] -> [.108.138.199.67][..443] [TLS.Deezer][AmazonAWS][Music][Fun] guessed: [....33] [ip4][..tcp] [..192.168.1.128][52070] -> [....18.65.82.67][...80] [HTTP][AmazonAWS][Web][Acceptable][] - idle: [....33] [ip4][..tcp] [..192.168.1.128][52070] -> [....18.65.82.67][...80] + idle: [....33] [ip4][..tcp] [..192.168.1.128][52070] -> [....18.65.82.67][...80] idle: [....29] [ip4][..tcp] [..192.168.1.128][39934] -> [..104.23.98.190][..443] [TLS.Pastebin][Cloudflare][Download][Potentially Dangerous] RISK: Unsafe Protocol idle: [....20] [ip4][..tcp] [..192.168.1.128][51248] -> [..95.131.169.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable] @@ -194,36 +194,36 @@ idle: [....21] [ip4][..tcp] [..192.168.1.128][39302] -> [..95.131.170.91][..443] [TLS.Tuenti][Unknown][VoIP][Acceptable] idle: [....17] [ip4][..tcp] [..192.168.1.128][48140] -> [.....23.1.66.79][..443] [TLS.CNN][Unknown][Web][Safe] idle: [....19] [ip4][..tcp] [..192.168.1.128][42884] -> [.185.125.190.21][..443] [TLS.UbuntuONE][UbuntuONE][Cloud][Acceptable] - new: [....38] [ip4][..tcp] [..192.168.1.128][57878] -> [.52.113.194.132][..443] + new: [....38] [ip4][..tcp] [..192.168.1.128][57878] -> [.52.113.194.132][..443] detected: [....38] [ip4][..tcp] [..192.168.1.128][57878] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.office.com] detection-update: [....38] [ip4][..tcp] [..192.168.1.128][57878] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.office.com] - new: [....39] [ip4][..tcp] [..192.168.1.128][33664] -> [108.138.185.106][..443] + new: [....39] [ip4][..tcp] [..192.168.1.128][33664] -> [108.138.185.106][..443] detected: [....39] [ip4][..tcp] [..192.168.1.128][33664] -> [108.138.185.106][..443] [TLS.AmazonVideo][AmazonAWS][Video][Fun][www.primevideo.com] detection-update: [....39] [ip4][..tcp] [..192.168.1.128][33664] -> [108.138.185.106][..443] [TLS.AmazonVideo][AmazonAWS][Video][Fun][www.primevideo.com] - new: [....40] [ip4][..tcp] [..192.168.1.128][56458] -> [142.250.185.142][..443] + new: [....40] [ip4][..tcp] [..192.168.1.128][56458] -> [142.250.185.142][..443] detected: [....40] [ip4][..tcp] [..192.168.1.128][56458] -> [142.250.185.142][..443] [TLS.GoogleDrive][Google][Cloud][Acceptable][drive.google.com] detection-update: [....40] [ip4][..tcp] [..192.168.1.128][56458] -> [142.250.185.142][..443] [TLS.GoogleDrive][Google][Cloud][Acceptable][drive.google.com] - new: [....41] [ip4][..tcp] [..192.168.1.128][33102] -> [...13.81.118.91][..443] + new: [....41] [ip4][..tcp] [..192.168.1.128][33102] -> [...13.81.118.91][..443] detected: [....41] [ip4][..tcp] [..192.168.1.128][33102] -> [...13.81.118.91][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][onedrive.com] detection-update: [....41] [ip4][..tcp] [..192.168.1.128][33102] -> [...13.81.118.91][..443] [TLS.Microsoft][Azure][Cloud][Safe][onedrive.com] - new: [....42] [ip4][..tcp] [..192.168.1.128][56836] -> [...13.107.42.13][..443] + new: [....42] [ip4][..tcp] [..192.168.1.128][56836] -> [...13.107.42.13][..443] detected: [....42] [ip4][..tcp] [..192.168.1.128][56836] -> [...13.107.42.13][..443] [TLS.MS_OneDrive][Azure][Cloud][Acceptable][onedrive.live.com] detection-update: [....42] [ip4][..tcp] [..192.168.1.128][56836] -> [...13.107.42.13][..443] [TLS.MS_OneDrive][Azure][Cloud][Acceptable][onedrive.live.com] - new: [....43] [ip4][..tcp] [..192.168.1.128][45014] -> [129.226.107.210][..443] + new: [....43] [ip4][..tcp] [..192.168.1.128][45014] -> [129.226.107.210][..443] detected: [....43] [ip4][..tcp] [..192.168.1.128][45014] -> [129.226.107.210][..443] [TLS.IFLIX][Tencent][Video][Fun][www.iflix.com] detection-update: [....43] [ip4][..tcp] [..192.168.1.128][45014] -> [129.226.107.210][..443] [TLS.IFLIX][Tencent][Video][Fun][www.iflix.com] detection-update: [....43] [ip4][..tcp] [..192.168.1.128][45014] -> [129.226.107.210][..443] [TLS.IFLIX][Tencent][Video][Fun][www.iflix.com] - new: [....44] [ip4][..udp] [..192.168.1.128][38642] -> [.216.58.212.142][..443] + new: [....44] [ip4][..udp] [..192.168.1.128][38642] -> [.216.58.212.142][..443] detected: [....44] [ip4][..udp] [..192.168.1.128][38642] -> [.216.58.212.142][..443] [QUIC.Google][Google][Web][Acceptable][hangouts.google.com] - new: [....45] [ip4][..tcp] [..192.168.1.128][50608] -> [142.250.185.206][..443] + new: [....45] [ip4][..tcp] [..192.168.1.128][50608] -> [142.250.185.206][..443] detected: [....45] [ip4][..tcp] [..192.168.1.128][50608] -> [142.250.185.206][..443] [TLS][Google][Web][Safe][googleplus.com] detection-update: [....45] [ip4][..tcp] [..192.168.1.128][50608] -> [142.250.185.206][..443] [TLS][Google][Web][Safe][googleplus.com] - new: [....46] [ip4][..udp] [..192.168.1.128][36832] -> [142.250.181.238][..443] + new: [....46] [ip4][..udp] [..192.168.1.128][36832] -> [142.250.181.238][..443] detected: [....46] [ip4][..udp] [..192.168.1.128][36832] -> [142.250.181.238][..443] [QUIC.GooglePlus][Google][SocialNetwork][Fun][plus.google.com] update: [....44] [ip4][..udp] [..192.168.1.128][38642] -> [.216.58.212.142][..443] [QUIC.Google][Google][Web][Acceptable] DAEMON-EVENT: [Processed: 512 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 10 / 46|skipped: 0|!detected: 0|guessed: 4|detection-updates: 48|updates: 1] - new: [....47] [ip4][..tcp] [..192.168.1.128][53978] -> [..208.85.40.158][..443] + new: [....47] [ip4][..tcp] [..192.168.1.128][53978] -> [..208.85.40.158][..443] detected: [....47] [ip4][..tcp] [..192.168.1.128][53978] -> [..208.85.40.158][..443] [TLS.Pandora][Unknown][Streaming][Fun][pandora.com] detection-update: [....47] [ip4][..tcp] [..192.168.1.128][53978] -> [..208.85.40.158][..443] [TLS.Pandora][Unknown][Streaming][Fun][pandora.com] detection-update: [....47] [ip4][..tcp] [..192.168.1.128][53978] -> [..208.85.40.158][..443] [TLS.Pandora][Unknown][Streaming][Fun][pandora.com] diff --git a/test/results/flow-info/default/skinny.pcap.out b/test/results/flow-info/default/skinny.pcap.out index 24ce9ee00..987c76adc 100644 --- a/test/results/flow-info/default/skinny.pcap.out +++ b/test/results/flow-info/default/skinny.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.195.58][49399] -> [.192.168.193.12][.2000] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.192.168.195.58][49399] -> [.192.168.193.12][.2000] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.192.168.195.58][49399] -> [.192.168.193.12][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] - new: [.....2] [ip4][..tcp] [.192.168.193.12][.2000] -> [.192.168.195.50][51532] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [.192.168.193.12][.2000] -> [.192.168.195.50][51532] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [.192.168.193.12][.2000] -> [.192.168.195.50][51532] [CiscoSkinny][Unknown][VoIP][Acceptable] analyse: [.....1] [ip4][..tcp] [.192.168.195.58][49399] -> [.192.168.193.12][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,13 +15,13 @@ [IATS(ms)....: 2.2,0.0,0.0,6.0,3.8,0.3,0.0,0.0,20.0,19.7,10.4,48.8,3559.6,0.0,0.1,3609.8,11.7,20.1,16.5,36.5,7.0,23.4,32.8,20.0,11.7,0.0,20.0,11.5,27.3,50.7,26.7] [PKTLENS.....: 64,68,56,64,46,364,68,76,68,46,200,60,46,64,180,76,46,252,46,88,46,184,46,184,46,184,172,46,92,92,46,92] [ENTROPIES...: 3.9,4.0,4.5,4.3,4.4,3.7,4.4,4.2,4.6,4.4,4.5,4.3,4.7,4.5,2.6,4.2,4.4,4.3,4.5,4.0,4.7,2.7,4.5,2.7,4.5,2.6,4.7,4.4,4.0,4.0,4.6,4.0] - new: [.....3] [ip4][..udp] [.192.168.195.58][32150] -> [.192.168.193.24][.9395] - new: [.....4] [ip4][..udp] [.192.168.195.58][32144] -> [.192.168.195.50][17718] + new: [.....3] [ip4][..udp] [.192.168.195.58][32150] -> [.192.168.193.24][.9395] + new: [.....4] [ip4][..udp] [.192.168.195.58][32144] -> [.192.168.195.50][17718] detected: [.....4] [ip4][..udp] [.192.168.195.58][32144] -> [.192.168.195.50][17718] [RTP][Unknown][Media][Acceptable] - new: [.....5] [ip4][..udp] [.192.168.195.50][17726] -> [.192.168.193.24][.9399] - new: [.....6] [ip4][..udp] [.192.168.195.58][32152] -> [.192.168.193.24][.9396] + new: [.....5] [ip4][..udp] [.192.168.195.50][17726] -> [.192.168.193.24][.9399] + new: [.....6] [ip4][..udp] [.192.168.195.58][32152] -> [.192.168.193.24][.9396] detected: [.....3] [ip4][..udp] [.192.168.195.58][32150] -> [.192.168.193.24][.9395] [RTP][Unknown][Media][Acceptable] - new: [.....7] [ip4][..udp] [.192.168.195.50][17732] -> [.192.168.193.24][.9400] + new: [.....7] [ip4][..udp] [.192.168.195.50][17732] -> [.192.168.193.24][.9400] detected: [.....5] [ip4][..udp] [.192.168.195.50][17726] -> [.192.168.193.24][.9399] [RTP][Unknown][Media][Acceptable] detected: [.....6] [ip4][..udp] [.192.168.195.58][32152] -> [.192.168.193.24][.9396] [RTP][Unknown][Media][Acceptable] detected: [.....7] [ip4][..udp] [.192.168.195.50][17732] -> [.192.168.193.24][.9400] [RTP][Unknown][Media][Acceptable] @@ -75,7 +75,7 @@ [IATS(ms)....: 20.0,20.0,20.1,20.0,20.0,20.0,20.0,20.0,20.0,20.0,20.0,20.0,20.0,20.1,20.0,20.0,20.0,20.1,19.9,20.0,19.9,20.0,19.9,20.0,20.1,20.0,20.0,20.0,20.0,20.0,20.0] [PKTLENS.....: 200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200,200] [ENTROPIES...: 4.9,5.0,5.1,5.2,5.8,5.2,4.8,5.0,5.2,4.8,4.8,4.9,4.7,4.5,4.6,4.6,4.5,4.5,4.3,4.4,4.6,4.4,4.4,4.5,4.8,4.7,4.7,3.9,4.3,5.2,5.6,5.5] - new: [.....8] [ip4][..tcp] [.192.168.195.58][50917] -> [.....10.16.2.25][.2000] [MIDSTREAM] + new: [.....8] [ip4][..tcp] [.192.168.195.58][50917] -> [.....10.16.2.25][.2000] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [.192.168.195.58][50917] -> [.....10.16.2.25][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] analyse: [.....2] [ip4][..tcp] [.192.168.193.12][.2000] -> [.192.168.195.50][51532] [CiscoSkinny][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -87,7 +87,7 @@ [IATS(ms)....: 0.0,0.1,0.7,0.7,19.9,3583.0,19.3,3622.2,2.1,0.0,0.0,18.0,15.9,20.1,36.3,2.1,20.0,30.9,40.0,6.9,19.1,13.1,64.1,28.3,103.9,42.3,80.4,6999.6,0.0,5.8,7045.9] [PKTLENS.....: 76,68,72,46,252,46,60,60,46,68,56,64,46,532,46,184,184,46,184,46,88,172,46,92,92,46,92,46,68,68,64,46] [ENTROPIES...: 4.2,4.7,4.6,4.6,4.3,4.5,4.2,4.5,4.6,4.1,4.5,4.3,4.4,3.3,4.4,2.7,2.6,4.4,2.7,4.4,3.8,4.8,4.5,4.0,3.9,4.6,4.0,4.6,4.5,4.6,4.4,4.6] - new: [.....9] [ip4][.icmp] [.192.168.195.50] -> [.192.168.195.58] + new: [.....9] [ip4][.icmp] [.192.168.195.50] -> [.192.168.195.58] detected: [.....9] [ip4][.icmp] [.192.168.195.50] -> [.192.168.195.58] [ICMP][Unknown][Network][Acceptable] idle: [.....9] [ip4][.icmp] [.192.168.195.50] -> [.192.168.195.58] [ICMP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [.192.168.195.58][49399] -> [.192.168.193.12][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/skype-conference-call.pcap.out b/test/results/flow-info/default/skype-conference-call.pcap.out index 83759e2ec..2f58f6218 100644 --- a/test/results/flow-info/default/skype-conference-call.pcap.out +++ b/test/results/flow-info/default/skype-conference-call.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.2.20][49282] -> [...104.46.40.49][60642] + new: [.....1] [ip4][..udp] [...192.168.2.20][49282] -> [...104.46.40.49][60642] detected: [.....1] [ip4][..udp] [...192.168.2.20][49282] -> [...104.46.40.49][60642] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [.....1] [ip4][..udp] [...192.168.2.20][49282] -> [...104.46.40.49][60642] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable] diff --git a/test/results/flow-info/default/skype.pcap.out b/test/results/flow-info/default/skype.pcap.out index 31e527880..5201b8cbc 100644 --- a/test/results/flow-info/default/skype.pcap.out +++ b/test/results/flow-info/default/skype.pcap.out @@ -1,51 +1,51 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.1.34][49163] -> [....192.168.1.1][...53] + new: [.....1] [ip4][..udp] [...192.168.1.34][49163] -> [....192.168.1.1][...53] detected: [.....1] [ip4][..udp] [...192.168.1.34][49163] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [.....2] [ip4][..udp] [...192.168.1.34][57406] -> [....192.168.1.1][...53] + new: [.....2] [ip4][..udp] [...192.168.1.34][57406] -> [....192.168.1.1][...53] detected: [.....2] [ip4][..udp] [...192.168.1.34][57406] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [.....3] [ip4][..udp] [...192.168.1.34][55711] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [...192.168.1.34][55711] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [...192.168.1.34][55711] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] - new: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] + new: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] detected: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] - new: [.....5] [ip4][..udp] [...192.168.1.34][54396] -> [....192.168.1.1][...53] + new: [.....5] [ip4][..udp] [...192.168.1.34][54396] -> [....192.168.1.1][...53] detected: [.....5] [ip4][..udp] [...192.168.1.34][54396] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][api.skype.com] - new: [.....6] [ip4][..udp] [...192.168.1.34][65426] -> [....192.168.1.1][...53] + new: [.....6] [ip4][..udp] [...192.168.1.34][65426] -> [....192.168.1.1][...53] detected: [.....6] [ip4][..udp] [...192.168.1.34][65426] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][api.skype.com] - new: [.....7] [ip4][..udp] [...192.168.1.34][64085] -> [....192.168.1.1][...53] + new: [.....7] [ip4][..udp] [...192.168.1.34][64085] -> [....192.168.1.1][...53] detected: [.....7] [ip4][..udp] [...192.168.1.34][64085] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e7768.b.akamaiedge.net] - new: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] + new: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] detected: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][db3msgr5011709.gateway.messenger.live.com] - new: [.....9] [ip4][..tcp] [...192.168.1.34][50026] -> [...65.55.223.33][40002] - new: [....10] [ip4][..udp] [...192.168.1.34][49793] -> [....192.168.1.1][...53] + new: [.....9] [ip4][..tcp] [...192.168.1.34][50026] -> [...65.55.223.33][40002] + new: [....10] [ip4][..udp] [...192.168.1.34][49793] -> [....192.168.1.1][...53] detected: [....10] [ip4][..udp] [...192.168.1.34][49793] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][dsn4.d.skype.net] - new: [....11] [ip4][..udp] [...192.168.1.34][65045] -> [....192.168.1.1][...53] + new: [....11] [ip4][..udp] [...192.168.1.34][65045] -> [....192.168.1.1][...53] detected: [....11] [ip4][..udp] [...192.168.1.34][65045] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][dsn4.d.skype.net] detection-update: [.....7] [ip4][..udp] [...192.168.1.34][64085] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e7768.b.akamaiedge.net] - new: [....12] [ip4][..tcp] [...192.168.1.34][50027] -> [...23.223.73.34][..443] - new: [....13] [ip4][..udp] [...192.168.1.34][49990] -> [....192.168.1.1][...53] + new: [....12] [ip4][..tcp] [...192.168.1.34][50027] -> [...23.223.73.34][..443] + new: [....13] [ip4][..udp] [...192.168.1.34][49990] -> [....192.168.1.1][...53] detected: [....13] [ip4][..udp] [...192.168.1.34][49990] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst6.r.skype.net] - new: [....14] [ip4][..udp] [...192.168.1.34][57288] -> [....192.168.1.1][...53] + new: [....14] [ip4][..udp] [...192.168.1.34][57288] -> [....192.168.1.1][...53] detected: [....14] [ip4][..udp] [...192.168.1.34][57288] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst6.r.skype.net] detection-update: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][db3msgr5011709.gateway.messenger.live.com] detected: [....12] [ip4][..tcp] [...192.168.1.34][50027] -> [...23.223.73.34][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][apps.skypeassets.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] + new: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] detected: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older) - new: [....16] [ip4][..udp] [...192.168.1.34][49903] -> [....192.168.1.1][...53] + new: [....16] [ip4][..udp] [...192.168.1.34][49903] -> [....192.168.1.1][...53] detected: [....16] [ip4][..udp] [...192.168.1.34][49903] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] - new: [....17] [ip4][..udp] [...192.168.1.34][51879] -> [....192.168.1.1][...53] + new: [....17] [ip4][..udp] [...192.168.1.34][51879] -> [....192.168.1.1][...53] detected: [....17] [ip4][..udp] [...192.168.1.34][51879] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] detection-update: [.....1] [ip4][..udp] [...192.168.1.34][49163] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [...192.168.1.34][57406] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic detection-update: [....17] [ip4][..udp] [...192.168.1.34][51879] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] - new: [....18] [ip4][..tcp] [...192.168.1.34][50029] -> [..23.206.33.166][..443] + new: [....18] [ip4][..tcp] [...192.168.1.34][50029] -> [..23.206.33.166][..443] detected: [....18] [ip4][..tcp] [...192.168.1.34][50029] -> [..23.206.33.166][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][apps.skype.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..udp] [...192.168.1.34][55711] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] @@ -74,10 +74,10 @@ [IATS(ms)....: 75.2,75.2,28.8,111.2,0.2,82.6,77.2,0.2,77.4,12.7,300.9,288.2,83.4,83.5,0.3,86.7,86.3,3.1,96.5,93.4,0.3,253.9,0.0,253.6,0.0,0.4,87.2,86.8,115.8,0.0,115.7] [PKTLENS.....: 64,56,52,146,1492,72,52,1492,850,52,159,52,111,111,52,281,233,52,681,233,52,249,745,265,52,52,617,153,1369,1492,57,52] [ENTROPIES...: 4.6,5.4,5.2,5.8,7.0,5.6,5.2,7.5,7.7,5.2,6.7,5.2,6.0,6.1,5.1,7.2,7.1,5.2,7.7,7.0,5.2,7.0,7.7,7.2,5.2,5.1,7.7,6.7,7.9,7.9,5.3,5.1] - new: [....19] [ip4][..tcp] [...192.168.1.34][50030] -> [...65.55.223.33][..443] - new: [....20] [ip4][..udp] [...192.168.1.34][60288] -> [....192.168.1.1][...53] + new: [....19] [ip4][..tcp] [...192.168.1.34][50030] -> [...65.55.223.33][..443] + new: [....20] [ip4][..udp] [...192.168.1.34][60288] -> [....192.168.1.1][...53] detected: [....20] [ip4][..udp] [...192.168.1.34][60288] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [....21] [ip4][..udp] [...192.168.1.34][57726] -> [....192.168.1.1][...53] + new: [....21] [ip4][..udp] [...192.168.1.34][57726] -> [....192.168.1.1][...53] detected: [....21] [ip4][..udp] [...192.168.1.34][57726] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] detection-update: [....16] [ip4][..udp] [...192.168.1.34][49903] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] RISK: Unidirectional Traffic @@ -85,341 +85,341 @@ RISK: Unidirectional Traffic detection-update: [....21] [ip4][..udp] [...192.168.1.34][57726] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic - new: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] + new: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] detected: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....23] [ip4][..tcp] [.108.160.170.46][..443] -> [...192.168.1.34][49445] [MIDSTREAM] + new: [....23] [ip4][..tcp] [.108.160.170.46][..443] -> [...192.168.1.34][49445] [MIDSTREAM] detected: [....23] [ip4][..tcp] [.108.160.170.46][..443] -> [...192.168.1.34][49445] [TLS][Dropbox][Web][Safe] - new: [....24] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.166][40022] + new: [....24] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.166][40022] detected: [....24] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.166][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] + new: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] detected: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....26] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.142][40023] + new: [....26] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.142][40023] detected: [....26] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.142][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....27] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40024] + new: [....27] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40024] detected: [....27] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....28] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] + new: [....28] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] detected: [....28] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] + new: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] detected: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....30] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40028] + new: [....30] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40028] detected: [....30] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] + new: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] detected: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] + new: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] detected: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] + new: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] detected: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40020] + new: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40020] detected: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.150][40004] + new: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.150][40004] detected: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.150][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40001] + new: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40001] detected: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.48][40008] + new: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.48][40008] detected: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.48][40008] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40024] + new: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40024] detected: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] + new: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] detected: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] + new: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] detected: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.162][40004] + new: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.162][40004] detected: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.162][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40011] + new: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40011] detected: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.172][40010] + new: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.172][40010] detected: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.172][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40029] + new: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40029] detected: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....45] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] + new: [....45] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] detected: [....45] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....46] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] + new: [....46] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] detected: [....46] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....47] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] + new: [....47] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] detected: [....47] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....48] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] + new: [....48] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] detected: [....48] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....49] [ip4][..tcp] [...192.168.1.34][50032] -> [...157.56.52.44][40032] - new: [....50] [ip4][..tcp] [...192.168.1.34][50033] -> [..157.55.56.170][40015] - new: [....51] [ip4][..tcp] [...192.168.1.34][50034] -> [.157.55.130.140][40033] - new: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40027] + new: [....49] [ip4][..tcp] [...192.168.1.34][50032] -> [...157.56.52.44][40032] + new: [....50] [ip4][..tcp] [...192.168.1.34][50033] -> [..157.55.56.170][40015] + new: [....51] [ip4][..tcp] [...192.168.1.34][50034] -> [.157.55.130.140][40033] + new: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40027] detected: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40012] + new: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40012] detected: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.150][40004] + new: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.150][40004] detected: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.150][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....55] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.25][40028] + new: [....55] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.25][40028] detected: [....55] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.25][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....56] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.153][40024] + new: [....56] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.153][40024] detected: [....56] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.153][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....57] [ip4][..tcp] [...192.168.1.34][50035] -> [213.199.179.175][40021] - new: [....58] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.38][40015] + new: [....57] [ip4][..tcp] [...192.168.1.34][50035] -> [213.199.179.175][40021] + new: [....58] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.38][40015] detected: [....58] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.38][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....59] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40008] + new: [....59] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40008] detected: [....59] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40008] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....60] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40002] + new: [....60] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40002] detected: [....60] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....61] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40012] + new: [....61] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40012] detected: [....61] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.17][40022] + new: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.17][40022] detected: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.17][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....63] [ip4][..tcp] [...192.168.1.34][50036] -> [...157.56.52.44][..443] - new: [....64] [ip4][..tcp] [...192.168.1.34][50037] -> [..157.55.56.170][..443] - new: [....65] [ip4][..tcp] [...192.168.1.34][50038] -> [.157.55.130.140][..443] - new: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] + new: [....63] [ip4][..tcp] [...192.168.1.34][50036] -> [...157.56.52.44][..443] + new: [....64] [ip4][..tcp] [...192.168.1.34][50037] -> [..157.55.56.170][..443] + new: [....65] [ip4][..tcp] [...192.168.1.34][50038] -> [.157.55.130.140][..443] + new: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] detected: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....67] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40005] + new: [....67] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40005] detected: [....67] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40005] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.45][40012] + new: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.45][40012] detected: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.45][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40001] + new: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40001] detected: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.45][40012] + new: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.45][40012] detected: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.45][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....71] [ip4][..tcp] [...192.168.1.34][50039] -> [213.199.179.175][..443] - new: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40022] + new: [....71] [ip4][..tcp] [...192.168.1.34][50039] -> [213.199.179.175][..443] + new: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40022] detected: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....73] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.159][40009] + new: [....73] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.159][40009] detected: [....73] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.159][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....74] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.142][40025] + new: [....74] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.142][40025] detected: [....74] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.142][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....75] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] + new: [....75] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] detected: [....75] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.21][40004] + new: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.21][40004] detected: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.21][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40027] + new: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40027] detected: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] + new: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] detected: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] + new: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] detected: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.168][40007] + new: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.168][40007] detected: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.168][40007] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....81] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40031] + new: [....81] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40031] detected: [....81] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.152][40001] + new: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.152][40001] detected: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.152][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] + new: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] detected: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] + new: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] detected: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.25][40028] + new: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.25][40028] detected: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.25][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.151][40027] + new: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.151][40027] detected: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.151][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....87] [ip4][..tcp] [...192.168.1.34][50044] -> [.157.55.130.167][40031] - new: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.166][40022] + new: [....87] [ip4][..tcp] [...192.168.1.34][50044] -> [.157.55.130.167][40031] + new: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.166][40022] detected: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.166][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.155][40004] + new: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.155][40004] detected: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40027] + new: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40027] detected: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.173][40012] + new: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.173][40012] detected: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.173][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.157][40010] + new: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.157][40010] detected: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.157][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....93] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] + new: [....93] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] detected: [....93] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40007] + new: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40007] detected: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40007] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40033] + new: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40033] detected: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40010] + new: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40010] detected: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....97] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.148][40029] + new: [....97] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.148][40029] detected: [....97] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.148][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.141][40020] + new: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.141][40020] detected: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.141][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....99] [ip4][..tcp] [...192.168.1.34][50045] -> [.157.55.130.167][..443] - new: [...100] [ip4][....2] [...192.168.1.92] -> [....224.0.0.251] + new: [....99] [ip4][..tcp] [...192.168.1.34][50045] -> [.157.55.130.167][..443] + new: [...100] [ip4][....2] [...192.168.1.92] -> [....224.0.0.251] detected: [...100] [ip4][....2] [...192.168.1.92] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [...101] [ip4][..tcp] [...192.168.1.34][50046] -> [.157.55.130.150][40011] - new: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40032] + new: [...101] [ip4][..tcp] [...192.168.1.34][50046] -> [.157.55.130.150][40011] + new: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40032] detected: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.175][40013] + new: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.175][40013] detected: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.175][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] + new: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] detected: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40027] + new: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40027] detected: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] + new: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] detected: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40013] + new: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40013] detected: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...108] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.26][40026] + new: [...108] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.26][40026] detected: [...108] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.26][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...109] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] + new: [...109] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] detected: [...109] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.41][40027] + new: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.41][40027] detected: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.41][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.47][40029] + new: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.47][40029] detected: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.47][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...112] [ip4][..tcp] [...192.168.1.34][50048] -> [.157.55.130.150][..443] - new: [...113] [ip4][..tcp] [...192.168.1.34][50049] -> [.157.55.130.166][40021] - new: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] + new: [...112] [ip4][..tcp] [...192.168.1.34][50048] -> [.157.55.130.150][..443] + new: [...113] [ip4][..tcp] [...192.168.1.34][50049] -> [.157.55.130.166][40021] + new: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] detected: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.168][40006] + new: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.168][40006] detected: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.168][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40023] + new: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40023] detected: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] + new: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] detected: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40011] + new: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40011] detected: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.155][40004] + new: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.155][40004] detected: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...120] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.143][40017] + new: [...120] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.143][40017] detected: [...120] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.143][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...121] [ip4][..udp] [...192.168.1.92][57621] -> [..192.168.1.255][57621] + new: [...121] [ip4][..udp] [...192.168.1.92][57621] -> [..192.168.1.255][57621] detected: [...121] [ip4][..udp] [...192.168.1.92][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [...122] [ip4][..tcp] [...192.168.1.34][50051] -> [.157.55.130.166][..443] - new: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.168][40006] + new: [...122] [ip4][..tcp] [...192.168.1.34][50051] -> [.157.55.130.166][..443] + new: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.168][40006] detected: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.168][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] + new: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] detected: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] + new: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] detected: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] + new: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] detected: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...127] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.32][40009] + new: [...127] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.32][40009] detected: [...127] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.32][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.141][40004] + new: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.141][40004] detected: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.141][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40026] + new: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40026] detected: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...130] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.161][40011] + new: [...130] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.161][40011] detected: [...130] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.161][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40034] + new: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40034] detected: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] + new: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] detected: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...133] [ip4][..tcp] [...192.168.1.34][50053] -> [..157.55.56.146][40030] - new: [...134] [ip4][..tcp] [...192.168.1.34][50054] -> [.157.55.130.153][40005] - new: [...135] [ip4][..tcp] [...192.168.1.34][50055] -> [..111.221.74.47][40030] - new: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] + new: [...133] [ip4][..tcp] [...192.168.1.34][50053] -> [..157.55.56.146][40030] + new: [...134] [ip4][..tcp] [...192.168.1.34][50054] -> [.157.55.130.153][40005] + new: [...135] [ip4][..tcp] [...192.168.1.34][50055] -> [..111.221.74.47][40030] + new: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] detected: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.153][40023] + new: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.153][40023] detected: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.153][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40030] + new: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40030] detected: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...139] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40026] + new: [...139] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40026] detected: [...139] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...140] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40022] + new: [...140] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40022] detected: [...140] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...141] [ip4][..tcp] [...192.168.1.34][50056] -> [..157.55.56.146][..443] - new: [...142] [ip4][..tcp] [...192.168.1.34][50057] -> [.157.55.130.153][..443] - new: [...143] [ip4][..tcp] [...192.168.1.34][50058] -> [..111.221.74.47][..443] - new: [...144] [ip4][..tcp] [...192.168.1.34][50059] -> [..111.221.74.38][40015] - new: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.21][40027] + new: [...141] [ip4][..tcp] [...192.168.1.34][50056] -> [..157.55.56.146][..443] + new: [...142] [ip4][..tcp] [...192.168.1.34][50057] -> [.157.55.130.153][..443] + new: [...143] [ip4][..tcp] [...192.168.1.34][50058] -> [..111.221.74.47][..443] + new: [...144] [ip4][..tcp] [...192.168.1.34][50059] -> [..111.221.74.38][40015] + new: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.21][40027] detected: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.21][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...146] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.140][40003] + new: [...146] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.140][40003] detected: [...146] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.140][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...147] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] + new: [...147] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] detected: [...147] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...148] [ip4][..tcp] [...192.168.1.34][50024] -> [..17.172.100.36][..443] [MIDSTREAM] - new: [...149] [ip4][..udp] [...192.168.1.34][55159] -> [....192.168.1.1][...53] + new: [...148] [ip4][..tcp] [...192.168.1.34][50024] -> [..17.172.100.36][..443] [MIDSTREAM] + new: [...149] [ip4][..udp] [...192.168.1.34][55159] -> [....192.168.1.1][...53] detected: [...149] [ip4][..udp] [...192.168.1.34][55159] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][a.config.skype.trafficmanager.net] - new: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] + new: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] detected: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][a.config.skype.trafficmanager.net] - new: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.147][40020] + new: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.147][40020] detected: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.147][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40020] + new: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40020] detected: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...153] [ip4][..tcp] [...192.168.1.34][50063] -> [..111.221.74.38][..443] + new: [...153] [ip4][..tcp] [...192.168.1.34][50063] -> [..111.221.74.38][..443] detection-update: [...149] [ip4][..udp] [...192.168.1.34][55159] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][a.config.skype.trafficmanager.net] RISK: Unidirectional Traffic detection-update: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][a.config.skype.trafficmanager.net] RISK: Unidirectional Traffic - new: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.166][40011] + new: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.166][40011] detected: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.166][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...155] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40026] + new: [...155] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40026] detected: [...155] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...156] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] + new: [...156] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] detected: [...156] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...157] [ip4][..udp] [...192.168.1.34][58458] -> [....192.168.1.1][...53] + new: [...157] [ip4][..udp] [...192.168.1.34][58458] -> [....192.168.1.1][...53] detected: [...157] [ip4][..udp] [...192.168.1.34][58458] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...158] [ip4][..udp] [...192.168.1.34][49360] -> [....192.168.1.1][...53] + new: [...158] [ip4][..udp] [...192.168.1.34][49360] -> [....192.168.1.1][...53] detected: [...158] [ip4][..udp] [...192.168.1.34][49360] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...159] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.145][40022] + new: [...159] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.145][40022] detected: [...159] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.145][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...160] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.26][40004] + new: [...160] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.26][40004] detected: [...160] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.26][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] detection-update: [...157] [ip4][..udp] [...192.168.1.34][58458] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic detection-update: [...158] [ip4][..udp] [...192.168.1.34][49360] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic - new: [...161] [ip4][..tcp] [...192.168.1.34][50065] -> [...65.55.223.12][40031] - new: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.151][40017] + new: [...161] [ip4][..tcp] [...192.168.1.34][50065] -> [...65.55.223.12][40031] + new: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.151][40017] detected: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.151][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.170][40011] + new: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.170][40011] detected: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.176][40020] + new: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.176][40020] detected: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.176][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.148][40010] + new: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.148][40010] detected: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.148][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...166] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40031] + new: [...166] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40031] detected: [...166] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...167] [ip4][..tcp] [...192.168.1.34][50066] -> [...65.55.223.12][..443] - new: [...168] [ip4][..tcp] [...192.168.1.34][50067] -> [..157.55.56.160][40027] - new: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.162][40029] + new: [...167] [ip4][..tcp] [...192.168.1.34][50066] -> [...65.55.223.12][..443] + new: [...168] [ip4][..tcp] [...192.168.1.34][50067] -> [..157.55.56.160][40027] + new: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.162][40029] detected: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.162][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...170] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.16][40032] + new: [...170] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.16][40032] detected: [...170] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.16][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.159][40021] + new: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.159][40021] detected: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.159][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][33033] + new: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][33033] detected: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40014] + new: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40014] detected: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40014] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...174] [ip4][..tcp] [...192.168.1.34][50069] -> [..157.55.56.160][..443] - new: [...175] [ip4][..udp] [...192.168.1.34][54343] -> [....192.168.1.1][...53] + new: [...174] [ip4][..tcp] [...192.168.1.34][50069] -> [..157.55.56.160][..443] + new: [...175] [ip4][..udp] [...192.168.1.34][54343] -> [....192.168.1.1][...53] detected: [...175] [ip4][..udp] [...192.168.1.34][54343] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst13.r.skype.net] - new: [...176] [ip4][..udp] [...192.168.1.34][58368] -> [....192.168.1.1][...53] + new: [...176] [ip4][..udp] [...192.168.1.34][58368] -> [....192.168.1.1][...53] detected: [...176] [ip4][..udp] [...192.168.1.34][58368] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst13.r.skype.net] - new: [...177] [ip4][..tcp] [...192.168.1.34][50070] -> [.157.55.130.170][40018] - new: [...178] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] + new: [...177] [ip4][..tcp] [...192.168.1.34][50070] -> [.157.55.130.170][40018] + new: [...178] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] detected: [...178] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.37][40032] + new: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.37][40032] detected: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.37][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] + new: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] detected: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.172][40019] + new: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.172][40019] detected: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.172][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40018] + new: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40018] detected: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] detection-update: [...175] [ip4][..udp] [...192.168.1.34][54343] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst13.r.skype.net] RISK: Unidirectional Traffic detection-update: [...176] [ip4][..udp] [...192.168.1.34][58368] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst13.r.skype.net] RISK: Unidirectional Traffic - new: [...183] [ip4][..tcp] [...192.168.1.34][50072] -> [.157.55.130.170][..443] - new: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.12][40031] + new: [...183] [ip4][..tcp] [...192.168.1.34][50072] -> [.157.55.130.170][..443] + new: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.12][40031] detected: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.12][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...185] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40034] + new: [...185] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40034] detected: [...185] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...186] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.31][40021] + new: [...186] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.31][40021] detected: [...186] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.31][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.29][40024] + new: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.29][40024] detected: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.29][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.147][40019] + new: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.147][40019] detected: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.147][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.168][40006] + new: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.168][40006] detected: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.168][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.29][40010] + new: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.29][40010] detected: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.29][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...191] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] + new: [...191] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] detected: [...191] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40009] + new: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40009] detected: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] + new: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] detected: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...194] [ip4][..tcp] [...192.168.1.34][50074] -> [.157.55.130.173][40003] - new: [...195] [ip4][..tcp] [...192.168.1.34][50075] -> [213.199.179.142][40003] - new: [...196] [ip4][..tcp] [...192.168.1.34][50076] -> [.157.55.235.156][40014] - new: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] + new: [...194] [ip4][..tcp] [...192.168.1.34][50074] -> [.157.55.130.173][40003] + new: [...195] [ip4][..tcp] [...192.168.1.34][50075] -> [213.199.179.142][40003] + new: [...196] [ip4][..tcp] [...192.168.1.34][50076] -> [.157.55.235.156][40014] + new: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] detected: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...198] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40032] + new: [...198] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40032] detected: [...198] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...199] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.152][40023] + new: [...199] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.152][40023] detected: [...199] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.152][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic @@ -450,34 +450,34 @@ update: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] update: [....11] [ip4][..udp] [...192.168.1.34][65045] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...200] [ip4][..tcp] [...192.168.1.34][50077] -> [.157.55.130.176][40022] - new: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40024] + new: [...200] [ip4][..tcp] [...192.168.1.34][50077] -> [.157.55.130.176][40022] + new: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40024] detected: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.165][40020] + new: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.165][40020] detected: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.165][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...203] [ip4][..tcp] [...192.168.1.34][50078] -> [.157.55.130.173][..443] - new: [...204] [ip4][..tcp] [...192.168.1.34][50079] -> [213.199.179.142][..443] - new: [...205] [ip4][..tcp] [...192.168.1.34][50080] -> [.157.55.235.156][..443] - new: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] + new: [...203] [ip4][..tcp] [...192.168.1.34][50078] -> [.157.55.130.173][..443] + new: [...204] [ip4][..tcp] [...192.168.1.34][50079] -> [213.199.179.142][..443] + new: [...205] [ip4][..tcp] [...192.168.1.34][50080] -> [.157.55.235.156][..443] + new: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] detected: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...207] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40027] + new: [...207] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40027] detected: [...207] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...208] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40003] + new: [...208] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40003] detected: [...208] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...209] [ip4][..tcp] [...192.168.1.34][50081] -> [.157.55.130.176][..443] - new: [...210] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] + new: [...209] [ip4][..tcp] [...192.168.1.34][50081] -> [.157.55.130.176][..443] + new: [...210] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] detected: [...210] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...211] [ip4][..tcp] [...192.168.1.34][50086] -> [.111.221.77.142][40023] - new: [...212] [ip4][..tcp] [...192.168.1.34][50087] -> [.111.221.77.142][..443] - new: [...213] [ip4][..tcp] [...192.168.1.34][50088] -> [.157.55.235.146][33033] - new: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] + new: [...211] [ip4][..tcp] [...192.168.1.34][50086] -> [.111.221.77.142][40023] + new: [...212] [ip4][..tcp] [...192.168.1.34][50087] -> [.111.221.77.142][..443] + new: [...213] [ip4][..tcp] [...192.168.1.34][50088] -> [.157.55.235.146][33033] + new: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] detected: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] detection-update: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] - new: [...215] [ip4][..tcp] [...192.168.1.34][50090] -> [..23.206.33.166][..443] + new: [...215] [ip4][..tcp] [...192.168.1.34][50090] -> [..23.206.33.166][..443] detected: [...215] [ip4][..tcp] [...192.168.1.34][50090] -> [..23.206.33.166][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][apps.skype.com] RISK: Obsolete TLS (v1.1 or older) - new: [...216] [ip4][..tcp] [...192.168.1.34][50091] -> [.157.55.235.146][..443] - new: [...217] [ip4][..tcp] [...192.168.1.34][50092] -> [.157.55.130.155][40020] + new: [...216] [ip4][..tcp] [...192.168.1.34][50091] -> [.157.55.235.146][..443] + new: [...217] [ip4][..tcp] [...192.168.1.34][50092] -> [.157.55.130.155][40020] update: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -490,15 +490,15 @@ update: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...218] [ip4][..tcp] [...192.168.1.34][50094] -> [.157.55.130.155][..443] - new: [...219] [ip4][..tcp] [...192.168.1.34][50096] -> [..111.221.74.46][40027] - new: [...220] [ip4][..tcp] [...192.168.1.34][50097] -> [.157.55.235.176][40022] - new: [...221] [ip4][..tcp] [...192.168.1.34][50098] -> [...65.55.223.15][40026] - new: [...222] [ip4][..tcp] [...192.168.1.34][50099] -> [....64.4.23.166][40022] - new: [...223] [ip4][..tcp] [...192.168.1.34][50100] -> [..111.221.74.46][..443] - new: [...224] [ip4][..tcp] [...192.168.1.34][50101] -> [.157.55.235.176][..443] - new: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] - new: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] + new: [...218] [ip4][..tcp] [...192.168.1.34][50094] -> [.157.55.130.155][..443] + new: [...219] [ip4][..tcp] [...192.168.1.34][50096] -> [..111.221.74.46][40027] + new: [...220] [ip4][..tcp] [...192.168.1.34][50097] -> [.157.55.235.176][40022] + new: [...221] [ip4][..tcp] [...192.168.1.34][50098] -> [...65.55.223.15][40026] + new: [...222] [ip4][..tcp] [...192.168.1.34][50099] -> [....64.4.23.166][40022] + new: [...223] [ip4][..tcp] [...192.168.1.34][50100] -> [..111.221.74.46][..443] + new: [...224] [ip4][..tcp] [...192.168.1.34][50101] -> [.157.55.235.176][..443] + new: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] + new: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] analyse: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.015| 19.851| 1.938| 5.863| 34377878.733| 1.700] @@ -563,19 +563,19 @@ update: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.150][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40007] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] - new: [...228] [ip4][..udp] [...192.168.1.34][49485] -> [239.255.255.250][.1900] + new: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] + new: [...228] [ip4][..udp] [...192.168.1.34][49485] -> [239.255.255.250][.1900] detected: [...228] [ip4][..udp] [...192.168.1.34][49485] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...229] [ip4][..udp] [...192.168.1.34][51066] -> [239.255.255.250][.1900] + new: [...229] [ip4][..udp] [...192.168.1.34][51066] -> [239.255.255.250][.1900] detected: [...229] [ip4][..udp] [...192.168.1.34][51066] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...230] [ip4][..udp] [...192.168.1.34][54067] -> [....192.168.1.1][.5351] + new: [...230] [ip4][..udp] [...192.168.1.34][54067] -> [....192.168.1.1][.5351] detected: [...230] [ip4][..udp] [...192.168.1.34][54067] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [...231] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] + new: [...231] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] detected: [...231] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] [ICMP][Unknown][Network][Acceptable] - new: [...232] [ip4][..tcp] [...192.168.1.34][50109] -> [.91.190.216.125][12350] + new: [...232] [ip4][..tcp] [...192.168.1.34][50109] -> [.91.190.216.125][12350] detection-update: [...230] [ip4][..udp] [...192.168.1.34][54067] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - analyse: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] + analyse: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.965| 0.176| 0.204| 41803.604| 4.200] [PKTLEN......: 52.000| 1492.000| 164.600| 286.000| 81813.500| 3.900] @@ -585,35 +585,35 @@ [IATS(ms)....: 244.0,244.1,0.5,204.3,761.0,964.7,0.5,202.0,201.5,40.2,40.2,162.2,162.2,40.2,40.2,200.9,0.0,201.0,204.1,204.1,0.1,240.8,240.6,207.5,0.0,207.6,3.0,4.5,199.6,198.0,41.6] [PKTLENS.....: 64,60,52,124,52,109,52,60,60,52,52,88,120,52,52,91,52,55,52,196,52,56,52,661,52,56,52,1492,106,605,535,52] [ENTROPIES...: 4.7,5.2,5.1,6.4,5.1,6.1,5.1,5.5,5.4,5.2,5.1,6.1,6.4,5.1,5.2,6.0,5.1,5.1,5.2,6.8,5.1,5.3,5.1,7.7,5.1,5.2,5.1,7.9,6.3,7.7,7.6,5.0] - new: [...233] [ip4][..tcp] [...192.168.1.34][50110] -> [.91.190.216.125][12350] - new: [...234] [ip4][..udp] [...192.168.1.34][13021] -> [..176.26.55.167][63773] + new: [...233] [ip4][..tcp] [...192.168.1.34][50110] -> [.91.190.216.125][12350] + new: [...234] [ip4][..udp] [...192.168.1.34][13021] -> [..176.26.55.167][63773] detected: [...234] [ip4][..udp] [...192.168.1.34][13021] -> [..176.26.55.167][63773] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...235] [ip4][..udp] [...192.168.1.34][13021] -> [..76.185.207.12][45493] + new: [...235] [ip4][..udp] [...192.168.1.34][13021] -> [..76.185.207.12][45493] detected: [...235] [ip4][..udp] [...192.168.1.34][13021] -> [..76.185.207.12][45493] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...236] [ip4][..udp] [...192.168.1.34][13021] -> [.176.97.100.249][26635] + new: [...236] [ip4][..udp] [...192.168.1.34][13021] -> [.176.97.100.249][26635] detected: [...236] [ip4][..udp] [...192.168.1.34][13021] -> [.176.97.100.249][26635] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [.....71.62.0.85][33647] + new: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [.....71.62.0.85][33647] detected: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [.....71.62.0.85][33647] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...238] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] + new: [...238] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] detected: [...238] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_afpovertcp._tcp.local] - new: [...239] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] + new: [...239] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] detected: [...239] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_afpovertcp._tcp.local] - new: [...240] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.145][..443] + new: [...240] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.145][..443] detected: [...240] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.145][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...241] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.39][..443] + new: [...241] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.39][..443] detected: [...241] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.39][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...242] [ip4][..tcp] [...192.168.1.34][50111] -> [.91.190.216.125][..443] - new: [...243] [ip4][..tcp] [...192.168.1.34][50112] -> [...76.167.161.6][20274] - new: [...244] [ip4][..tcp] [...192.168.1.34][50113] -> [...71.238.7.203][18767] - new: [...245] [ip4][..tcp] [...192.168.1.34][50114] -> [..5.248.186.221][31010] - new: [...246] [ip4][..tcp] [...192.168.1.34][50115] -> [....86.31.35.30][59621] - new: [...247] [ip4][..tcp] [...192.168.1.34][50116] -> [...81.83.77.141][17639] - new: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] - new: [...249] [ip4][..tcp] [...192.168.1.34][50118] -> [..5.248.186.221][31010] - new: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] - new: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] - new: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] - analyse: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] + new: [...242] [ip4][..tcp] [...192.168.1.34][50111] -> [.91.190.216.125][..443] + new: [...243] [ip4][..tcp] [...192.168.1.34][50112] -> [...76.167.161.6][20274] + new: [...244] [ip4][..tcp] [...192.168.1.34][50113] -> [...71.238.7.203][18767] + new: [...245] [ip4][..tcp] [...192.168.1.34][50114] -> [..5.248.186.221][31010] + new: [...246] [ip4][..tcp] [...192.168.1.34][50115] -> [....86.31.35.30][59621] + new: [...247] [ip4][..tcp] [...192.168.1.34][50116] -> [...81.83.77.141][17639] + new: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] + new: [...249] [ip4][..tcp] [...192.168.1.34][50118] -> [..5.248.186.221][31010] + new: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] + new: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] + new: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] + analyse: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.200| 0.063| 0.061| 3703.968| 4.200] [PKTLEN......: 52.000| 1235.000| 159.800| 252.000| 63524.500| 4.000] @@ -623,23 +623,23 @@ [IATS(ms)....: 83.4,83.5,0.1,64.1,64.0,0.4,68.5,68.1,2.9,71.2,68.2,199.8,199.7,154.2,154.1,2.6,133.8,131.2,0.2,0.1,0.1,64.3,8.4,55.5,127.9,0.2,0.2,70.5,0.0,70.1,0.2] [PKTLENS.....: 64,60,52,112,99,52,69,66,52,806,66,52,52,56,1235,52,609,152,130,80,119,109,52,52,132,52,80,73,347,52,52,79] [ENTROPIES...: 4.7,5.3,5.2,6.3,6.2,5.2,5.5,5.4,5.1,7.7,5.5,5.1,5.1,5.3,7.9,5.1,7.6,6.6,6.4,5.7,6.4,6.3,5.2,5.2,6.4,5.2,5.9,5.7,7.3,5.2,5.1,5.7] - new: [...253] [ip4][..tcp] [...192.168.1.34][50123] -> [...80.14.46.121][.4415] - new: [...254] [ip4][..tcp] [...192.168.1.34][50124] -> [..81.133.19.185][44431] - new: [...255] [ip4][..tcp] [..17.143.160.22][.5223] -> [...192.168.1.34][49447] [MIDSTREAM] + new: [...253] [ip4][..tcp] [...192.168.1.34][50123] -> [...80.14.46.121][.4415] + new: [...254] [ip4][..tcp] [...192.168.1.34][50124] -> [..81.133.19.185][44431] + new: [...255] [ip4][..tcp] [..17.143.160.22][.5223] -> [...192.168.1.34][49447] [MIDSTREAM] detected: [...255] [ip4][..tcp] [..17.143.160.22][.5223] -> [...192.168.1.34][49447] [TLS][Apple][Web][Safe] RISK: Known Proto on Non Std Port - new: [...256] [ip4][..tcp] [...192.168.1.34][50125] -> [.91.190.218.125][12350] - new: [...257] [ip4][..tcp] [...192.168.1.34][50126] -> [..91.190.216.23][12350] - new: [...258] [ip4][..tcp] [...192.168.1.34][50127] -> [...80.14.46.121][.4415] - new: [...259] [ip4][..udp] [...192.168.1.34][62454] -> [....192.168.1.1][...53] + new: [...256] [ip4][..tcp] [...192.168.1.34][50125] -> [.91.190.218.125][12350] + new: [...257] [ip4][..tcp] [...192.168.1.34][50126] -> [..91.190.216.23][12350] + new: [...258] [ip4][..tcp] [...192.168.1.34][50127] -> [...80.14.46.121][.4415] + new: [...259] [ip4][..udp] [...192.168.1.34][62454] -> [....192.168.1.1][...53] detected: [...259] [ip4][..udp] [...192.168.1.34][62454] -> [....192.168.1.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p05-keyvalueservice.icloud.com.akadns.net] detection-update: [...259] [ip4][..udp] [...192.168.1.34][62454] -> [....192.168.1.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable][p05-keyvalueservice.icloud.com.akadns.net] - new: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] + new: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] detected: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p05-keyvalueservice.icloud.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] [TLS.AppleiCloud][Apple][Web][Acceptable][p05-keyvalueservice.icloud.com] RISK: TLS (probably) Not Carrying HTTPS - new: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] + new: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] analyse: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.605| 0.068| 0.136| 18472.737| 3.000] @@ -686,11 +686,11 @@ update: [...140] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...262] [ip4][..udp] [...192.168.1.34][52742] -> [....192.168.1.1][...53] + new: [...262] [ip4][..udp] [...192.168.1.34][52742] -> [....192.168.1.1][...53] detected: [...262] [ip4][..udp] [...192.168.1.34][52742] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst5.r.skype.net] - new: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] + new: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] detected: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst5.r.skype.net] - analyse: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] + analyse: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 1.782| 0.325| 0.510| 259840.393| 3.600] [PKTLEN......: 52.000| 1176.000| 143.300| 243.100| 59118.200| 3.900] @@ -704,32 +704,32 @@ RISK: Unidirectional Traffic detection-update: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst5.r.skype.net] RISK: Unidirectional Traffic - new: [...264] [ip4][..udp] [...192.168.1.34][52714] -> [....192.168.1.1][...53] + new: [...264] [ip4][..udp] [...192.168.1.34][52714] -> [....192.168.1.1][...53] detected: [...264] [ip4][..udp] [...192.168.1.34][52714] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [...265] [ip4][..udp] [...192.168.1.34][51802] -> [....192.168.1.1][...53] + new: [...265] [ip4][..udp] [...192.168.1.34][51802] -> [....192.168.1.1][...53] detected: [...265] [ip4][..udp] [...192.168.1.34][51802] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [...266] [ip4][..tcp] [...192.168.1.34][50130] -> [...212.161.8.36][13392] + new: [...266] [ip4][..tcp] [...192.168.1.34][50130] -> [...212.161.8.36][13392] detection-update: [...264] [ip4][..udp] [...192.168.1.34][52714] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic detection-update: [...265] [ip4][..udp] [...192.168.1.34][51802] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic - new: [...267] [ip4][..udp] [...192.168.1.34][63421] -> [....192.168.1.1][...53] + new: [...267] [ip4][..udp] [...192.168.1.34][63421] -> [....192.168.1.1][...53] detected: [...267] [ip4][..udp] [...192.168.1.34][63421] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...268] [ip4][..udp] [...192.168.1.34][65037] -> [....192.168.1.1][...53] + new: [...268] [ip4][..udp] [...192.168.1.34][65037] -> [....192.168.1.1][...53] detected: [...268] [ip4][..udp] [...192.168.1.34][65037] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...269] [ip4][..tcp] [...192.168.1.34][50131] -> [...212.161.8.36][13392] + new: [...269] [ip4][..tcp] [...192.168.1.34][50131] -> [...212.161.8.36][13392] detected: [...269] [ip4][..tcp] [...192.168.1.34][50131] -> [...212.161.8.36][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port detection-update: [...267] [ip4][..udp] [...192.168.1.34][63421] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic detection-update: [...268] [ip4][..udp] [...192.168.1.34][65037] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic - new: [...270] [ip4][..tcp] [...192.168.1.34][50132] -> [...149.13.32.15][13392] + new: [...270] [ip4][..tcp] [...192.168.1.34][50132] -> [...149.13.32.15][13392] detected: [...242] [ip4][..tcp] [...192.168.1.34][50111] -> [.91.190.216.125][..443] [TLS][Unknown][Web][Safe] - new: [...271] [ip4][..tcp] [...192.168.1.34][50133] -> [...149.13.32.15][13392] + new: [...271] [ip4][..tcp] [...192.168.1.34][50133] -> [...149.13.32.15][13392] detected: [...271] [ip4][..tcp] [...192.168.1.34][50133] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [...272] [ip4][..udp] [...192.168.1.92][50084] -> [239.255.255.250][.1900] + new: [...272] [ip4][..udp] [...192.168.1.92][50084] -> [239.255.255.250][.1900] detected: [...272] [ip4][..udp] [...192.168.1.92][50084] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] update: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] RISK: Unidirectional Traffic @@ -768,7 +768,7 @@ update: [...185] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.162][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...273] [ip4][..udp] [...192.168.1.34][13021] -> [106.188.249.186][15120] + new: [...273] [ip4][..udp] [...192.168.1.34][13021] -> [106.188.249.186][15120] detected: [...273] [ip4][..udp] [...192.168.1.34][13021] -> [106.188.249.186][15120] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic @@ -815,7 +815,7 @@ update: [....11] [ip4][..udp] [...192.168.1.34][65045] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - analyse: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] + analyse: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 25.524| 1.927| 6.197| 38401982.071| 2.000] [PKTLEN......: 52.000| 1076.000| 142.500| 232.300| 53983.100| 4.000] @@ -825,15 +825,15 @@ [IATS(ms)....: 228.1,228.2,0.1,219.6,219.5,0.4,214.5,214.2,209.7,209.7,0.1,381.8,2061.0,2011.7,148.2,480.5,212.1,212.2,3.6,275.2,271.5,0.2,220.2,0.0,220.1,0.1,216.1,216.0,136.2,25387.6,25523.8] [PKTLENS.....: 64,64,52,109,87,52,69,66,52,66,52,56,52,829,52,1076,52,142,52,609,94,120,79,52,98,52,81,108,52,52,67,52] [ENTROPIES...: 4.6,4.7,4.9,6.2,5.9,5.3,5.7,5.6,5.3,5.7,5.3,5.3,5.2,7.8,5.1,7.8,5.2,6.5,5.1,7.7,5.9,6.4,5.9,5.2,6.1,5.2,5.9,6.1,5.3,5.3,5.8,5.3] - new: [...274] [ip4][..udp] [...192.168.1.34][56886] -> [239.255.255.250][.1900] + new: [...274] [ip4][..udp] [...192.168.1.34][56886] -> [239.255.255.250][.1900] detected: [...274] [ip4][..udp] [...192.168.1.34][56886] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...275] [ip4][..udp] [...192.168.1.34][64560] -> [239.255.255.250][.1900] + new: [...275] [ip4][..udp] [...192.168.1.34][64560] -> [239.255.255.250][.1900] detected: [...275] [ip4][..udp] [...192.168.1.34][64560] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...276] [ip4][..udp] [...192.168.1.34][49511] -> [....192.168.1.1][.5351] + new: [...276] [ip4][..udp] [...192.168.1.34][49511] -> [....192.168.1.1][.5351] detected: [...276] [ip4][..udp] [...192.168.1.34][49511] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] detection-update: [...276] [ip4][..udp] [...192.168.1.34][49511] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...277] [ip4][..tcp] [...192.168.1.34][50134] -> [...157.56.53.47][12350] + new: [...277] [ip4][..tcp] [...192.168.1.34][50134] -> [...157.56.53.47][12350] update: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -848,9 +848,9 @@ update: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...278] [ip4][....2] [....192.168.1.1] -> [......224.0.0.1] + new: [...278] [ip4][....2] [....192.168.1.1] -> [......224.0.0.1] detected: [...278] [ip4][....2] [....192.168.1.1] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [...279] [ip4][..udp] [...192.168.1.34][..123] -> [..17.253.48.245][..123] + new: [...279] [ip4][..udp] [...192.168.1.34][..123] -> [..17.253.48.245][..123] detected: [...279] [ip4][..udp] [...192.168.1.34][..123] -> [..17.253.48.245][..123] [NTP][Apple][System][Acceptable] update: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.21][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -918,9 +918,9 @@ update: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.150][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40007] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...280] [ip4][..tcp] [...192.168.1.34][50135] -> [...76.167.161.6][20274] - new: [...281] [ip4][..tcp] [...192.168.1.34][50136] -> [...71.238.7.203][18767] - new: [...282] [ip4][..tcp] [...192.168.1.34][50137] -> [..5.248.186.221][31010] + new: [...280] [ip4][..tcp] [...192.168.1.34][50135] -> [...76.167.161.6][20274] + new: [...281] [ip4][..tcp] [...192.168.1.34][50136] -> [...71.238.7.203][18767] + new: [...282] [ip4][..tcp] [...192.168.1.34][50137] -> [..5.248.186.221][31010] update: [...108] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.26][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.47][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -970,9 +970,9 @@ update: [...140] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] - new: [...284] [ip4][..tcp] [...192.168.1.34][50139] -> [..5.248.186.221][31010] - new: [...285] [ip4][..tcp] [...192.168.1.34][50140] -> [...76.167.161.6][20274] + new: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] + new: [...284] [ip4][..tcp] [...192.168.1.34][50139] -> [..5.248.186.221][31010] + new: [...285] [ip4][..tcp] [...192.168.1.34][50140] -> [...76.167.161.6][20274] update: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] RISK: Unidirectional Traffic update: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.37][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1013,18 +1013,18 @@ update: [...185] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.162][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...286] [ip4][..tcp] [...192.168.1.34][50141] -> [...80.14.46.121][.4415] - new: [...287] [ip4][..tcp] [...192.168.1.34][50142] -> [...80.14.46.121][.4415] - new: [...288] [ip4][..tcp] [...192.168.1.34][50143] -> [.78.202.226.115][29059] - new: [...289] [ip4][..tcp] [...192.168.1.34][50144] -> [.78.202.226.115][29059] - new: [...290] [ip4][....2] [...192.168.1.34] -> [....224.0.0.251] + new: [...286] [ip4][..tcp] [...192.168.1.34][50141] -> [...80.14.46.121][.4415] + new: [...287] [ip4][..tcp] [...192.168.1.34][50142] -> [...80.14.46.121][.4415] + new: [...288] [ip4][..tcp] [...192.168.1.34][50143] -> [.78.202.226.115][29059] + new: [...289] [ip4][..tcp] [...192.168.1.34][50144] -> [.78.202.226.115][29059] + new: [...290] [ip4][....2] [...192.168.1.34] -> [....224.0.0.251] detected: [...290] [ip4][....2] [...192.168.1.34] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [...291] [ip4][..tcp] [...192.168.1.34][50145] -> [...157.56.53.51][12350] + new: [...291] [ip4][..tcp] [...192.168.1.34][50145] -> [...157.56.53.51][12350] guessed: [....19] [ip4][..tcp] [...192.168.1.34][50030] -> [...65.55.223.33][..443] [TLS][Unknown][Web][Safe] - end: [....19] [ip4][..tcp] [...192.168.1.34][50030] -> [...65.55.223.33][..443] + end: [....19] [ip4][..tcp] [...192.168.1.34][50030] -> [...65.55.223.33][..443] not-detected: [.....9] [ip4][..tcp] [...192.168.1.34][50026] -> [...65.55.223.33][40002] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [.....9] [ip4][..tcp] [...192.168.1.34][50026] -> [...65.55.223.33][40002] + end: [.....9] [ip4][..tcp] [...192.168.1.34][50026] -> [...65.55.223.33][40002] update: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [.....6] [ip4][..udp] [...192.168.1.34][65426] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -1074,23 +1074,23 @@ update: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...276] [ip4][..udp] [...192.168.1.34][49511] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...292] [ip4][..tcp] [...192.168.1.34][50146] -> [...157.56.53.51][..443] - new: [...293] [ip4][..udp] [...192.168.1.34][55893] -> [....192.168.1.1][...53] + new: [...292] [ip4][..tcp] [...192.168.1.34][50146] -> [...157.56.53.51][..443] + new: [...293] [ip4][..udp] [...192.168.1.34][55893] -> [....192.168.1.1][...53] detected: [...293] [ip4][..udp] [...192.168.1.34][55893] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] detection-update: [...293] [ip4][..udp] [...192.168.1.34][55893] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] RISK: Unidirectional Traffic not-detected: [....50] [ip4][..tcp] [...192.168.1.34][50033] -> [..157.55.56.170][40015] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....50] [ip4][..tcp] [...192.168.1.34][50033] -> [..157.55.56.170][40015] + end: [....50] [ip4][..tcp] [...192.168.1.34][50033] -> [..157.55.56.170][40015] not-detected: [....51] [ip4][..tcp] [...192.168.1.34][50034] -> [.157.55.130.140][40033] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....51] [ip4][..tcp] [...192.168.1.34][50034] -> [.157.55.130.140][40033] + end: [....51] [ip4][..tcp] [...192.168.1.34][50034] -> [.157.55.130.140][40033] guessed: [...148] [ip4][..tcp] [...192.168.1.34][50024] -> [..17.172.100.36][..443] [TLS][Apple][Web][Safe] - end: [...148] [ip4][..tcp] [...192.168.1.34][50024] -> [..17.172.100.36][..443] + end: [...148] [ip4][..tcp] [...192.168.1.34][50024] -> [..17.172.100.36][..443] guessed: [....65] [ip4][..tcp] [...192.168.1.34][50038] -> [.157.55.130.140][..443] [TLS][Unknown][Web][Safe] - end: [....65] [ip4][..tcp] [...192.168.1.34][50038] -> [.157.55.130.140][..443] + end: [....65] [ip4][..tcp] [...192.168.1.34][50038] -> [.157.55.130.140][..443] guessed: [....63] [ip4][..tcp] [...192.168.1.34][50036] -> [...157.56.52.44][..443] [TLS][Unknown][Web][Safe] - end: [....63] [ip4][..tcp] [...192.168.1.34][50036] -> [...157.56.52.44][..443] + end: [....63] [ip4][..tcp] [...192.168.1.34][50036] -> [...157.56.52.44][..443] update: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -1104,7 +1104,7 @@ update: [....29] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....25] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.155][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....32] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - analyse: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] + analyse: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 30.126| 1.349| 5.301| 28102044.418| 1.900] [PKTLEN......: 52.000| 1076.000| 141.400| 232.500| 54056.900| 4.000] @@ -1116,59 +1116,59 @@ [ENTROPIES...: 4.7,4.7,4.9,6.0,6.0,5.3,5.7,5.7,5.3,5.7,5.3,5.3,5.3,7.7,5.4,7.8,5.1,6.6,5.2,7.6,6.1,6.5,5.9,6.2,5.2,5.8,5.2,6.2,5.2,5.3,5.2,5.3] not-detected: [...221] [ip4][..tcp] [...192.168.1.34][50098] -> [...65.55.223.15][40026] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...221] [ip4][..tcp] [...192.168.1.34][50098] -> [...65.55.223.15][40026] + end: [...221] [ip4][..tcp] [...192.168.1.34][50098] -> [...65.55.223.15][40026] not-detected: [...101] [ip4][..tcp] [...192.168.1.34][50046] -> [.157.55.130.150][40011] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...101] [ip4][..tcp] [...192.168.1.34][50046] -> [.157.55.130.150][40011] + end: [...101] [ip4][..tcp] [...192.168.1.34][50046] -> [.157.55.130.150][40011] not-detected: [...134] [ip4][..tcp] [...192.168.1.34][50054] -> [.157.55.130.153][40005] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...134] [ip4][..tcp] [...192.168.1.34][50054] -> [.157.55.130.153][40005] + end: [...134] [ip4][..tcp] [...192.168.1.34][50054] -> [.157.55.130.153][40005] idle: [.....4] [ip4][..udp] [...192.168.1.34][52850] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...113] [ip4][..tcp] [...192.168.1.34][50049] -> [.157.55.130.166][40021] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...113] [ip4][..tcp] [...192.168.1.34][50049] -> [.157.55.130.166][40021] + end: [...113] [ip4][..tcp] [...192.168.1.34][50049] -> [.157.55.130.166][40021] not-detected: [....87] [ip4][..tcp] [...192.168.1.34][50044] -> [.157.55.130.167][40031] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....87] [ip4][..tcp] [...192.168.1.34][50044] -> [.157.55.130.167][40031] + end: [....87] [ip4][..tcp] [...192.168.1.34][50044] -> [.157.55.130.167][40031] not-detected: [...194] [ip4][..tcp] [...192.168.1.34][50074] -> [.157.55.130.173][40003] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...194] [ip4][..tcp] [...192.168.1.34][50074] -> [.157.55.130.173][40003] + end: [...194] [ip4][..tcp] [...192.168.1.34][50074] -> [.157.55.130.173][40003] not-detected: [...133] [ip4][..tcp] [...192.168.1.34][50053] -> [..157.55.56.146][40030] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...133] [ip4][..tcp] [...192.168.1.34][50053] -> [..157.55.56.146][40030] + end: [...133] [ip4][..tcp] [...192.168.1.34][50053] -> [..157.55.56.146][40030] idle: [...150] [ip4][..udp] [...192.168.1.34][63108] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] RISK: Unidirectional Traffic not-detected: [...177] [ip4][..tcp] [...192.168.1.34][50070] -> [.157.55.130.170][40018] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...177] [ip4][..tcp] [...192.168.1.34][50070] -> [.157.55.130.170][40018] + end: [...177] [ip4][..tcp] [...192.168.1.34][50070] -> [.157.55.130.170][40018] not-detected: [...196] [ip4][..tcp] [...192.168.1.34][50076] -> [.157.55.235.156][40014] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...196] [ip4][..tcp] [...192.168.1.34][50076] -> [.157.55.235.156][40014] + end: [...196] [ip4][..tcp] [...192.168.1.34][50076] -> [.157.55.235.156][40014] not-detected: [...168] [ip4][..tcp] [...192.168.1.34][50067] -> [..157.55.56.160][40027] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...168] [ip4][..tcp] [...192.168.1.34][50067] -> [..157.55.56.160][40027] + end: [...168] [ip4][..tcp] [...192.168.1.34][50067] -> [..157.55.56.160][40027] not-detected: [...200] [ip4][..tcp] [...192.168.1.34][50077] -> [.157.55.130.176][40022] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...200] [ip4][..tcp] [...192.168.1.34][50077] -> [.157.55.130.176][40022] + end: [...200] [ip4][..tcp] [...192.168.1.34][50077] -> [.157.55.130.176][40022] not-detected: [...217] [ip4][..tcp] [...192.168.1.34][50092] -> [.157.55.130.155][40020] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...217] [ip4][..tcp] [...192.168.1.34][50092] -> [.157.55.130.155][40020] + end: [...217] [ip4][..tcp] [...192.168.1.34][50092] -> [.157.55.130.155][40020] not-detected: [....57] [ip4][..tcp] [...192.168.1.34][50035] -> [213.199.179.175][40021] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....57] [ip4][..tcp] [...192.168.1.34][50035] -> [213.199.179.175][40021] + end: [....57] [ip4][..tcp] [...192.168.1.34][50035] -> [213.199.179.175][40021] not-detected: [...220] [ip4][..tcp] [...192.168.1.34][50097] -> [.157.55.235.176][40022] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...220] [ip4][..tcp] [...192.168.1.34][50097] -> [.157.55.235.176][40022] + end: [...220] [ip4][..tcp] [...192.168.1.34][50097] -> [.157.55.235.176][40022] not-detected: [...288] [ip4][..tcp] [...192.168.1.34][50143] -> [.78.202.226.115][29059] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...288] [ip4][..tcp] [...192.168.1.34][50143] -> [.78.202.226.115][29059] + end: [...288] [ip4][..tcp] [...192.168.1.34][50143] -> [.78.202.226.115][29059] not-detected: [...289] [ip4][..tcp] [...192.168.1.34][50144] -> [.78.202.226.115][29059] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...289] [ip4][..tcp] [...192.168.1.34][50144] -> [.78.202.226.115][29059] + end: [...289] [ip4][..tcp] [...192.168.1.34][50144] -> [.78.202.226.115][29059] not-detected: [...195] [ip4][..tcp] [...192.168.1.34][50075] -> [213.199.179.142][40003] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...195] [ip4][..tcp] [...192.168.1.34][50075] -> [213.199.179.142][40003] + end: [...195] [ip4][..tcp] [...192.168.1.34][50075] -> [213.199.179.142][40003] idle: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.21][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....31] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.28][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1184,14 +1184,14 @@ idle: [...214] [ip4][..udp] [...192.168.1.34][63321] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] not-detected: [....49] [ip4][..tcp] [...192.168.1.34][50032] -> [...157.56.52.44][40032] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....49] [ip4][..tcp] [...192.168.1.34][50032] -> [...157.56.52.44][40032] + end: [....49] [ip4][..tcp] [...192.168.1.34][50032] -> [...157.56.52.44][40032] idle: [...149] [ip4][..udp] [...192.168.1.34][55159] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] RISK: Unidirectional Traffic idle: [.....6] [ip4][..udp] [...192.168.1.34][65426] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] + end: [...227] [ip4][..tcp] [...192.168.1.34][50108] -> [...157.56.52.28][40009] idle: [...228] [ip4][..udp] [...192.168.1.34][49485] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [...231] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] [ICMP][Unknown][Network][Acceptable] idle: [...267] [ip4][..udp] [...192.168.1.34][63421] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -1217,51 +1217,51 @@ idle: [...260] [ip4][..tcp] [...192.168.1.34][50128] -> [..17.172.100.36][..443] [TLS.AppleiCloud][Apple][Web][Acceptable] RISK: TLS (probably) Not Carrying HTTPS guessed: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] [TLS][Unknown][Web][Safe] - end: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] + end: [...226] [ip4][..tcp] [...192.168.1.34][50103] -> [....64.4.23.166][..443] idle: [...158] [ip4][..udp] [...192.168.1.34][49360] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...239] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] not-detected: [...266] [ip4][..tcp] [...192.168.1.34][50130] -> [...212.161.8.36][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...266] [ip4][..tcp] [...192.168.1.34][50130] -> [...212.161.8.36][13392] + end: [...266] [ip4][..tcp] [...192.168.1.34][50130] -> [...212.161.8.36][13392] end: [...269] [ip4][..tcp] [...192.168.1.34][50131] -> [...212.161.8.36][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port not-detected: [...243] [ip4][..tcp] [...192.168.1.34][50112] -> [...76.167.161.6][20274] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...243] [ip4][..tcp] [...192.168.1.34][50112] -> [...76.167.161.6][20274] + end: [...243] [ip4][..tcp] [...192.168.1.34][50112] -> [...76.167.161.6][20274] not-detected: [...280] [ip4][..tcp] [...192.168.1.34][50135] -> [...76.167.161.6][20274] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...280] [ip4][..tcp] [...192.168.1.34][50135] -> [...76.167.161.6][20274] + end: [...280] [ip4][..tcp] [...192.168.1.34][50135] -> [...76.167.161.6][20274] not-detected: [...232] [ip4][..tcp] [...192.168.1.34][50109] -> [.91.190.216.125][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...232] [ip4][..tcp] [...192.168.1.34][50109] -> [.91.190.216.125][12350] + end: [...232] [ip4][..tcp] [...192.168.1.34][50109] -> [.91.190.216.125][12350] not-detected: [...233] [ip4][..tcp] [...192.168.1.34][50110] -> [.91.190.216.125][12350] [Unknown][Unknown][Unrated] - end: [...233] [ip4][..tcp] [...192.168.1.34][50110] -> [.91.190.216.125][12350] + end: [...233] [ip4][..tcp] [...192.168.1.34][50110] -> [.91.190.216.125][12350] not-detected: [...285] [ip4][..tcp] [...192.168.1.34][50140] -> [...76.167.161.6][20274] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...285] [ip4][..tcp] [...192.168.1.34][50140] -> [...76.167.161.6][20274] + end: [...285] [ip4][..tcp] [...192.168.1.34][50140] -> [...76.167.161.6][20274] idle: [...273] [ip4][..udp] [...192.168.1.34][13021] -> [106.188.249.186][15120] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...256] [ip4][..tcp] [...192.168.1.34][50125] -> [.91.190.218.125][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...256] [ip4][..tcp] [...192.168.1.34][50125] -> [.91.190.218.125][12350] + end: [...256] [ip4][..tcp] [...192.168.1.34][50125] -> [.91.190.218.125][12350] not-detected: [...257] [ip4][..tcp] [...192.168.1.34][50126] -> [..91.190.216.23][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...257] [ip4][..tcp] [...192.168.1.34][50126] -> [..91.190.216.23][12350] + end: [...257] [ip4][..tcp] [...192.168.1.34][50126] -> [..91.190.216.23][12350] not-detected: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] [Unknown][Unknown][Unrated] - end: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] + end: [...261] [ip4][..tcp] [...192.168.1.34][50129] -> [.91.190.218.125][12350] idle: [....21] [ip4][..udp] [...192.168.1.34][57726] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [.....3] [ip4][..udp] [...192.168.1.34][55711] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [...143] [ip4][..tcp] [...192.168.1.34][50058] -> [..111.221.74.47][..443] [TLS][Unknown][Web][Safe] - end: [...143] [ip4][..tcp] [...192.168.1.34][50058] -> [..111.221.74.47][..443] + end: [...143] [ip4][..tcp] [...192.168.1.34][50058] -> [..111.221.74.47][..443] guessed: [...153] [ip4][..tcp] [...192.168.1.34][50063] -> [..111.221.74.38][..443] [TLS][Unknown][Web][Safe] - end: [...153] [ip4][..tcp] [...192.168.1.34][50063] -> [..111.221.74.38][..443] + end: [...153] [ip4][..tcp] [...192.168.1.34][50063] -> [..111.221.74.38][..443] idle: [...238] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] guessed: [...212] [ip4][..tcp] [...192.168.1.34][50087] -> [.111.221.77.142][..443] [TLS][Unknown][Web][Safe] - end: [...212] [ip4][..tcp] [...192.168.1.34][50087] -> [.111.221.77.142][..443] + end: [...212] [ip4][..tcp] [...192.168.1.34][50087] -> [.111.221.77.142][..443] guessed: [...223] [ip4][..tcp] [...192.168.1.34][50100] -> [..111.221.74.46][..443] [TLS][Unknown][Web][Safe] - end: [...223] [ip4][..tcp] [...192.168.1.34][50100] -> [..111.221.74.46][..443] + end: [...223] [ip4][..tcp] [...192.168.1.34][50100] -> [..111.221.74.46][..443] idle: [...121] [ip4][..udp] [...192.168.1.92][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] idle: [...272] [ip4][..udp] [...192.168.1.92][50084] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1273,35 +1273,35 @@ idle: [.....7] [ip4][..udp] [...192.168.1.34][64085] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] not-detected: [...244] [ip4][..tcp] [...192.168.1.34][50113] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...244] [ip4][..tcp] [...192.168.1.34][50113] -> [...71.238.7.203][18767] + end: [...244] [ip4][..tcp] [...192.168.1.34][50113] -> [...71.238.7.203][18767] idle: [...265] [ip4][..udp] [...192.168.1.34][51802] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...253] [ip4][..tcp] [...192.168.1.34][50123] -> [...80.14.46.121][.4415] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...253] [ip4][..tcp] [...192.168.1.34][50123] -> [...80.14.46.121][.4415] + end: [...253] [ip4][..tcp] [...192.168.1.34][50123] -> [...80.14.46.121][.4415] not-detected: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] + end: [...248] [ip4][..tcp] [...192.168.1.34][50117] -> [...71.238.7.203][18767] not-detected: [...258] [ip4][..tcp] [...192.168.1.34][50127] -> [...80.14.46.121][.4415] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...258] [ip4][..tcp] [...192.168.1.34][50127] -> [...80.14.46.121][.4415] + end: [...258] [ip4][..tcp] [...192.168.1.34][50127] -> [...80.14.46.121][.4415] idle: [....22] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [...109] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...286] [ip4][..tcp] [...192.168.1.34][50141] -> [...80.14.46.121][.4415] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...286] [ip4][..tcp] [...192.168.1.34][50141] -> [...80.14.46.121][.4415] + end: [...286] [ip4][..tcp] [...192.168.1.34][50141] -> [...80.14.46.121][.4415] idle: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.141][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.150][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...287] [ip4][..tcp] [...192.168.1.34][50142] -> [...80.14.46.121][.4415] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...287] [ip4][..tcp] [...192.168.1.34][50142] -> [...80.14.46.121][.4415] + end: [...287] [ip4][..tcp] [...192.168.1.34][50142] -> [...80.14.46.121][.4415] not-detected: [...281] [ip4][..tcp] [...192.168.1.34][50136] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...281] [ip4][..tcp] [...192.168.1.34][50136] -> [...71.238.7.203][18767] + end: [...281] [ip4][..tcp] [...192.168.1.34][50136] -> [...71.238.7.203][18767] idle: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.168][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] + end: [...283] [ip4][..tcp] [...192.168.1.34][50138] -> [...71.238.7.203][18767] idle: [....73] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.159][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1328,16 +1328,16 @@ RISK: Unidirectional Traffic not-detected: [...247] [ip4][..tcp] [...192.168.1.34][50116] -> [...81.83.77.141][17639] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...247] [ip4][..tcp] [...192.168.1.34][50116] -> [...81.83.77.141][17639] + end: [...247] [ip4][..tcp] [...192.168.1.34][50116] -> [...81.83.77.141][17639] not-detected: [...246] [ip4][..tcp] [...192.168.1.34][50115] -> [....86.31.35.30][59621] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...246] [ip4][..tcp] [...192.168.1.34][50115] -> [....86.31.35.30][59621] + end: [...246] [ip4][..tcp] [...192.168.1.34][50115] -> [....86.31.35.30][59621] not-detected: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] + end: [...251] [ip4][..tcp] [...192.168.1.34][50121] -> [...81.83.77.141][17639] not-detected: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] + end: [...250] [ip4][..tcp] [...192.168.1.34][50119] -> [....86.31.35.30][59621] end: [....12] [ip4][..tcp] [...192.168.1.34][50027] -> [...23.223.73.34][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] RISK: TLS (probably) Not Carrying HTTPS idle: [...240] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.145][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1345,14 +1345,14 @@ RISK: Unidirectional Traffic not-detected: [...222] [ip4][..tcp] [...192.168.1.34][50099] -> [....64.4.23.166][40022] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...222] [ip4][..tcp] [...192.168.1.34][50099] -> [....64.4.23.166][40022] + end: [...222] [ip4][..tcp] [...192.168.1.34][50099] -> [....64.4.23.166][40022] not-detected: [...213] [ip4][..tcp] [...192.168.1.34][50088] -> [.157.55.235.146][33033] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...213] [ip4][..tcp] [...192.168.1.34][50088] -> [.157.55.235.146][33033] + end: [...213] [ip4][..tcp] [...192.168.1.34][50088] -> [.157.55.235.146][33033] idle: [....20] [ip4][..udp] [...192.168.1.34][60288] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [...167] [ip4][..tcp] [...192.168.1.34][50066] -> [...65.55.223.12][..443] [TLS][Unknown][Web][Safe] - end: [...167] [ip4][..tcp] [...192.168.1.34][50066] -> [...65.55.223.12][..443] + end: [...167] [ip4][..tcp] [...192.168.1.34][50066] -> [...65.55.223.12][..443] idle: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1385,11 +1385,11 @@ idle: [....27] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...277] [ip4][..tcp] [...192.168.1.34][50134] -> [...157.56.53.47][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...277] [ip4][..tcp] [...192.168.1.34][50134] -> [...157.56.53.47][12350] + end: [...277] [ip4][..tcp] [...192.168.1.34][50134] -> [...157.56.53.47][12350] idle: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] guessed: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] [TLS][Unknown][Web][Safe] - end: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] + end: [...225] [ip4][..tcp] [...192.168.1.34][50102] -> [...65.55.223.15][..443] idle: [....28] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....55] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.25][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....30] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1400,77 +1400,77 @@ idle: [...170] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.16][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...291] [ip4][..tcp] [...192.168.1.34][50145] -> [...157.56.53.51][12350] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...291] [ip4][..tcp] [...192.168.1.34][50145] -> [...157.56.53.51][12350] + idle: [...291] [ip4][..tcp] [...192.168.1.34][50145] -> [...157.56.53.51][12350] guessed: [....64] [ip4][..tcp] [...192.168.1.34][50037] -> [..157.55.56.170][..443] [TLS][Unknown][Web][Safe] - end: [....64] [ip4][..tcp] [...192.168.1.34][50037] -> [..157.55.56.170][..443] + end: [....64] [ip4][..tcp] [...192.168.1.34][50037] -> [..157.55.56.170][..443] guessed: [....99] [ip4][..tcp] [...192.168.1.34][50045] -> [.157.55.130.167][..443] [TLS][Unknown][Web][Safe] - end: [....99] [ip4][..tcp] [...192.168.1.34][50045] -> [.157.55.130.167][..443] + end: [....99] [ip4][..tcp] [...192.168.1.34][50045] -> [.157.55.130.167][..443] guessed: [...112] [ip4][..tcp] [...192.168.1.34][50048] -> [.157.55.130.150][..443] [TLS][Unknown][Web][Safe] - end: [...112] [ip4][..tcp] [...192.168.1.34][50048] -> [.157.55.130.150][..443] + end: [...112] [ip4][..tcp] [...192.168.1.34][50048] -> [.157.55.130.150][..443] guessed: [...122] [ip4][..tcp] [...192.168.1.34][50051] -> [.157.55.130.166][..443] [TLS][Unknown][Web][Safe] - end: [...122] [ip4][..tcp] [...192.168.1.34][50051] -> [.157.55.130.166][..443] + end: [...122] [ip4][..tcp] [...192.168.1.34][50051] -> [.157.55.130.166][..443] guessed: [...141] [ip4][..tcp] [...192.168.1.34][50056] -> [..157.55.56.146][..443] [TLS][Unknown][Web][Safe] - end: [...141] [ip4][..tcp] [...192.168.1.34][50056] -> [..157.55.56.146][..443] + end: [...141] [ip4][..tcp] [...192.168.1.34][50056] -> [..157.55.56.146][..443] guessed: [...142] [ip4][..tcp] [...192.168.1.34][50057] -> [.157.55.130.153][..443] [TLS][Unknown][Web][Safe] - end: [...142] [ip4][..tcp] [...192.168.1.34][50057] -> [.157.55.130.153][..443] + end: [...142] [ip4][..tcp] [...192.168.1.34][50057] -> [.157.55.130.153][..443] not-detected: [...245] [ip4][..tcp] [...192.168.1.34][50114] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...245] [ip4][..tcp] [...192.168.1.34][50114] -> [..5.248.186.221][31010] + end: [...245] [ip4][..tcp] [...192.168.1.34][50114] -> [..5.248.186.221][31010] not-detected: [...249] [ip4][..tcp] [...192.168.1.34][50118] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] - end: [...249] [ip4][..tcp] [...192.168.1.34][50118] -> [..5.248.186.221][31010] + end: [...249] [ip4][..tcp] [...192.168.1.34][50118] -> [..5.248.186.221][31010] guessed: [...174] [ip4][..tcp] [...192.168.1.34][50069] -> [..157.55.56.160][..443] [TLS][Unknown][Web][Safe] - end: [...174] [ip4][..tcp] [...192.168.1.34][50069] -> [..157.55.56.160][..443] + end: [...174] [ip4][..tcp] [...192.168.1.34][50069] -> [..157.55.56.160][..443] guessed: [...183] [ip4][..tcp] [...192.168.1.34][50072] -> [.157.55.130.170][..443] [TLS][Unknown][Web][Safe] - end: [...183] [ip4][..tcp] [...192.168.1.34][50072] -> [.157.55.130.170][..443] + end: [...183] [ip4][..tcp] [...192.168.1.34][50072] -> [.157.55.130.170][..443] idle: [...259] [ip4][..udp] [...192.168.1.34][62454] -> [....192.168.1.1][...53] [DNS.AppleiCloud][Unknown][Network][Acceptable] guessed: [...203] [ip4][..tcp] [...192.168.1.34][50078] -> [.157.55.130.173][..443] [TLS][Unknown][Web][Safe] - end: [...203] [ip4][..tcp] [...192.168.1.34][50078] -> [.157.55.130.173][..443] + end: [...203] [ip4][..tcp] [...192.168.1.34][50078] -> [.157.55.130.173][..443] guessed: [...205] [ip4][..tcp] [...192.168.1.34][50080] -> [.157.55.235.156][..443] [TLS][Unknown][Web][Safe] - end: [...205] [ip4][..tcp] [...192.168.1.34][50080] -> [.157.55.235.156][..443] + end: [...205] [ip4][..tcp] [...192.168.1.34][50080] -> [.157.55.235.156][..443] guessed: [...209] [ip4][..tcp] [...192.168.1.34][50081] -> [.157.55.130.176][..443] [TLS][Unknown][Web][Safe] - end: [...209] [ip4][..tcp] [...192.168.1.34][50081] -> [.157.55.130.176][..443] + end: [...209] [ip4][..tcp] [...192.168.1.34][50081] -> [.157.55.130.176][..443] not-detected: [...282] [ip4][..tcp] [...192.168.1.34][50137] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...282] [ip4][..tcp] [...192.168.1.34][50137] -> [..5.248.186.221][31010] + end: [...282] [ip4][..tcp] [...192.168.1.34][50137] -> [..5.248.186.221][31010] idle: [...176] [ip4][..udp] [...192.168.1.34][58368] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...284] [ip4][..tcp] [...192.168.1.34][50139] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...284] [ip4][..tcp] [...192.168.1.34][50139] -> [..5.248.186.221][31010] + end: [...284] [ip4][..tcp] [...192.168.1.34][50139] -> [..5.248.186.221][31010] guessed: [...216] [ip4][..tcp] [...192.168.1.34][50091] -> [.157.55.235.146][..443] [TLS][Unknown][Web][Safe] - end: [...216] [ip4][..tcp] [...192.168.1.34][50091] -> [.157.55.235.146][..443] + end: [...216] [ip4][..tcp] [...192.168.1.34][50091] -> [.157.55.235.146][..443] guessed: [...218] [ip4][..tcp] [...192.168.1.34][50094] -> [.157.55.130.155][..443] [TLS][Unknown][Web][Safe] - end: [...218] [ip4][..tcp] [...192.168.1.34][50094] -> [.157.55.130.155][..443] + end: [...218] [ip4][..tcp] [...192.168.1.34][50094] -> [.157.55.130.155][..443] guessed: [....71] [ip4][..tcp] [...192.168.1.34][50039] -> [213.199.179.175][..443] [TLS][Unknown][Web][Safe] - end: [....71] [ip4][..tcp] [...192.168.1.34][50039] -> [213.199.179.175][..443] + end: [....71] [ip4][..tcp] [...192.168.1.34][50039] -> [213.199.179.175][..443] guessed: [...224] [ip4][..tcp] [...192.168.1.34][50101] -> [.157.55.235.176][..443] [TLS][Unknown][Web][Safe] - end: [...224] [ip4][..tcp] [...192.168.1.34][50101] -> [.157.55.235.176][..443] + end: [...224] [ip4][..tcp] [...192.168.1.34][50101] -> [.157.55.235.176][..443] guessed: [...204] [ip4][..tcp] [...192.168.1.34][50079] -> [213.199.179.142][..443] [TLS][Unknown][Web][Safe] - end: [...204] [ip4][..tcp] [...192.168.1.34][50079] -> [213.199.179.142][..443] + end: [...204] [ip4][..tcp] [...192.168.1.34][50079] -> [213.199.179.142][..443] idle: [...263] [ip4][..udp] [...192.168.1.34][56387] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...175] [ip4][..udp] [...192.168.1.34][54343] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...144] [ip4][..tcp] [...192.168.1.34][50059] -> [..111.221.74.38][40015] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...144] [ip4][..tcp] [...192.168.1.34][50059] -> [..111.221.74.38][40015] + end: [...144] [ip4][..tcp] [...192.168.1.34][50059] -> [..111.221.74.38][40015] not-detected: [...135] [ip4][..tcp] [...192.168.1.34][50055] -> [..111.221.74.47][40030] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...135] [ip4][..tcp] [...192.168.1.34][50055] -> [..111.221.74.47][40030] + end: [...135] [ip4][..tcp] [...192.168.1.34][50055] -> [..111.221.74.47][40030] idle: [...157] [ip4][..udp] [...192.168.1.34][58458] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...211] [ip4][..tcp] [...192.168.1.34][50086] -> [.111.221.77.142][40023] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...211] [ip4][..tcp] [...192.168.1.34][50086] -> [.111.221.77.142][40023] + end: [...211] [ip4][..tcp] [...192.168.1.34][50086] -> [.111.221.77.142][40023] not-detected: [...219] [ip4][..tcp] [...192.168.1.34][50096] -> [..111.221.74.46][40027] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...219] [ip4][..tcp] [...192.168.1.34][50096] -> [..111.221.74.46][40027] + end: [...219] [ip4][..tcp] [...192.168.1.34][50096] -> [..111.221.74.46][40027] idle: [.....5] [ip4][..udp] [...192.168.1.34][54396] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...274] [ip4][..udp] [...192.168.1.34][56886] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [...270] [ip4][..tcp] [...192.168.1.34][50132] -> [...149.13.32.15][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...270] [ip4][..tcp] [...192.168.1.34][50132] -> [...149.13.32.15][13392] + end: [...270] [ip4][..tcp] [...192.168.1.34][50132] -> [...149.13.32.15][13392] end: [...271] [ip4][..tcp] [...192.168.1.34][50133] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port end: [....15] [ip4][..tcp] [...192.168.1.34][50028] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] @@ -1480,7 +1480,7 @@ idle: [.....8] [ip4][..udp] [...192.168.1.34][58681] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] guessed: [...292] [ip4][..tcp] [...192.168.1.34][50146] -> [...157.56.53.51][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [...292] [ip4][..tcp] [...192.168.1.34][50146] -> [...157.56.53.51][..443] + idle: [...292] [ip4][..tcp] [...192.168.1.34][50146] -> [...157.56.53.51][..443] idle: [....60] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...160] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.26][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.29][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1498,10 +1498,10 @@ idle: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] + end: [...252] [ip4][..tcp] [...192.168.1.34][50122] -> [..81.133.19.185][44431] not-detected: [...254] [ip4][..tcp] [...192.168.1.34][50124] -> [..81.133.19.185][44431] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...254] [ip4][..tcp] [...192.168.1.34][50124] -> [..81.133.19.185][44431] + end: [...254] [ip4][..tcp] [...192.168.1.34][50124] -> [..81.133.19.185][44431] idle: [...234] [ip4][..udp] [...192.168.1.34][13021] -> [..176.26.55.167][63773] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.152][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...208] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1568,5 +1568,5 @@ idle: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40034] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...161] [ip4][..tcp] [...192.168.1.34][50065] -> [...65.55.223.12][40031] [Unknown][Unknown][Unrated] - end: [...161] [ip4][..tcp] [...192.168.1.34][50065] -> [...65.55.223.12][40031] + end: [...161] [ip4][..tcp] [...192.168.1.34][50065] -> [...65.55.223.12][40031] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/skype_no_unknown.pcap.out b/test/results/flow-info/default/skype_no_unknown.pcap.out index 864f34dea..3e75b6649 100644 --- a/test/results/flow-info/default/skype_no_unknown.pcap.out +++ b/test/results/flow-info/default/skype_no_unknown.pcap.out @@ -1,49 +1,49 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][....2] [..192.168.1.219] -> [.....224.0.0.22] + new: [.....1] [ip4][....2] [..192.168.1.219] -> [.....224.0.0.22] detected: [.....1] [ip4][....2] [..192.168.1.219] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.1.34][55028] -> [....192.168.1.1][...53] + new: [.....2] [ip4][..udp] [...192.168.1.34][55028] -> [....192.168.1.1][...53] detected: [.....2] [ip4][..udp] [...192.168.1.34][55028] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][a.config.skype.com] - new: [.....3] [ip4][..udp] [...192.168.1.34][64971] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [...192.168.1.34][64971] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [...192.168.1.34][64971] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][a.config.skype.com] - new: [.....4] [ip4][..udp] [...192.168.1.34][60688] -> [....192.168.1.1][...53] + new: [.....4] [ip4][..udp] [...192.168.1.34][60688] -> [....192.168.1.1][...53] detected: [.....4] [ip4][..udp] [...192.168.1.34][60688] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] - new: [.....5] [ip4][..udp] [...192.168.1.34][58631] -> [....192.168.1.1][...53] + new: [.....5] [ip4][..udp] [...192.168.1.34][58631] -> [....192.168.1.1][...53] detected: [.....5] [ip4][..udp] [...192.168.1.34][58631] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] - new: [.....6] [ip4][..udp] [...192.168.1.34][64240] -> [....192.168.1.1][...53] + new: [.....6] [ip4][..udp] [...192.168.1.34][64240] -> [....192.168.1.1][...53] detected: [.....6] [ip4][..udp] [...192.168.1.34][64240] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][api.skype.com] - new: [.....7] [ip4][..udp] [...192.168.1.34][49864] -> [....192.168.1.1][...53] + new: [.....7] [ip4][..udp] [...192.168.1.34][49864] -> [....192.168.1.1][...53] detected: [.....7] [ip4][..udp] [...192.168.1.34][49864] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][api.skype.com] - new: [.....8] [ip4][..udp] [...192.168.1.34][61016] -> [....192.168.1.1][...53] + new: [.....8] [ip4][..udp] [...192.168.1.34][61016] -> [....192.168.1.1][...53] detected: [.....8] [ip4][..udp] [...192.168.1.34][61016] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][apps.skypeassets.com] - new: [.....9] [ip4][..udp] [...192.168.1.34][57694] -> [....192.168.1.1][...53] + new: [.....9] [ip4][..udp] [...192.168.1.34][57694] -> [....192.168.1.1][...53] detected: [.....9] [ip4][..udp] [...192.168.1.34][57694] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][db3msgr5011709.gateway.messenger.live.com] detection-update: [.....9] [ip4][..udp] [...192.168.1.34][57694] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][db3msgr5011709.gateway.messenger.live.com] - new: [....10] [ip4][..tcp] [...192.168.1.34][51229] -> [...157.56.52.28][40009] - new: [....11] [ip4][..udp] [...192.168.1.34][62875] -> [....192.168.1.1][...53] + new: [....10] [ip4][..tcp] [...192.168.1.34][51229] -> [...157.56.52.28][40009] + new: [....11] [ip4][..udp] [...192.168.1.34][62875] -> [....192.168.1.1][...53] detected: [....11] [ip4][..udp] [...192.168.1.34][62875] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][dsn13.d.skype.net] - new: [....12] [ip4][..udp] [...192.168.1.34][59113] -> [....192.168.1.1][...53] + new: [....12] [ip4][..udp] [...192.168.1.34][59113] -> [....192.168.1.1][...53] detected: [....12] [ip4][..udp] [...192.168.1.34][59113] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][dsn13.d.skype.net] - new: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] - new: [....14] [ip4][..udp] [...192.168.1.34][57592] -> [....192.168.1.1][...53] + new: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] + new: [....14] [ip4][..udp] [...192.168.1.34][57592] -> [....192.168.1.1][...53] detected: [....14] [ip4][..udp] [...192.168.1.34][57592] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst11.r.skype.net] - new: [....15] [ip4][..udp] [...192.168.1.34][53372] -> [....192.168.1.1][...53] + new: [....15] [ip4][..udp] [...192.168.1.34][53372] -> [....192.168.1.1][...53] detected: [....15] [ip4][..udp] [...192.168.1.34][53372] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst11.r.skype.net] detected: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older) - new: [....16] [ip4][..udp] [...192.168.1.34][63514] -> [....192.168.1.1][...53] + new: [....16] [ip4][..udp] [...192.168.1.34][63514] -> [....192.168.1.1][...53] detected: [....16] [ip4][..udp] [...192.168.1.34][63514] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] detection-update: [.....2] [ip4][..udp] [...192.168.1.34][55028] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][a.config.skype.com] RISK: Unidirectional Traffic detection-update: [.....3] [ip4][..udp] [...192.168.1.34][64971] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][a.config.skype.com] RISK: Unidirectional Traffic - new: [....17] [ip4][..udp] [...192.168.1.34][63661] -> [....192.168.1.1][...53] + new: [....17] [ip4][..udp] [...192.168.1.34][63661] -> [....192.168.1.1][...53] detected: [....17] [ip4][..udp] [...192.168.1.34][63661] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] detection-update: [....17] [ip4][..udp] [...192.168.1.34][63661] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] - new: [....18] [ip4][..tcp] [...192.168.1.34][51231] -> [..23.206.33.166][..443] + new: [....18] [ip4][..tcp] [...192.168.1.34][51231] -> [..23.206.33.166][..443] detection-update: [.....5] [ip4][..udp] [...192.168.1.34][58631] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] RISK: Unidirectional Traffic detection-update: [.....4] [ip4][..udp] [...192.168.1.34][60688] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][conn.skype.akadns.net] @@ -62,7 +62,7 @@ RISK: Unidirectional Traffic detection-update: [....15] [ip4][..udp] [...192.168.1.34][53372] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst11.r.skype.net] RISK: Unidirectional Traffic - new: [....19] [ip4][..tcp] [.17.143.160.149][.5223] -> [...192.168.1.34][50407] [MIDSTREAM] + new: [....19] [ip4][..tcp] [.17.143.160.149][.5223] -> [...192.168.1.34][50407] [MIDSTREAM] detected: [....19] [ip4][..tcp] [.17.143.160.149][.5223] -> [...192.168.1.34][50407] [TLS][Apple][Web][Safe] RISK: Known Proto on Non Std Port analyse: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] @@ -75,14 +75,14 @@ [IATS(ms)....: 75.6,75.7,27.5,108.8,0.2,81.5,75.6,0.8,76.4,15.4,302.2,286.8,74.7,74.7,0.5,91.1,90.5,1.7,83.6,81.9,0.3,247.1,246.9,0.3,0.2,0.3,92.3,92.0,289.8,38.7,0.0] [PKTLENS.....: 64,56,52,146,1492,72,52,1492,850,52,159,52,111,111,52,281,233,52,681,233,52,249,745,52,265,52,617,153,1369,52,1492,57] [ENTROPIES...: 4.6,5.2,5.2,5.7,7.0,5.6,5.1,7.5,7.7,5.1,6.7,5.2,6.0,6.1,5.1,7.3,7.0,5.1,7.7,7.0,5.1,7.2,7.7,5.2,7.2,5.2,7.7,6.6,7.9,5.2,7.9,5.3] - new: [....20] [ip4][..udp] [...192.168.1.34][50055] -> [....192.168.1.1][...53] + new: [....20] [ip4][..udp] [...192.168.1.34][50055] -> [....192.168.1.1][...53] detected: [....20] [ip4][..udp] [...192.168.1.34][50055] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [....21] [ip4][..udp] [...192.168.1.34][51753] -> [....192.168.1.1][...53] + new: [....21] [ip4][..udp] [...192.168.1.34][51753] -> [....192.168.1.1][...53] detected: [....21] [ip4][..udp] [...192.168.1.34][51753] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [....22] [ip4][..tcp] [...192.168.1.34][51232] -> [...157.56.52.28][..443] + new: [....22] [ip4][..tcp] [...192.168.1.34][51232] -> [...157.56.52.28][..443] detection-update: [....16] [ip4][..udp] [...192.168.1.34][63514] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][ui.skype.com] RISK: Unidirectional Traffic - new: [....23] [ip4][..tcp] [...192.168.1.34][51227] -> [..17.172.100.36][..443] [MIDSTREAM] + new: [....23] [ip4][..tcp] [...192.168.1.34][51227] -> [..17.172.100.36][..443] [MIDSTREAM] detected: [....23] [ip4][..tcp] [...192.168.1.34][51227] -> [..17.172.100.36][..443] [TLS][Apple][Web][Safe] detection-update: [....23] [ip4][..tcp] [...192.168.1.34][51227] -> [..17.172.100.36][..443] [TLS][Apple][Web][Safe] RISK: Unidirectional Traffic @@ -101,360 +101,360 @@ [IATS(ms)....: 0.1,141.8,4.6,11.8,0.0,158.2,0.0,1.4,0.0,1.4,0.0,933.1,0.1,1077.4,3.9,16.1,0.0,164.2,0.0,1.9,0.0,1.8,0.0,866.4,0.1,1010.6,5.0,11.8,160.8,0.2,0.1] [PKTLENS.....: 666,608,46,46,373,76,40,40,642,66,40,40,659,616,46,46,373,76,40,40,647,66,40,40,663,542,46,46,373,40,76,40] [ENTROPIES...: 7.7,7.7,4.7,4.5,7.4,5.7,4.8,4.9,7.6,5.6,4.8,4.8,7.7,7.7,4.6,4.6,7.5,5.7,4.8,4.8,7.7,5.6,4.8,4.9,7.7,7.6,4.6,4.5,7.4,4.8,5.8,4.8] - new: [....24] [ip4][..udp] [...192.168.1.34][..137] -> [..192.168.1.255][..137] + new: [....24] [ip4][..udp] [...192.168.1.34][..137] -> [..192.168.1.255][..137] detected: [....24] [ip4][..udp] [...192.168.1.34][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][__msbrowse__] - new: [....25] [ip4][..udp] [....192.168.1.1][..137] -> [...192.168.1.34][..137] + new: [....25] [ip4][..udp] [....192.168.1.1][..137] -> [...192.168.1.34][..137] detected: [....25] [ip4][..udp] [....192.168.1.1][..137] -> [...192.168.1.34][..137] [NetBIOS][Unknown][System][Acceptable][__msbrowse__] - new: [....26] [ip4][..udp] [...192.168.1.34][..138] -> [..192.168.1.255][..138] + new: [....26] [ip4][..udp] [...192.168.1.34][..138] -> [..192.168.1.255][..138] detected: [....26] [ip4][..udp] [...192.168.1.34][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][lucasmacbookpro] RISK: Unsafe Protocol - new: [....27] [ip4][..udp] [....192.168.1.1][..138] -> [...192.168.1.34][..138] + new: [....27] [ip4][..udp] [....192.168.1.1][..138] -> [...192.168.1.34][..138] detected: [....27] [ip4][..udp] [....192.168.1.1][..138] -> [...192.168.1.34][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][alicegate] RISK: Unsafe Protocol - new: [....28] [ip4][..udp] [...192.168.1.92][..137] -> [..192.168.1.255][..137] + new: [....28] [ip4][..udp] [...192.168.1.92][..137] -> [..192.168.1.255][..137] detected: [....28] [ip4][..udp] [...192.168.1.92][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] - new: [....29] [ip4][..udp] [...192.168.1.92][..138] -> [..192.168.1.255][..138] + new: [....29] [ip4][..udp] [...192.168.1.92][..138] -> [..192.168.1.255][..138] detected: [....29] [ip4][..udp] [...192.168.1.92][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][lucas-imac] RISK: Unsafe Protocol - new: [....30] [ip4][..udp] [...192.168.1.92][53826] -> [..192.168.1.255][..137] + new: [....30] [ip4][..udp] [...192.168.1.92][53826] -> [..192.168.1.255][..137] detected: [....30] [ip4][..udp] [...192.168.1.92][53826] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][lucas-imac] - new: [....31] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] + new: [....31] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] detected: [....31] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] - new: [....32] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] + new: [....32] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] detected: [....32] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] detection-update: [....31] [ip6][..udp] [...............fe80::c62c:3ff:fe06:49fe][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] - new: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.170][40015] + new: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.170][40015] detected: [....33] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.170][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40026] + new: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40026] detected: [....34] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.15][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40002] + new: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40002] detected: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40027] + new: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40027] detected: [....36] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.145][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40028] + new: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40028] detected: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40025] + new: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40025] detected: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.34][40027] + new: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.34][40027] detected: [....39] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.34][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.168][40024] + new: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.168][40024] detected: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.168][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] + new: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] detected: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] + new: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] detected: [....42] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.143][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40019] + new: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40019] detected: [....43] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.44][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.173][40013] + new: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.173][40013] detected: [....44] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.173][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....45] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.167][40024] + new: [....45] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.167][40024] detected: [....45] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.167][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....46] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40004] + new: [....46] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40004] detected: [....46] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.165][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....47] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40025] + new: [....47] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40025] detected: [....47] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.17][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....48] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] + new: [....48] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] detected: [....48] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....49] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] + new: [....49] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] detected: [....49] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....50] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.32][40022] + new: [....50] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.32][40022] detected: [....50] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.32][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....51] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.33][40011] + new: [....51] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.33][40011] detected: [....51] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.33][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40008] + new: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40008] detected: [....52] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.145][40008] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.13][40009] + new: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.13][40009] detected: [....53] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.13][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.19][40020] + new: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.19][40020] detected: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.19][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....55] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] + new: [....55] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] detected: [....55] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....56] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] + new: [....56] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] detected: [....56] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....57] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] + new: [....57] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] detected: [....57] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....58] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] + new: [....58] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] detected: [....58] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....59] [ip4][..tcp] [...192.168.1.34][51234] -> [.157.55.235.147][40001] - new: [....60] [ip4][..tcp] [...192.168.1.34][51235] -> [...65.55.223.45][40009] - new: [....61] [ip4][..tcp] [...192.168.1.34][51236] -> [..111.221.74.45][40008] - new: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.171][40012] + new: [....59] [ip4][..tcp] [...192.168.1.34][51234] -> [.157.55.235.147][40001] + new: [....60] [ip4][..tcp] [...192.168.1.34][51235] -> [...65.55.223.45][40009] + new: [....61] [ip4][..tcp] [...192.168.1.34][51236] -> [..111.221.74.45][40008] + new: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.171][40012] detected: [....62] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.171][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....63] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.65][33033] + new: [....63] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.65][33033] detected: [....63] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.65][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....64] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.140][40003] + new: [....64] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.140][40003] detected: [....64] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.140][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....65] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.39][40031] + new: [....65] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.39][40031] detected: [....65] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.39][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.25][40010] + new: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.25][40010] detected: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.25][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....67] [ip4][..tcp] [...192.168.1.34][51237] -> [.157.55.130.176][40022] - new: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40014] + new: [....67] [ip4][..tcp] [...192.168.1.34][51237] -> [.157.55.130.176][40022] + new: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40014] detected: [....68] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.28][40014] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40013] + new: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40013] detected: [....69] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.154][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40020] + new: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40020] detected: [....70] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.44][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....71] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] + new: [....71] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] detected: [....71] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40017] + new: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40017] detected: [....72] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.154][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....73] [ip4][..tcp] [...192.168.1.34][51238] -> [.157.55.235.147][..443] - new: [....74] [ip4][..tcp] [...192.168.1.34][51239] -> [...65.55.223.45][..443] - new: [....75] [ip4][..tcp] [...192.168.1.34][51240] -> [..111.221.74.45][..443] - new: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] + new: [....73] [ip4][..tcp] [...192.168.1.34][51238] -> [.157.55.235.147][..443] + new: [....74] [ip4][..tcp] [...192.168.1.34][51239] -> [...65.55.223.45][..443] + new: [....75] [ip4][..tcp] [...192.168.1.34][51240] -> [..111.221.74.45][..443] + new: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] detected: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.160][40030] + new: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.160][40030] detected: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.160][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.12][40031] + new: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.12][40031] detected: [....78] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.12][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] + new: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] detected: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.174][40025] + new: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.174][40025] detected: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.174][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....81] [ip4][..tcp] [...192.168.1.34][51241] -> [.157.55.130.176][..443] - new: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.13][40009] + new: [....81] [ip4][..tcp] [...192.168.1.34][51241] -> [.157.55.130.176][..443] + new: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.13][40009] detected: [....82] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.13][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] + new: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] detected: [....83] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.46][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.174][40019] + new: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.174][40019] detected: [....84] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.174][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.22][40009] + new: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.22][40009] detected: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.22][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40024] + new: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40024] detected: [....86] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.145][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....87] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.150][40007] + new: [....87] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.150][40007] detected: [....87] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.150][40007] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] + new: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] detected: [....88] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.15][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.162][40033] + new: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.162][40033] detected: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.162][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40031] + new: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40031] detected: [....90] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.159][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40029] + new: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40029] detected: [....91] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.148][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.142][40023] + new: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.142][40023] detected: [....92] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.142][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....93] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] + new: [....93] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] detected: [....93] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.149][40011] + new: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.149][40011] detected: [....94] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.149][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40029] + new: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40029] detected: [....95] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.151][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40004] + new: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40004] detected: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....97] [ip4][..tcp] [...192.168.1.34][51246] -> [...157.56.52.44][40020] - new: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40019] + new: [....97] [ip4][..tcp] [...192.168.1.34][51246] -> [...157.56.52.44][40020] + new: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40019] detected: [....98] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.156][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [....99] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.27][40029] + new: [....99] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.27][40029] detected: [....99] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.27][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...100] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40013] + new: [...100] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40013] detected: [...100] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.142][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...101] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.154][40032] + new: [...101] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.154][40032] detected: [...101] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.154][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40002] + new: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40002] detected: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40006] + new: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40006] detected: [...103] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.42][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40020] + new: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40020] detected: [...104] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.172][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.167][40029] + new: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.167][40029] detected: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.167][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.140][40003] + new: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.140][40003] detected: [...106] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.140][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.156][40031] + new: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.156][40031] detected: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.156][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...108] [ip4][..tcp] [...192.168.1.34][51247] -> [...157.56.52.44][..443] - new: [...109] [ip4][..tcp] [...192.168.1.34][51248] -> [.111.221.77.175][40030] - new: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.13][40021] + new: [...108] [ip4][..tcp] [...192.168.1.34][51247] -> [...157.56.52.44][..443] + new: [...109] [ip4][..tcp] [...192.168.1.34][51248] -> [.111.221.77.175][40030] + new: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.13][40021] detected: [...110] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.13][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.27][40027] + new: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.27][40027] detected: [...111] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.27][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...112] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] + new: [...112] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] detected: [...112] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...113] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40008] + new: [...113] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40008] detected: [...113] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.160][40008] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.42][40005] + new: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.42][40005] detected: [...114] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.42][40005] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.16][40032] + new: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.16][40032] detected: [...115] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.16][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40018] + new: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40018] detected: [...116] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40031] + new: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40031] detected: [...117] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.176][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40032] + new: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40032] detected: [...118] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.24][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.20][40033] + new: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.20][40033] detected: [...119] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.20][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...120] [ip4][..tcp] [...192.168.1.34][51250] -> [.111.221.77.175][..443] - new: [...121] [ip4][..tcp] [...192.168.1.34][51251] -> [....64.4.23.166][40029] - new: [...122] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40016] + new: [...120] [ip4][..tcp] [...192.168.1.34][51250] -> [.111.221.77.175][..443] + new: [...121] [ip4][..tcp] [...192.168.1.34][51251] -> [....64.4.23.166][40029] + new: [...122] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40016] detected: [...122] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40016] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.20][40033] + new: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.20][40033] detected: [...123] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.20][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.144][40032] + new: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.144][40032] detected: [...124] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.144][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40004] + new: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40004] detected: [...125] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.165][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40033] + new: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40033] detected: [...126] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...127] [ip4][..tcp] [108.160.163.108][..443] -> [...192.168.1.34][51222] [MIDSTREAM] + new: [...127] [ip4][..tcp] [108.160.163.108][..443] -> [...192.168.1.34][51222] [MIDSTREAM] detected: [...127] [ip4][..tcp] [108.160.163.108][..443] -> [...192.168.1.34][51222] [TLS][Dropbox][Web][Safe] - new: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40032] + new: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40032] detected: [...128] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.24][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40016] + new: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40016] detected: [...129] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.160][40016] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...130] [ip4][..tcp] [...192.168.1.34][51253] -> [....64.4.23.166][..443] - new: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40026] + new: [...130] [ip4][..tcp] [...192.168.1.34][51253] -> [....64.4.23.166][..443] + new: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40026] detected: [...131] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.28][40026] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] + new: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] detected: [...132] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...133] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.152][40022] + new: [...133] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.152][40022] detected: [...133] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.152][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...134] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.172][40011] + new: [...134] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.172][40011] detected: [...134] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.172][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...135] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] + new: [...135] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] detected: [...135] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.151][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.176][40001] + new: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.176][40001] detected: [...136] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.176][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] + new: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] detected: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40027] + new: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40027] detected: [...138] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.155][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...139] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] + new: [...139] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] detected: [...139] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [...140] [ip4][....2] [..192.168.1.229] -> [....224.0.0.251] + new: [...140] [ip4][....2] [..192.168.1.229] -> [....224.0.0.251] detected: [...140] [ip4][....2] [..192.168.1.229] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [...141] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] + new: [...141] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] detected: [...141] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.154][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...142] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.149][40030] + new: [...142] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.149][40030] detected: [...142] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.149][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...143] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.171][40030] + new: [...143] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.171][40030] detected: [...143] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.171][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...144] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40031] + new: [...144] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40031] detected: [...144] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.161][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.148][40033] + new: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.148][40033] detected: [...145] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.148][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] ERROR-EVENT: Unknown packet type [1/16] - new: [...146] [ip4][..tcp] [...192.168.1.34][51255] -> [.157.55.130.142][40005] - new: [...147] [ip4][..tcp] [...192.168.1.34][51256] -> [.111.221.77.142][40013] - new: [...148] [ip4][..tcp] [...192.168.1.34][51257] -> [.157.55.235.170][40032] - new: [...149] [ip4][..tcp] [...192.168.1.34][51258] -> [213.199.179.176][40021] - new: [...150] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40016] + new: [...146] [ip4][..tcp] [...192.168.1.34][51255] -> [.157.55.130.142][40005] + new: [...147] [ip4][..tcp] [...192.168.1.34][51256] -> [.111.221.77.142][40013] + new: [...148] [ip4][..tcp] [...192.168.1.34][51257] -> [.157.55.235.170][40032] + new: [...149] [ip4][..tcp] [...192.168.1.34][51258] -> [213.199.179.176][40021] + new: [...150] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40016] detected: [...150] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.149][40016] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] + new: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] detected: [...151] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.19][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.140][40011] + new: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.140][40011] detected: [...152] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.140][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...153] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.167][40031] + new: [...153] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.167][40031] detected: [...153] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.167][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] + new: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] detected: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...155] [ip4][..udp] [...192.168.1.34][63342] -> [....192.168.1.1][...53] + new: [...155] [ip4][..udp] [...192.168.1.34][63342] -> [....192.168.1.1][...53] detected: [...155] [ip4][..udp] [...192.168.1.34][63342] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [...156] [ip4][..udp] [...192.168.1.34][64258] -> [....192.168.1.1][...53] + new: [...156] [ip4][..udp] [...192.168.1.34][64258] -> [....192.168.1.1][...53] detected: [...156] [ip4][..udp] [...192.168.1.34][64258] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] - new: [...157] [ip4][..tcp] [...192.168.1.34][51259] -> [.111.221.77.142][..443] - new: [...158] [ip4][..tcp] [...192.168.1.34][51260] -> [.157.55.130.142][..443] - new: [...159] [ip4][..tcp] [...192.168.1.34][51261] -> [.157.55.235.170][..443] - new: [...160] [ip4][..tcp] [...192.168.1.34][51262] -> [213.199.179.176][..443] - new: [...161] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] + new: [...157] [ip4][..tcp] [...192.168.1.34][51259] -> [.111.221.77.142][..443] + new: [...158] [ip4][..tcp] [...192.168.1.34][51260] -> [.157.55.130.142][..443] + new: [...159] [ip4][..tcp] [...192.168.1.34][51261] -> [.157.55.235.170][..443] + new: [...160] [ip4][..tcp] [...192.168.1.34][51262] -> [213.199.179.176][..443] + new: [...161] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] detected: [...161] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.166][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40024] + new: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40024] detected: [...162] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.145][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.42][40024] + new: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.42][40024] detected: [...163] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.42][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] detection-update: [...155] [ip4][..udp] [...192.168.1.34][63342] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic detection-update: [...156] [ip4][..udp] [...192.168.1.34][64258] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][b.config.skype.com] RISK: Unidirectional Traffic - new: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] + new: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] detected: [...164] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.38][40015] + new: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.38][40015] detected: [...165] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.38][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...166] [ip4][..udp] [...192.168.1.34][61095] -> [....192.168.1.1][...53] + new: [...166] [ip4][..udp] [...192.168.1.34][61095] -> [....192.168.1.1][...53] detected: [...166] [ip4][..udp] [...192.168.1.34][61095] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...167] [ip4][..udp] [...192.168.1.34][55866] -> [....192.168.1.1][...53] + new: [...167] [ip4][..udp] [...192.168.1.34][55866] -> [....192.168.1.1][...53] detected: [...167] [ip4][..udp] [...192.168.1.34][55866] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] - new: [...168] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.38][40015] + new: [...168] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.38][40015] detected: [...168] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.38][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.40][40017] + new: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.40][40017] detected: [...169] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.40][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] detection-update: [...167] [ip4][..udp] [...192.168.1.34][55866] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic detection-update: [...166] [ip4][..udp] [...192.168.1.34][61095] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][pipe.prd.skypedata.akadns.net] RISK: Unidirectional Traffic - new: [...170] [ip4][..tcp] [...192.168.1.34][51267] -> [..111.221.74.18][40025] - new: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.171][40031] + new: [...170] [ip4][..tcp] [...192.168.1.34][51267] -> [..111.221.74.18][40025] + new: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.171][40031] detected: [...171] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.171][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] + new: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] detected: [...172] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.43][40001] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40023] + new: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40023] detected: [...173] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.20][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...174] [ip4][....2] [..192.168.1.219] -> [...233.89.188.1] + new: [...174] [ip4][....2] [..192.168.1.219] -> [...233.89.188.1] detected: [...174] [ip4][....2] [..192.168.1.219] -> [...233.89.188.1] [IGMP][Unknown][Network][Acceptable] - new: [...175] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40003] + new: [...175] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40003] detected: [...175] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.140][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...176] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.158][40021] + new: [...176] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.158][40021] detected: [...176] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.158][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...177] [ip4][..tcp] [...192.168.1.34][51268] -> [..111.221.74.18][..443] - new: [...178] [ip4][..tcp] [...192.168.1.34][51269] -> [213.199.179.175][40029] - new: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.171][40006] + new: [...177] [ip4][..tcp] [...192.168.1.34][51268] -> [..111.221.74.18][..443] + new: [...178] [ip4][..tcp] [...192.168.1.34][51269] -> [213.199.179.175][40029] + new: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.171][40006] detected: [...179] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.171][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.173][40003] + new: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.173][40003] detected: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.173][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.143][40018] + new: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.143][40018] detected: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] + new: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] detected: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...183] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40006] + new: [...183] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40006] detected: [...183] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.150][40014] + new: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.150][40014] detected: [...184] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.150][40014] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...185] [ip4][..tcp] [...192.168.1.34][51271] -> [213.199.179.175][..443] - new: [...186] [ip4][..tcp] [...192.168.1.34][51272] -> [.157.55.235.152][40029] - new: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.147][40014] + new: [...185] [ip4][..tcp] [...192.168.1.34][51271] -> [213.199.179.175][..443] + new: [...186] [ip4][..tcp] [...192.168.1.34][51272] -> [.157.55.235.152][40029] + new: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.147][40014] detected: [...187] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.147][40014] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][40025] + new: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][40025] detected: [...188] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.18][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40022] + new: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40022] detected: [...189] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.160][40022] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][40030] + new: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][40030] detected: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...191] [ip4][..tcp] [...192.168.1.34][51274] -> [.157.55.235.152][..443] - new: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.170][40018] + new: [...191] [ip4][..tcp] [...192.168.1.34][51274] -> [.157.55.235.152][..443] + new: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.170][40018] detected: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.170][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.159][40016] + new: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.159][40016] detected: [...193] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.159][40016] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...194] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.170][40021] + new: [...194] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.170][40021] detected: [...194] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.170][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...195] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40029] + new: [...195] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40029] detected: [...195] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.24][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...196] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40027] + new: [...196] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40027] detected: [...196] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.158][40027] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.16][40032] + new: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.16][40032] detected: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.16][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...198] [ip4][..udp] [...192.168.1.34][60413] -> [....192.168.1.1][...53] + new: [...198] [ip4][..udp] [...192.168.1.34][60413] -> [....192.168.1.1][...53] detected: [...198] [ip4][..udp] [...192.168.1.34][60413] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst0.r.skype.net] - new: [...199] [ip4][..udp] [...192.168.1.34][64364] -> [....192.168.1.1][...53] + new: [...199] [ip4][..udp] [...192.168.1.34][64364] -> [....192.168.1.1][...53] detected: [...199] [ip4][..udp] [...192.168.1.34][64364] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst0.r.skype.net] - new: [...200] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.149][40030] + new: [...200] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.149][40030] detected: [...200] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.149][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.29][40010] + new: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.29][40010] detected: [...201] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.29][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] detection-update: [...198] [ip4][..udp] [...192.168.1.34][60413] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst0.r.skype.net] RISK: Unidirectional Traffic detection-update: [...199] [ip4][..udp] [...192.168.1.34][64364] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][335.0.7.7.3.rst0.r.skype.net] RISK: Unidirectional Traffic - new: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.43][40006] + new: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.43][40006] detected: [...202] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.43][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...203] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] + new: [...203] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] detected: [...203] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...204] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40030] + new: [...204] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40030] detected: [...204] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.15][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...205] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.144][40009] + new: [...205] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.144][40009] detected: [...205] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.144][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40025] + new: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40025] detected: [...206] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.40][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [.....8] [ip4][..udp] [...192.168.1.34][61016] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [...192.168.1.34][59113] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -485,43 +485,43 @@ RISK: Unidirectional Traffic update: [.....3] [ip4][..udp] [...192.168.1.34][64971] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...207] [ip4][..tcp] [...192.168.1.34][51276] -> [.157.55.235.146][40021] - new: [...208] [ip4][..tcp] [...192.168.1.34][51277] -> [.157.55.235.156][40026] - new: [...209] [ip4][..tcp] [...192.168.1.34][51278] -> [....64.4.23.159][40009] - new: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] - new: [...211] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] + new: [...207] [ip4][..tcp] [...192.168.1.34][51276] -> [.157.55.235.146][40021] + new: [...208] [ip4][..tcp] [...192.168.1.34][51277] -> [.157.55.235.156][40026] + new: [...209] [ip4][..tcp] [...192.168.1.34][51278] -> [....64.4.23.159][40009] + new: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] + new: [...211] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] detected: [...211] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.175][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...212] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.173][40012] + new: [...212] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.173][40012] detected: [...212] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.173][40012] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...213] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40023] + new: [...213] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40023] detected: [...213] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.175][40023] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...214] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] + new: [...214] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] detected: [...214] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.17][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...215] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] + new: [...215] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] detected: [...215] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...216] [ip4][..tcp] [...192.168.1.34][51280] -> [.157.55.235.146][..443] - new: [...217] [ip4][..tcp] [...192.168.1.34][51281] -> [.157.55.235.156][..443] - new: [...218] [ip4][..tcp] [...192.168.1.34][51282] -> [....64.4.23.159][..443] - new: [...219] [ip4][..tcp] [...192.168.1.34][51283] -> [..111.221.74.48][..443] - new: [...220] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] + new: [...216] [ip4][..tcp] [...192.168.1.34][51280] -> [.157.55.235.146][..443] + new: [...217] [ip4][..tcp] [...192.168.1.34][51281] -> [.157.55.235.156][..443] + new: [...218] [ip4][..tcp] [...192.168.1.34][51282] -> [....64.4.23.159][..443] + new: [...219] [ip4][..tcp] [...192.168.1.34][51283] -> [..111.221.74.48][..443] + new: [...220] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] detected: [...220] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.157][40013] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...221] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] + new: [...221] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] detected: [...221] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.155][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...222] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] + new: [...222] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] detected: [...222] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.141][40015] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...223] [ip4][..udp] [...192.168.1.34][59237] -> [239.255.255.250][.1900] + new: [...223] [ip4][..udp] [...192.168.1.34][59237] -> [239.255.255.250][.1900] detected: [...223] [ip4][..udp] [...192.168.1.34][59237] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...224] [ip4][..udp] [...192.168.1.34][58061] -> [239.255.255.250][.1900] + new: [...224] [ip4][..udp] [...192.168.1.34][58061] -> [239.255.255.250][.1900] detected: [...224] [ip4][..udp] [...192.168.1.34][58061] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [...225] [ip4][..udp] [...192.168.1.34][59052] -> [....192.168.1.1][.5351] + new: [...225] [ip4][..udp] [...192.168.1.34][59052] -> [....192.168.1.1][.5351] detected: [...225] [ip4][..udp] [...192.168.1.34][59052] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] - new: [...226] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] + new: [...226] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] detected: [...226] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] [ICMP][Unknown][Network][Acceptable] - new: [...227] [ip4][..tcp] [...192.168.1.34][51284] -> [.91.190.218.125][12350] + new: [...227] [ip4][..tcp] [...192.168.1.34][51284] -> [.91.190.218.125][12350] detection-update: [...225] [ip4][..udp] [...192.168.1.34][59052] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [...228] [ip4][..tcp] [...192.168.1.34][51285] -> [.91.190.218.125][12350] - analyse: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] + new: [...228] [ip4][..tcp] [...192.168.1.34][51285] -> [.91.190.218.125][12350] + analyse: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 1.297| 0.245| 0.278| 77244.252| 4.100] [PKTLEN......: 52.000| 1492.000| 166.600| 288.600| 83264.900| 3.900] @@ -531,37 +531,37 @@ [IATS(ms)....: 1006.2,1296.9,290.8,0.6,292.8,2.2,294.3,0.5,293.3,292.8,39.6,39.6,253.3,253.3,40.1,40.1,350.4,0.0,350.4,293.9,293.9,0.1,334.3,334.2,300.0,0.0,300.0,2.1,4.2,292.4,290.3] [PKTLENS.....: 64,64,60,52,102,52,155,52,60,60,52,52,98,81,52,52,91,52,55,52,196,52,56,52,661,52,56,52,1492,106,603,595] [ENTROPIES...: 4.6,4.7,5.4,5.2,6.1,5.3,6.7,5.2,5.4,5.4,5.2,5.2,6.3,6.0,5.2,5.1,6.2,5.3,5.2,5.3,6.9,5.2,5.3,5.2,7.7,5.2,5.3,5.2,7.9,6.2,7.7,7.6] - new: [...229] [ip4][..tcp] [...192.168.1.34][51286] -> [.91.190.218.125][..443] - new: [...230] [ip4][..udp] [...192.168.1.34][13021] -> [.174.49.171.224][32011] + new: [...229] [ip4][..tcp] [...192.168.1.34][51286] -> [.91.190.218.125][..443] + new: [...230] [ip4][..udp] [...192.168.1.34][13021] -> [.174.49.171.224][32011] detected: [...230] [ip4][..udp] [...192.168.1.34][13021] -> [.174.49.171.224][32011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...231] [ip4][..udp] [...192.168.1.34][13021] -> [...83.31.12.173][23939] + new: [...231] [ip4][..udp] [...192.168.1.34][13021] -> [...83.31.12.173][23939] detected: [...231] [ip4][..udp] [...192.168.1.34][13021] -> [...83.31.12.173][23939] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...232] [ip4][..udp] [...192.168.1.34][13021] -> [.189.138.161.88][19521] + new: [...232] [ip4][..udp] [...192.168.1.34][13021] -> [.189.138.161.88][19521] detected: [...232] [ip4][..udp] [...192.168.1.34][13021] -> [.189.138.161.88][19521] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...233] [ip4][..udp] [...192.168.1.34][13021] -> [189.188.134.174][22436] + new: [...233] [ip4][..udp] [...192.168.1.34][13021] -> [189.188.134.174][22436] detected: [...233] [ip4][..udp] [...192.168.1.34][13021] -> [189.188.134.174][22436] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...234] [ip4][..tcp] [...192.168.1.34][51288] -> [...76.167.161.6][20274] - new: [...235] [ip4][..tcp] [...192.168.1.34][51289] -> [...71.238.7.203][18767] - new: [...236] [ip4][..tcp] [...192.168.1.34][51290] -> [..5.248.186.221][31010] - new: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.14][..443] + new: [...234] [ip4][..tcp] [...192.168.1.34][51288] -> [...76.167.161.6][20274] + new: [...235] [ip4][..tcp] [...192.168.1.34][51289] -> [...71.238.7.203][18767] + new: [...236] [ip4][..tcp] [...192.168.1.34][51290] -> [..5.248.186.221][31010] + new: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.14][..443] detected: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.14][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...238] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.141][..443] + new: [...238] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.141][..443] detected: [...238] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.141][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...239] [ip4][..tcp] [...192.168.1.34][51291] -> [...81.83.77.141][17639] - new: [...240] [ip4][..tcp] [...192.168.1.34][51292] -> [...71.238.7.203][18767] - new: [...241] [ip4][..tcp] [...192.168.1.34][51293] -> [..5.248.186.221][31010] - new: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] - new: [...243] [ip4][..udp] [...192.168.1.34][59788] -> [....192.168.1.1][...53] + new: [...239] [ip4][..tcp] [...192.168.1.34][51291] -> [...81.83.77.141][17639] + new: [...240] [ip4][..tcp] [...192.168.1.34][51292] -> [...71.238.7.203][18767] + new: [...241] [ip4][..tcp] [...192.168.1.34][51293] -> [..5.248.186.221][31010] + new: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] + new: [...243] [ip4][..udp] [...192.168.1.34][59788] -> [....192.168.1.1][...53] detected: [...243] [ip4][..udp] [...192.168.1.34][59788] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] detection-update: [...243] [ip4][..udp] [...192.168.1.34][59788] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][e4593.g.akamaiedge.net] - new: [...244] [ip4][..tcp] [...192.168.1.34][51295] -> [..23.206.33.166][..443] + new: [...244] [ip4][..tcp] [...192.168.1.34][51295] -> [..23.206.33.166][..443] detected: [...244] [ip4][..tcp] [...192.168.1.34][51295] -> [..23.206.33.166][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable][apps.skype.com] RISK: Obsolete TLS (v1.1 or older) - new: [...245] [ip4][..tcp] [...192.168.1.34][51296] -> [.91.190.216.125][12350] - new: [...246] [ip4][..tcp] [...192.168.1.34][51297] -> [..91.190.216.24][12350] - new: [...247] [ip4][..tcp] [...192.168.1.34][51298] -> [.82.224.110.241][38895] - new: [...248] [ip4][..tcp] [...192.168.1.34][51299] -> [.91.190.216.125][12350] - new: [...249] [ip4][..tcp] [...192.168.1.34][51300] -> [...76.167.161.6][20274] + new: [...245] [ip4][..tcp] [...192.168.1.34][51296] -> [.91.190.216.125][12350] + new: [...246] [ip4][..tcp] [...192.168.1.34][51297] -> [..91.190.216.24][12350] + new: [...247] [ip4][..tcp] [...192.168.1.34][51298] -> [.82.224.110.241][38895] + new: [...248] [ip4][..tcp] [...192.168.1.34][51299] -> [.91.190.216.125][12350] + new: [...249] [ip4][..tcp] [...192.168.1.34][51300] -> [...76.167.161.6][20274] update: [....38] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.27][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....24] [ip4][..udp] [...192.168.1.34][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] update: [....25] [ip4][..udp] [....192.168.1.1][..137] -> [...192.168.1.34][..137] [NetBIOS][Unknown][System][Acceptable] @@ -585,10 +585,10 @@ update: [....40] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.168][40024] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...250] [ip4][..tcp] [...192.168.1.34][51301] -> [.82.224.110.241][38895] - new: [...251] [ip4][..tcp] [...192.168.1.34][51302] -> [.91.190.216.125][..443] - new: [...252] [ip4][..tcp] [...192.168.1.34][51303] -> [...80.121.84.93][62381] - analyse: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] + new: [...250] [ip4][..tcp] [...192.168.1.34][51301] -> [.82.224.110.241][38895] + new: [...251] [ip4][..tcp] [...192.168.1.34][51302] -> [.91.190.216.125][..443] + new: [...252] [ip4][..tcp] [...192.168.1.34][51303] -> [...80.121.84.93][62381] + analyse: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.004| 0.281| 0.501| 251090.993| 3.500] [PKTLEN......: 52.000| 1176.000| 143.200| 243.000| 59065.600| 3.900] @@ -598,19 +598,19 @@ [IATS(ms)....: 69.8,69.9,0.1,64.1,63.9,0.4,65.4,65.0,2.0,66.7,64.9,268.0,267.9,126.5,126.5,3.7,173.4,169.7,0.2,68.9,95.7,164.4,0.2,67.0,66.9,198.4,1936.2,2004.1,795.9,1062.3,592.6] [PKTLENS.....: 64,60,52,117,80,52,68,66,52,804,66,52,52,56,1176,52,608,95,96,78,52,95,52,79,73,52,52,90,52,91,52,97] [ENTROPIES...: 4.6,5.3,5.2,6.3,5.7,5.2,5.6,5.6,5.2,7.7,5.6,5.2,5.2,5.3,7.8,5.2,7.7,6.1,6.2,5.7,5.1,6.0,5.1,5.9,5.7,5.2,5.2,6.0,5.2,6.0,5.2,6.1] - new: [...253] [ip4][..tcp] [...192.168.1.34][51305] -> [...149.13.32.15][13392] - new: [...254] [ip4][..tcp] [...192.168.1.34][51306] -> [...80.121.84.93][62381] - new: [...255] [ip4][..tcp] [...192.168.1.34][51307] -> [...149.13.32.15][13392] - new: [...256] [ip4][..tcp] [...192.168.1.34][51308] -> [...80.121.84.93][..443] + new: [...253] [ip4][..tcp] [...192.168.1.34][51305] -> [...149.13.32.15][13392] + new: [...254] [ip4][..tcp] [...192.168.1.34][51306] -> [...80.121.84.93][62381] + new: [...255] [ip4][..tcp] [...192.168.1.34][51307] -> [...149.13.32.15][13392] + new: [...256] [ip4][..tcp] [...192.168.1.34][51308] -> [...80.121.84.93][..443] detected: [...255] [ip4][..tcp] [...192.168.1.34][51307] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [...257] [ip4][..tcp] [...192.168.1.34][51309] -> [...149.13.32.15][13392] - new: [...258] [ip4][..tcp] [...192.168.1.34][51311] -> [..93.79.224.176][14506] - new: [...259] [ip4][..tcp] [...192.168.1.34][51312] -> [...149.13.32.15][13392] + new: [...257] [ip4][..tcp] [...192.168.1.34][51309] -> [...149.13.32.15][13392] + new: [...258] [ip4][..tcp] [...192.168.1.34][51311] -> [..93.79.224.176][14506] + new: [...259] [ip4][..tcp] [...192.168.1.34][51312] -> [...149.13.32.15][13392] detected: [...259] [ip4][..tcp] [...192.168.1.34][51312] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [...260] [ip4][..tcp] [...192.168.1.34][51313] -> [...212.161.8.36][13392] - new: [...261] [ip4][..tcp] [...192.168.1.34][51314] -> [..93.79.224.176][14506] + new: [...260] [ip4][..tcp] [...192.168.1.34][51313] -> [...212.161.8.36][13392] + new: [...261] [ip4][..tcp] [...192.168.1.34][51314] -> [..93.79.224.176][14506] update: [...102] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.33][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....66] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.25][40010] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....54] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.19][40020] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -666,15 +666,15 @@ update: [....80] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.174][40025] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [....77] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.160][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] update: [...107] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.156][40031] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] - new: [...262] [ip4][..tcp] [...192.168.1.34][51315] -> [...212.161.8.36][13392] + new: [...262] [ip4][..tcp] [...192.168.1.34][51315] -> [...212.161.8.36][13392] detected: [...262] [ip4][..tcp] [...192.168.1.34][51315] -> [...212.161.8.36][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [...263] [ip4][..tcp] [...192.168.1.34][51316] -> [...149.13.32.15][13392] - new: [...264] [ip4][..tcp] [...192.168.1.34][51317] -> [...149.13.32.15][13392] + new: [...263] [ip4][..tcp] [...192.168.1.34][51316] -> [...149.13.32.15][13392] + new: [...264] [ip4][..tcp] [...192.168.1.34][51317] -> [...149.13.32.15][13392] detected: [...264] [ip4][..tcp] [...192.168.1.34][51317] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port - new: [...265] [ip4][..tcp] [...192.168.1.34][51318] -> [...212.161.8.36][13392] - new: [...266] [ip4][..udp] [...192.168.1.34][13021] -> [..133.236.67.25][49195] + new: [...265] [ip4][..tcp] [...192.168.1.34][51318] -> [...212.161.8.36][13392] + new: [...266] [ip4][..udp] [...192.168.1.34][13021] -> [..133.236.67.25][49195] detected: [...266] [ip4][..udp] [...192.168.1.34][13021] -> [..133.236.67.25][49195] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] analyse: [....49] [ip4][..udp] [..192.168.0.254][.1025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] min| max| avg| stddev| variance| entropy @@ -686,20 +686,20 @@ [IATS(ms)....: 0.6,0.6,0.5,0.5,0.5,99.7,0.6,0.6,0.6,19856.6,16.2,17.0,16.6,16.5,16.7,19850.6,16.2,16.5,16.7,16.7,16.6,17.0,16.6,16.7,16.6,19850.6,16.0,16.7,16.8,16.7,16.6] [PKTLENS.....: 319,337,391,383,313,355,387,333,385,379,313,355,387,333,385,379,319,337,391,383,313,355,387,333,385,379,319,337,391,383,313,355] [ENTROPIES...: 5.8,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.8,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.7,5.8,5.7,5.7,5.7,5.7,5.7] - new: [...267] [ip4][..tcp] [...192.168.1.34][51319] -> [...212.161.8.36][13392] + new: [...267] [ip4][..tcp] [...192.168.1.34][51319] -> [...212.161.8.36][13392] idle: [...233] [ip4][..udp] [...192.168.1.34][13021] -> [189.188.134.174][22436] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] guessed: [....75] [ip4][..tcp] [...192.168.1.34][51240] -> [..111.221.74.45][..443] [TLS][Unknown][Web][Safe] - end: [....75] [ip4][..tcp] [...192.168.1.34][51240] -> [..111.221.74.45][..443] + end: [....75] [ip4][..tcp] [...192.168.1.34][51240] -> [..111.221.74.45][..443] idle: [.....8] [ip4][..udp] [...192.168.1.34][61016] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] guessed: [...120] [ip4][..tcp] [...192.168.1.34][51250] -> [.111.221.77.175][..443] [TLS][Unknown][Web][Safe] - end: [...120] [ip4][..tcp] [...192.168.1.34][51250] -> [.111.221.77.175][..443] + end: [...120] [ip4][..tcp] [...192.168.1.34][51250] -> [.111.221.77.175][..443] guessed: [...157] [ip4][..tcp] [...192.168.1.34][51259] -> [.111.221.77.142][..443] [TLS][Unknown][Web][Safe] - end: [...157] [ip4][..tcp] [...192.168.1.34][51259] -> [.111.221.77.142][..443] + end: [...157] [ip4][..tcp] [...192.168.1.34][51259] -> [.111.221.77.142][..443] guessed: [...177] [ip4][..tcp] [...192.168.1.34][51268] -> [..111.221.74.18][..443] [TLS][Unknown][Web][Safe] - end: [...177] [ip4][..tcp] [...192.168.1.34][51268] -> [..111.221.74.18][..443] + end: [...177] [ip4][..tcp] [...192.168.1.34][51268] -> [..111.221.74.18][..443] guessed: [...219] [ip4][..tcp] [...192.168.1.34][51283] -> [..111.221.74.48][..443] [TLS][Unknown][Web][Safe] RISK: TCP Connection Issues - end: [...219] [ip4][..tcp] [...192.168.1.34][51283] -> [..111.221.74.48][..443] + end: [...219] [ip4][..tcp] [...192.168.1.34][51283] -> [..111.221.74.48][..443] idle: [...266] [ip4][..udp] [...192.168.1.34][13021] -> [..133.236.67.25][49195] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...166] [ip4][..udp] [...192.168.1.34][61095] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic @@ -725,12 +725,12 @@ RISK: Unidirectional Traffic not-detected: [...235] [ip4][..tcp] [...192.168.1.34][51289] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...235] [ip4][..tcp] [...192.168.1.34][51289] -> [...71.238.7.203][18767] + end: [...235] [ip4][..tcp] [...192.168.1.34][51289] -> [...71.238.7.203][18767] end: [....18] [ip4][..tcp] [...192.168.1.34][51231] -> [..23.206.33.166][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] RISK: TLS (probably) Not Carrying HTTPS not-detected: [...240] [ip4][..tcp] [...192.168.1.34][51292] -> [...71.238.7.203][18767] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...240] [ip4][..tcp] [...192.168.1.34][51292] -> [...71.238.7.203][18767] + idle: [...240] [ip4][..tcp] [...192.168.1.34][51292] -> [...71.238.7.203][18767] idle: [.....2] [ip4][..udp] [...192.168.1.34][55028] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic end: [...244] [ip4][..tcp] [...192.168.1.34][51295] -> [..23.206.33.166][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] @@ -739,80 +739,80 @@ idle: [....19] [ip4][..tcp] [.17.143.160.149][.5223] -> [...192.168.1.34][50407] [TLS][Apple][Web][Safe] RISK: Known Proto on Non Std Port guessed: [...229] [ip4][..tcp] [...192.168.1.34][51286] -> [.91.190.218.125][..443] [TLS][Unknown][Web][Safe] - end: [...229] [ip4][..tcp] [...192.168.1.34][51286] -> [.91.190.218.125][..443] + end: [...229] [ip4][..tcp] [...192.168.1.34][51286] -> [.91.190.218.125][..443] idle: [...155] [ip4][..udp] [...192.168.1.34][63342] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...258] [ip4][..tcp] [...192.168.1.34][51311] -> [..93.79.224.176][14506] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...258] [ip4][..tcp] [...192.168.1.34][51311] -> [..93.79.224.176][14506] + end: [...258] [ip4][..tcp] [...192.168.1.34][51311] -> [..93.79.224.176][14506] not-detected: [...261] [ip4][..tcp] [...192.168.1.34][51314] -> [..93.79.224.176][14506] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...261] [ip4][..tcp] [...192.168.1.34][51314] -> [..93.79.224.176][14506] + idle: [...261] [ip4][..tcp] [...192.168.1.34][51314] -> [..93.79.224.176][14506] guessed: [...251] [ip4][..tcp] [...192.168.1.34][51302] -> [.91.190.216.125][..443] [TLS][Unknown][Web][Safe] - end: [...251] [ip4][..tcp] [...192.168.1.34][51302] -> [.91.190.216.125][..443] + end: [...251] [ip4][..tcp] [...192.168.1.34][51302] -> [.91.190.216.125][..443] not-detected: [...239] [ip4][..tcp] [...192.168.1.34][51291] -> [...81.83.77.141][17639] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...239] [ip4][..tcp] [...192.168.1.34][51291] -> [...81.83.77.141][17639] + end: [...239] [ip4][..tcp] [...192.168.1.34][51291] -> [...81.83.77.141][17639] not-detected: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] + idle: [...242] [ip4][..tcp] [...192.168.1.34][51294] -> [...81.83.77.141][17639] not-detected: [...247] [ip4][..tcp] [...192.168.1.34][51298] -> [.82.224.110.241][38895] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...247] [ip4][..tcp] [...192.168.1.34][51298] -> [.82.224.110.241][38895] + end: [...247] [ip4][..tcp] [...192.168.1.34][51298] -> [.82.224.110.241][38895] not-detected: [...250] [ip4][..tcp] [...192.168.1.34][51301] -> [.82.224.110.241][38895] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...250] [ip4][..tcp] [...192.168.1.34][51301] -> [.82.224.110.241][38895] + idle: [...250] [ip4][..tcp] [...192.168.1.34][51301] -> [.82.224.110.241][38895] idle: [...226] [ip4][.icmp] [....192.168.1.1] -> [...192.168.1.34] [ICMP][Unknown][Network][Acceptable] idle: [....57] [ip4][..udp] [...192.168.1.92][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [....55] [ip4][..udp] [...192.168.1.34][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] not-detected: [...121] [ip4][..tcp] [...192.168.1.34][51251] -> [....64.4.23.166][40029] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...121] [ip4][..tcp] [...192.168.1.34][51251] -> [....64.4.23.166][40029] + end: [...121] [ip4][..tcp] [...192.168.1.34][51251] -> [....64.4.23.166][40029] not-detected: [...209] [ip4][..tcp] [...192.168.1.34][51278] -> [....64.4.23.159][40009] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...209] [ip4][..tcp] [...192.168.1.34][51278] -> [....64.4.23.159][40009] + end: [...209] [ip4][..tcp] [...192.168.1.34][51278] -> [....64.4.23.159][40009] idle: [...139] [ip4][....2] [..192.168.0.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] idle: [...140] [ip4][....2] [..192.168.1.229] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] idle: [.....1] [ip4][....2] [..192.168.1.219] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] idle: [....16] [ip4][..udp] [...192.168.1.34][63514] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [....74] [ip4][..tcp] [...192.168.1.34][51239] -> [...65.55.223.45][..443] [TLS][Unknown][Web][Safe] - end: [....74] [ip4][..tcp] [...192.168.1.34][51239] -> [...65.55.223.45][..443] + end: [....74] [ip4][..tcp] [...192.168.1.34][51239] -> [...65.55.223.45][..443] idle: [...203] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...154] [ip4][..udp] [...192.168.1.34][13021] -> [.111.221.77.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....15] [ip4][..udp] [...192.168.1.34][53372] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [....73] [ip4][..tcp] [...192.168.1.34][51238] -> [.157.55.235.147][..443] [TLS][Unknown][Web][Safe] - end: [....73] [ip4][..tcp] [...192.168.1.34][51238] -> [.157.55.235.147][..443] + end: [....73] [ip4][..tcp] [...192.168.1.34][51238] -> [.157.55.235.147][..443] not-detected: [...236] [ip4][..tcp] [...192.168.1.34][51290] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...236] [ip4][..tcp] [...192.168.1.34][51290] -> [..5.248.186.221][31010] + end: [...236] [ip4][..tcp] [...192.168.1.34][51290] -> [..5.248.186.221][31010] guessed: [....81] [ip4][..tcp] [...192.168.1.34][51241] -> [.157.55.130.176][..443] [TLS][Unknown][Web][Safe] - end: [....81] [ip4][..tcp] [...192.168.1.34][51241] -> [.157.55.130.176][..443] + end: [....81] [ip4][..tcp] [...192.168.1.34][51241] -> [.157.55.130.176][..443] idle: [....58] [ip4][..udp] [...192.168.1.92][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [....56] [ip4][..udp] [...192.168.1.34][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] not-detected: [...241] [ip4][..tcp] [...192.168.1.34][51293] -> [..5.248.186.221][31010] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...241] [ip4][..tcp] [...192.168.1.34][51293] -> [..5.248.186.221][31010] + idle: [...241] [ip4][..tcp] [...192.168.1.34][51293] -> [..5.248.186.221][31010] guessed: [...158] [ip4][..tcp] [...192.168.1.34][51260] -> [.157.55.130.142][..443] [TLS][Unknown][Web][Safe] - end: [...158] [ip4][..tcp] [...192.168.1.34][51260] -> [.157.55.130.142][..443] + end: [...158] [ip4][..tcp] [...192.168.1.34][51260] -> [.157.55.130.142][..443] guessed: [...159] [ip4][..tcp] [...192.168.1.34][51261] -> [.157.55.235.170][..443] [TLS][Unknown][Web][Safe] - end: [...159] [ip4][..tcp] [...192.168.1.34][51261] -> [.157.55.235.170][..443] + end: [...159] [ip4][..tcp] [...192.168.1.34][51261] -> [.157.55.235.170][..443] idle: [...230] [ip4][..udp] [...192.168.1.34][13021] -> [.174.49.171.224][32011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] guessed: [...191] [ip4][..tcp] [...192.168.1.34][51274] -> [.157.55.235.152][..443] [TLS][Unknown][Web][Safe] - end: [...191] [ip4][..tcp] [...192.168.1.34][51274] -> [.157.55.235.152][..443] + end: [...191] [ip4][..tcp] [...192.168.1.34][51274] -> [.157.55.235.152][..443] guessed: [...216] [ip4][..tcp] [...192.168.1.34][51280] -> [.157.55.235.146][..443] [TLS][Unknown][Web][Safe] - end: [...216] [ip4][..tcp] [...192.168.1.34][51280] -> [.157.55.235.146][..443] + end: [...216] [ip4][..tcp] [...192.168.1.34][51280] -> [.157.55.235.146][..443] guessed: [...217] [ip4][..tcp] [...192.168.1.34][51281] -> [.157.55.235.156][..443] [TLS][Unknown][Web][Safe] - end: [...217] [ip4][..tcp] [...192.168.1.34][51281] -> [.157.55.235.156][..443] + end: [...217] [ip4][..tcp] [...192.168.1.34][51281] -> [.157.55.235.156][..443] idle: [....17] [ip4][..udp] [...192.168.1.34][63661] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] guessed: [...160] [ip4][..tcp] [...192.168.1.34][51262] -> [213.199.179.176][..443] [TLS][Unknown][Web][Safe] - end: [...160] [ip4][..tcp] [...192.168.1.34][51262] -> [213.199.179.176][..443] + end: [...160] [ip4][..tcp] [...192.168.1.34][51262] -> [213.199.179.176][..443] guessed: [...185] [ip4][..tcp] [...192.168.1.34][51271] -> [213.199.179.175][..443] [TLS][Unknown][Web][Safe] - end: [...185] [ip4][..tcp] [...192.168.1.34][51271] -> [213.199.179.175][..443] + end: [...185] [ip4][..tcp] [...192.168.1.34][51271] -> [213.199.179.175][..443] not-detected: [....61] [ip4][..tcp] [...192.168.1.34][51236] -> [..111.221.74.45][40008] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....61] [ip4][..tcp] [...192.168.1.34][51236] -> [..111.221.74.45][40008] + end: [....61] [ip4][..tcp] [...192.168.1.34][51236] -> [..111.221.74.45][40008] idle: [....28] [ip4][..udp] [...192.168.1.92][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....25] [ip4][..udp] [....192.168.1.1][..137] -> [...192.168.1.34][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....24] [ip4][..udp] [...192.168.1.34][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -827,43 +827,43 @@ idle: [...232] [ip4][..udp] [...192.168.1.34][13021] -> [.189.138.161.88][19521] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...147] [ip4][..tcp] [...192.168.1.34][51256] -> [.111.221.77.142][40013] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...147] [ip4][..tcp] [...192.168.1.34][51256] -> [.111.221.77.142][40013] + end: [...147] [ip4][..tcp] [...192.168.1.34][51256] -> [.111.221.77.142][40013] idle: [....14] [ip4][..udp] [...192.168.1.34][57592] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...109] [ip4][..tcp] [...192.168.1.34][51248] -> [.111.221.77.175][40030] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...109] [ip4][..tcp] [...192.168.1.34][51248] -> [.111.221.77.175][40030] + end: [...109] [ip4][..tcp] [...192.168.1.34][51248] -> [.111.221.77.175][40030] not-detected: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] + idle: [...210] [ip4][..tcp] [...192.168.1.34][51279] -> [..111.221.74.48][40008] not-detected: [...170] [ip4][..tcp] [...192.168.1.34][51267] -> [..111.221.74.18][40025] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...170] [ip4][..tcp] [...192.168.1.34][51267] -> [..111.221.74.18][40025] + end: [...170] [ip4][..tcp] [...192.168.1.34][51267] -> [..111.221.74.18][40025] idle: [...237] [ip4][..udp] [...192.168.1.34][13021] -> [..111.221.74.14][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...224] [ip4][..udp] [...192.168.1.34][58061] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [...127] [ip4][..tcp] [108.160.163.108][..443] -> [...192.168.1.34][51222] [TLS][Dropbox][Web][Safe] not-detected: [...253] [ip4][..tcp] [...192.168.1.34][51305] -> [...149.13.32.15][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...253] [ip4][..tcp] [...192.168.1.34][51305] -> [...149.13.32.15][13392] + end: [...253] [ip4][..tcp] [...192.168.1.34][51305] -> [...149.13.32.15][13392] end: [...255] [ip4][..tcp] [...192.168.1.34][51307] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port not-detected: [...257] [ip4][..tcp] [...192.168.1.34][51309] -> [...149.13.32.15][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...257] [ip4][..tcp] [...192.168.1.34][51309] -> [...149.13.32.15][13392] + end: [...257] [ip4][..tcp] [...192.168.1.34][51309] -> [...149.13.32.15][13392] end: [...259] [ip4][..tcp] [...192.168.1.34][51312] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port not-detected: [...263] [ip4][..tcp] [...192.168.1.34][51316] -> [...149.13.32.15][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...263] [ip4][..tcp] [...192.168.1.34][51316] -> [...149.13.32.15][13392] + end: [...263] [ip4][..tcp] [...192.168.1.34][51316] -> [...149.13.32.15][13392] end: [...264] [ip4][..tcp] [...192.168.1.34][51317] -> [...149.13.32.15][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port idle: [.....9] [ip4][..udp] [...192.168.1.34][57694] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] idle: [....13] [ip4][..tcp] [...192.168.1.34][51230] -> [.157.56.126.211][..443] [TLS.Skype_Teams][Unknown][VoIP][Acceptable] RISK: Obsolete TLS (v1.1 or older) guessed: [....22] [ip4][..tcp] [...192.168.1.34][51232] -> [...157.56.52.28][..443] [TLS][Unknown][Web][Safe] - end: [....22] [ip4][..tcp] [...192.168.1.34][51232] -> [...157.56.52.28][..443] + end: [....22] [ip4][..tcp] [...192.168.1.34][51232] -> [...157.56.52.28][..443] guessed: [...108] [ip4][..tcp] [...192.168.1.34][51247] -> [...157.56.52.44][..443] [TLS][Unknown][Web][Safe] - end: [...108] [ip4][..tcp] [...192.168.1.34][51247] -> [...157.56.52.44][..443] + end: [...108] [ip4][..tcp] [...192.168.1.34][51247] -> [...157.56.52.44][..443] idle: [...243] [ip4][..udp] [...192.168.1.34][59788] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] idle: [....32] [ip4][..udp] [...192.168.1.92][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] idle: [....21] [ip4][..udp] [...192.168.1.34][51753] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] @@ -880,7 +880,7 @@ idle: [...215] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.170][40011] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] guessed: [...256] [ip4][..tcp] [...192.168.1.34][51308] -> [...80.121.84.93][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [...256] [ip4][..tcp] [...192.168.1.34][51308] -> [...80.121.84.93][..443] + idle: [...256] [ip4][..tcp] [...192.168.1.34][51308] -> [...80.121.84.93][..443] idle: [....71] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.173][40017] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....79] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...176] [ip4][..udp] [...192.168.1.34][13021] -> [....64.4.23.158][40021] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -896,7 +896,7 @@ idle: [....30] [ip4][..udp] [...192.168.1.92][53826] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] not-detected: [....60] [ip4][..tcp] [...192.168.1.34][51235] -> [...65.55.223.45][40009] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....60] [ip4][..tcp] [...192.168.1.34][51235] -> [...65.55.223.45][40009] + end: [....60] [ip4][..tcp] [...192.168.1.34][51235] -> [...65.55.223.45][40009] idle: [....76] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.146][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [.....7] [ip4][..udp] [...192.168.1.34][49864] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic @@ -904,38 +904,38 @@ RISK: Unidirectional Traffic not-detected: [....59] [ip4][..tcp] [...192.168.1.34][51234] -> [.157.55.235.147][40001] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....59] [ip4][..tcp] [...192.168.1.34][51234] -> [.157.55.235.147][40001] + end: [....59] [ip4][..tcp] [...192.168.1.34][51234] -> [.157.55.235.147][40001] idle: [...156] [ip4][..udp] [...192.168.1.34][64258] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [....67] [ip4][..tcp] [...192.168.1.34][51237] -> [.157.55.130.176][40022] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....67] [ip4][..tcp] [...192.168.1.34][51237] -> [.157.55.130.176][40022] + end: [....67] [ip4][..tcp] [...192.168.1.34][51237] -> [.157.55.130.176][40022] not-detected: [...146] [ip4][..tcp] [...192.168.1.34][51255] -> [.157.55.130.142][40005] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...146] [ip4][..tcp] [...192.168.1.34][51255] -> [.157.55.130.142][40005] + end: [...146] [ip4][..tcp] [...192.168.1.34][51255] -> [.157.55.130.142][40005] not-detected: [...148] [ip4][..tcp] [...192.168.1.34][51257] -> [.157.55.235.170][40032] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...148] [ip4][..tcp] [...192.168.1.34][51257] -> [.157.55.235.170][40032] + end: [...148] [ip4][..tcp] [...192.168.1.34][51257] -> [.157.55.235.170][40032] not-detected: [...207] [ip4][..tcp] [...192.168.1.34][51276] -> [.157.55.235.146][40021] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...207] [ip4][..tcp] [...192.168.1.34][51276] -> [.157.55.235.146][40021] + end: [...207] [ip4][..tcp] [...192.168.1.34][51276] -> [.157.55.235.146][40021] idle: [...238] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.141][..443] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...186] [ip4][..tcp] [...192.168.1.34][51272] -> [.157.55.235.152][40029] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...186] [ip4][..tcp] [...192.168.1.34][51272] -> [.157.55.235.152][40029] + end: [...186] [ip4][..tcp] [...192.168.1.34][51272] -> [.157.55.235.152][40029] not-detected: [...208] [ip4][..tcp] [...192.168.1.34][51277] -> [.157.55.235.156][40026] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...208] [ip4][..tcp] [...192.168.1.34][51277] -> [.157.55.235.156][40026] + end: [...208] [ip4][..tcp] [...192.168.1.34][51277] -> [.157.55.235.156][40026] idle: [...225] [ip4][..udp] [...192.168.1.34][59052] -> [....192.168.1.1][.5351] [NAT-PMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...149] [ip4][..tcp] [...192.168.1.34][51258] -> [213.199.179.176][40021] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...149] [ip4][..tcp] [...192.168.1.34][51258] -> [213.199.179.176][40021] + end: [...149] [ip4][..tcp] [...192.168.1.34][51258] -> [213.199.179.176][40021] idle: [...199] [ip4][..udp] [...192.168.1.34][64364] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic not-detected: [...178] [ip4][..tcp] [...192.168.1.34][51269] -> [213.199.179.175][40029] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...178] [ip4][..tcp] [...192.168.1.34][51269] -> [213.199.179.175][40029] + end: [...178] [ip4][..tcp] [...192.168.1.34][51269] -> [213.199.179.175][40029] idle: [....20] [ip4][..udp] [...192.168.1.34][50055] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...182] [ip4][..udp] [...192.168.1.34][13021] -> [...157.56.52.18][33033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -969,25 +969,25 @@ RISK: Unidirectional Traffic not-detected: [....10] [ip4][..tcp] [...192.168.1.34][51229] -> [...157.56.52.28][40009] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....10] [ip4][..tcp] [...192.168.1.34][51229] -> [...157.56.52.28][40009] + end: [....10] [ip4][..tcp] [...192.168.1.34][51229] -> [...157.56.52.28][40009] not-detected: [....97] [ip4][..tcp] [...192.168.1.34][51246] -> [...157.56.52.44][40020] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [....97] [ip4][..tcp] [...192.168.1.34][51246] -> [...157.56.52.44][40020] + end: [....97] [ip4][..tcp] [...192.168.1.34][51246] -> [...157.56.52.44][40020] not-detected: [...252] [ip4][..tcp] [...192.168.1.34][51303] -> [...80.121.84.93][62381] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...252] [ip4][..tcp] [...192.168.1.34][51303] -> [...80.121.84.93][62381] + idle: [...252] [ip4][..tcp] [...192.168.1.34][51303] -> [...80.121.84.93][62381] not-detected: [...254] [ip4][..tcp] [...192.168.1.34][51306] -> [...80.121.84.93][62381] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...254] [ip4][..tcp] [...192.168.1.34][51306] -> [...80.121.84.93][62381] + idle: [...254] [ip4][..tcp] [...192.168.1.34][51306] -> [...80.121.84.93][62381] end: [....23] [ip4][..tcp] [...192.168.1.34][51227] -> [..17.172.100.36][..443] [TLS][Apple][Web][Safe] idle: [.....5] [ip4][..udp] [...192.168.1.34][58631] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [.....4] [ip4][..udp] [...192.168.1.34][60688] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic guessed: [...130] [ip4][..tcp] [...192.168.1.34][51253] -> [....64.4.23.166][..443] [TLS][Unknown][Web][Safe] - end: [...130] [ip4][..tcp] [...192.168.1.34][51253] -> [....64.4.23.166][..443] + end: [...130] [ip4][..tcp] [...192.168.1.34][51253] -> [....64.4.23.166][..443] guessed: [...218] [ip4][..tcp] [...192.168.1.34][51282] -> [....64.4.23.159][..443] [TLS][Unknown][Web][Safe] - end: [...218] [ip4][..tcp] [...192.168.1.34][51282] -> [....64.4.23.159][..443] + end: [...218] [ip4][..tcp] [...192.168.1.34][51282] -> [....64.4.23.159][..443] idle: [....35] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.33][40002] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...183] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.43][40006] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....85] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.22][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1005,15 +1005,15 @@ idle: [...197] [ip4][..udp] [...192.168.1.34][13021] -> [...65.55.223.16][40032] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...260] [ip4][..tcp] [...192.168.1.34][51313] -> [...212.161.8.36][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...260] [ip4][..tcp] [...192.168.1.34][51313] -> [...212.161.8.36][13392] + end: [...260] [ip4][..tcp] [...192.168.1.34][51313] -> [...212.161.8.36][13392] end: [...262] [ip4][..tcp] [...192.168.1.34][51315] -> [...212.161.8.36][13392] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port not-detected: [...265] [ip4][..tcp] [...192.168.1.34][51318] -> [...212.161.8.36][13392] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...265] [ip4][..tcp] [...192.168.1.34][51318] -> [...212.161.8.36][13392] + idle: [...265] [ip4][..tcp] [...192.168.1.34][51318] -> [...212.161.8.36][13392] not-detected: [...267] [ip4][..tcp] [...192.168.1.34][51319] -> [...212.161.8.36][13392] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...267] [ip4][..tcp] [...192.168.1.34][51319] -> [...212.161.8.36][13392] + idle: [...267] [ip4][..tcp] [...192.168.1.34][51319] -> [...212.161.8.36][13392] idle: [....11] [ip4][..udp] [...192.168.1.34][62875] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable] RISK: Unidirectional Traffic idle: [...180] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.173][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1040,7 +1040,7 @@ idle: [...122] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.144][40016] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...234] [ip4][..tcp] [...192.168.1.34][51288] -> [...76.167.161.6][20274] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...234] [ip4][..tcp] [...192.168.1.34][51288] -> [...76.167.161.6][20274] + end: [...234] [ip4][..tcp] [...192.168.1.34][51288] -> [...76.167.161.6][20274] idle: [...192] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.170][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...181] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.143][40018] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...137] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.148][40019] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1057,7 +1057,7 @@ idle: [....37] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.130.165][40028] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...249] [ip4][..tcp] [...192.168.1.34][51300] -> [...76.167.161.6][20274] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...249] [ip4][..tcp] [...192.168.1.34][51300] -> [...76.167.161.6][20274] + end: [...249] [ip4][..tcp] [...192.168.1.34][51300] -> [...76.167.161.6][20274] idle: [...105] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.167][40029] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...190] [ip4][..udp] [...192.168.1.34][13021] -> [..157.55.56.146][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....41] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.143][40030] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] @@ -1070,17 +1070,17 @@ idle: [....89] [ip4][..udp] [...192.168.1.34][13021] -> [.157.55.235.162][40033] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] not-detected: [...227] [ip4][..tcp] [...192.168.1.34][51284] -> [.91.190.218.125][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...227] [ip4][..tcp] [...192.168.1.34][51284] -> [.91.190.218.125][12350] + end: [...227] [ip4][..tcp] [...192.168.1.34][51284] -> [.91.190.218.125][12350] not-detected: [...228] [ip4][..tcp] [...192.168.1.34][51285] -> [.91.190.218.125][12350] [Unknown][Unknown][Unrated] - end: [...228] [ip4][..tcp] [...192.168.1.34][51285] -> [.91.190.218.125][12350] + end: [...228] [ip4][..tcp] [...192.168.1.34][51285] -> [.91.190.218.125][12350] not-detected: [...245] [ip4][..tcp] [...192.168.1.34][51296] -> [.91.190.216.125][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - end: [...245] [ip4][..tcp] [...192.168.1.34][51296] -> [.91.190.216.125][12350] + end: [...245] [ip4][..tcp] [...192.168.1.34][51296] -> [.91.190.216.125][12350] not-detected: [...246] [ip4][..tcp] [...192.168.1.34][51297] -> [..91.190.216.24][12350] [Unknown][Unknown][Unrated] RISK: Fully encrypted flow - idle: [...246] [ip4][..tcp] [...192.168.1.34][51297] -> [..91.190.216.24][12350] + idle: [...246] [ip4][..tcp] [...192.168.1.34][51297] -> [..91.190.216.24][12350] not-detected: [...248] [ip4][..tcp] [...192.168.1.34][51299] -> [.91.190.216.125][12350] [Unknown][Unknown][Unrated] - end: [...248] [ip4][..tcp] [...192.168.1.34][51299] -> [.91.190.216.125][12350] + end: [...248] [ip4][..tcp] [...192.168.1.34][51299] -> [.91.190.216.125][12350] idle: [....64] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.140][40003] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [....96] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.165][40004] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] idle: [...205] [ip4][..udp] [...192.168.1.34][13021] -> [213.199.179.144][40009] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/skype_udp.pcap.out b/test/results/flow-info/default/skype_udp.pcap.out index 976445351..15b7c5edc 100644 --- a/test/results/flow-info/default/skype_udp.pcap.out +++ b/test/results/flow-info/default/skype_udp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.1.2][35990] -> [.24.224.190.149][39262] + new: [.....1] [ip4][..udp] [....192.168.1.2][35990] -> [.24.224.190.149][39262] detected: [.....1] [ip4][..udp] [....192.168.1.2][35990] -> [.24.224.190.149][39262] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic idle: [.....1] [ip4][..udp] [....192.168.1.2][35990] -> [.24.224.190.149][39262] [Skype_Teams.Skype_TeamsCall][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/smb_deletefile.pcap.out b/test/results/flow-info/default/smb_deletefile.pcap.out index c1a6b1560..e5a73608b 100644 --- a/test/results/flow-info/default/smb_deletefile.pcap.out +++ b/test/results/flow-info/default/smb_deletefile.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [NetBIOS.SMBv23][Unknown][System][Acceptable][] analyse: [.....1] [ip4][..tcp] [..192.168.1.118][56848] -> [..192.168.1.187][..445] [NetBIOS.SMBv23][Unknown][System][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/smb_frags.pcap.out b/test/results/flow-info/default/smb_frags.pcap.out index b379823ad..c17116df7 100644 --- a/test/results/flow-info/default/smb_frags.pcap.out +++ b/test/results/flow-info/default/smb_frags.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.10.202.211.125][54120] -> [.....10.202.7.8][..445] + new: [.....1] [ip4][..tcp] [.10.202.211.125][54120] -> [.....10.202.7.8][..445] detected: [.....1] [ip4][..tcp] [.10.202.211.125][54120] -> [.....10.202.7.8][..445] [NetBIOS.SMBv1][Unknown][System][Dangerous][] RISK: Known Proto on Non Std Port, SMB Insecure Vers, Unsafe Protocol end: [.....1] [ip4][..tcp] [.10.202.211.125][54120] -> [.....10.202.7.8][..445] [NetBIOS.SMBv1][Unknown][System][Dangerous] diff --git a/test/results/flow-info/default/smbv1.pcap.out b/test/results/flow-info/default/smbv1.pcap.out index 00a1026a6..3996de48f 100644 --- a/test/results/flow-info/default/smbv1.pcap.out +++ b/test/results/flow-info/default/smbv1.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.172.16.156.130][50927] -> [...10.128.0.243][..445] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.172.16.156.130][50927] -> [...10.128.0.243][..445] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.172.16.156.130][50927] -> [...10.128.0.243][..445] [NetBIOS.SMBv1][Unknown][System][Dangerous][] RISK: Known Proto on Non Std Port, SMB Insecure Vers, Unsafe Protocol idle: [.....1] [ip4][..tcp] [.172.16.156.130][50927] -> [...10.128.0.243][..445] [NetBIOS.SMBv1][Unknown][System][Dangerous] diff --git a/test/results/flow-info/default/smpp_in_general.pcap.out b/test/results/flow-info/default/smpp_in_general.pcap.out index 1b4513344..fef6befee 100644 --- a/test/results/flow-info/default/smpp_in_general.pcap.out +++ b/test/results/flow-info/default/smpp_in_general.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.10.226.202.118][.1770] -> [..10.226.202.53][.9000] + new: [.....1] [ip4][..tcp] [.10.226.202.118][.1770] -> [..10.226.202.53][.9000] detected: [.....1] [ip4][..tcp] [.10.226.202.118][.1770] -> [..10.226.202.53][.9000] [SMPP][Unknown][Download][Acceptable] end: [.....1] [ip4][..tcp] [.10.226.202.118][.1770] -> [..10.226.202.53][.9000] [SMPP][Unknown][Download][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/smtp-starttls.pcap.out b/test/results/flow-info/default/smtp-starttls.pcap.out index 8fc28daf2..a15a625ff 100644 --- a/test/results/flow-info/default/smtp-starttls.pcap.out +++ b/test/results/flow-info/default/smtp-starttls.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] + new: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] detected: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTP.Google][Google][Email][Acceptable][mx.google.com] detection-update: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTPS.Google][Google][Email][Acceptable] detection-update: [.....1] [ip4][..tcp] [.......10.0.0.1][57406] -> [..173.194.68.26][...25] [SMTPS.Google][Google][Email][Acceptable] @@ -22,7 +22,7 @@ [ENTROPIES...: 4.5,5.2,4.9,5.7,4.9,4.9,5.0,5.8,5.1,5.4,5.2,6.6,7.4,4.9,7.2,7.3,6.9,6.0,6.9,6.1,6.2,6.2,4.9,6.5,7.7,4.9,5.6,4.9,6.3,4.8,5.6,6.3] DAEMON-EVENT: [Processed: 36 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 0] - new: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] + new: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] detected: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] [SMTP][Unknown][Email][Acceptable][jw-vm08-int-dns.webernetz.net] detection-update: [.....2] [ip6][..tcp] [...2003:de:2016:125:fc36:8317:4e86:cb72][.7562] -> [...............2003:de:2016:120::a08:53][...25] [SMTPS][Unknown][Email][Safe] RISK: TLS (probably) Not Carrying HTTPS, TLS Susp Extn diff --git a/test/results/flow-info/default/smtp.pcap.out b/test/results/flow-info/default/smtp.pcap.out index d93f98ee0..954c37560 100644 --- a/test/results/flow-info/default/smtp.pcap.out +++ b/test/results/flow-info/default/smtp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..194.7.248.153][.2127] -> [.172.16.114.207][...25] + new: [.....1] [ip4][..tcp] [..194.7.248.153][.2127] -> [.172.16.114.207][...25] detected: [.....1] [ip4][..tcp] [..194.7.248.153][.2127] -> [.172.16.114.207][...25] [SMTP][Unknown][Email][Acceptable][pigeon.eyrie.af.mil] analyse: [.....1] [ip4][..tcp] [..194.7.248.153][.2127] -> [.172.16.114.207][...25] [SMTP][Unknown][Email][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/smtps.pcapng.out b/test/results/flow-info/default/smtps.pcapng.out index d82e298f7..80b081b41 100644 --- a/test/results/flow-info/default/smtps.pcapng.out +++ b/test/results/flow-info/default/smtps.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....62.43.36.99][37682] -> [...21.65.95.132][..465] + new: [.....1] [ip4][..tcp] [....62.43.36.99][37682] -> [...21.65.95.132][..465] detected: [.....1] [ip4][..tcp] [....62.43.36.99][37682] -> [...21.65.95.132][..465] [SMTPS][Unknown][Email][Safe] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..tcp] [....62.43.36.99][37682] -> [...21.65.95.132][..465] [SMTPS][Unknown][Email][Safe] diff --git a/test/results/flow-info/default/snapchat.pcap.out b/test/results/flow-info/default/snapchat.pcap.out index 0c05e1d1a..10e66fb5d 100644 --- a/test/results/flow-info/default/snapchat.pcap.out +++ b/test/results/flow-info/default/snapchat.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.8.0.1][33233] -> [.74.125.136.141][..443] + new: [.....1] [ip4][..tcp] [.......10.8.0.1][33233] -> [.74.125.136.141][..443] detected: [.....1] [ip4][..tcp] [.......10.8.0.1][33233] -> [.74.125.136.141][..443] [TLS][Google][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..tcp] [.......10.8.0.1][33233] -> [.74.125.136.141][..443] [TLS][Google][Web][Safe][] RISK: TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn - new: [.....2] [ip4][..tcp] [.......10.8.0.1][44536] -> [.74.125.136.141][..443] - new: [.....3] [ip4][..tcp] [.......10.8.0.1][56193] -> [.74.125.136.141][..443] + new: [.....2] [ip4][..tcp] [.......10.8.0.1][44536] -> [.74.125.136.141][..443] + new: [.....3] [ip4][..tcp] [.......10.8.0.1][56193] -> [.74.125.136.141][..443] detected: [.....2] [ip4][..tcp] [.......10.8.0.1][44536] -> [.74.125.136.141][..443] [TLS.Snapchat][Google][SocialNetwork][Fun][feelinsonice-hrd.appspot.com] detected: [.....3] [ip4][..tcp] [.......10.8.0.1][56193] -> [.74.125.136.141][..443] [TLS.Snapchat][Google][SocialNetwork][Fun][feelinsonice-hrd.appspot.com] detection-update: [.....2] [ip4][..tcp] [.......10.8.0.1][44536] -> [.74.125.136.141][..443] [TLS.Snapchat][Google][SocialNetwork][Fun][feelinsonice-hrd.appspot.com] diff --git a/test/results/flow-info/default/snapchat_call.pcapng.out b/test/results/flow-info/default/snapchat_call.pcapng.out index e21a0548e..b54683abf 100644 --- a/test/results/flow-info/default/snapchat_call.pcapng.out +++ b/test/results/flow-info/default/snapchat_call.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.169][42083] -> [.18.184.138.142][..443] + new: [.....1] [ip4][..udp] [.192.168.12.169][42083] -> [.18.184.138.142][..443] detected: [.....1] [ip4][..udp] [.192.168.12.169][42083] -> [.18.184.138.142][..443] [QUIC][AmazonAWS][Web][Acceptable] RISK: Missing SNI TLS Extn detection-update: [.....1] [ip4][..udp] [.192.168.12.169][42083] -> [.18.184.138.142][..443] [QUIC.SnapchatCall][AmazonAWS][VoIP][Acceptable] diff --git a/test/results/flow-info/default/snapchat_call_v1.pcapng.out b/test/results/flow-info/default/snapchat_call_v1.pcapng.out index bdb0aa4d4..f5d8bc752 100644 --- a/test/results/flow-info/default/snapchat_call_v1.pcapng.out +++ b/test/results/flow-info/default/snapchat_call_v1.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.169][47520] -> [.34.246.231.140][..443] + new: [.....1] [ip4][..udp] [.192.168.12.169][47520] -> [.34.246.231.140][..443] detected: [.....1] [ip4][..udp] [.192.168.12.169][47520] -> [.34.246.231.140][..443] [QUIC.Snapchat][AmazonAWS][SocialNetwork][Fun][str1-euwest1-34-246-231-140.addlive.io] detection-update: [.....1] [ip4][..udp] [.192.168.12.169][47520] -> [.34.246.231.140][..443] [QUIC.SnapchatCall][AmazonAWS][VoIP][Acceptable][str1-euwest1-34-246-231-140.addlive.io] analyse: [.....1] [ip4][..udp] [.192.168.12.169][47520] -> [.34.246.231.140][..443] [QUIC.SnapchatCall][AmazonAWS][VoIP][Acceptable] diff --git a/test/results/flow-info/default/snmp.pcap.out b/test/results/flow-info/default/snmp.pcap.out index b229da58b..cf0062bda 100644 --- a/test/results/flow-info/default/snmp.pcap.out +++ b/test/results/flow-info/default/snmp.pcap.out @@ -1,22 +1,22 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] + new: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] detected: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] detection-update: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] + new: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] detected: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] detection-update: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] - new: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] + new: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] detected: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] detection-update: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [...65.2.162.193][58433] -> [.130.70.149.185][..161] + new: [.....4] [ip4][..udp] [...65.2.162.193][58433] -> [.130.70.149.185][..161] detected: [.....4] [ip4][..udp] [...65.2.162.193][58433] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] detection-update: [.....4] [ip4][..udp] [...65.2.162.193][58433] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] update: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [..30.54.142.240][56251] -> [..250.58.112.87][..161] + new: [.....5] [ip4][..udp] [..30.54.142.240][56251] -> [..250.58.112.87][..161] detected: [.....5] [ip4][..udp] [..30.54.142.240][56251] -> [..250.58.112.87][..161] [SNMP][Unknown][Network][Acceptable] - new: [.....6] [ip4][..udp] [..30.54.142.240][52435] -> [..250.58.112.87][..161] + new: [.....6] [ip4][..udp] [..30.54.142.240][52435] -> [..250.58.112.87][..161] detected: [.....6] [ip4][..udp] [..30.54.142.240][52435] -> [..250.58.112.87][..161] [SNMP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] update: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] @@ -24,9 +24,9 @@ update: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 28 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 5] - new: [.....7] [ip4][..udp] [..35.95.158.217][60440] -> [...30.79.214.36][..161] + new: [.....7] [ip4][..udp] [..35.95.158.217][60440] -> [...30.79.214.36][..161] detected: [.....7] [ip4][..udp] [..35.95.158.217][60440] -> [...30.79.214.36][..161] [SNMP][AmazonAWS][Network][Acceptable] - new: [.....8] [ip4][..udp] [..35.95.158.217][49306] -> [...30.79.214.36][..161] + new: [.....8] [ip4][..udp] [..35.95.158.217][49306] -> [...30.79.214.36][..161] detected: [.....8] [ip4][..udp] [..35.95.158.217][49306] -> [...30.79.214.36][..161] [SNMP][AmazonAWS][Network][Acceptable] idle: [.....2] [ip4][..udp] [...65.2.162.193][59988] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] idle: [.....1] [ip4][..udp] [..176.211.60.43][43015] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] @@ -34,15 +34,15 @@ idle: [.....4] [ip4][..udp] [...65.2.162.193][58433] -> [.130.70.149.185][..161] [SNMP][AmazonAWS][Network][Acceptable] idle: [.....3] [ip4][..udp] [..176.211.60.43][37224] -> [...97.0.115.163][..161] [SNMP][Unknown][Network][Acceptable] idle: [.....6] [ip4][..udp] [..30.54.142.240][52435] -> [..250.58.112.87][..161] [SNMP][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [.131.179.49.165][60694] -> [..254.158.1.169][..161] + new: [.....9] [ip4][..udp] [.131.179.49.165][60694] -> [..254.158.1.169][..161] detected: [.....9] [ip4][..udp] [.131.179.49.165][60694] -> [..254.158.1.169][..161] [SNMP][Unknown][Network][Acceptable] - new: [....10] [ip4][..udp] [.131.179.49.165][35970] -> [..254.158.1.169][..161] + new: [....10] [ip4][..udp] [.131.179.49.165][35970] -> [..254.158.1.169][..161] detected: [....10] [ip4][..udp] [.131.179.49.165][35970] -> [..254.158.1.169][..161] [SNMP][Unknown][Network][Acceptable] update: [.....7] [ip4][..udp] [..35.95.158.217][60440] -> [...30.79.214.36][..161] [SNMP][AmazonAWS][Network][Acceptable] update: [.....8] [ip4][..udp] [..35.95.158.217][49306] -> [...30.79.214.36][..161] [SNMP][AmazonAWS][Network][Acceptable] DAEMON-EVENT: [Processed: 52 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 7] - new: [....11] [ip4][..udp] [..92.135.15.240][54318] -> [.137.49.110.186][..162] + new: [....11] [ip4][..udp] [..92.135.15.240][54318] -> [.137.49.110.186][..162] detected: [....11] [ip4][..udp] [..92.135.15.240][54318] -> [.137.49.110.186][..162] [SNMP][Unknown][Network][Acceptable] idle: [.....9] [ip4][..udp] [.131.179.49.165][60694] -> [..254.158.1.169][..161] [SNMP][Unknown][Network][Acceptable] idle: [.....7] [ip4][..udp] [..35.95.158.217][60440] -> [...30.79.214.36][..161] [SNMP][AmazonAWS][Network][Acceptable] @@ -50,26 +50,26 @@ idle: [....10] [ip4][..udp] [.131.179.49.165][35970] -> [..254.158.1.169][..161] [SNMP][Unknown][Network][Acceptable] detection-update: [....11] [ip4][..udp] [..92.135.15.240][54318] -> [.137.49.110.186][..162] [SNMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] + new: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] detected: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] [SNMP][Unknown][Network][Acceptable] idle: [....11] [ip4][..udp] [..92.135.15.240][54318] -> [.137.49.110.186][..162] [SNMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic detection-update: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] [SNMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [....13] [ip4][..udp] [.113.19.156.111][54318] -> [.135.201.124.55][..162] + new: [....13] [ip4][..udp] [.113.19.156.111][54318] -> [.135.201.124.55][..162] detected: [....13] [ip4][..udp] [.113.19.156.111][54318] -> [.135.201.124.55][..162] [SNMP][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] [SNMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - new: [....14] [ip4][..udp] [..205.83.36.228][54318] -> [.160.174.106.32][..162] + new: [....14] [ip4][..udp] [..205.83.36.228][54318] -> [.160.174.106.32][..162] detected: [....14] [ip4][..udp] [..205.83.36.228][54318] -> [.160.174.106.32][..162] [SNMP][Unknown][Network][Acceptable] - new: [....15] [ip4][..udp] [.124.53.196.176][54318] -> [..103.248.22.47][..162] + new: [....15] [ip4][..udp] [.124.53.196.176][54318] -> [..103.248.22.47][..162] detected: [....15] [ip4][..udp] [.124.53.196.176][54318] -> [..103.248.22.47][..162] [SNMP][Unknown][Network][Acceptable] update: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] [SNMP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic update: [....13] [ip4][..udp] [.113.19.156.111][54318] -> [.135.201.124.55][..162] [SNMP][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 62 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 15|skipped: 0|!detected: 0|guessed: 0|detection-updates: 6|updates: 10] - new: [....16] [ip4][..udp] [...10.231.2.134][..161] -> [....10.72.247.4][61088] + new: [....16] [ip4][..udp] [...10.231.2.134][..161] -> [....10.72.247.4][61088] detected: [....16] [ip4][..udp] [...10.231.2.134][..161] -> [....10.72.247.4][61088] [SNMP][Unknown][Network][Acceptable] RISK: Error Code idle: [....12] [ip4][..udp] [.200.76.132.137][54318] -> [189.111.255.214][..162] [SNMP][Unknown][Network][Acceptable] @@ -77,7 +77,7 @@ idle: [....13] [ip4][..udp] [.113.19.156.111][54318] -> [.135.201.124.55][..162] [SNMP][Unknown][Network][Acceptable] idle: [....15] [ip4][..udp] [.124.53.196.176][54318] -> [..103.248.22.47][..162] [SNMP][Unknown][Network][Acceptable] idle: [....14] [ip4][..udp] [..205.83.36.228][54318] -> [.160.174.106.32][..162] [SNMP][Unknown][Network][Acceptable] - new: [....17] [ip4][..udp] [.....10.99.8.88][43242] -> [.10.100.253.146][..161] + new: [....17] [ip4][..udp] [.....10.99.8.88][43242] -> [.10.100.253.146][..161] detected: [....17] [ip4][..udp] [.....10.99.8.88][43242] -> [.10.100.253.146][..161] [SNMP][Unknown][Network][Acceptable] detection-update: [....17] [ip4][..udp] [.....10.99.8.88][43242] -> [.10.100.253.146][..161] [SNMP][Unknown][Network][Acceptable] RISK: Error Code diff --git a/test/results/flow-info/default/soap.pcap.out b/test/results/flow-info/default/soap.pcap.out index ec6be6953..fa0eedb0c 100644 --- a/test/results/flow-info/default/soap.pcap.out +++ b/test/results/flow-info/default/soap.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] - new: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] + new: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [HTTP.SOAP][Unknown][Cloud][Acceptable][go.microsoft.com] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] + new: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] detected: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] [SOAP][Unknown][RPC][Acceptable] idle: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] [SOAP][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [HTTP.SOAP][Unknown][Cloud][Acceptable] RISK: Known Proto on Non Std Port guessed: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] + end: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/socks.pcap.out b/test/results/flow-info/default/socks.pcap.out index e7a7780b5..cb5f7ef0a 100644 --- a/test/results/flow-info/default/socks.pcap.out +++ b/test/results/flow-info/default/socks.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.1][.1637] -> [.......10.0.0.2][21477] + new: [.....1] [ip4][..tcp] [.......10.0.0.1][.1637] -> [.......10.0.0.2][21477] detected: [.....1] [ip4][..tcp] [.......10.0.0.1][.1637] -> [.......10.0.0.2][21477] [SOCKS][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 14 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [.10.180.156.185][53533] -> [.10.180.156.249][.1080] + new: [.....2] [ip4][..tcp] [.10.180.156.185][53533] -> [.10.180.156.249][.1080] detected: [.....2] [ip4][..tcp] [.10.180.156.185][53533] -> [.10.180.156.249][.1080] [SOCKS][Unknown][Web][Acceptable] - new: [.....3] [ip4][..tcp] [.10.180.156.185][53534] -> [.10.180.156.249][.1080] + new: [.....3] [ip4][..tcp] [.10.180.156.185][53534] -> [.10.180.156.249][.1080] detected: [.....3] [ip4][..tcp] [.10.180.156.185][53534] -> [.10.180.156.249][.1080] [SOCKS][Unknown][Web][Acceptable] - new: [.....4] [ip4][..tcp] [.10.180.156.185][53535] -> [.10.180.156.249][.1080] + new: [.....4] [ip4][..tcp] [.10.180.156.185][53535] -> [.10.180.156.249][.1080] detected: [.....4] [ip4][..tcp] [.10.180.156.185][53535] -> [.10.180.156.249][.1080] [SOCKS][Unknown][Web][Acceptable] end: [.....1] [ip4][..tcp] [.......10.0.0.1][.1637] -> [.......10.0.0.2][21477] [SOCKS][Unknown][Web][Acceptable] RISK: Known Proto on Non Std Port diff --git a/test/results/flow-info/default/softether.pcap.out b/test/results/flow-info/default/softether.pcap.out index 5a831d66f..cec8edd93 100644 --- a/test/results/flow-info/default/softether.pcap.out +++ b/test/results/flow-info/default/softether.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] + new: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] detected: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] detection-update: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] update: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] @@ -9,12 +9,12 @@ update: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 3] - new: [.....2] [ip4][..tcp] [..192.168.2.100][37504] -> [..130.158.75.45][...80] + new: [.....2] [ip4][..tcp] [..192.168.2.100][37504] -> [..130.158.75.45][...80] detected: [.....2] [ip4][..tcp] [..192.168.2.100][37504] -> [..130.158.75.45][...80] [HTTP.Softether][Unknown][VPN][Acceptable][x0.x0.dev.open.servers.ddns.softether-network.net] idle: [.....1] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 3] - new: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] + new: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] detected: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] idle: [.....2] [ip4][..tcp] [..192.168.2.100][37504] -> [..130.158.75.45][...80] [HTTP.Softether][Unknown][VPN][Acceptable] update: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] @@ -23,7 +23,7 @@ update: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 34 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 6] - new: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] + new: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] detected: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] [Softether][Unknown][VPN][Acceptable] update: [.....3] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] detection-update: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] [Softether][Unknown][VPN][Acceptable] @@ -41,7 +41,7 @@ update: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] [Softether][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 15] - new: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] + new: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] detected: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] [Softether][Unknown][VPN][Acceptable] idle: [.....4] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.105][.5004] [Softether][Unknown][VPN][Acceptable] update: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] [Softether][Unknown][VPN][Acceptable] @@ -55,7 +55,7 @@ update: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] [Softether][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 100 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 22] - new: [.....6] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] + new: [.....6] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] detected: [.....6] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] idle: [.....5] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.112][.5004] [Softether][Unknown][VPN][Acceptable] update: [.....6] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] @@ -72,7 +72,7 @@ DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 5|updates: 29] analyse: [.....6] [ip4][..udp] [..192.168.2.100][51381] -> [..130.158.6.113][.5004] [Softether][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy - [IAT.........: 0.257| 1566.080| 9319.382| 0.000| 0.000| 1.100] + [IAT.........: 0.257|143300.001| 9319.382| 0.000| 0.000| 1.100] [PKTLEN......: 29.000| 508.000| 90.300| 132.500| 17556.200| 4.100] [BINS(c->s)..: 15,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] [BINS(s->c)..: 13,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] diff --git a/test/results/flow-info/default/someip-tp.pcap.out b/test/results/flow-info/default/someip-tp.pcap.out index f6b599674..259b0c0c8 100644 --- a/test/results/flow-info/default/someip-tp.pcap.out +++ b/test/results/flow-info/default/someip-tp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....10.0.1.207][56772] -> [.......10.0.1.1][18193] + new: [.....1] [ip4][..udp] [.....10.0.1.207][56772] -> [.......10.0.1.1][18193] detected: [.....1] [ip4][..udp] [.....10.0.1.207][56772] -> [.......10.0.1.1][18193] [SOMEIP][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..udp] [.....10.0.1.207][56772] -> [.......10.0.1.1][18193] [SOMEIP][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/someip-udp-method-call.pcapng.out b/test/results/flow-info/default/someip-udp-method-call.pcapng.out index f03431f0b..73d871f41 100644 --- a/test/results/flow-info/default/someip-udp-method-call.pcapng.out +++ b/test/results/flow-info/default/someip-udp-method-call.pcapng.out @@ -1,10 +1,10 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.0.1][49190] -> [......224.0.0.1][49190] + new: [.....1] [ip4][..udp] [....192.168.0.1][49190] -> [......224.0.0.1][49190] detected: [.....1] [ip4][..udp] [....192.168.0.1][49190] -> [......224.0.0.1][49190] [SOMEIP][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [..192.168.0.125][49191] -> [....192.168.0.1][49201] + new: [.....2] [ip4][..udp] [..192.168.0.125][49191] -> [....192.168.0.1][49201] detected: [.....2] [ip4][..udp] [..192.168.0.125][49191] -> [....192.168.0.1][49201] [SOMEIP][Unknown][RPC][Acceptable] RISK: Known Proto on Non Std Port idle: [.....2] [ip4][..udp] [..192.168.0.125][49191] -> [....192.168.0.1][49201] [SOMEIP][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/source_engine.pcap.out b/test/results/flow-info/default/source_engine.pcap.out index 3843dc08e..620ddc362 100644 --- a/test/results/flow-info/default/source_engine.pcap.out +++ b/test/results/flow-info/default/source_engine.pcap.out @@ -1,77 +1,77 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.222.204.159.87][20595] -> [206.125.246.211][27015] + new: [.....1] [ip4][..udp] [.222.204.159.87][20595] -> [206.125.246.211][27015] detected: [.....1] [ip4][..udp] [.222.204.159.87][20595] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 1 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.174.134.158.83][47464] -> [206.125.246.217][27015] + new: [.....2] [ip4][..udp] [.174.134.158.83][47464] -> [206.125.246.217][27015] detected: [.....2] [ip4][..udp] [.174.134.158.83][47464] -> [206.125.246.217][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [.222.204.159.87][20595] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 2 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [237.117.185.247][41251] -> [206.125.246.219][27015] + new: [.....3] [ip4][..udp] [237.117.185.247][41251] -> [206.125.246.219][27015] detected: [.....3] [ip4][..udp] [237.117.185.247][41251] -> [206.125.246.219][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....2] [ip4][..udp] [.174.134.158.83][47464] -> [206.125.246.217][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 3 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..udp] [.252.187.173.26][42155] -> [206.125.246.211][27015] + new: [.....4] [ip4][..udp] [.252.187.173.26][42155] -> [206.125.246.211][27015] detected: [.....4] [ip4][..udp] [.252.187.173.26][42155] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....3] [ip4][..udp] [237.117.185.247][41251] -> [206.125.246.219][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 4 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [167.166.182.152][53321] -> [206.125.246.212][27015] + new: [.....5] [ip4][..udp] [167.166.182.152][53321] -> [206.125.246.212][27015] detected: [.....5] [ip4][..udp] [167.166.182.152][53321] -> [206.125.246.212][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....4] [ip4][..udp] [.252.187.173.26][42155] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] - new: [.....6] [ip4][..udp] [.151.182.246.17][52464] -> [206.125.246.217][27015] + new: [.....6] [ip4][..udp] [.151.182.246.17][52464] -> [206.125.246.217][27015] detected: [.....6] [ip4][..udp] [.151.182.246.17][52464] -> [206.125.246.217][27015] [Source_Engine][Unknown][Game][Fun] update: [.....5] [ip4][..udp] [167.166.182.152][53321] -> [206.125.246.212][27015] [Source_Engine][Unknown][Game][Fun] - new: [.....7] [ip4][..udp] [197.114.186.247][64888] -> [206.125.246.213][27015] + new: [.....7] [ip4][..udp] [197.114.186.247][64888] -> [206.125.246.213][27015] detected: [.....7] [ip4][..udp] [197.114.186.247][64888] -> [206.125.246.213][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....5] [ip4][..udp] [167.166.182.152][53321] -> [206.125.246.212][27015] [Source_Engine][Unknown][Game][Fun] update: [.....6] [ip4][..udp] [.151.182.246.17][52464] -> [206.125.246.217][27015] [Source_Engine][Unknown][Game][Fun] - new: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] + new: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] detected: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....6] [ip4][..udp] [.151.182.246.17][52464] -> [206.125.246.217][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....7] [ip4][..udp] [197.114.186.247][64888] -> [206.125.246.213][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....9] [ip4][..udp] [237.117.153.178][24647] -> [206.125.246.215][27015] + new: [.....9] [ip4][..udp] [237.117.153.178][24647] -> [206.125.246.215][27015] detected: [.....9] [ip4][..udp] [237.117.153.178][24647] -> [206.125.246.215][27015] [Source_Engine][Unknown][Game][Fun] update: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] - new: [....10] [ip4][..udp] [.252.141.177.26][21572] -> [206.125.246.216][27015] + new: [....10] [ip4][..udp] [.252.141.177.26][21572] -> [206.125.246.216][27015] detected: [....10] [ip4][..udp] [.252.141.177.26][21572] -> [206.125.246.216][27015] [Source_Engine][Unknown][Game][Fun] update: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] update: [.....9] [ip4][..udp] [237.117.153.178][24647] -> [206.125.246.215][27015] [Source_Engine][Unknown][Game][Fun] - new: [....11] [ip4][..udp] [165.165.117.188][48822] -> [206.125.246.211][27015] + new: [....11] [ip4][..udp] [165.165.117.188][48822] -> [206.125.246.211][27015] detected: [....11] [ip4][..udp] [165.165.117.188][48822] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] idle: [....10] [ip4][..udp] [.252.141.177.26][21572] -> [206.125.246.216][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....8] [ip4][..udp] [197.114.186.247][38846] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] idle: [.....9] [ip4][..udp] [237.117.153.178][24647] -> [206.125.246.215][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 11 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....12] [ip4][..udp] [.140.151.209.84][.8335] -> [206.125.246.214][27015] + new: [....12] [ip4][..udp] [.140.151.209.84][.8335] -> [206.125.246.214][27015] detected: [....12] [ip4][..udp] [.140.151.209.84][.8335] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] idle: [....11] [ip4][..udp] [165.165.117.188][48822] -> [206.125.246.211][27015] [Source_Engine][Unknown][Game][Fun] - new: [....13] [ip4][..udp] [197.114.186.247][41194] -> [206.125.246.214][27015] + new: [....13] [ip4][..udp] [197.114.186.247][41194] -> [206.125.246.214][27015] detected: [....13] [ip4][..udp] [197.114.186.247][41194] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] idle: [....12] [ip4][..udp] [.140.151.209.84][.8335] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 13 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 13|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....14] [ip4][..udp] [222.158.181.242][58235] -> [206.125.246.222][27015] + new: [....14] [ip4][..udp] [222.158.181.242][58235] -> [206.125.246.222][27015] detected: [....14] [ip4][..udp] [222.158.181.242][58235] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] idle: [....13] [ip4][..udp] [197.114.186.247][41194] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] - new: [....15] [ip4][..udp] [237.139.153.112][.3722] -> [206.125.246.219][27015] + new: [....15] [ip4][..udp] [237.139.153.112][.3722] -> [206.125.246.219][27015] detected: [....15] [ip4][..udp] [237.139.153.112][.3722] -> [206.125.246.219][27015] [Source_Engine][Unknown][Game][Fun] idle: [....14] [ip4][..udp] [222.158.181.242][58235] -> [206.125.246.222][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 15|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....16] [ip4][..udp] [118.149.186.147][21285] -> [206.125.246.214][27015] + new: [....16] [ip4][..udp] [118.149.186.147][21285] -> [206.125.246.214][27015] detected: [....16] [ip4][..udp] [118.149.186.147][21285] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] idle: [....15] [ip4][..udp] [237.139.153.112][.3722] -> [206.125.246.219][27015] [Source_Engine][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 16|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....17] [ip4][..udp] [.151.182.246.17][17890] -> [206.125.246.221][27015] + new: [....17] [ip4][..udp] [.151.182.246.17][17890] -> [206.125.246.221][27015] detected: [....17] [ip4][..udp] [.151.182.246.17][17890] -> [206.125.246.221][27015] [Source_Engine][Unknown][Game][Fun] idle: [....16] [ip4][..udp] [118.149.186.147][21285] -> [206.125.246.214][27015] [Source_Engine][Unknown][Game][Fun] idle: [....17] [ip4][..udp] [.151.182.246.17][17890] -> [206.125.246.221][27015] [Source_Engine][Unknown][Game][Fun] diff --git a/test/results/flow-info/default/sql_injection.pcap.out b/test/results/flow-info/default/sql_injection.pcap.out index 3b87eb348..3e16f867c 100644 --- a/test/results/flow-info/default/sql_injection.pcap.out +++ b/test/results/flow-info/default/sql_injection.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.3.109][53528] -> [..192.168.3.107][...80] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.3.109][53528] -> [..192.168.3.107][...80] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.3.109][53528] -> [..192.168.3.107][...80] [HTTP][Unknown][Web][Acceptable][192.168.3.107] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI idle: [.....1] [ip4][..tcp] [..192.168.3.109][53528] -> [..192.168.3.107][...80] [HTTP][Unknown][Web][Acceptable] diff --git a/test/results/flow-info/default/srvloc-v1.pcapng.out b/test/results/flow-info/default/srvloc-v1.pcapng.out index 1148377f7..f49d9e0fe 100644 --- a/test/results/flow-info/default/srvloc-v1.pcapng.out +++ b/test/results/flow-info/default/srvloc-v1.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.23.220.116.175][..427] -> [.192.168.199.71][57782] + new: [.....1] [ip4][..udp] [.23.220.116.175][..427] -> [.192.168.199.71][57782] detected: [.....1] [ip4][..udp] [.23.220.116.175][..427] -> [.192.168.199.71][57782] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [.....2] [ip4][..udp] [..250.83.105.78][51708] -> [.172.30.246.115][..427] + new: [.....2] [ip4][..udp] [..250.83.105.78][51708] -> [.172.30.246.115][..427] detected: [.....2] [ip4][..udp] [..250.83.105.78][51708] -> [.172.30.246.115][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....1] [ip4][..udp] [.23.220.116.175][..427] -> [.192.168.199.71][57782] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..udp] [..250.83.105.78][51708] -> [.172.30.246.115][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/srvloc.pcap.out b/test/results/flow-info/default/srvloc.pcap.out index 89d87f1de..9c658737d 100644 --- a/test/results/flow-info/default/srvloc.pcap.out +++ b/test/results/flow-info/default/srvloc.pcap.out @@ -1,1729 +1,1729 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..37.40.101.196][53106] -> [...85.111.52.57][..427] + new: [.....1] [ip4][..udp] [..37.40.101.196][53106] -> [...85.111.52.57][..427] detected: [.....1] [ip4][..udp] [..37.40.101.196][53106] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 1 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [.27.134.169.220][45163] -> [...90.141.37.56][..427] + new: [.....2] [ip4][..udp] [.27.134.169.220][45163] -> [...90.141.37.56][..427] detected: [.....2] [ip4][..udp] [.27.134.169.220][45163] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....1] [ip4][..udp] [..37.40.101.196][53106] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [.....3] [ip4][..udp] [..44.99.113.150][40623] -> [.186.112.202.53][..427] + new: [.....3] [ip4][..udp] [..44.99.113.150][40623] -> [.186.112.202.53][..427] detected: [.....3] [ip4][..udp] [..44.99.113.150][40623] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [.....2] [ip4][..udp] [.27.134.169.220][45163] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 3 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....4] [ip4][..udp] [..44.99.113.150][34697] -> [..90.145.180.58][..427] + new: [.....4] [ip4][..udp] [..44.99.113.150][34697] -> [..90.145.180.58][..427] detected: [.....4] [ip4][..udp] [..44.99.113.150][34697] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....3] [ip4][..udp] [..44.99.113.150][40623] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..udp] [.27.134.169.220][45163] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [.....5] [ip4][..udp] [208.100.177.136][33246] -> [...90.141.37.56][..427] + new: [.....5] [ip4][..udp] [208.100.177.136][33246] -> [...90.141.37.56][..427] detected: [.....5] [ip4][..udp] [208.100.177.136][33246] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [.....4] [ip4][..udp] [..44.99.113.150][34697] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 5 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....6] [ip4][..udp] [.45.124.147.156][33510] -> [...85.111.52.57][..427] + new: [.....6] [ip4][..udp] [.45.124.147.156][33510] -> [...85.111.52.57][..427] detected: [.....6] [ip4][..udp] [.45.124.147.156][33510] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....5] [ip4][..udp] [208.100.177.136][33246] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....4] [ip4][..udp] [..44.99.113.150][34697] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [.....7] [ip4][..udp] [.45.124.147.156][50663] -> [.165.114.202.61][..427] + new: [.....7] [ip4][..udp] [.45.124.147.156][50663] -> [.165.114.202.61][..427] detected: [.....7] [ip4][..udp] [.45.124.147.156][50663] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [.....8] [ip4][..udp] [.45.124.147.156][41268] -> [.165.114.202.61][..427] + new: [.....8] [ip4][..udp] [.45.124.147.156][41268] -> [.165.114.202.61][..427] detected: [.....8] [ip4][..udp] [.45.124.147.156][41268] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....6] [ip4][..udp] [.45.124.147.156][33510] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [.....9] [ip4][..udp] [.236.155.96.147][43154] -> [..90.147.171.51][..427] + new: [.....9] [ip4][..udp] [.236.155.96.147][43154] -> [..90.147.171.51][..427] detected: [.....9] [ip4][..udp] [.236.155.96.147][43154] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....8] [ip4][..udp] [.45.124.147.156][41268] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....7] [ip4][..udp] [.45.124.147.156][50663] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 10 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [....10] [ip4][..udp] [.45.124.147.156][57141] -> [..74.111.203.55][..427] + new: [....10] [ip4][..udp] [.45.124.147.156][57141] -> [..74.111.203.55][..427] detected: [....10] [ip4][..udp] [.45.124.147.156][57141] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [.....9] [ip4][..udp] [.236.155.96.147][43154] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 11 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [....11] [ip4][..udp] [184.180.168.240][38061] -> [..165.144.84.62][..427] + new: [....11] [ip4][..udp] [184.180.168.240][38061] -> [..165.144.84.62][..427] detected: [....11] [ip4][..udp] [184.180.168.240][38061] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....10] [ip4][..udp] [.45.124.147.156][57141] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 12 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [....12] [ip4][..udp] [236.131.162.157][38756] -> [..69.109.187.54][..427] + new: [....12] [ip4][..udp] [236.131.162.157][38756] -> [..69.109.187.54][..427] detected: [....12] [ip4][..udp] [236.131.162.157][38756] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....11] [ip4][..udp] [184.180.168.240][38061] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 13 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 2] - new: [....13] [ip4][..udp] [.200.31.144.158][39908] -> [...85.111.52.57][..427] + new: [....13] [ip4][..udp] [.200.31.144.158][39908] -> [...85.111.52.57][..427] detected: [....13] [ip4][..udp] [.200.31.144.158][39908] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....12] [ip4][..udp] [236.131.162.157][38756] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....14] [ip4][..udp] [.200.31.144.158][40656] -> [..69.109.187.54][..427] + new: [....14] [ip4][..udp] [.200.31.144.158][40656] -> [..69.109.187.54][..427] detected: [....14] [ip4][..udp] [.200.31.144.158][40656] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....13] [ip4][..udp] [.200.31.144.158][39908] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....15] [ip4][..udp] [.200.31.144.158][37600] -> [.186.112.202.53][..427] + new: [....15] [ip4][..udp] [.200.31.144.158][37600] -> [.186.112.202.53][..427] detected: [....15] [ip4][..udp] [.200.31.144.158][37600] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....14] [ip4][..udp] [.200.31.144.158][40656] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 15|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [....16] [ip4][..udp] [..70.28.101.252][53651] -> [..90.147.171.51][..427] + new: [....16] [ip4][..udp] [..70.28.101.252][53651] -> [..90.147.171.51][..427] detected: [....16] [ip4][..udp] [..70.28.101.252][53651] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....15] [ip4][..udp] [.200.31.144.158][37600] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....14] [ip4][..udp] [.200.31.144.158][40656] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 16|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [....17] [ip4][..udp] [.200.31.144.158][38913] -> [..74.111.203.55][..427] + new: [....17] [ip4][..udp] [.200.31.144.158][38913] -> [..74.111.203.55][..427] detected: [....17] [ip4][..udp] [.200.31.144.158][38913] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....16] [ip4][..udp] [..70.28.101.252][53651] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....18] [ip4][..udp] [.200.31.144.158][33453] -> [..90.111.212.50][..427] + new: [....18] [ip4][..udp] [.200.31.144.158][33453] -> [..90.111.212.50][..427] detected: [....18] [ip4][..udp] [.200.31.144.158][33453] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....17] [ip4][..udp] [.200.31.144.158][38913] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 19 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 18|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 4] - new: [....19] [ip4][..udp] [.200.31.144.158][60963] -> [...90.141.37.56][..427] + new: [....19] [ip4][..udp] [.200.31.144.158][60963] -> [...90.141.37.56][..427] detected: [....19] [ip4][..udp] [.200.31.144.158][60963] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....17] [ip4][..udp] [.200.31.144.158][38913] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....18] [ip4][..udp] [.200.31.144.158][33453] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....20] [ip4][..udp] [.200.31.144.158][41259] -> [..90.147.171.51][..427] + new: [....20] [ip4][..udp] [.200.31.144.158][41259] -> [..90.147.171.51][..427] detected: [....20] [ip4][..udp] [.200.31.144.158][41259] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....19] [ip4][..udp] [.200.31.144.158][60963] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 21 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 20|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....21] [ip4][..udp] [...62.230.4.248][56007] -> [..165.144.84.62][..427] + new: [....21] [ip4][..udp] [...62.230.4.248][56007] -> [..165.144.84.62][..427] detected: [....21] [ip4][..udp] [...62.230.4.248][56007] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....19] [ip4][..udp] [.200.31.144.158][60963] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....20] [ip4][..udp] [.200.31.144.158][41259] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 22 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 21|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....22] [ip4][..udp] [.200.31.144.158][52741] -> [.165.114.202.61][..427] + new: [....22] [ip4][..udp] [.200.31.144.158][52741] -> [.165.114.202.61][..427] detected: [....22] [ip4][..udp] [.200.31.144.158][52741] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....21] [ip4][..udp] [...62.230.4.248][56007] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....23] [ip4][..udp] [.200.31.144.158][39516] -> [..90.145.180.58][..427] + new: [....23] [ip4][..udp] [.200.31.144.158][39516] -> [..90.145.180.58][..427] detected: [....23] [ip4][..udp] [.200.31.144.158][39516] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....22] [ip4][..udp] [.200.31.144.158][52741] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....24] [ip4][..udp] [.200.31.144.158][43074] -> [..165.144.84.62][..427] + new: [....24] [ip4][..udp] [.200.31.144.158][43074] -> [..165.144.84.62][..427] detected: [....24] [ip4][..udp] [.200.31.144.158][43074] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....23] [ip4][..udp] [.200.31.144.158][39516] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 25 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 24|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....25] [ip4][..udp] [198.229.224.110][56395] -> [..90.145.180.58][..427] + new: [....25] [ip4][..udp] [198.229.224.110][56395] -> [..90.145.180.58][..427] detected: [....25] [ip4][..udp] [198.229.224.110][56395] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....24] [ip4][..udp] [.200.31.144.158][43074] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....23] [ip4][..udp] [.200.31.144.158][39516] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 26 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 25|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....26] [ip4][..udp] [..67.159.16.150][27095] -> [..165.144.84.62][..427] + new: [....26] [ip4][..udp] [..67.159.16.150][27095] -> [..165.144.84.62][..427] detected: [....26] [ip4][..udp] [..67.159.16.150][27095] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....25] [ip4][..udp] [198.229.224.110][56395] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 27 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 26|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....27] [ip4][..udp] [.217.217.186.39][52663] -> [.186.112.202.53][..427] + new: [....27] [ip4][..udp] [.217.217.186.39][52663] -> [.186.112.202.53][..427] detected: [....27] [ip4][..udp] [.217.217.186.39][52663] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....26] [ip4][..udp] [..67.159.16.150][27095] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....28] [ip4][..udp] [..35.252.69.113][26160] -> [..69.109.187.54][..427] + new: [....28] [ip4][..udp] [..35.252.69.113][26160] -> [..69.109.187.54][..427] detected: [....28] [ip4][..udp] [..35.252.69.113][26160] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....27] [ip4][..udp] [.217.217.186.39][52663] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 29 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 28|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....29] [ip4][..udp] [.34.102.125.120][45441] -> [...90.141.37.56][..427] + new: [....29] [ip4][..udp] [.34.102.125.120][45441] -> [...90.141.37.56][..427] detected: [....29] [ip4][..udp] [.34.102.125.120][45441] -> [...90.141.37.56][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] idle: [....28] [ip4][..udp] [..35.252.69.113][26160] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....30] [ip4][..udp] [.27.134.169.220][58691] -> [..90.147.171.51][..427] + new: [....30] [ip4][..udp] [.27.134.169.220][58691] -> [..90.147.171.51][..427] detected: [....30] [ip4][..udp] [.27.134.169.220][58691] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....29] [ip4][..udp] [.34.102.125.120][45441] -> [...90.141.37.56][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] DAEMON-EVENT: [Processed: 31 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 30|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....31] [ip4][..udp] [134.180.144.149][33386] -> [.186.112.202.53][..427] + new: [....31] [ip4][..udp] [134.180.144.149][33386] -> [.186.112.202.53][..427] detected: [....31] [ip4][..udp] [134.180.144.149][33386] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....30] [ip4][..udp] [.27.134.169.220][58691] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 32 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 31|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 6] - new: [....32] [ip4][..udp] [.36.231.109.217][50939] -> [..90.145.180.58][..427] + new: [....32] [ip4][..udp] [.36.231.109.217][50939] -> [..90.145.180.58][..427] detected: [....32] [ip4][..udp] [.36.231.109.217][50939] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....31] [ip4][..udp] [134.180.144.149][33386] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....33] [ip4][..udp] [.227.199.90.122][41334] -> [..90.111.212.50][..427] + new: [....33] [ip4][..udp] [.227.199.90.122][41334] -> [..90.111.212.50][..427] detected: [....33] [ip4][..udp] [.227.199.90.122][41334] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....32] [ip4][..udp] [.36.231.109.217][50939] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....34] [ip4][..udp] [182.180.120.139][58970] -> [...85.111.52.57][..427] + new: [....34] [ip4][..udp] [182.180.120.139][58970] -> [...85.111.52.57][..427] detected: [....34] [ip4][..udp] [182.180.120.139][58970] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....33] [ip4][..udp] [.227.199.90.122][41334] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 35 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 34|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 7] - new: [....35] [ip4][..udp] [200.180.144.114][55489] -> [..90.111.212.50][..427] + new: [....35] [ip4][..udp] [200.180.144.114][55489] -> [..90.111.212.50][..427] detected: [....35] [ip4][..udp] [200.180.144.114][55489] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....33] [ip4][..udp] [.227.199.90.122][41334] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....34] [ip4][..udp] [182.180.120.139][58970] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....36] [ip4][..udp] [.70.180.111.241][60983] -> [.165.114.202.61][..427] + new: [....36] [ip4][..udp] [.70.180.111.241][60983] -> [.165.114.202.61][..427] detected: [....36] [ip4][..udp] [.70.180.111.241][60983] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....35] [ip4][..udp] [200.180.144.114][55489] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....37] [ip4][..udp] [236.131.162.157][38679] -> [...90.141.37.56][..427] + new: [....37] [ip4][..udp] [236.131.162.157][38679] -> [...90.141.37.56][..427] detected: [....37] [ip4][..udp] [236.131.162.157][38679] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....36] [ip4][..udp] [.70.180.111.241][60983] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....38] [ip4][..udp] [.47.123.189.155][56038] -> [..90.147.171.51][..427] + new: [....38] [ip4][..udp] [.47.123.189.155][56038] -> [..90.147.171.51][..427] detected: [....38] [ip4][..udp] [.47.123.189.155][56038] -> [..90.147.171.51][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [....36] [ip4][..udp] [.70.180.111.241][60983] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....37] [ip4][..udp] [236.131.162.157][38679] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 39 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 38|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....39] [ip4][..udp] [.70.180.111.241][48096] -> [..74.111.203.55][..427] + new: [....39] [ip4][..udp] [.70.180.111.241][48096] -> [..74.111.203.55][..427] detected: [....39] [ip4][..udp] [.70.180.111.241][48096] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....37] [ip4][..udp] [236.131.162.157][38679] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....38] [ip4][..udp] [.47.123.189.155][56038] -> [..90.147.171.51][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] - new: [....40] [ip4][..udp] [182.180.120.139][46563] -> [..90.145.180.58][..427] + new: [....40] [ip4][..udp] [182.180.120.139][46563] -> [..90.145.180.58][..427] detected: [....40] [ip4][..udp] [182.180.120.139][46563] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....39] [ip4][..udp] [.70.180.111.241][48096] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 41 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 40|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....41] [ip4][..udp] [..218.19.29.186][56315] -> [..90.111.212.50][..427] + new: [....41] [ip4][..udp] [..218.19.29.186][56315] -> [..90.111.212.50][..427] detected: [....41] [ip4][..udp] [..218.19.29.186][56315] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....40] [ip4][..udp] [182.180.120.139][46563] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 42 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 41|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....42] [ip4][..udp] [186.213.158.225][51349] -> [..69.109.187.54][..427] + new: [....42] [ip4][..udp] [186.213.158.225][51349] -> [..69.109.187.54][..427] detected: [....42] [ip4][..udp] [186.213.158.225][51349] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....41] [ip4][..udp] [..218.19.29.186][56315] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 43 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 42|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....43] [ip4][..udp] [231.223.121.213][.7086] -> [...90.141.37.56][..427] + new: [....43] [ip4][..udp] [231.223.121.213][.7086] -> [...90.141.37.56][..427] detected: [....43] [ip4][..udp] [231.223.121.213][.7086] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....42] [ip4][..udp] [186.213.158.225][51349] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 44 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 43|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....44] [ip4][..udp] [..20.133.112.32][11510] -> [.165.114.202.61][..427] + new: [....44] [ip4][..udp] [..20.133.112.32][11510] -> [.165.114.202.61][..427] detected: [....44] [ip4][..udp] [..20.133.112.32][11510] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....43] [ip4][..udp] [231.223.121.213][.7086] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 46 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 44|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....45] [ip4][..udp] [..83.48.216.235][51745] -> [.186.112.202.53][..427] + new: [....45] [ip4][..udp] [..83.48.216.235][51745] -> [.186.112.202.53][..427] detected: [....45] [ip4][..udp] [..83.48.216.235][51745] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....44] [ip4][..udp] [..20.133.112.32][11510] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 47 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 45|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....46] [ip4][..udp] [.154.97.132.119][64306] -> [..165.144.84.62][..427] + new: [....46] [ip4][..udp] [.154.97.132.119][64306] -> [..165.144.84.62][..427] detected: [....46] [ip4][..udp] [.154.97.132.119][64306] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....45] [ip4][..udp] [..83.48.216.235][51745] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 48 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 46|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....47] [ip4][..udp] [..83.48.216.235][56358] -> [..90.145.180.58][..427] + new: [....47] [ip4][..udp] [..83.48.216.235][56358] -> [..90.145.180.58][..427] detected: [....47] [ip4][..udp] [..83.48.216.235][56358] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....46] [ip4][..udp] [.154.97.132.119][64306] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 49 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 47|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....48] [ip4][..udp] [.....72.30.8.39][43690] -> [..90.111.212.50][..427] + new: [....48] [ip4][..udp] [.....72.30.8.39][43690] -> [..90.111.212.50][..427] detected: [....48] [ip4][..udp] [.....72.30.8.39][43690] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....47] [ip4][..udp] [..83.48.216.235][56358] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....49] [ip4][..udp] [.....71.38.8.47][42689] -> [...90.141.37.56][..427] + new: [....49] [ip4][..udp] [.....71.38.8.47][42689] -> [...90.141.37.56][..427] detected: [....49] [ip4][..udp] [.....71.38.8.47][42689] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....48] [ip4][..udp] [.....72.30.8.39][43690] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 51 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 49|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 9] - new: [....50] [ip4][..udp] [.121.106.247.20][12409] -> [..165.144.84.62][..427] + new: [....50] [ip4][..udp] [.121.106.247.20][12409] -> [..165.144.84.62][..427] detected: [....50] [ip4][..udp] [.121.106.247.20][12409] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....49] [ip4][..udp] [.....71.38.8.47][42689] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....51] [ip4][..udp] [.....55.94.8.63][43995] -> [..90.145.180.58][..427] + new: [....51] [ip4][..udp] [.....55.94.8.63][43995] -> [..90.145.180.58][..427] detected: [....51] [ip4][..udp] [.....55.94.8.63][43995] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....50] [ip4][..udp] [.121.106.247.20][12409] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....52] [ip4][..udp] [..185.225.247.8][48375] -> [.165.114.202.61][..427] + new: [....52] [ip4][..udp] [..185.225.247.8][48375] -> [.165.114.202.61][..427] detected: [....52] [ip4][..udp] [..185.225.247.8][48375] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....50] [ip4][..udp] [.121.106.247.20][12409] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....51] [ip4][..udp] [.....55.94.8.63][43995] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 54 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 52|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 11] - new: [....53] [ip4][..udp] [.....121.82.8.7][60170] -> [...85.111.52.57][..427] + new: [....53] [ip4][..udp] [.....121.82.8.7][60170] -> [...85.111.52.57][..427] detected: [....53] [ip4][..udp] [.....121.82.8.7][60170] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....52] [ip4][..udp] [..185.225.247.8][48375] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....51] [ip4][..udp] [.....55.94.8.63][43995] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....54] [ip4][..udp] [.121.106.247.20][55474] -> [.186.112.202.53][..427] + new: [....54] [ip4][..udp] [.121.106.247.20][55474] -> [.186.112.202.53][..427] detected: [....54] [ip4][..udp] [.121.106.247.20][55474] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....53] [ip4][..udp] [.....121.82.8.7][60170] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 56 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 54|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 11] - new: [....55] [ip4][..udp] [.121.106.247.20][55474] -> [..90.147.171.51][..427] + new: [....55] [ip4][..udp] [.121.106.247.20][55474] -> [..90.147.171.51][..427] detected: [....55] [ip4][..udp] [.121.106.247.20][55474] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....54] [ip4][..udp] [.121.106.247.20][55474] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....56] [ip4][..udp] [..200.97.247.24][22124] -> [..74.111.203.55][..427] + new: [....56] [ip4][..udp] [..200.97.247.24][22124] -> [..74.111.203.55][..427] detected: [....56] [ip4][..udp] [..200.97.247.24][22124] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....55] [ip4][..udp] [.121.106.247.20][55474] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 58 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 56|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 12] - new: [....57] [ip4][..udp] [..121.35.244.56][30580] -> [..90.145.180.58][..427] + new: [....57] [ip4][..udp] [..121.35.244.56][30580] -> [..90.145.180.58][..427] detected: [....57] [ip4][..udp] [..121.35.244.56][30580] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....55] [ip4][..udp] [.121.106.247.20][55474] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....56] [ip4][..udp] [..200.97.247.24][22124] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....58] [ip4][..udp] [...154.96.5.121][26060] -> [..69.109.187.54][..427] + new: [....58] [ip4][..udp] [...154.96.5.121][26060] -> [..69.109.187.54][..427] detected: [....58] [ip4][..udp] [...154.96.5.121][26060] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....57] [ip4][..udp] [..121.35.244.56][30580] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....59] [ip4][..udp] [..38.236.38.224][52729] -> [.165.114.202.61][..427] + new: [....59] [ip4][..udp] [..38.236.38.224][52729] -> [.165.114.202.61][..427] detected: [....59] [ip4][..udp] [..38.236.38.224][52729] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....57] [ip4][..udp] [..121.35.244.56][30580] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....58] [ip4][..udp] [...154.96.5.121][26060] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 61 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 59|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....60] [ip4][..udp] [..69.230.164.78][55275] -> [...90.141.37.56][..427] + new: [....60] [ip4][..udp] [..69.230.164.78][55275] -> [...90.141.37.56][..427] detected: [....60] [ip4][..udp] [..69.230.164.78][55275] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....58] [ip4][..udp] [...154.96.5.121][26060] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....59] [ip4][..udp] [..38.236.38.224][52729] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 62 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 60|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....61] [ip4][..udp] [..235.98.65.133][31778] -> [..165.144.84.62][..427] + new: [....61] [ip4][..udp] [..235.98.65.133][31778] -> [..165.144.84.62][..427] detected: [....61] [ip4][..udp] [..235.98.65.133][31778] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....60] [ip4][..udp] [..69.230.164.78][55275] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 64 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 61|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....62] [ip4][..udp] [..88.31.110.219][50660] -> [.186.112.202.53][..427] + new: [....62] [ip4][..udp] [..88.31.110.219][50660] -> [.186.112.202.53][..427] detected: [....62] [ip4][..udp] [..88.31.110.219][50660] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....61] [ip4][..udp] [..235.98.65.133][31778] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 65 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 62|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....63] [ip4][..udp] [...35.0.100.115][62892] -> [.165.114.202.61][..427] + new: [....63] [ip4][..udp] [...35.0.100.115][62892] -> [.165.114.202.61][..427] detected: [....63] [ip4][..udp] [...35.0.100.115][62892] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....62] [ip4][..udp] [..88.31.110.219][50660] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 66 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 63|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....64] [ip4][..udp] [.34.102.125.120][17423] -> [..165.144.84.62][..427] + new: [....64] [ip4][..udp] [.34.102.125.120][17423] -> [..165.144.84.62][..427] detected: [....64] [ip4][..udp] [.34.102.125.120][17423] -> [..165.144.84.62][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] idle: [....63] [ip4][..udp] [...35.0.100.115][62892] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 67 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 64|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....65] [ip4][..udp] [.70.232.230.229][51197] -> [...85.111.52.57][..427] + new: [....65] [ip4][..udp] [.70.232.230.229][51197] -> [...85.111.52.57][..427] detected: [....65] [ip4][..udp] [.70.232.230.229][51197] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....64] [ip4][..udp] [.34.102.125.120][17423] -> [..165.144.84.62][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] DAEMON-EVENT: [Processed: 68 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 65|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....66] [ip4][..udp] [172.237.152.209][51708] -> [..165.144.84.62][..427] + new: [....66] [ip4][..udp] [172.237.152.209][51708] -> [..165.144.84.62][..427] detected: [....66] [ip4][..udp] [172.237.152.209][51708] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....65] [ip4][..udp] [.70.232.230.229][51197] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 69 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 66|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....67] [ip4][..udp] [...58.36.157.61][53238] -> [..74.111.203.55][..427] + new: [....67] [ip4][..udp] [...58.36.157.61][53238] -> [..74.111.203.55][..427] detected: [....67] [ip4][..udp] [...58.36.157.61][53238] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....66] [ip4][..udp] [172.237.152.209][51708] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 67|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....68] [ip4][..udp] [.227.134.81.212][37207] -> [...85.111.52.57][..427] + new: [....68] [ip4][..udp] [.227.134.81.212][37207] -> [...85.111.52.57][..427] detected: [....68] [ip4][..udp] [.227.134.81.212][37207] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....67] [ip4][..udp] [...58.36.157.61][53238] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 71 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 68|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....69] [ip4][..udp] [..39.59.139.121][51157] -> [...85.111.52.57][..427] + new: [....69] [ip4][..udp] [..39.59.139.121][51157] -> [...85.111.52.57][..427] detected: [....69] [ip4][..udp] [..39.59.139.121][51157] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....68] [ip4][..udp] [.227.134.81.212][37207] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 72 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 69|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....70] [ip4][..udp] [.227.134.81.212][45177] -> [..90.111.212.50][..427] + new: [....70] [ip4][..udp] [.227.134.81.212][45177] -> [..90.111.212.50][..427] detected: [....70] [ip4][..udp] [.227.134.81.212][45177] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....69] [ip4][..udp] [..39.59.139.121][51157] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 73 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 70|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....71] [ip4][..udp] [.103.71.146.222][47772] -> [.165.114.202.61][..427] + new: [....71] [ip4][..udp] [.103.71.146.222][47772] -> [.165.114.202.61][..427] detected: [....71] [ip4][..udp] [.103.71.146.222][47772] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....70] [ip4][..udp] [.227.134.81.212][45177] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 74 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 71|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....72] [ip4][..udp] [238.132.112.150][44248] -> [..90.147.171.51][..427] + new: [....72] [ip4][..udp] [238.132.112.150][44248] -> [..90.147.171.51][..427] detected: [....72] [ip4][..udp] [238.132.112.150][44248] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....71] [ip4][..udp] [.103.71.146.222][47772] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 72|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....73] [ip4][..udp] [134.180.144.149][47037] -> [..90.145.180.58][..427] + new: [....73] [ip4][..udp] [134.180.144.149][47037] -> [..90.145.180.58][..427] detected: [....73] [ip4][..udp] [134.180.144.149][47037] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....72] [ip4][..udp] [238.132.112.150][44248] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....74] [ip4][..udp] [.236.155.96.147][44475] -> [..90.111.212.50][..427] + new: [....74] [ip4][..udp] [.236.155.96.147][44475] -> [..90.111.212.50][..427] detected: [....74] [ip4][..udp] [.236.155.96.147][44475] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....73] [ip4][..udp] [134.180.144.149][47037] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 77 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 74|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....75] [ip4][..udp] [182.180.120.139][33156] -> [..74.111.203.55][..427] + new: [....75] [ip4][..udp] [182.180.120.139][33156] -> [..74.111.203.55][..427] detected: [....75] [ip4][..udp] [182.180.120.139][33156] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....74] [ip4][..udp] [.236.155.96.147][44475] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....76] [ip4][..udp] [..19.99.147.148][49052] -> [...90.141.37.56][..427] + new: [....76] [ip4][..udp] [..19.99.147.148][49052] -> [...90.141.37.56][..427] detected: [....76] [ip4][..udp] [..19.99.147.148][49052] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....75] [ip4][..udp] [182.180.120.139][33156] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 79 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 76|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....77] [ip4][..udp] [.47.123.177.154][44018] -> [.165.114.202.61][..427] + new: [....77] [ip4][..udp] [.47.123.177.154][44018] -> [.165.114.202.61][..427] detected: [....77] [ip4][..udp] [.47.123.177.154][44018] -> [.165.114.202.61][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] - new: [....78] [ip4][..udp] [..46.100.97.147][37387] -> [..165.144.84.62][..427] + new: [....78] [ip4][..udp] [..46.100.97.147][37387] -> [..165.144.84.62][..427] detected: [....78] [ip4][..udp] [..46.100.97.147][37387] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....76] [ip4][..udp] [..19.99.147.148][49052] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 81 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 78|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 14] - new: [....79] [ip4][..udp] [134.180.144.149][48737] -> [.186.112.202.53][..427] + new: [....79] [ip4][..udp] [134.180.144.149][48737] -> [.186.112.202.53][..427] detected: [....79] [ip4][..udp] [134.180.144.149][48737] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....78] [ip4][..udp] [..46.100.97.147][37387] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....77] [ip4][..udp] [.47.123.177.154][44018] -> [.165.114.202.61][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] - new: [....80] [ip4][..udp] [200.180.144.114][57533] -> [..69.109.187.54][..427] + new: [....80] [ip4][..udp] [200.180.144.114][57533] -> [..69.109.187.54][..427] detected: [....80] [ip4][..udp] [200.180.144.114][57533] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....79] [ip4][..udp] [134.180.144.149][48737] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....81] [ip4][..udp] [.47.123.177.154][35950] -> [...85.111.52.57][..427] + new: [....81] [ip4][..udp] [.47.123.177.154][35950] -> [...85.111.52.57][..427] detected: [....81] [ip4][..udp] [.47.123.177.154][35950] -> [...85.111.52.57][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [....80] [ip4][..udp] [200.180.144.114][57533] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....79] [ip4][..udp] [134.180.144.149][48737] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 84 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 81|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 15] - new: [....82] [ip4][..udp] [.....44.49.31.2][51197] -> [..90.147.171.51][..427] + new: [....82] [ip4][..udp] [.....44.49.31.2][51197] -> [..90.147.171.51][..427] detected: [....82] [ip4][..udp] [.....44.49.31.2][51197] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....81] [ip4][..udp] [.47.123.177.154][35950] -> [...85.111.52.57][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] - new: [....83] [ip4][..udp] [..19.99.146.156][54379] -> [..90.145.180.58][..427] + new: [....83] [ip4][..udp] [..19.99.146.156][54379] -> [..90.145.180.58][..427] detected: [....83] [ip4][..udp] [..19.99.146.156][54379] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....82] [ip4][..udp] [.....44.49.31.2][51197] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 86 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 83|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 15] - new: [....84] [ip4][..udp] [....174.50.7.11][55450] -> [..69.109.187.54][..427] + new: [....84] [ip4][..udp] [....174.50.7.11][55450] -> [..69.109.187.54][..427] detected: [....84] [ip4][..udp] [....174.50.7.11][55450] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....83] [ip4][..udp] [..19.99.146.156][54379] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....85] [ip4][..udp] [.58.218.184.177][54059] -> [..90.111.212.50][..427] + new: [....85] [ip4][..udp] [.58.218.184.177][54059] -> [..90.111.212.50][..427] detected: [....85] [ip4][..udp] [.58.218.184.177][54059] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....84] [ip4][..udp] [....174.50.7.11][55450] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 88 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 85|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....86] [ip4][..udp] [...31.0.154.114][40383] -> [..90.145.180.58][..427] + new: [....86] [ip4][..udp] [...31.0.154.114][40383] -> [..90.145.180.58][..427] detected: [....86] [ip4][..udp] [...31.0.154.114][40383] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....84] [ip4][..udp] [....174.50.7.11][55450] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....85] [ip4][..udp] [.58.218.184.177][54059] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 89 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 86|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....87] [ip4][..udp] [.66.228.194.219][53105] -> [.186.112.202.53][..427] + new: [....87] [ip4][..udp] [.66.228.194.219][53105] -> [.186.112.202.53][..427] detected: [....87] [ip4][..udp] [.66.228.194.219][53105] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....86] [ip4][..udp] [...31.0.154.114][40383] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 90 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 87|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....88] [ip4][..udp] [..67.159.16.150][43759] -> [..74.111.203.55][..427] + new: [....88] [ip4][..udp] [..67.159.16.150][43759] -> [..74.111.203.55][..427] detected: [....88] [ip4][..udp] [..67.159.16.150][43759] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....87] [ip4][..udp] [.66.228.194.219][53105] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 91 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 88|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....89] [ip4][..udp] [.200.31.144.158][53596] -> [..90.111.212.50][..427] + new: [....89] [ip4][..udp] [.200.31.144.158][53596] -> [..90.111.212.50][..427] detected: [....89] [ip4][..udp] [.200.31.144.158][53596] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....88] [ip4][..udp] [..67.159.16.150][43759] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 92 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 89|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....90] [ip4][..udp] [.200.31.144.158][47879] -> [..69.109.187.54][..427] + new: [....90] [ip4][..udp] [.200.31.144.158][47879] -> [..69.109.187.54][..427] detected: [....90] [ip4][..udp] [.200.31.144.158][47879] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....89] [ip4][..udp] [.200.31.144.158][53596] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....91] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] + new: [....91] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] detected: [....91] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....90] [ip4][..udp] [.200.31.144.158][47879] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 94 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 91|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 16] - new: [....92] [ip4][..udp] [.200.31.144.158][51364] -> [..165.144.84.62][..427] + new: [....92] [ip4][..udp] [.200.31.144.158][51364] -> [..165.144.84.62][..427] detected: [....92] [ip4][..udp] [.200.31.144.158][51364] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....91] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....93] [ip4][..udp] [.200.31.144.158][41690] -> [..74.111.203.55][..427] + new: [....93] [ip4][..udp] [.200.31.144.158][41690] -> [..74.111.203.55][..427] detected: [....93] [ip4][..udp] [.200.31.144.158][41690] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....92] [ip4][..udp] [.200.31.144.158][51364] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....94] [ip4][..udp] [.200.31.144.158][51228] -> [.165.114.202.61][..427] + new: [....94] [ip4][..udp] [.200.31.144.158][51228] -> [.165.114.202.61][..427] detected: [....94] [ip4][..udp] [.200.31.144.158][51228] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....92] [ip4][..udp] [.200.31.144.158][51364] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....93] [ip4][..udp] [.200.31.144.158][41690] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 97 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 94|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 18] - new: [....95] [ip4][..udp] [..35.252.69.113][59682] -> [...90.141.37.56][..427] + new: [....95] [ip4][..udp] [..35.252.69.113][59682] -> [...90.141.37.56][..427] detected: [....95] [ip4][..udp] [..35.252.69.113][59682] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....93] [ip4][..udp] [.200.31.144.158][41690] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....94] [ip4][..udp] [.200.31.144.158][51228] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....96] [ip4][..udp] [..208.209.71.22][55733] -> [...85.111.52.57][..427] + new: [....96] [ip4][..udp] [..208.209.71.22][55733] -> [...85.111.52.57][..427] detected: [....96] [ip4][..udp] [..208.209.71.22][55733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....95] [ip4][..udp] [..35.252.69.113][59682] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [....97] [ip4][..udp] [.200.31.144.158][40943] -> [...90.141.37.56][..427] + new: [....97] [ip4][..udp] [.200.31.144.158][40943] -> [...90.141.37.56][..427] detected: [....97] [ip4][..udp] [.200.31.144.158][40943] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....95] [ip4][..udp] [..35.252.69.113][59682] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [....96] [ip4][..udp] [..208.209.71.22][55733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 100 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 97|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [....98] [ip4][..udp] [.200.31.144.158][33048] -> [..90.145.180.58][..427] + new: [....98] [ip4][..udp] [.200.31.144.158][33048] -> [..90.145.180.58][..427] detected: [....98] [ip4][..udp] [.200.31.144.158][33048] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....96] [ip4][..udp] [..208.209.71.22][55733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....97] [ip4][..udp] [.200.31.144.158][40943] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 101 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 98|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [....99] [ip4][..udp] [.19.156.188.155][47964] -> [.186.112.202.53][..427] + new: [....99] [ip4][..udp] [.19.156.188.155][47964] -> [.186.112.202.53][..427] detected: [....99] [ip4][..udp] [.19.156.188.155][47964] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....98] [ip4][..udp] [.200.31.144.158][33048] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 102 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 99|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [...100] [ip4][..udp] [.210.12.216.151][54477] -> [..90.145.180.58][..427] + new: [...100] [ip4][..udp] [.210.12.216.151][54477] -> [..90.145.180.58][..427] detected: [...100] [ip4][..udp] [.210.12.216.151][54477] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [....99] [ip4][..udp] [.19.156.188.155][47964] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 103 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 100|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [...101] [ip4][..udp] [..70.28.101.252][52969] -> [...90.141.37.56][..427] + new: [...101] [ip4][..udp] [..70.28.101.252][52969] -> [...90.141.37.56][..427] detected: [...101] [ip4][..udp] [..70.28.101.252][52969] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...100] [ip4][..udp] [.210.12.216.151][54477] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 104 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 101|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [...102] [ip4][..udp] [....57.3.49.213][25820] -> [..74.111.203.55][..427] + new: [...102] [ip4][..udp] [....57.3.49.213][25820] -> [..74.111.203.55][..427] detected: [...102] [ip4][..udp] [....57.3.49.213][25820] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...101] [ip4][..udp] [..70.28.101.252][52969] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...103] [ip4][..udp] [.70.193.198.250][29011] -> [..69.109.187.54][..427] + new: [...103] [ip4][..udp] [.70.193.198.250][29011] -> [..69.109.187.54][..427] detected: [...103] [ip4][..udp] [.70.193.198.250][29011] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...102] [ip4][..udp] [....57.3.49.213][25820] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 106 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 103|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [...104] [ip4][..udp] [...87.0.217.242][54220] -> [...85.111.52.57][..427] + new: [...104] [ip4][..udp] [...87.0.217.242][54220] -> [...85.111.52.57][..427] detected: [...104] [ip4][..udp] [...87.0.217.242][54220] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...103] [ip4][..udp] [.70.193.198.250][29011] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...105] [ip4][..udp] [.54.251.198.222][40998] -> [..165.144.84.62][..427] + new: [...105] [ip4][..udp] [.54.251.198.222][40998] -> [..165.144.84.62][..427] detected: [...105] [ip4][..udp] [.54.251.198.222][40998] -> [..165.144.84.62][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...104] [ip4][..udp] [...87.0.217.242][54220] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 108 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 105|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 20] - new: [...106] [ip4][..udp] [...87.39.57.211][42486] -> [...90.141.37.56][..427] + new: [...106] [ip4][..udp] [...87.39.57.211][42486] -> [...90.141.37.56][..427] detected: [...106] [ip4][..udp] [...87.39.57.211][42486] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...105] [ip4][..udp] [.54.251.198.222][40998] -> [..165.144.84.62][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] - new: [...107] [ip4][..udp] [..88.219.46.235][.7636] -> [..90.147.171.51][..427] + new: [...107] [ip4][..udp] [..88.219.46.235][.7636] -> [..90.147.171.51][..427] detected: [...107] [ip4][..udp] [..88.219.46.235][.7636] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...106] [ip4][..udp] [...87.39.57.211][42486] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...108] [ip4][..udp] [..173.241.63.36][56717] -> [..74.111.203.55][..427] + new: [...108] [ip4][..udp] [..173.241.63.36][56717] -> [..74.111.203.55][..427] detected: [...108] [ip4][..udp] [..173.241.63.36][56717] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...107] [ip4][..udp] [..88.219.46.235][.7636] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...109] [ip4][..udp] [..167.57.49.219][49798] -> [..90.111.212.50][..427] + new: [...109] [ip4][..udp] [..167.57.49.219][49798] -> [..90.111.212.50][..427] detected: [...109] [ip4][..udp] [..167.57.49.219][49798] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...107] [ip4][..udp] [..88.219.46.235][.7636] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...108] [ip4][..udp] [..173.241.63.36][56717] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...110] [ip4][..udp] [.168.222.38.193][38055] -> [.186.112.202.53][..427] + new: [...110] [ip4][..udp] [.168.222.38.193][38055] -> [.186.112.202.53][..427] detected: [...110] [ip4][..udp] [.168.222.38.193][38055] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...108] [ip4][..udp] [..173.241.63.36][56717] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...109] [ip4][..udp] [..167.57.49.219][49798] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 113 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 110|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 23] - new: [...111] [ip4][..udp] [..46.204.255.75][55098] -> [..165.144.84.62][..427] + new: [...111] [ip4][..udp] [..46.204.255.75][55098] -> [..165.144.84.62][..427] detected: [...111] [ip4][..udp] [..46.204.255.75][55098] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...112] [ip4][..udp] [..88.219.46.235][44462] -> [..90.145.180.58][..427] + new: [...112] [ip4][..udp] [..88.219.46.235][44462] -> [..90.145.180.58][..427] detected: [...112] [ip4][..udp] [..88.219.46.235][44462] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...109] [ip4][..udp] [..167.57.49.219][49798] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...110] [ip4][..udp] [.168.222.38.193][38055] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...111] [ip4][..udp] [..46.204.255.75][55098] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 115 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 112|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...113] [ip4][..udp] [..167.57.49.219][62479] -> [.165.114.202.61][..427] + new: [...113] [ip4][..udp] [..167.57.49.219][62479] -> [.165.114.202.61][..427] detected: [...113] [ip4][..udp] [..167.57.49.219][62479] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...112] [ip4][..udp] [..88.219.46.235][44462] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...110] [ip4][..udp] [.168.222.38.193][38055] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...111] [ip4][..udp] [..46.204.255.75][55098] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...114] [ip4][..udp] [...83.14.224.14][55733] -> [.165.114.202.61][..427] + new: [...114] [ip4][..udp] [...83.14.224.14][55733] -> [.165.114.202.61][..427] detected: [...114] [ip4][..udp] [...83.14.224.14][55733] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...113] [ip4][..udp] [..167.57.49.219][62479] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 117 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 114|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...115] [ip4][..udp] [.159.60.180.118][43688] -> [..69.109.187.54][..427] + new: [...115] [ip4][..udp] [.159.60.180.118][43688] -> [..69.109.187.54][..427] detected: [...115] [ip4][..udp] [.159.60.180.118][43688] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...114] [ip4][..udp] [...83.14.224.14][55733] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 118 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 115|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...116] [ip4][..udp] [134.180.144.149][38375] -> [..90.147.171.51][..427] + new: [...116] [ip4][..udp] [134.180.144.149][38375] -> [..90.147.171.51][..427] detected: [...116] [ip4][..udp] [134.180.144.149][38375] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...115] [ip4][..udp] [.159.60.180.118][43688] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 119 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 116|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...117] [ip4][..udp] [134.180.144.149][52853] -> [...90.141.37.56][..427] + new: [...117] [ip4][..udp] [134.180.144.149][52853] -> [...90.141.37.56][..427] detected: [...117] [ip4][..udp] [134.180.144.149][52853] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...116] [ip4][..udp] [134.180.144.149][38375] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 120 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 117|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...118] [ip4][..udp] [239.100.141.153][53222] -> [.165.114.202.61][..427] + new: [...118] [ip4][..udp] [239.100.141.153][53222] -> [.165.114.202.61][..427] detected: [...118] [ip4][..udp] [239.100.141.153][53222] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...117] [ip4][..udp] [134.180.144.149][52853] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 121 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 118|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 25] - new: [...119] [ip4][..udp] [..45.99.146.146][34238] -> [..90.111.212.50][..427] + new: [...119] [ip4][..udp] [..45.99.146.146][34238] -> [..90.111.212.50][..427] detected: [...119] [ip4][..udp] [..45.99.146.146][34238] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...118] [ip4][..udp] [239.100.141.153][53222] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...120] [ip4][..udp] [182.180.120.139][60043] -> [..165.144.84.62][..427] + new: [...120] [ip4][..udp] [182.180.120.139][60043] -> [..165.144.84.62][..427] detected: [...120] [ip4][..udp] [182.180.120.139][60043] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...119] [ip4][..udp] [..45.99.146.146][34238] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 123 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 120|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...121] [ip4][..udp] [..46.100.97.147][55816] -> [..74.111.203.55][..427] + new: [...121] [ip4][..udp] [..46.100.97.147][55816] -> [..74.111.203.55][..427] detected: [...121] [ip4][..udp] [..46.100.97.147][55816] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...120] [ip4][..udp] [182.180.120.139][60043] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...119] [ip4][..udp] [..45.99.146.146][34238] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 124 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 121|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...122] [ip4][..udp] [.47.123.177.154][47805] -> [..69.109.187.54][..427] + new: [...122] [ip4][..udp] [.47.123.177.154][47805] -> [..69.109.187.54][..427] detected: [...122] [ip4][..udp] [.47.123.177.154][47805] -> [..69.109.187.54][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [...121] [ip4][..udp] [..46.100.97.147][55816] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...123] [ip4][..udp] [134.180.144.149][51113] -> [..90.145.180.58][..427] + new: [...123] [ip4][..udp] [134.180.144.149][51113] -> [..90.145.180.58][..427] detected: [...123] [ip4][..udp] [134.180.144.149][51113] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...124] [ip4][..udp] [.70.180.111.241][39226] -> [.186.112.202.53][..427] + new: [...124] [ip4][..udp] [.70.180.111.241][39226] -> [.186.112.202.53][..427] detected: [...124] [ip4][..udp] [.70.180.111.241][39226] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...122] [ip4][..udp] [.47.123.177.154][47805] -> [..69.109.187.54][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [...123] [ip4][..udp] [134.180.144.149][51113] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 127 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 124|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...125] [ip4][..udp] [...35.0.100.115][.9681] -> [..165.144.84.62][..427] + new: [...125] [ip4][..udp] [...35.0.100.115][.9681] -> [..165.144.84.62][..427] detected: [...125] [ip4][..udp] [...35.0.100.115][.9681] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...124] [ip4][..udp] [.70.180.111.241][39226] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...126] [ip4][..udp] [226.158.252.127][24595] -> [..74.111.203.55][..427] + new: [...126] [ip4][..udp] [226.158.252.127][24595] -> [..74.111.203.55][..427] detected: [...126] [ip4][..udp] [226.158.252.127][24595] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...125] [ip4][..udp] [...35.0.100.115][.9681] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 129 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 126|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...127] [ip4][..udp] [...66.24.225.77][56086] -> [..74.111.203.55][..427] + new: [...127] [ip4][..udp] [...66.24.225.77][56086] -> [..74.111.203.55][..427] detected: [...127] [ip4][..udp] [...66.24.225.77][56086] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...126] [ip4][..udp] [226.158.252.127][24595] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 130 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 127|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...128] [ip4][..udp] [...83.14.224.14][49307] -> [..90.145.180.58][..427] + new: [...128] [ip4][..udp] [...83.14.224.14][49307] -> [..90.145.180.58][..427] detected: [...128] [ip4][..udp] [...83.14.224.14][49307] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...127] [ip4][..udp] [...66.24.225.77][56086] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 131 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 128|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...129] [ip4][..udp] [.98.103.253.115][44099] -> [...90.141.37.56][..427] + new: [...129] [ip4][..udp] [.98.103.253.115][44099] -> [...90.141.37.56][..427] detected: [...129] [ip4][..udp] [.98.103.253.115][44099] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...128] [ip4][..udp] [...83.14.224.14][49307] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 132 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 129|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...130] [ip4][..udp] [226.128.122.118][29946] -> [.165.114.202.61][..427] + new: [...130] [ip4][..udp] [226.128.122.118][29946] -> [.165.114.202.61][..427] detected: [...130] [ip4][..udp] [226.128.122.118][29946] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...129] [ip4][..udp] [.98.103.253.115][44099] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 133 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 130|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...131] [ip4][..udp] [..64.63.219.226][57092] -> [..90.147.171.51][..427] + new: [...131] [ip4][..udp] [..64.63.219.226][57092] -> [..90.147.171.51][..427] detected: [...131] [ip4][..udp] [..64.63.219.226][57092] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...130] [ip4][..udp] [226.128.122.118][29946] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 134 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 131|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 26] - new: [...132] [ip4][..udp] [160.184.203.250][41825] -> [..74.111.203.55][..427] + new: [...132] [ip4][..udp] [160.184.203.250][41825] -> [..74.111.203.55][..427] detected: [...132] [ip4][..udp] [160.184.203.250][41825] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...131] [ip4][..udp] [..64.63.219.226][57092] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...133] [ip4][..udp] [..64.63.219.226][57092] -> [.165.114.202.61][..427] + new: [...133] [ip4][..udp] [..64.63.219.226][57092] -> [.165.114.202.61][..427] detected: [...133] [ip4][..udp] [..64.63.219.226][57092] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...132] [ip4][..udp] [160.184.203.250][41825] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 136 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 133|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 27] - new: [...134] [ip4][..udp] [..64.71.218.224][20366] -> [...85.111.52.57][..427] + new: [...134] [ip4][..udp] [..64.71.218.224][20366] -> [...85.111.52.57][..427] detected: [...134] [ip4][..udp] [..64.71.218.224][20366] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...133] [ip4][..udp] [..64.63.219.226][57092] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...132] [ip4][..udp] [160.184.203.250][41825] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...135] [ip4][..udp] [...64.65.52.246][10179] -> [..165.144.84.62][..427] + new: [...135] [ip4][..udp] [...64.65.52.246][10179] -> [..165.144.84.62][..427] detected: [...135] [ip4][..udp] [...64.65.52.246][10179] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...134] [ip4][..udp] [..64.71.218.224][20366] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...136] [ip4][..udp] [..64.63.219.226][10207] -> [...90.141.37.56][..427] + new: [...136] [ip4][..udp] [..64.63.219.226][10207] -> [...90.141.37.56][..427] detected: [...136] [ip4][..udp] [..64.63.219.226][10207] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...137] [ip4][..udp] [.161.193.58.225][64776] -> [.186.112.202.53][..427] + new: [...137] [ip4][..udp] [.161.193.58.225][64776] -> [.186.112.202.53][..427] detected: [...137] [ip4][..udp] [.161.193.58.225][64776] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...135] [ip4][..udp] [...64.65.52.246][10179] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...136] [ip4][..udp] [..64.63.219.226][10207] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...134] [ip4][..udp] [..64.71.218.224][20366] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 140 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 137|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 28] - new: [...138] [ip4][..udp] [..65.62.197.248][45675] -> [..69.109.187.54][..427] + new: [...138] [ip4][..udp] [..65.62.197.248][45675] -> [..69.109.187.54][..427] detected: [...138] [ip4][..udp] [..65.62.197.248][45675] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...137] [ip4][..udp] [.161.193.58.225][64776] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] DAEMON-EVENT: [Processed: 141 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 138|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 28] - new: [...139] [ip4][..udp] [..16.99.147.146][48728] -> [..165.144.84.62][..427] + new: [...139] [ip4][..udp] [..16.99.147.146][48728] -> [..165.144.84.62][..427] detected: [...139] [ip4][..udp] [..16.99.147.146][48728] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...138] [ip4][..udp] [..65.62.197.248][45675] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 142 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 139|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 28] - new: [...140] [ip4][..udp] [.75.153.126.243][54378] -> [..69.109.187.54][..427] + new: [...140] [ip4][..udp] [.75.153.126.243][54378] -> [..69.109.187.54][..427] detected: [...140] [ip4][..udp] [.75.153.126.243][54378] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...139] [ip4][..udp] [..16.99.147.146][48728] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...141] [ip4][..udp] [.70.216.186.103][55880] -> [..165.144.84.62][..427] + new: [...141] [ip4][..udp] [.70.216.186.103][55880] -> [..165.144.84.62][..427] detected: [...141] [ip4][..udp] [.70.216.186.103][55880] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...140] [ip4][..udp] [.75.153.126.243][54378] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 144 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 141|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 28] - new: [...142] [ip4][..udp] [..82.14.191.177][51704] -> [.186.112.202.53][..427] + new: [...142] [ip4][..udp] [..82.14.191.177][51704] -> [.186.112.202.53][..427] detected: [...142] [ip4][..udp] [..82.14.191.177][51704] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...141] [ip4][..udp] [.70.216.186.103][55880] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...143] [ip4][..udp] [..70.28.101.252][49306] -> [..69.109.187.54][..427] + new: [...143] [ip4][..udp] [..70.28.101.252][49306] -> [..69.109.187.54][..427] detected: [...143] [ip4][..udp] [..70.28.101.252][49306] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...142] [ip4][..udp] [..82.14.191.177][51704] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...144] [ip4][..udp] [..166.235.162.1][50338] -> [.165.114.202.61][..427] + new: [...144] [ip4][..udp] [..166.235.162.1][50338] -> [.165.114.202.61][..427] detected: [...144] [ip4][..udp] [..166.235.162.1][50338] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...142] [ip4][..udp] [..82.14.191.177][51704] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...143] [ip4][..udp] [..70.28.101.252][49306] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 147 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 144|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...145] [ip4][..udp] [...38.238.166.9][56529] -> [..90.147.171.51][..427] + new: [...145] [ip4][..udp] [...38.238.166.9][56529] -> [..90.147.171.51][..427] detected: [...145] [ip4][..udp] [...38.238.166.9][56529] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...143] [ip4][..udp] [..70.28.101.252][49306] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...144] [ip4][..udp] [..166.235.162.1][50338] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 148 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 145|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...146] [ip4][..udp] [..206.204.24.90][51495] -> [...90.141.37.56][..427] + new: [...146] [ip4][..udp] [..206.204.24.90][51495] -> [...90.141.37.56][..427] detected: [...146] [ip4][..udp] [..206.204.24.90][51495] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...145] [ip4][..udp] [...38.238.166.9][56529] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 149 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 146|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...147] [ip4][..udp] [165.128.253.116][.5073] -> [..90.147.171.51][..427] + new: [...147] [ip4][..udp] [165.128.253.116][.5073] -> [..90.147.171.51][..427] detected: [...147] [ip4][..udp] [165.128.253.116][.5073] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...146] [ip4][..udp] [..206.204.24.90][51495] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 150 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 147|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...148] [ip4][..udp] [.217.31.231.255][56070] -> [..90.111.212.50][..427] + new: [...148] [ip4][..udp] [.217.31.231.255][56070] -> [..90.111.212.50][..427] detected: [...148] [ip4][..udp] [.217.31.231.255][56070] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...147] [ip4][..udp] [165.128.253.116][.5073] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 151 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 148|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...149] [ip4][..udp] [.28.102.134.210][45382] -> [..69.109.187.54][..427] + new: [...149] [ip4][..udp] [.28.102.134.210][45382] -> [..69.109.187.54][..427] detected: [...149] [ip4][..udp] [.28.102.134.210][45382] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...148] [ip4][..udp] [.217.31.231.255][56070] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 152 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 149|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...150] [ip4][..udp] [..173.241.63.36][50984] -> [...85.111.52.57][..427] + new: [...150] [ip4][..udp] [..173.241.63.36][50984] -> [...85.111.52.57][..427] detected: [...150] [ip4][..udp] [..173.241.63.36][50984] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...149] [ip4][..udp] [.28.102.134.210][45382] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 153 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 150|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...151] [ip4][..udp] [...81.24.43.106][60145] -> [..90.111.212.50][..427] + new: [...151] [ip4][..udp] [...81.24.43.106][60145] -> [..90.111.212.50][..427] detected: [...151] [ip4][..udp] [...81.24.43.106][60145] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...150] [ip4][..udp] [..173.241.63.36][50984] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 154 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 151|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...152] [ip4][..udp] [...81.24.43.106][57096] -> [..74.111.203.55][..427] + new: [...152] [ip4][..udp] [...81.24.43.106][57096] -> [..74.111.203.55][..427] detected: [...152] [ip4][..udp] [...81.24.43.106][57096] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...151] [ip4][..udp] [...81.24.43.106][60145] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 155 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 152|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 30] - new: [...153] [ip4][..udp] [...81.24.43.106][58419] -> [..69.109.187.54][..427] + new: [...153] [ip4][..udp] [...81.24.43.106][58419] -> [..69.109.187.54][..427] detected: [...153] [ip4][..udp] [...81.24.43.106][58419] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...152] [ip4][..udp] [...81.24.43.106][57096] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...154] [ip4][..udp] [...81.24.43.106][52243] -> [...85.111.52.57][..427] + new: [...154] [ip4][..udp] [...81.24.43.106][52243] -> [...85.111.52.57][..427] detected: [...154] [ip4][..udp] [...81.24.43.106][52243] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...153] [ip4][..udp] [...81.24.43.106][58419] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 157 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 154|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...155] [ip4][..udp] [.70.180.111.241][39508] -> [..165.144.84.62][..427] + new: [...155] [ip4][..udp] [.70.180.111.241][39508] -> [..165.144.84.62][..427] detected: [...155] [ip4][..udp] [.70.180.111.241][39508] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...153] [ip4][..udp] [...81.24.43.106][58419] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...154] [ip4][..udp] [...81.24.43.106][52243] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 158 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 155|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...156] [ip4][..udp] [208.100.177.136][45704] -> [..90.111.212.50][..427] + new: [...156] [ip4][..udp] [208.100.177.136][45704] -> [..90.111.212.50][..427] detected: [...156] [ip4][..udp] [208.100.177.136][45704] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...155] [ip4][..udp] [.70.180.111.241][39508] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...157] [ip4][..udp] [...81.24.43.106][47011] -> [..165.144.84.62][..427] + new: [...157] [ip4][..udp] [...81.24.43.106][47011] -> [..165.144.84.62][..427] detected: [...157] [ip4][..udp] [...81.24.43.106][47011] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...156] [ip4][..udp] [208.100.177.136][45704] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 160 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 157|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...158] [ip4][..udp] [182.180.120.139][33316] -> [..69.109.187.54][..427] + new: [...158] [ip4][..udp] [182.180.120.139][33316] -> [..69.109.187.54][..427] detected: [...158] [ip4][..udp] [182.180.120.139][33316] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...157] [ip4][..udp] [...81.24.43.106][47011] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...159] [ip4][..udp] [182.180.120.139][38297] -> [...90.141.37.56][..427] + new: [...159] [ip4][..udp] [182.180.120.139][38297] -> [...90.141.37.56][..427] detected: [...159] [ip4][..udp] [182.180.120.139][38297] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...158] [ip4][..udp] [182.180.120.139][33316] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 162 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 159|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...160] [ip4][..udp] [.246.75.104.115][49217] -> [..90.145.180.58][..427] + new: [...160] [ip4][..udp] [.246.75.104.115][49217] -> [..90.145.180.58][..427] detected: [...160] [ip4][..udp] [.246.75.104.115][49217] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...159] [ip4][..udp] [182.180.120.139][38297] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...161] [ip4][..udp] [.246.75.104.115][50697] -> [.186.112.202.53][..427] + new: [...161] [ip4][..udp] [.246.75.104.115][50697] -> [.186.112.202.53][..427] detected: [...161] [ip4][..udp] [.246.75.104.115][50697] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 164 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 161|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...162] [ip4][..udp] [.45.124.147.156][57093] -> [...85.111.52.57][..427] + new: [...162] [ip4][..udp] [.45.124.147.156][57093] -> [...85.111.52.57][..427] detected: [...162] [ip4][..udp] [.45.124.147.156][57093] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...161] [ip4][..udp] [.246.75.104.115][50697] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...160] [ip4][..udp] [.246.75.104.115][49217] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...163] [ip4][..udp] [...81.24.43.106][60815] -> [...90.141.37.56][..427] + new: [...163] [ip4][..udp] [...81.24.43.106][60815] -> [...90.141.37.56][..427] detected: [...163] [ip4][..udp] [...81.24.43.106][60815] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...162] [ip4][..udp] [.45.124.147.156][57093] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 166 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 163|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 31] - new: [...164] [ip4][..udp] [.246.75.104.115][34990] -> [..74.111.203.55][..427] + new: [...164] [ip4][..udp] [.246.75.104.115][34990] -> [..74.111.203.55][..427] detected: [...164] [ip4][..udp] [.246.75.104.115][34990] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...163] [ip4][..udp] [...81.24.43.106][60815] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...165] [ip4][..udp] [239.100.141.153][41989] -> [..90.147.171.51][..427] + new: [...165] [ip4][..udp] [239.100.141.153][41989] -> [..90.147.171.51][..427] detected: [...165] [ip4][..udp] [239.100.141.153][41989] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...164] [ip4][..udp] [.246.75.104.115][34990] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...166] [ip4][..udp] [184.180.168.240][39574] -> [.165.114.202.61][..427] + new: [...166] [ip4][..udp] [184.180.168.240][39574] -> [.165.114.202.61][..427] detected: [...166] [ip4][..udp] [184.180.168.240][39574] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 169 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 166|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...167] [ip4][..udp] [...81.24.43.106][58836] -> [..90.147.171.51][..427] + new: [...167] [ip4][..udp] [...81.24.43.106][58836] -> [..90.147.171.51][..427] detected: [...167] [ip4][..udp] [...81.24.43.106][58836] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...166] [ip4][..udp] [184.180.168.240][39574] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...164] [ip4][..udp] [.246.75.104.115][34990] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...165] [ip4][..udp] [239.100.141.153][41989] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 170 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 167|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...168] [ip4][..udp] [.100.56.155.112][.1724] -> [..90.147.171.51][..427] + new: [...168] [ip4][..udp] [.100.56.155.112][.1724] -> [..90.147.171.51][..427] detected: [...168] [ip4][..udp] [.100.56.155.112][.1724] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...167] [ip4][..udp] [...81.24.43.106][58836] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 171 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 168|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...169] [ip4][..udp] [.227.134.81.212][10457] -> [..74.111.203.55][..427] + new: [...169] [ip4][..udp] [.227.134.81.212][10457] -> [..74.111.203.55][..427] detected: [...169] [ip4][..udp] [.227.134.81.212][10457] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...168] [ip4][..udp] [.100.56.155.112][.1724] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 172 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 169|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...170] [ip4][..udp] [.75.137.134.242][.6448] -> [..74.111.203.55][..427] + new: [...170] [ip4][..udp] [.75.137.134.242][.6448] -> [..74.111.203.55][..427] detected: [...170] [ip4][..udp] [.75.137.134.242][.6448] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...169] [ip4][..udp] [.227.134.81.212][10457] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 173 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 170|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...171] [ip4][..udp] [..91.33.106.218][.2534] -> [..165.144.84.62][..427] + new: [...171] [ip4][..udp] [..91.33.106.218][.2534] -> [..165.144.84.62][..427] detected: [...171] [ip4][..udp] [..91.33.106.218][.2534] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...170] [ip4][..udp] [.75.137.134.242][.6448] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 174 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 171|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...172] [ip4][..udp] [.34.119.122.126][.6239] -> [...85.111.52.57][..427] + new: [...172] [ip4][..udp] [.34.119.122.126][.6239] -> [...85.111.52.57][..427] detected: [...172] [ip4][..udp] [.34.119.122.126][.6239] -> [...85.111.52.57][..427] [Service_Location_Protocol][Google][RPC][Acceptable] idle: [...171] [ip4][..udp] [..91.33.106.218][.2534] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 175 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 172|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...173] [ip4][..udp] [..46.100.97.147][52664] -> [.165.114.202.61][..427] + new: [...173] [ip4][..udp] [..46.100.97.147][52664] -> [.165.114.202.61][..427] detected: [...173] [ip4][..udp] [..46.100.97.147][52664] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...172] [ip4][..udp] [.34.119.122.126][.6239] -> [...85.111.52.57][..427] [Service_Location_Protocol][Google][RPC][Acceptable] DAEMON-EVENT: [Processed: 176 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 173|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...174] [ip4][..udp] [...81.24.43.106][48098] -> [..90.145.180.58][..427] + new: [...174] [ip4][..udp] [...81.24.43.106][48098] -> [..90.145.180.58][..427] detected: [...174] [ip4][..udp] [...81.24.43.106][48098] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...173] [ip4][..udp] [..46.100.97.147][52664] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 177 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 174|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...175] [ip4][..udp] [...81.24.43.106][43525] -> [.165.114.202.61][..427] + new: [...175] [ip4][..udp] [...81.24.43.106][43525] -> [.165.114.202.61][..427] detected: [...175] [ip4][..udp] [...81.24.43.106][43525] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...174] [ip4][..udp] [...81.24.43.106][48098] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 178 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 175|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...176] [ip4][..udp] [...33.216.90.56][53342] -> [..90.147.171.51][..427] + new: [...176] [ip4][..udp] [...33.216.90.56][53342] -> [..90.147.171.51][..427] detected: [...176] [ip4][..udp] [...33.216.90.56][53342] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...175] [ip4][..udp] [...81.24.43.106][43525] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...177] [ip4][..udp] [..161.47.199.37][50010] -> [.186.112.202.53][..427] + new: [...177] [ip4][..udp] [..161.47.199.37][50010] -> [.186.112.202.53][..427] detected: [...177] [ip4][..udp] [..161.47.199.37][50010] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...176] [ip4][..udp] [...33.216.90.56][53342] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 180 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 177|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...178] [ip4][..udp] [.93.102.124.112][41596] -> [..90.111.212.50][..427] + new: [...178] [ip4][..udp] [.93.102.124.112][41596] -> [..90.111.212.50][..427] detected: [...178] [ip4][..udp] [.93.102.124.112][41596] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...177] [ip4][..udp] [..161.47.199.37][50010] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 181 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 178|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 32] - new: [...179] [ip4][..udp] [.119.34.147.222][56878] -> [..90.145.180.58][..427] + new: [...179] [ip4][..udp] [.119.34.147.222][56878] -> [..90.145.180.58][..427] detected: [...179] [ip4][..udp] [.119.34.147.222][56878] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...178] [ip4][..udp] [.93.102.124.112][41596] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...180] [ip4][..udp] [249.149.111.219][57636] -> [...90.141.37.56][..427] + new: [...180] [ip4][..udp] [249.149.111.219][57636] -> [...90.141.37.56][..427] detected: [...180] [ip4][..udp] [249.149.111.219][57636] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...179] [ip4][..udp] [.119.34.147.222][56878] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...181] [ip4][..udp] [118.158.148.196][44102] -> [.165.114.202.61][..427] + new: [...181] [ip4][..udp] [118.158.148.196][44102] -> [.165.114.202.61][..427] detected: [...181] [ip4][..udp] [118.158.148.196][44102] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...182] [ip4][..udp] [134.217.184.242][23876] -> [...85.111.52.57][..427] + new: [...182] [ip4][..udp] [134.217.184.242][23876] -> [...85.111.52.57][..427] detected: [...182] [ip4][..udp] [134.217.184.242][23876] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...180] [ip4][..udp] [249.149.111.219][57636] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...181] [ip4][..udp] [118.158.148.196][44102] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...183] [ip4][..udp] [..185.97.76.211][42268] -> [..69.109.187.54][..427] + new: [...183] [ip4][..udp] [..185.97.76.211][42268] -> [..69.109.187.54][..427] detected: [...183] [ip4][..udp] [..185.97.76.211][42268] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...181] [ip4][..udp] [118.158.148.196][44102] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...182] [ip4][..udp] [134.217.184.242][23876] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 186 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 183|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...184] [ip4][..udp] [.71.170.115.245][44124] -> [..74.111.203.55][..427] + new: [...184] [ip4][..udp] [.71.170.115.245][44124] -> [..74.111.203.55][..427] detected: [...184] [ip4][..udp] [.71.170.115.245][44124] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...183] [ip4][..udp] [..185.97.76.211][42268] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...182] [ip4][..udp] [134.217.184.242][23876] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...185] [ip4][..udp] [.198.153.87.225][34996] -> [..165.144.84.62][..427] + new: [...185] [ip4][..udp] [.198.153.87.225][34996] -> [..165.144.84.62][..427] detected: [...185] [ip4][..udp] [.198.153.87.225][34996] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...184] [ip4][..udp] [.71.170.115.245][44124] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...186] [ip4][..udp] [.71.170.115.245][44124] -> [..90.111.212.50][..427] + new: [...186] [ip4][..udp] [.71.170.115.245][44124] -> [..90.111.212.50][..427] detected: [...186] [ip4][..udp] [.71.170.115.245][44124] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...185] [ip4][..udp] [.198.153.87.225][34996] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...187] [ip4][..udp] [134.217.184.242][41215] -> [..90.147.171.51][..427] + new: [...187] [ip4][..udp] [134.217.184.242][41215] -> [..90.147.171.51][..427] detected: [...187] [ip4][..udp] [134.217.184.242][41215] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 190 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 187|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...188] [ip4][..udp] [..56.82.128.250][53705] -> [.186.112.202.53][..427] + new: [...188] [ip4][..udp] [..56.82.128.250][53705] -> [.186.112.202.53][..427] detected: [...188] [ip4][..udp] [..56.82.128.250][53705] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...187] [ip4][..udp] [134.217.184.242][41215] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...186] [ip4][..udp] [.71.170.115.245][44124] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 191 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 188|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...189] [ip4][..udp] [.218.211.196.58][52158] -> [...85.111.52.57][..427] + new: [...189] [ip4][..udp] [.218.211.196.58][52158] -> [...85.111.52.57][..427] detected: [...189] [ip4][..udp] [.218.211.196.58][52158] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...188] [ip4][..udp] [..56.82.128.250][53705] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 192 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 189|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...190] [ip4][..udp] [236.131.162.157][34095] -> [..90.147.171.51][..427] + new: [...190] [ip4][..udp] [236.131.162.157][34095] -> [..90.147.171.51][..427] detected: [...190] [ip4][..udp] [236.131.162.157][34095] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...189] [ip4][..udp] [.218.211.196.58][52158] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 193 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 190|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...191] [ip4][..udp] [.177.48.184.247][56640] -> [.165.114.202.61][..427] + new: [...191] [ip4][..udp] [.177.48.184.247][56640] -> [.165.114.202.61][..427] detected: [...191] [ip4][..udp] [.177.48.184.247][56640] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...190] [ip4][..udp] [236.131.162.157][34095] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 194 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 191|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...192] [ip4][..udp] [..69.36.231.230][53489] -> [..90.111.212.50][..427] + new: [...192] [ip4][..udp] [..69.36.231.230][53489] -> [..90.111.212.50][..427] detected: [...192] [ip4][..udp] [..69.36.231.230][53489] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...191] [ip4][..udp] [.177.48.184.247][56640] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 195 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 192|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...193] [ip4][..udp] [...44.239.95.30][56105] -> [..74.111.203.55][..427] + new: [...193] [ip4][..udp] [...44.239.95.30][56105] -> [..74.111.203.55][..427] detected: [...193] [ip4][..udp] [...44.239.95.30][56105] -> [..74.111.203.55][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...192] [ip4][..udp] [..69.36.231.230][53489] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 196 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 193|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...194] [ip4][..udp] [....80.16.0.251][49389] -> [..165.144.84.62][..427] + new: [...194] [ip4][..udp] [....80.16.0.251][49389] -> [..165.144.84.62][..427] detected: [...194] [ip4][..udp] [....80.16.0.251][49389] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...193] [ip4][..udp] [...44.239.95.30][56105] -> [..74.111.203.55][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] DAEMON-EVENT: [Processed: 197 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 194|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...195] [ip4][..udp] [...165.37.39.94][49159] -> [..69.109.187.54][..427] + new: [...195] [ip4][..udp] [...165.37.39.94][49159] -> [..69.109.187.54][..427] detected: [...195] [ip4][..udp] [...165.37.39.94][49159] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...194] [ip4][..udp] [....80.16.0.251][49389] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 198 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 195|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...196] [ip4][..udp] [..178.14.64.233][55586] -> [...90.141.37.56][..427] + new: [...196] [ip4][..udp] [..178.14.64.233][55586] -> [...90.141.37.56][..427] detected: [...196] [ip4][..udp] [..178.14.64.233][55586] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...195] [ip4][..udp] [...165.37.39.94][49159] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 199 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 196|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...197] [ip4][..udp] [.200.31.144.158][47437] -> [.165.114.202.61][..427] + new: [...197] [ip4][..udp] [.200.31.144.158][47437] -> [.165.114.202.61][..427] detected: [...197] [ip4][..udp] [.200.31.144.158][47437] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...196] [ip4][..udp] [..178.14.64.233][55586] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 200 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 197|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...198] [ip4][..udp] [.200.31.144.158][44893] -> [..69.109.187.54][..427] + new: [...198] [ip4][..udp] [.200.31.144.158][44893] -> [..69.109.187.54][..427] detected: [...198] [ip4][..udp] [.200.31.144.158][44893] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...197] [ip4][..udp] [.200.31.144.158][47437] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...199] [ip4][..udp] [.200.31.144.158][46878] -> [...85.111.52.57][..427] + new: [...199] [ip4][..udp] [.200.31.144.158][46878] -> [...85.111.52.57][..427] detected: [...199] [ip4][..udp] [.200.31.144.158][46878] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...198] [ip4][..udp] [.200.31.144.158][44893] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 202 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 199|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...200] [ip4][..udp] [.200.31.144.158][39691] -> [..90.111.212.50][..427] + new: [...200] [ip4][..udp] [.200.31.144.158][39691] -> [..90.111.212.50][..427] detected: [...200] [ip4][..udp] [.200.31.144.158][39691] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...199] [ip4][..udp] [.200.31.144.158][46878] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 203 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 200|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...201] [ip4][..udp] [.200.31.144.158][59069] -> [..74.111.203.55][..427] + new: [...201] [ip4][..udp] [.200.31.144.158][59069] -> [..74.111.203.55][..427] detected: [...201] [ip4][..udp] [.200.31.144.158][59069] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...200] [ip4][..udp] [.200.31.144.158][39691] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...202] [ip4][..udp] [.200.31.144.158][51406] -> [..90.147.171.51][..427] + new: [...202] [ip4][..udp] [.200.31.144.158][51406] -> [..90.147.171.51][..427] detected: [...202] [ip4][..udp] [.200.31.144.158][51406] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...201] [ip4][..udp] [.200.31.144.158][59069] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 205 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 202|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 34] - new: [...203] [ip4][..udp] [.200.31.144.158][35296] -> [...90.141.37.56][..427] + new: [...203] [ip4][..udp] [.200.31.144.158][35296] -> [...90.141.37.56][..427] detected: [...203] [ip4][..udp] [.200.31.144.158][35296] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...202] [ip4][..udp] [.200.31.144.158][51406] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...204] [ip4][..udp] [.200.31.144.158][48172] -> [..90.145.180.58][..427] + new: [...204] [ip4][..udp] [.200.31.144.158][48172] -> [..90.145.180.58][..427] detected: [...204] [ip4][..udp] [.200.31.144.158][48172] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...202] [ip4][..udp] [.200.31.144.158][51406] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...203] [ip4][..udp] [.200.31.144.158][35296] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 207 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 204|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 36] - new: [...205] [ip4][..udp] [.200.31.144.158][53249] -> [..165.144.84.62][..427] + new: [...205] [ip4][..udp] [.200.31.144.158][53249] -> [..165.144.84.62][..427] detected: [...205] [ip4][..udp] [.200.31.144.158][53249] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...203] [ip4][..udp] [.200.31.144.158][35296] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...204] [ip4][..udp] [.200.31.144.158][48172] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 208 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 205|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 36] - new: [...206] [ip4][..udp] [..16.100.83.145][60232] -> [..90.147.171.51][..427] + new: [...206] [ip4][..udp] [..16.100.83.145][60232] -> [..90.147.171.51][..427] detected: [...206] [ip4][..udp] [..16.100.83.145][60232] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...205] [ip4][..udp] [.200.31.144.158][53249] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...207] [ip4][..udp] [184.180.168.240][36840] -> [.186.112.202.53][..427] + new: [...207] [ip4][..udp] [184.180.168.240][36840] -> [.186.112.202.53][..427] detected: [...207] [ip4][..udp] [184.180.168.240][36840] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...206] [ip4][..udp] [..16.100.83.145][60232] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...208] [ip4][..udp] [..16.99.147.146][34236] -> [..90.111.212.50][..427] + new: [...208] [ip4][..udp] [..16.99.147.146][34236] -> [..90.111.212.50][..427] detected: [...208] [ip4][..udp] [..16.99.147.146][34236] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...206] [ip4][..udp] [..16.100.83.145][60232] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...207] [ip4][..udp] [184.180.168.240][36840] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 211 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 208|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...209] [ip4][..udp] [182.180.120.139][53230] -> [..90.145.180.58][..427] + new: [...209] [ip4][..udp] [182.180.120.139][53230] -> [..90.145.180.58][..427] detected: [...209] [ip4][..udp] [182.180.120.139][53230] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...208] [ip4][..udp] [..16.99.147.146][34236] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 212 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 209|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...210] [ip4][..udp] [182.180.120.139][38609] -> [...90.141.37.56][..427] + new: [...210] [ip4][..udp] [182.180.120.139][38609] -> [...90.141.37.56][..427] detected: [...210] [ip4][..udp] [182.180.120.139][38609] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...209] [ip4][..udp] [182.180.120.139][53230] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 213 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 210|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...211] [ip4][..udp] [..19.99.147.148][36797] -> [.165.114.202.61][..427] + new: [...211] [ip4][..udp] [..19.99.147.148][36797] -> [.165.114.202.61][..427] detected: [...211] [ip4][..udp] [..19.99.147.148][36797] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...210] [ip4][..udp] [182.180.120.139][38609] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...212] [ip4][..udp] [.45.131.161.152][36751] -> [..165.144.84.62][..427] + new: [...212] [ip4][..udp] [.45.131.161.152][36751] -> [..165.144.84.62][..427] detected: [...212] [ip4][..udp] [.45.131.161.152][36751] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...211] [ip4][..udp] [..19.99.147.148][36797] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 215 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 212|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...213] [ip4][..udp] [.45.100.140.153][54538] -> [..74.111.203.55][..427] + new: [...213] [ip4][..udp] [.45.100.140.153][54538] -> [..74.111.203.55][..427] detected: [...213] [ip4][..udp] [.45.100.140.153][54538] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...212] [ip4][..udp] [.45.131.161.152][36751] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 216 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 213|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...214] [ip4][..udp] [.103.71.146.222][26355] -> [...90.141.37.56][..427] + new: [...214] [ip4][..udp] [.103.71.146.222][26355] -> [...90.141.37.56][..427] detected: [...214] [ip4][..udp] [.103.71.146.222][26355] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...213] [ip4][..udp] [.45.100.140.153][54538] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 217 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 214|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 37] - new: [...215] [ip4][..udp] [.103.71.146.222][64387] -> [..90.147.171.51][..427] + new: [...215] [ip4][..udp] [.103.71.146.222][64387] -> [..90.147.171.51][..427] detected: [...215] [ip4][..udp] [.103.71.146.222][64387] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...214] [ip4][..udp] [.103.71.146.222][26355] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...216] [ip4][..udp] [.100.56.155.112][53130] -> [..90.111.212.50][..427] + new: [...216] [ip4][..udp] [.100.56.155.112][53130] -> [..90.111.212.50][..427] detected: [...216] [ip4][..udp] [.100.56.155.112][53130] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...215] [ip4][..udp] [.103.71.146.222][64387] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 219 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 216|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 38] - new: [...217] [ip4][..udp] [...186.27.5.237][51315] -> [..90.147.171.51][..427] + new: [...217] [ip4][..udp] [...186.27.5.237][51315] -> [..90.147.171.51][..427] detected: [...217] [ip4][..udp] [...186.27.5.237][51315] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...215] [ip4][..udp] [.103.71.146.222][64387] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...216] [ip4][..udp] [.100.56.155.112][53130] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...218] [ip4][..udp] [..167.7.154.125][.8220] -> [...85.111.52.57][..427] + new: [...218] [ip4][..udp] [..167.7.154.125][.8220] -> [...85.111.52.57][..427] detected: [...218] [ip4][..udp] [..167.7.154.125][.8220] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...217] [ip4][..udp] [...186.27.5.237][51315] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 221 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 218|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...219] [ip4][..udp] [..46.100.97.147][59003] -> [...85.111.52.57][..427] + new: [...219] [ip4][..udp] [..46.100.97.147][59003] -> [...85.111.52.57][..427] detected: [...219] [ip4][..udp] [..46.100.97.147][59003] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...218] [ip4][..udp] [..167.7.154.125][.8220] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...217] [ip4][..udp] [...186.27.5.237][51315] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 222 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 219|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...220] [ip4][..udp] [..67.159.16.150][35493] -> [...90.141.37.56][..427] + new: [...220] [ip4][..udp] [..67.159.16.150][35493] -> [...90.141.37.56][..427] detected: [...220] [ip4][..udp] [..67.159.16.150][35493] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...219] [ip4][..udp] [..46.100.97.147][59003] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 223 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 220|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...221] [ip4][..udp] [..67.159.16.150][35856] -> [..69.109.187.54][..427] + new: [...221] [ip4][..udp] [..67.159.16.150][35856] -> [..69.109.187.54][..427] detected: [...221] [ip4][..udp] [..67.159.16.150][35856] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...220] [ip4][..udp] [..67.159.16.150][35493] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 224 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 221|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...222] [ip4][..udp] [....34.220.38.0][54720] -> [.186.112.202.53][..427] + new: [...222] [ip4][..udp] [....34.220.38.0][54720] -> [.186.112.202.53][..427] detected: [...222] [ip4][..udp] [....34.220.38.0][54720] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...221] [ip4][..udp] [..67.159.16.150][35856] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 225 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 222|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...223] [ip4][..udp] [..173.49.159.50][54834] -> [..74.111.203.55][..427] + new: [...223] [ip4][..udp] [..173.49.159.50][54834] -> [..74.111.203.55][..427] detected: [...223] [ip4][..udp] [..173.49.159.50][54834] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...222] [ip4][..udp] [....34.220.38.0][54720] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] DAEMON-EVENT: [Processed: 226 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 223|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...224] [ip4][..udp] [.206.17.216.171][53625] -> [..69.109.187.54][..427] + new: [...224] [ip4][..udp] [.206.17.216.171][53625] -> [..69.109.187.54][..427] detected: [...224] [ip4][..udp] [.206.17.216.171][53625] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...223] [ip4][..udp] [..173.49.159.50][54834] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 227 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 224|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...225] [ip4][..udp] [..64.56.203.178][42341] -> [..74.111.203.55][..427] + new: [...225] [ip4][..udp] [..64.56.203.178][42341] -> [..74.111.203.55][..427] detected: [...225] [ip4][..udp] [..64.56.203.178][42341] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...224] [ip4][..udp] [.206.17.216.171][53625] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 228 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 225|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 39] - new: [...226] [ip4][..udp] [..166.70.59.181][46093] -> [..90.111.212.50][..427] + new: [...226] [ip4][..udp] [..166.70.59.181][46093] -> [..90.111.212.50][..427] detected: [...226] [ip4][..udp] [..166.70.59.181][46093] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...225] [ip4][..udp] [..64.56.203.178][42341] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...227] [ip4][..udp] [167.185.203.175][.8162] -> [..165.144.84.62][..427] + new: [...227] [ip4][..udp] [167.185.203.175][.8162] -> [..165.144.84.62][..427] detected: [...227] [ip4][..udp] [167.185.203.175][.8162] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...226] [ip4][..udp] [..166.70.59.181][46093] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...228] [ip4][..udp] [...33.26.187.87][52761] -> [...90.141.37.56][..427] + new: [...228] [ip4][..udp] [...33.26.187.87][52761] -> [...90.141.37.56][..427] detected: [...228] [ip4][..udp] [...33.26.187.87][52761] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...226] [ip4][..udp] [..166.70.59.181][46093] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...227] [ip4][..udp] [167.185.203.175][.8162] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...229] [ip4][..udp] [.88.192.213.176][63574] -> [.165.114.202.61][..427] + new: [...229] [ip4][..udp] [.88.192.213.176][63574] -> [.165.114.202.61][..427] detected: [...229] [ip4][..udp] [.88.192.213.176][63574] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...227] [ip4][..udp] [167.185.203.175][.8162] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...228] [ip4][..udp] [...33.26.187.87][52761] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...230] [ip4][..udp] [184.199.219.188][30639] -> [...90.141.37.56][..427] + new: [...230] [ip4][..udp] [184.199.219.188][30639] -> [...90.141.37.56][..427] detected: [...230] [ip4][..udp] [184.199.219.188][30639] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...229] [ip4][..udp] [.88.192.213.176][63574] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...228] [ip4][..udp] [...33.26.187.87][52761] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 233 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 230|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 42] - new: [...231] [ip4][..udp] [166.199.219.182][28881] -> [..69.109.187.54][..427] + new: [...231] [ip4][..udp] [166.199.219.182][28881] -> [..69.109.187.54][..427] detected: [...231] [ip4][..udp] [166.199.219.182][28881] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...230] [ip4][..udp] [184.199.219.188][30639] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 234 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 231|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...232] [ip4][..udp] [..95.64.196.186][18841] -> [.186.112.202.53][..427] + new: [...232] [ip4][..udp] [..95.64.196.186][18841] -> [.186.112.202.53][..427] detected: [...232] [ip4][..udp] [..95.64.196.186][18841] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...230] [ip4][..udp] [184.199.219.188][30639] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...231] [ip4][..udp] [166.199.219.182][28881] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...233] [ip4][..udp] [..88.63.218.184][51027] -> [..90.145.180.58][..427] + new: [...233] [ip4][..udp] [..88.63.218.184][51027] -> [..90.145.180.58][..427] detected: [...233] [ip4][..udp] [..88.63.218.184][51027] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...232] [ip4][..udp] [..95.64.196.186][18841] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 236 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 233|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...234] [ip4][..udp] [...71.64.36.183][57381] -> [...85.111.52.57][..427] + new: [...234] [ip4][..udp] [...71.64.36.183][57381] -> [...85.111.52.57][..427] detected: [...234] [ip4][..udp] [...71.64.36.183][57381] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...233] [ip4][..udp] [..88.63.218.184][51027] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 237 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 234|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...235] [ip4][..udp] [165.211.188.239][50862] -> [.165.114.202.61][..427] + new: [...235] [ip4][..udp] [165.211.188.239][50862] -> [.165.114.202.61][..427] detected: [...235] [ip4][..udp] [165.211.188.239][50862] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...234] [ip4][..udp] [...71.64.36.183][57381] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 238 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 235|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...236] [ip4][..udp] [...31.0.154.114][31214] -> [...90.141.37.56][..427] + new: [...236] [ip4][..udp] [...31.0.154.114][31214] -> [...90.141.37.56][..427] detected: [...236] [ip4][..udp] [...31.0.154.114][31214] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...235] [ip4][..udp] [165.211.188.239][50862] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 239 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 236|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...237] [ip4][..udp] [.34.119.122.126][19055] -> [..165.144.84.62][..427] + new: [...237] [ip4][..udp] [.34.119.122.126][19055] -> [..165.144.84.62][..427] detected: [...237] [ip4][..udp] [.34.119.122.126][19055] -> [..165.144.84.62][..427] [Service_Location_Protocol][Google][RPC][Acceptable] idle: [...236] [ip4][..udp] [...31.0.154.114][31214] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...238] [ip4][..udp] [..89.214.56.129][50635] -> [...85.111.52.57][..427] + new: [...238] [ip4][..udp] [..89.214.56.129][50635] -> [...85.111.52.57][..427] detected: [...238] [ip4][..udp] [..89.214.56.129][50635] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...237] [ip4][..udp] [.34.119.122.126][19055] -> [..165.144.84.62][..427] [Service_Location_Protocol][Google][RPC][Acceptable] DAEMON-EVENT: [Processed: 241 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 238|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...239] [ip4][..udp] [..193.209.38.96][56783] -> [..90.111.212.50][..427] + new: [...239] [ip4][..udp] [..193.209.38.96][56783] -> [..90.111.212.50][..427] detected: [...239] [ip4][..udp] [..193.209.38.96][56783] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...238] [ip4][..udp] [..89.214.56.129][50635] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 242 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 239|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...240] [ip4][..udp] [..34.16.223.107][49482] -> [..165.144.84.62][..427] + new: [...240] [ip4][..udp] [..34.16.223.107][49482] -> [..165.144.84.62][..427] detected: [...240] [ip4][..udp] [..34.16.223.107][49482] -> [..165.144.84.62][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] idle: [...239] [ip4][..udp] [..193.209.38.96][56783] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 243 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 240|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...241] [ip4][..udp] [..235.96.127.30][30596] -> [..165.144.84.62][..427] + new: [...241] [ip4][..udp] [..235.96.127.30][30596] -> [..165.144.84.62][..427] detected: [...241] [ip4][..udp] [..235.96.127.30][30596] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...240] [ip4][..udp] [..34.16.223.107][49482] -> [..165.144.84.62][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] DAEMON-EVENT: [Processed: 245 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 241|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...242] [ip4][..udp] [...154.96.5.121][30879] -> [..74.111.203.55][..427] + new: [...242] [ip4][..udp] [...154.96.5.121][30879] -> [..74.111.203.55][..427] detected: [...242] [ip4][..udp] [...154.96.5.121][30879] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...241] [ip4][..udp] [..235.96.127.30][30596] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 246 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 242|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...243] [ip4][..udp] [208.123.176.154][53775] -> [...90.141.37.56][..427] + new: [...243] [ip4][..udp] [208.123.176.154][53775] -> [...90.141.37.56][..427] detected: [...243] [ip4][..udp] [208.123.176.154][53775] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...242] [ip4][..udp] [...154.96.5.121][30879] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 247 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 243|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...244] [ip4][..udp] [.236.131.82.145][40660] -> [..69.109.187.54][..427] + new: [...244] [ip4][..udp] [.236.131.82.145][40660] -> [..69.109.187.54][..427] detected: [...244] [ip4][..udp] [.236.131.82.145][40660] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...243] [ip4][..udp] [208.123.176.154][53775] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 248 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 244|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 43] - new: [...245] [ip4][..udp] [.19.156.188.155][47749] -> [..74.111.203.55][..427] + new: [...245] [ip4][..udp] [.19.156.188.155][47749] -> [..74.111.203.55][..427] detected: [...245] [ip4][..udp] [.19.156.188.155][47749] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...244] [ip4][..udp] [.236.131.82.145][40660] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...246] [ip4][..udp] [237.132.176.136][34418] -> [..165.144.84.62][..427] + new: [...246] [ip4][..udp] [237.132.176.136][34418] -> [..165.144.84.62][..427] detected: [...246] [ip4][..udp] [237.132.176.136][34418] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...245] [ip4][..udp] [.19.156.188.155][47749] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 250 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 246|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...247] [ip4][..udp] [.45.124.147.156][55189] -> [.165.114.202.61][..427] + new: [...247] [ip4][..udp] [.45.124.147.156][55189] -> [.165.114.202.61][..427] detected: [...247] [ip4][..udp] [.45.124.147.156][55189] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...246] [ip4][..udp] [237.132.176.136][34418] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...245] [ip4][..udp] [.19.156.188.155][47749] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 251 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 247|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...248] [ip4][..udp] [.70.180.111.241][37873] -> [..90.145.180.58][..427] + new: [...248] [ip4][..udp] [.70.180.111.241][37873] -> [..90.145.180.58][..427] detected: [...248] [ip4][..udp] [.70.180.111.241][37873] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...247] [ip4][..udp] [.45.124.147.156][55189] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 252 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 248|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...249] [ip4][..udp] [.47.123.177.154][50527] -> [..90.111.212.50][..427] + new: [...249] [ip4][..udp] [.47.123.177.154][50527] -> [..90.111.212.50][..427] detected: [...249] [ip4][..udp] [.47.123.177.154][50527] -> [..90.111.212.50][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [...248] [ip4][..udp] [.70.180.111.241][37873] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 253 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 249|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...250] [ip4][..udp] [.227.199.90.122][22596] -> [..74.111.203.55][..427] + new: [...250] [ip4][..udp] [.227.199.90.122][22596] -> [..74.111.203.55][..427] detected: [...250] [ip4][..udp] [.227.199.90.122][22596] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...249] [ip4][..udp] [.47.123.177.154][50527] -> [..90.111.212.50][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] DAEMON-EVENT: [Processed: 254 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 250|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...251] [ip4][..udp] [...161.45.5.172][56443] -> [..90.147.171.51][..427] + new: [...251] [ip4][..udp] [...161.45.5.172][56443] -> [..90.147.171.51][..427] detected: [...251] [ip4][..udp] [...161.45.5.172][56443] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...250] [ip4][..udp] [.227.199.90.122][22596] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 255 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 251|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...252] [ip4][..udp] [...66.24.225.77][55319] -> [...85.111.52.57][..427] + new: [...252] [ip4][..udp] [...66.24.225.77][55319] -> [...85.111.52.57][..427] detected: [...252] [ip4][..udp] [...66.24.225.77][55319] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...251] [ip4][..udp] [...161.45.5.172][56443] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 256 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 252|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...253] [ip4][..udp] [..88.56.155.126][14639] -> [.186.112.202.53][..427] + new: [...253] [ip4][..udp] [..88.56.155.126][14639] -> [.186.112.202.53][..427] detected: [...253] [ip4][..udp] [..88.56.155.126][14639] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...252] [ip4][..udp] [...66.24.225.77][55319] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 257 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 253|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...254] [ip4][..udp] [..35.252.69.113][15055] -> [..69.109.187.54][..427] + new: [...254] [ip4][..udp] [..35.252.69.113][15055] -> [..69.109.187.54][..427] detected: [...254] [ip4][..udp] [..35.252.69.113][15055] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...253] [ip4][..udp] [..88.56.155.126][14639] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 258 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 254|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 44] - new: [...255] [ip4][..udp] [...93.22.25.240][53557] -> [..165.144.84.62][..427] + new: [...255] [ip4][..udp] [...93.22.25.240][53557] -> [..165.144.84.62][..427] detected: [...255] [ip4][..udp] [...93.22.25.240][53557] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...254] [ip4][..udp] [..35.252.69.113][15055] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...256] [ip4][..udp] [..94.46.221.227][49978] -> [...90.141.37.56][..427] + new: [...256] [ip4][..udp] [..94.46.221.227][49978] -> [...90.141.37.56][..427] detected: [...256] [ip4][..udp] [..94.46.221.227][49978] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...255] [ip4][..udp] [...93.22.25.240][53557] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...257] [ip4][..udp] [..211.49.103.57][55377] -> [..69.109.187.54][..427] + new: [...257] [ip4][..udp] [..211.49.103.57][55377] -> [..69.109.187.54][..427] detected: [...257] [ip4][..udp] [..211.49.103.57][55377] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...256] [ip4][..udp] [..94.46.221.227][49978] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...255] [ip4][..udp] [...93.22.25.240][53557] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 261 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 257|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...258] [ip4][..udp] [..67.159.16.150][57227] -> [.186.112.202.53][..427] + new: [...258] [ip4][..udp] [..67.159.16.150][57227] -> [.186.112.202.53][..427] detected: [...258] [ip4][..udp] [..67.159.16.150][57227] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...257] [ip4][..udp] [..211.49.103.57][55377] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 262 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 258|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...259] [ip4][..udp] [..70.210.130.41][50379] -> [.186.112.202.53][..427] + new: [...259] [ip4][..udp] [..70.210.130.41][50379] -> [.186.112.202.53][..427] detected: [...259] [ip4][..udp] [..70.210.130.41][50379] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...258] [ip4][..udp] [..67.159.16.150][57227] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 263 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 259|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...260] [ip4][..udp] [.217.23.159.199][54694] -> [..74.111.203.55][..427] + new: [...260] [ip4][..udp] [.217.23.159.199][54694] -> [..74.111.203.55][..427] detected: [...260] [ip4][..udp] [.217.23.159.199][54694] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...259] [ip4][..udp] [..70.210.130.41][50379] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 264 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 260|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...261] [ip4][..udp] [208.243.248.212][54962] -> [.165.114.202.61][..427] + new: [...261] [ip4][..udp] [208.243.248.212][54962] -> [.165.114.202.61][..427] detected: [...261] [ip4][..udp] [208.243.248.212][54962] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...260] [ip4][..udp] [.217.23.159.199][54694] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 265 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 261|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...262] [ip4][..udp] [..42.224.153.12][15346] -> [..90.147.171.51][..427] + new: [...262] [ip4][..udp] [..42.224.153.12][15346] -> [..90.147.171.51][..427] detected: [...262] [ip4][..udp] [..42.224.153.12][15346] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...261] [ip4][..udp] [208.243.248.212][54962] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 267 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 262|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...263] [ip4][..udp] [199.221.139.233][45906] -> [..90.145.180.58][..427] + new: [...263] [ip4][..udp] [199.221.139.233][45906] -> [..90.145.180.58][..427] detected: [...263] [ip4][..udp] [199.221.139.233][45906] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...262] [ip4][..udp] [..42.224.153.12][15346] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...264] [ip4][..udp] [.246.237.99.253][12689] -> [..69.109.187.54][..427] + new: [...264] [ip4][..udp] [.246.237.99.253][12689] -> [..69.109.187.54][..427] detected: [...264] [ip4][..udp] [.246.237.99.253][12689] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...263] [ip4][..udp] [199.221.139.233][45906] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 269 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 264|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 45] - new: [...265] [ip4][..udp] [.247.45.112.206][20029] -> [..90.111.212.50][..427] + new: [...265] [ip4][..udp] [.247.45.112.206][20029] -> [..90.111.212.50][..427] detected: [...265] [ip4][..udp] [.247.45.112.206][20029] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...264] [ip4][..udp] [.246.237.99.253][12689] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...266] [ip4][..udp] [..56.174.92.201][12782] -> [.165.114.202.61][..427] + new: [...266] [ip4][..udp] [..56.174.92.201][12782] -> [.165.114.202.61][..427] detected: [...266] [ip4][..udp] [..56.174.92.201][12782] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...265] [ip4][..udp] [.247.45.112.206][20029] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...267] [ip4][..udp] [..70.38.107.241][.3833] -> [...85.111.52.57][..427] + new: [...267] [ip4][..udp] [..70.38.107.241][.3833] -> [...85.111.52.57][..427] detected: [...267] [ip4][..udp] [..70.38.107.241][.3833] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...266] [ip4][..udp] [..56.174.92.201][12782] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 272 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 267|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...268] [ip4][..udp] [..70.106.99.214][10633] -> [..74.111.203.55][..427] + new: [...268] [ip4][..udp] [..70.106.99.214][10633] -> [..74.111.203.55][..427] detected: [...268] [ip4][..udp] [..70.106.99.214][10633] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...266] [ip4][..udp] [..56.174.92.201][12782] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...267] [ip4][..udp] [..70.38.107.241][.3833] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...269] [ip4][..udp] [.246.237.99.253][28232] -> [..165.144.84.62][..427] + new: [...269] [ip4][..udp] [.246.237.99.253][28232] -> [..165.144.84.62][..427] detected: [...269] [ip4][..udp] [.246.237.99.253][28232] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...268] [ip4][..udp] [..70.106.99.214][10633] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 274 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 269|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...270] [ip4][..udp] [.200.29.108.217][55185] -> [...90.141.37.56][..427] + new: [...270] [ip4][..udp] [.200.29.108.217][55185] -> [...90.141.37.56][..427] detected: [...270] [ip4][..udp] [.200.29.108.217][55185] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...269] [ip4][..udp] [.246.237.99.253][28232] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 275 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 270|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...271] [ip4][..udp] [..67.159.16.150][48238] -> [...85.111.52.57][..427] + new: [...271] [ip4][..udp] [..67.159.16.150][48238] -> [...85.111.52.57][..427] detected: [...271] [ip4][..udp] [..67.159.16.150][48238] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...270] [ip4][..udp] [.200.29.108.217][55185] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 276 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 271|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...272] [ip4][..udp] [...35.0.100.115][24038] -> [..165.144.84.62][..427] + new: [...272] [ip4][..udp] [...35.0.100.115][24038] -> [..165.144.84.62][..427] detected: [...272] [ip4][..udp] [...35.0.100.115][24038] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...271] [ip4][..udp] [..67.159.16.150][48238] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 277 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 272|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...273] [ip4][..udp] [.91.255.107.116][29445] -> [.165.114.202.61][..427] + new: [...273] [ip4][..udp] [.91.255.107.116][29445] -> [.165.114.202.61][..427] detected: [...273] [ip4][..udp] [.91.255.107.116][29445] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...272] [ip4][..udp] [...35.0.100.115][24038] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...274] [ip4][..udp] [...98.137.3.114][.5334] -> [.165.114.202.61][..427] + new: [...274] [ip4][..udp] [...98.137.3.114][.5334] -> [.165.114.202.61][..427] detected: [...274] [ip4][..udp] [...98.137.3.114][.5334] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...273] [ip4][..udp] [.91.255.107.116][29445] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 279 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 274|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...275] [ip4][..udp] [.224.127.98.214][19171] -> [..90.147.171.51][..427] + new: [...275] [ip4][..udp] [.224.127.98.214][19171] -> [..90.147.171.51][..427] detected: [...275] [ip4][..udp] [.224.127.98.214][19171] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...274] [ip4][..udp] [...98.137.3.114][.5334] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 280 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 275|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...276] [ip4][..udp] [157.120.252.123][37363] -> [..90.145.180.58][..427] + new: [...276] [ip4][..udp] [157.120.252.123][37363] -> [..90.145.180.58][..427] detected: [...276] [ip4][..udp] [157.120.252.123][37363] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...275] [ip4][..udp] [.224.127.98.214][19171] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 281 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 276|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...277] [ip4][..udp] [.246.75.104.115][37519] -> [..90.145.180.58][..427] + new: [...277] [ip4][..udp] [.246.75.104.115][37519] -> [..90.145.180.58][..427] detected: [...277] [ip4][..udp] [.246.75.104.115][37519] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...276] [ip4][..udp] [157.120.252.123][37363] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 282 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 277|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...278] [ip4][..udp] [.236.155.96.147][47606] -> [..74.111.203.55][..427] + new: [...278] [ip4][..udp] [.236.155.96.147][47606] -> [..74.111.203.55][..427] detected: [...278] [ip4][..udp] [.236.155.96.147][47606] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...277] [ip4][..udp] [.246.75.104.115][37519] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 283 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 278|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...279] [ip4][..udp] [..45.99.146.146][32910] -> [..90.111.212.50][..427] + new: [...279] [ip4][..udp] [..45.99.146.146][32910] -> [..90.111.212.50][..427] detected: [...279] [ip4][..udp] [..45.99.146.146][32910] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...278] [ip4][..udp] [.236.155.96.147][47606] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 284 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 279|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 46] - new: [...280] [ip4][..udp] [200.180.144.114][52790] -> [.186.112.202.53][..427] + new: [...280] [ip4][..udp] [200.180.144.114][52790] -> [.186.112.202.53][..427] detected: [...280] [ip4][..udp] [200.180.144.114][52790] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...279] [ip4][..udp] [..45.99.146.146][32910] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...281] [ip4][..udp] [134.180.144.149][36409] -> [..69.109.187.54][..427] + new: [...281] [ip4][..udp] [134.180.144.149][36409] -> [..69.109.187.54][..427] detected: [...281] [ip4][..udp] [134.180.144.149][36409] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...280] [ip4][..udp] [200.180.144.114][52790] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...282] [ip4][..udp] [182.180.120.139][60621] -> [.165.114.202.61][..427] + new: [...282] [ip4][..udp] [182.180.120.139][60621] -> [.165.114.202.61][..427] detected: [...282] [ip4][..udp] [182.180.120.139][60621] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...281] [ip4][..udp] [134.180.144.149][36409] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...280] [ip4][..udp] [200.180.144.114][52790] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 287 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 282|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 47] - new: [...283] [ip4][..udp] [..45.99.146.146][60327] -> [..165.144.84.62][..427] + new: [...283] [ip4][..udp] [..45.99.146.146][60327] -> [..165.144.84.62][..427] detected: [...283] [ip4][..udp] [..45.99.146.146][60327] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...282] [ip4][..udp] [182.180.120.139][60621] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...284] [ip4][..udp] [200.180.144.114][56239] -> [...90.141.37.56][..427] + new: [...284] [ip4][..udp] [200.180.144.114][56239] -> [...90.141.37.56][..427] detected: [...284] [ip4][..udp] [200.180.144.114][56239] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...283] [ip4][..udp] [..45.99.146.146][60327] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 289 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 284|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 47] - new: [...285] [ip4][..udp] [.236.155.96.147][41408] -> [...85.111.52.57][..427] + new: [...285] [ip4][..udp] [.236.155.96.147][41408] -> [...85.111.52.57][..427] detected: [...285] [ip4][..udp] [.236.155.96.147][41408] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...284] [ip4][..udp] [200.180.144.114][56239] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 290 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 285|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 47] - new: [...286] [ip4][..udp] [162.219.248.180][51156] -> [..90.147.171.51][..427] + new: [...286] [ip4][..udp] [162.219.248.180][51156] -> [..90.147.171.51][..427] detected: [...286] [ip4][..udp] [162.219.248.180][51156] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...285] [ip4][..udp] [.236.155.96.147][41408] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 291 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 286|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 47] - new: [...287] [ip4][..udp] [.200.31.144.158][55455] -> [...85.111.52.57][..427] + new: [...287] [ip4][..udp] [.200.31.144.158][55455] -> [...85.111.52.57][..427] detected: [...287] [ip4][..udp] [.200.31.144.158][55455] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...286] [ip4][..udp] [162.219.248.180][51156] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...288] [ip4][..udp] [.200.31.144.158][50780] -> [.165.114.202.61][..427] + new: [...288] [ip4][..udp] [.200.31.144.158][50780] -> [.165.114.202.61][..427] detected: [...288] [ip4][..udp] [.200.31.144.158][50780] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...287] [ip4][..udp] [.200.31.144.158][55455] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 293 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 288|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 48] - new: [...289] [ip4][..udp] [.200.31.144.158][56478] -> [.186.112.202.53][..427] + new: [...289] [ip4][..udp] [.200.31.144.158][56478] -> [.186.112.202.53][..427] detected: [...289] [ip4][..udp] [.200.31.144.158][56478] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...287] [ip4][..udp] [.200.31.144.158][55455] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...288] [ip4][..udp] [.200.31.144.158][50780] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 294 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 289|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 48] - new: [...290] [ip4][..udp] [.200.31.144.158][48895] -> [..165.144.84.62][..427] + new: [...290] [ip4][..udp] [.200.31.144.158][48895] -> [..165.144.84.62][..427] detected: [...290] [ip4][..udp] [.200.31.144.158][48895] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...289] [ip4][..udp] [.200.31.144.158][56478] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...291] [ip4][..udp] [.200.31.144.158][37856] -> [..69.109.187.54][..427] + new: [...291] [ip4][..udp] [.200.31.144.158][37856] -> [..69.109.187.54][..427] detected: [...291] [ip4][..udp] [.200.31.144.158][37856] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...290] [ip4][..udp] [.200.31.144.158][48895] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...292] [ip4][..udp] [212.154.223.103][55839] -> [...90.141.37.56][..427] + new: [...292] [ip4][..udp] [212.154.223.103][55839] -> [...90.141.37.56][..427] detected: [...292] [ip4][..udp] [212.154.223.103][55839] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...290] [ip4][..udp] [.200.31.144.158][48895] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...291] [ip4][..udp] [.200.31.144.158][37856] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 298 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 292|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 49] - new: [...293] [ip4][..udp] [.75.137.134.242][59307] -> [.165.114.202.61][..427] + new: [...293] [ip4][..udp] [.75.137.134.242][59307] -> [.165.114.202.61][..427] detected: [...293] [ip4][..udp] [.75.137.134.242][59307] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...292] [ip4][..udp] [212.154.223.103][55839] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...294] [ip4][..udp] [.200.31.144.158][53742] -> [...90.141.37.56][..427] + new: [...294] [ip4][..udp] [.200.31.144.158][53742] -> [...90.141.37.56][..427] detected: [...294] [ip4][..udp] [.200.31.144.158][53742] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...293] [ip4][..udp] [.75.137.134.242][59307] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 300 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 294|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 49] - new: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] + new: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] detected: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...294] [ip4][..udp] [.200.31.144.158][53742] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] + new: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] detected: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...297] [ip4][..udp] [.200.31.144.158][50776] -> [..90.111.212.50][..427] + new: [...297] [ip4][..udp] [.200.31.144.158][50776] -> [..90.111.212.50][..427] detected: [...297] [ip4][..udp] [.200.31.144.158][50776] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...298] [ip4][..udp] [.200.31.144.158][49681] -> [..90.145.180.58][..427] + new: [...298] [ip4][..udp] [.200.31.144.158][49681] -> [..90.145.180.58][..427] detected: [...298] [ip4][..udp] [.200.31.144.158][49681] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...295] [ip4][..udp] [.200.31.144.158][33892] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...297] [ip4][..udp] [.200.31.144.158][50776] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...299] [ip4][..udp] [.200.31.144.158][36077] -> [..74.111.203.55][..427] + new: [...299] [ip4][..udp] [.200.31.144.158][36077] -> [..74.111.203.55][..427] detected: [...299] [ip4][..udp] [.200.31.144.158][36077] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...296] [ip4][..udp] [.197.23.155.213][51534] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...298] [ip4][..udp] [.200.31.144.158][49681] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...297] [ip4][..udp] [.200.31.144.158][50776] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 305 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 299|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...300] [ip4][..udp] [.66.224.226.183][52476] -> [..165.144.84.62][..427] + new: [...300] [ip4][..udp] [.66.224.226.183][52476] -> [..165.144.84.62][..427] detected: [...300] [ip4][..udp] [.66.224.226.183][52476] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...299] [ip4][..udp] [.200.31.144.158][36077] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 306 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 300|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...301] [ip4][..udp] [..91.33.106.218][59902] -> [..69.109.187.54][..427] + new: [...301] [ip4][..udp] [..91.33.106.218][59902] -> [..69.109.187.54][..427] detected: [...301] [ip4][..udp] [..91.33.106.218][59902] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...300] [ip4][..udp] [.66.224.226.183][52476] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 307 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 301|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...302] [ip4][..udp] [..206.204.24.90][50356] -> [...85.111.52.57][..427] + new: [...302] [ip4][..udp] [..206.204.24.90][50356] -> [...85.111.52.57][..427] detected: [...302] [ip4][..udp] [..206.204.24.90][50356] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...301] [ip4][..udp] [..91.33.106.218][59902] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 308 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 302|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...303] [ip4][..udp] [..76.45.103.228][55007] -> [..90.111.212.50][..427] + new: [...303] [ip4][..udp] [..76.45.103.228][55007] -> [..90.111.212.50][..427] detected: [...303] [ip4][..udp] [..76.45.103.228][55007] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...302] [ip4][..udp] [..206.204.24.90][50356] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...304] [ip4][..udp] [218.118.131.113][.8622] -> [.186.112.202.53][..427] + new: [...304] [ip4][..udp] [218.118.131.113][.8622] -> [.186.112.202.53][..427] detected: [...304] [ip4][..udp] [218.118.131.113][.8622] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...303] [ip4][..udp] [..76.45.103.228][55007] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 310 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 304|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...305] [ip4][..udp] [.189.229.250.75][50111] -> [.165.114.202.61][..427] + new: [...305] [ip4][..udp] [.189.229.250.75][50111] -> [.165.114.202.61][..427] detected: [...305] [ip4][..udp] [.189.229.250.75][50111] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...304] [ip4][..udp] [218.118.131.113][.8622] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 311 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 305|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...306] [ip4][..udp] [165.128.253.116][21256] -> [..69.109.187.54][..427] + new: [...306] [ip4][..udp] [165.128.253.116][21256] -> [..69.109.187.54][..427] detected: [...306] [ip4][..udp] [165.128.253.116][21256] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...305] [ip4][..udp] [.189.229.250.75][50111] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 312 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 306|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...307] [ip4][..udp] [..94.230.158.79][55750] -> [..74.111.203.55][..427] + new: [...307] [ip4][..udp] [..94.230.158.79][55750] -> [..74.111.203.55][..427] detected: [...307] [ip4][..udp] [..94.230.158.79][55750] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...306] [ip4][..udp] [165.128.253.116][21256] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...308] [ip4][..udp] [..35.252.69.113][37602] -> [..90.145.180.58][..427] + new: [...308] [ip4][..udp] [..35.252.69.113][37602] -> [..90.145.180.58][..427] detected: [...308] [ip4][..udp] [..35.252.69.113][37602] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...307] [ip4][..udp] [..94.230.158.79][55750] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 314 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 308|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...309] [ip4][..udp] [152.255.170.124][46606] -> [..90.147.171.51][..427] + new: [...309] [ip4][..udp] [152.255.170.124][46606] -> [..90.147.171.51][..427] detected: [...309] [ip4][..udp] [152.255.170.124][46606] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...308] [ip4][..udp] [..35.252.69.113][37602] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 315 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 309|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...310] [ip4][..udp] [..67.159.16.150][54818] -> [.165.114.202.61][..427] + new: [...310] [ip4][..udp] [..67.159.16.150][54818] -> [.165.114.202.61][..427] detected: [...310] [ip4][..udp] [..67.159.16.150][54818] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...309] [ip4][..udp] [152.255.170.124][46606] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 316 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 310|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...311] [ip4][..udp] [...93.26.159.17][57065] -> [.186.112.202.53][..427] + new: [...311] [ip4][..udp] [...93.26.159.17][57065] -> [.186.112.202.53][..427] detected: [...311] [ip4][..udp] [...93.26.159.17][57065] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...310] [ip4][..udp] [..67.159.16.150][54818] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 317 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 311|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...312] [ip4][..udp] [.217.31.231.255][49891] -> [...90.141.37.56][..427] + new: [...312] [ip4][..udp] [.217.31.231.255][49891] -> [...90.141.37.56][..427] detected: [...312] [ip4][..udp] [.217.31.231.255][49891] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...311] [ip4][..udp] [...93.26.159.17][57065] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 318 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 312|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...313] [ip4][..udp] [..67.159.16.150][12620] -> [..165.144.84.62][..427] + new: [...313] [ip4][..udp] [..67.159.16.150][12620] -> [..165.144.84.62][..427] detected: [...313] [ip4][..udp] [..67.159.16.150][12620] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...312] [ip4][..udp] [.217.31.231.255][49891] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 319 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 313|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...314] [ip4][..udp] [.91.255.107.116][12480] -> [...85.111.52.57][..427] + new: [...314] [ip4][..udp] [.91.255.107.116][12480] -> [...85.111.52.57][..427] detected: [...314] [ip4][..udp] [.91.255.107.116][12480] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...313] [ip4][..udp] [..67.159.16.150][12620] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...315] [ip4][..udp] [175.239.255.217][53820] -> [..69.109.187.54][..427] + new: [...315] [ip4][..udp] [175.239.255.217][53820] -> [..69.109.187.54][..427] detected: [...315] [ip4][..udp] [175.239.255.217][53820] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...314] [ip4][..udp] [.91.255.107.116][12480] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 321 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 315|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...316] [ip4][..udp] [..67.159.16.150][53644] -> [..90.145.180.58][..427] + new: [...316] [ip4][..udp] [..67.159.16.150][53644] -> [..90.145.180.58][..427] detected: [...316] [ip4][..udp] [..67.159.16.150][53644] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...315] [ip4][..udp] [175.239.255.217][53820] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 322 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 316|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...317] [ip4][..udp] [..7.110.179.205][58317] -> [..165.144.84.62][..427] + new: [...317] [ip4][..udp] [..7.110.179.205][58317] -> [..165.144.84.62][..427] detected: [...317] [ip4][..udp] [..7.110.179.205][58317] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...316] [ip4][..udp] [..67.159.16.150][53644] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 323 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 317|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 54] - new: [...318] [ip4][..udp] [201.237.135.210][37975] -> [.165.114.202.61][..427] + new: [...318] [ip4][..udp] [201.237.135.210][37975] -> [.165.114.202.61][..427] detected: [...318] [ip4][..udp] [201.237.135.210][37975] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...317] [ip4][..udp] [..7.110.179.205][58317] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...319] [ip4][..udp] [.57.162.128.234][63808] -> [...85.111.52.57][..427] + new: [...319] [ip4][..udp] [.57.162.128.234][63808] -> [...85.111.52.57][..427] detected: [...319] [ip4][..udp] [.57.162.128.234][63808] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...318] [ip4][..udp] [201.237.135.210][37975] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 325 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 319|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...320] [ip4][..udp] [..120.46.80.212][60012] -> [..74.111.203.55][..427] + new: [...320] [ip4][..udp] [..120.46.80.212][60012] -> [..74.111.203.55][..427] detected: [...320] [ip4][..udp] [..120.46.80.212][60012] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...319] [ip4][..udp] [.57.162.128.234][63808] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...318] [ip4][..udp] [201.237.135.210][37975] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 326 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 320|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...321] [ip4][..udp] [.57.162.128.234][48188] -> [..69.109.187.54][..427] + new: [...321] [ip4][..udp] [.57.162.128.234][48188] -> [..69.109.187.54][..427] detected: [...321] [ip4][..udp] [.57.162.128.234][48188] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...320] [ip4][..udp] [..120.46.80.212][60012] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...322] [ip4][..udp] [.57.162.128.234][19665] -> [...90.141.37.56][..427] + new: [...322] [ip4][..udp] [.57.162.128.234][19665] -> [...90.141.37.56][..427] detected: [...322] [ip4][..udp] [.57.162.128.234][19665] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...321] [ip4][..udp] [.57.162.128.234][48188] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 328 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 322|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...323] [ip4][..udp] [201.237.135.210][.6545] -> [..90.145.180.58][..427] + new: [...323] [ip4][..udp] [201.237.135.210][.6545] -> [..90.145.180.58][..427] detected: [...323] [ip4][..udp] [201.237.135.210][.6545] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...322] [ip4][..udp] [.57.162.128.234][19665] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...324] [ip4][..udp] [.247.93.183.197][10997] -> [..90.147.171.51][..427] + new: [...324] [ip4][..udp] [.247.93.183.197][10997] -> [..90.147.171.51][..427] detected: [...324] [ip4][..udp] [.247.93.183.197][10997] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...325] [ip4][..udp] [.247.93.183.197][.8213] -> [.186.112.202.53][..427] + new: [...325] [ip4][..udp] [.247.93.183.197][.8213] -> [.186.112.202.53][..427] detected: [...325] [ip4][..udp] [.247.93.183.197][.8213] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...323] [ip4][..udp] [201.237.135.210][.6545] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 331 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 325|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...326] [ip4][..udp] [....37.97.4.125][16072] -> [...90.141.37.56][..427] + new: [...326] [ip4][..udp] [....37.97.4.125][16072] -> [...90.141.37.56][..427] detected: [...326] [ip4][..udp] [....37.97.4.125][16072] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...325] [ip4][..udp] [.247.93.183.197][.8213] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...324] [ip4][..udp] [.247.93.183.197][10997] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 332 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 326|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...327] [ip4][..udp] [.246.75.104.115][34761] -> [...85.111.52.57][..427] + new: [...327] [ip4][..udp] [.246.75.104.115][34761] -> [...85.111.52.57][..427] detected: [...327] [ip4][..udp] [.246.75.104.115][34761] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...326] [ip4][..udp] [....37.97.4.125][16072] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 333 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 327|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...328] [ip4][..udp] [182.180.120.139][51620] -> [...90.141.37.56][..427] + new: [...328] [ip4][..udp] [182.180.120.139][51620] -> [...90.141.37.56][..427] detected: [...328] [ip4][..udp] [182.180.120.139][51620] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...327] [ip4][..udp] [.246.75.104.115][34761] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 334 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 328|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...329] [ip4][..udp] [..19.99.146.156][41843] -> [..90.145.180.58][..427] + new: [...329] [ip4][..udp] [..19.99.146.156][41843] -> [..90.145.180.58][..427] detected: [...329] [ip4][..udp] [..19.99.146.156][41843] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...328] [ip4][..udp] [182.180.120.139][51620] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...330] [ip4][..udp] [.98.103.253.115][29266] -> [..90.111.212.50][..427] + new: [...330] [ip4][..udp] [.98.103.253.115][29266] -> [..90.111.212.50][..427] detected: [...330] [ip4][..udp] [.98.103.253.115][29266] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 336 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 330|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...331] [ip4][..udp] [200.180.144.114][34997] -> [..90.111.212.50][..427] + new: [...331] [ip4][..udp] [200.180.144.114][34997] -> [..90.111.212.50][..427] detected: [...331] [ip4][..udp] [200.180.144.114][34997] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...329] [ip4][..udp] [..19.99.146.156][41843] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...330] [ip4][..udp] [.98.103.253.115][29266] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 337 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 331|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...332] [ip4][..udp] [200.180.144.114][32881] -> [..90.147.171.51][..427] + new: [...332] [ip4][..udp] [200.180.144.114][32881] -> [..90.147.171.51][..427] detected: [...332] [ip4][..udp] [200.180.144.114][32881] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...331] [ip4][..udp] [200.180.144.114][34997] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 338 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 332|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...333] [ip4][..udp] [200.180.144.114][36679] -> [..165.144.84.62][..427] + new: [...333] [ip4][..udp] [200.180.144.114][36679] -> [..165.144.84.62][..427] detected: [...333] [ip4][..udp] [200.180.144.114][36679] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...332] [ip4][..udp] [200.180.144.114][32881] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 339 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 333|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...334] [ip4][..udp] [.19.156.188.155][50741] -> [.186.112.202.53][..427] + new: [...334] [ip4][..udp] [.19.156.188.155][50741] -> [.186.112.202.53][..427] detected: [...334] [ip4][..udp] [.19.156.188.155][50741] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...333] [ip4][..udp] [200.180.144.114][36679] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 340 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 334|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...335] [ip4][..udp] [134.180.144.149][52293] -> [..69.109.187.54][..427] + new: [...335] [ip4][..udp] [134.180.144.149][52293] -> [..69.109.187.54][..427] detected: [...335] [ip4][..udp] [134.180.144.149][52293] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...334] [ip4][..udp] [.19.156.188.155][50741] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...336] [ip4][..udp] [200.180.144.114][57184] -> [..74.111.203.55][..427] + new: [...336] [ip4][..udp] [200.180.144.114][57184] -> [..74.111.203.55][..427] detected: [...336] [ip4][..udp] [200.180.144.114][57184] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...335] [ip4][..udp] [134.180.144.149][52293] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 342 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 336|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...337] [ip4][..udp] [..46.100.97.147][54751] -> [.165.114.202.61][..427] + new: [...337] [ip4][..udp] [..46.100.97.147][54751] -> [.165.114.202.61][..427] detected: [...337] [ip4][..udp] [..46.100.97.147][54751] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...336] [ip4][..udp] [200.180.144.114][57184] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 343 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 337|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 55] - new: [...338] [ip4][..udp] [..199.17.16.175][58914] -> [..90.147.171.51][..427] + new: [...338] [ip4][..udp] [..199.17.16.175][58914] -> [..90.147.171.51][..427] detected: [...338] [ip4][..udp] [..199.17.16.175][58914] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...337] [ip4][..udp] [..46.100.97.147][54751] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...339] [ip4][..udp] [..199.17.16.175][58914] -> [.165.114.202.61][..427] + new: [...339] [ip4][..udp] [..199.17.16.175][58914] -> [.165.114.202.61][..427] detected: [...339] [ip4][..udp] [..199.17.16.175][58914] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...340] [ip4][..udp] [..199.17.16.175][58914] -> [..69.109.187.54][..427] + new: [...340] [ip4][..udp] [..199.17.16.175][58914] -> [..69.109.187.54][..427] detected: [...340] [ip4][..udp] [..199.17.16.175][58914] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...341] [ip4][..udp] [..199.17.16.175][58914] -> [.186.112.202.53][..427] + new: [...341] [ip4][..udp] [..199.17.16.175][58914] -> [.186.112.202.53][..427] detected: [...341] [ip4][..udp] [..199.17.16.175][58914] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...342] [ip4][..udp] [..199.17.16.175][58914] -> [..90.111.212.50][..427] + new: [...342] [ip4][..udp] [..199.17.16.175][58914] -> [..90.111.212.50][..427] detected: [...342] [ip4][..udp] [..199.17.16.175][58914] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...339] [ip4][..udp] [..199.17.16.175][58914] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...338] [ip4][..udp] [..199.17.16.175][58914] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 348 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 342|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...343] [ip4][..udp] [..198.215.2.104][55462] -> [.165.114.202.61][..427] + new: [...343] [ip4][..udp] [..198.215.2.104][55462] -> [.165.114.202.61][..427] detected: [...343] [ip4][..udp] [..198.215.2.104][55462] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...342] [ip4][..udp] [..199.17.16.175][58914] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...341] [ip4][..udp] [..199.17.16.175][58914] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...339] [ip4][..udp] [..199.17.16.175][58914] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...338] [ip4][..udp] [..199.17.16.175][58914] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...340] [ip4][..udp] [..199.17.16.175][58914] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...344] [ip4][..udp] [.27.134.169.220][54219] -> [.165.114.202.61][..427] + new: [...344] [ip4][..udp] [.27.134.169.220][54219] -> [.165.114.202.61][..427] detected: [...344] [ip4][..udp] [.27.134.169.220][54219] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...343] [ip4][..udp] [..198.215.2.104][55462] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 350 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 344|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...345] [ip4][..udp] [....80.16.56.40][49864] -> [..74.111.203.55][..427] + new: [...345] [ip4][..udp] [....80.16.56.40][49864] -> [..74.111.203.55][..427] detected: [...345] [ip4][..udp] [....80.16.56.40][49864] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...344] [ip4][..udp] [.27.134.169.220][54219] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 351 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 345|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...346] [ip4][..udp] [206.240.152.225][52955] -> [..90.145.180.58][..427] + new: [...346] [ip4][..udp] [206.240.152.225][52955] -> [..90.145.180.58][..427] detected: [...346] [ip4][..udp] [206.240.152.225][52955] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...345] [ip4][..udp] [....80.16.56.40][49864] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 352 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 346|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...347] [ip4][..udp] [.172.206.191.39][55684] -> [..165.144.84.62][..427] + new: [...347] [ip4][..udp] [.172.206.191.39][55684] -> [..165.144.84.62][..427] detected: [...347] [ip4][..udp] [.172.206.191.39][55684] -> [..165.144.84.62][..427] [Service_Location_Protocol][Azure][RPC][Acceptable] idle: [...346] [ip4][..udp] [206.240.152.225][52955] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 353 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 347|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...348] [ip4][..udp] [..175.206.31.84][52553] -> [..69.109.187.54][..427] + new: [...348] [ip4][..udp] [..175.206.31.84][52553] -> [..69.109.187.54][..427] detected: [...348] [ip4][..udp] [..175.206.31.84][52553] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...347] [ip4][..udp] [.172.206.191.39][55684] -> [..165.144.84.62][..427] [Service_Location_Protocol][Azure][RPC][Acceptable] DAEMON-EVENT: [Processed: 354 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 348|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...349] [ip4][..udp] [...80.51.127.74][54217] -> [...85.111.52.57][..427] + new: [...349] [ip4][..udp] [...80.51.127.74][54217] -> [...85.111.52.57][..427] detected: [...349] [ip4][..udp] [...80.51.127.74][54217] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...348] [ip4][..udp] [..175.206.31.84][52553] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 355 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 349|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...350] [ip4][..udp] [...198.23.89.28][51231] -> [.186.112.202.53][..427] + new: [...350] [ip4][..udp] [...198.23.89.28][51231] -> [.186.112.202.53][..427] detected: [...350] [ip4][..udp] [...198.23.89.28][51231] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...349] [ip4][..udp] [...80.51.127.74][54217] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 356 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 350|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...351] [ip4][..udp] [...98.137.3.114][25821] -> [..74.111.203.55][..427] + new: [...351] [ip4][..udp] [...98.137.3.114][25821] -> [..74.111.203.55][..427] detected: [...351] [ip4][..udp] [...98.137.3.114][25821] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...350] [ip4][..udp] [...198.23.89.28][51231] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...352] [ip4][..udp] [219.160.101.209][10322] -> [.186.112.202.53][..427] + new: [...352] [ip4][..udp] [219.160.101.209][10322] -> [.186.112.202.53][..427] detected: [...352] [ip4][..udp] [219.160.101.209][10322] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...351] [ip4][..udp] [...98.137.3.114][25821] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 358 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 352|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...353] [ip4][..udp] [161.231.128.245][50837] -> [...90.141.37.56][..427] + new: [...353] [ip4][..udp] [161.231.128.245][50837] -> [...90.141.37.56][..427] detected: [...353] [ip4][..udp] [161.231.128.245][50837] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...352] [ip4][..udp] [219.160.101.209][10322] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 359 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 353|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...354] [ip4][..udp] [..166.191.37.51][27637] -> [.165.114.202.61][..427] + new: [...354] [ip4][..udp] [..166.191.37.51][27637] -> [.165.114.202.61][..427] detected: [...354] [ip4][..udp] [..166.191.37.51][27637] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...355] [ip4][..udp] [...70.63.213.48][64393] -> [..90.147.171.51][..427] + new: [...355] [ip4][..udp] [...70.63.213.48][64393] -> [..90.147.171.51][..427] detected: [...355] [ip4][..udp] [...70.63.213.48][64393] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...353] [ip4][..udp] [161.231.128.245][50837] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 361 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 355|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 57] - new: [...356] [ip4][..udp] [..89.198.219.40][13087] -> [..69.109.187.54][..427] + new: [...356] [ip4][..udp] [..89.198.219.40][13087] -> [..69.109.187.54][..427] detected: [...356] [ip4][..udp] [..89.198.219.40][13087] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...355] [ip4][..udp] [...70.63.213.48][64393] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...354] [ip4][..udp] [..166.191.37.51][27637] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...357] [ip4][..udp] [..190.65.219.43][.9161] -> [..90.111.212.50][..427] + new: [...357] [ip4][..udp] [..190.65.219.43][.9161] -> [..90.111.212.50][..427] detected: [...357] [ip4][..udp] [..190.65.219.43][.9161] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...356] [ip4][..udp] [..89.198.219.40][13087] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...358] [ip4][..udp] [.191.198.219.36][43241] -> [...85.111.52.57][..427] + new: [...358] [ip4][..udp] [.191.198.219.36][43241] -> [...85.111.52.57][..427] detected: [...358] [ip4][..udp] [.191.198.219.36][43241] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...357] [ip4][..udp] [..190.65.219.43][.9161] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...359] [ip4][..udp] [..166.191.37.51][27637] -> [.186.112.202.53][..427] + new: [...359] [ip4][..udp] [..166.191.37.51][27637] -> [.186.112.202.53][..427] detected: [...359] [ip4][..udp] [..166.191.37.51][27637] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 365 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 359|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 58] - new: [...360] [ip4][..udp] [...94.70.203.49][.9065] -> [..74.111.203.55][..427] + new: [...360] [ip4][..udp] [...94.70.203.49][.9065] -> [..74.111.203.55][..427] detected: [...360] [ip4][..udp] [...94.70.203.49][.9065] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...358] [ip4][..udp] [.191.198.219.36][43241] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...359] [ip4][..udp] [..166.191.37.51][27637] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...357] [ip4][..udp] [..190.65.219.43][.9161] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...361] [ip4][..udp] [..166.191.37.51][27637] -> [..165.144.84.62][..427] + new: [...361] [ip4][..udp] [..166.191.37.51][27637] -> [..165.144.84.62][..427] detected: [...361] [ip4][..udp] [..166.191.37.51][27637] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...362] [ip4][..udp] [...166.65.42.37][37412] -> [...90.141.37.56][..427] + new: [...362] [ip4][..udp] [...166.65.42.37][37412] -> [...90.141.37.56][..427] detected: [...362] [ip4][..udp] [...166.65.42.37][37412] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...360] [ip4][..udp] [...94.70.203.49][.9065] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...363] [ip4][..udp] [...185.211.4.13][55127] -> [..90.111.212.50][..427] + new: [...363] [ip4][..udp] [...185.211.4.13][55127] -> [..90.111.212.50][..427] detected: [...363] [ip4][..udp] [...185.211.4.13][55127] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...362] [ip4][..udp] [...166.65.42.37][37412] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...361] [ip4][..udp] [..166.191.37.51][27637] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 369 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 363|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...364] [ip4][..udp] [.100.56.155.112][12751] -> [...90.141.37.56][..427] + new: [...364] [ip4][..udp] [.100.56.155.112][12751] -> [...90.141.37.56][..427] detected: [...364] [ip4][..udp] [.100.56.155.112][12751] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...362] [ip4][..udp] [...166.65.42.37][37412] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...363] [ip4][..udp] [...185.211.4.13][55127] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...361] [ip4][..udp] [..166.191.37.51][27637] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 370 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 364|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...365] [ip4][..udp] [.227.199.90.122][44046] -> [..90.111.212.50][..427] + new: [...365] [ip4][..udp] [.227.199.90.122][44046] -> [..90.111.212.50][..427] detected: [...365] [ip4][..udp] [.227.199.90.122][44046] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...364] [ip4][..udp] [.100.56.155.112][12751] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 371 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 365|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...366] [ip4][..udp] [200.180.144.114][47863] -> [..90.147.171.51][..427] + new: [...366] [ip4][..udp] [200.180.144.114][47863] -> [..90.147.171.51][..427] detected: [...366] [ip4][..udp] [200.180.144.114][47863] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...365] [ip4][..udp] [.227.199.90.122][44046] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 372 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 366|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...367] [ip4][..udp] [..19.99.146.156][32952] -> [..74.111.203.55][..427] + new: [...367] [ip4][..udp] [..19.99.146.156][32952] -> [..74.111.203.55][..427] detected: [...367] [ip4][..udp] [..19.99.146.156][32952] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...366] [ip4][..udp] [200.180.144.114][47863] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 373 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 367|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...368] [ip4][..udp] [209.124.163.157][55599] -> [..69.109.187.54][..427] + new: [...368] [ip4][..udp] [209.124.163.157][55599] -> [..69.109.187.54][..427] detected: [...368] [ip4][..udp] [209.124.163.157][55599] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...367] [ip4][..udp] [..19.99.146.156][32952] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 374 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 368|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...369] [ip4][..udp] [.227.134.81.212][54859] -> [..90.145.180.58][..427] + new: [...369] [ip4][..udp] [.227.134.81.212][54859] -> [..90.145.180.58][..427] detected: [...369] [ip4][..udp] [.227.134.81.212][54859] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...368] [ip4][..udp] [209.124.163.157][55599] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 375 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 369|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...370] [ip4][..udp] [.45.131.161.152][49844] -> [.186.112.202.53][..427] + new: [...370] [ip4][..udp] [.45.131.161.152][49844] -> [.186.112.202.53][..427] detected: [...370] [ip4][..udp] [.45.131.161.152][49844] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...369] [ip4][..udp] [.227.134.81.212][54859] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...371] [ip4][..udp] [134.180.144.149][49951] -> [..90.145.180.58][..427] + new: [...371] [ip4][..udp] [134.180.144.149][49951] -> [..90.145.180.58][..427] detected: [...371] [ip4][..udp] [134.180.144.149][49951] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...370] [ip4][..udp] [.45.131.161.152][49844] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 377 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 371|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...372] [ip4][..udp] [184.180.168.240][42561] -> [...85.111.52.57][..427] + new: [...372] [ip4][..udp] [184.180.168.240][42561] -> [...85.111.52.57][..427] detected: [...372] [ip4][..udp] [184.180.168.240][42561] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...371] [ip4][..udp] [134.180.144.149][49951] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...373] [ip4][..udp] [210.124.156.149][41895] -> [..165.144.84.62][..427] + new: [...373] [ip4][..udp] [210.124.156.149][41895] -> [..165.144.84.62][..427] detected: [...373] [ip4][..udp] [210.124.156.149][41895] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...372] [ip4][..udp] [184.180.168.240][42561] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 379 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 373|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...374] [ip4][..udp] [182.180.120.139][45313] -> [.165.114.202.61][..427] + new: [...374] [ip4][..udp] [182.180.120.139][45313] -> [.165.114.202.61][..427] detected: [...374] [ip4][..udp] [182.180.120.139][45313] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...373] [ip4][..udp] [210.124.156.149][41895] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...375] [ip4][..udp] [208.123.176.154][58457] -> [...90.141.37.56][..427] + new: [...375] [ip4][..udp] [208.123.176.154][58457] -> [...90.141.37.56][..427] detected: [...375] [ip4][..udp] [208.123.176.154][58457] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...374] [ip4][..udp] [182.180.120.139][45313] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 381 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 375|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...376] [ip4][..udp] [.27.134.169.220][38445] -> [...85.111.52.57][..427] + new: [...376] [ip4][..udp] [.27.134.169.220][38445] -> [...85.111.52.57][..427] detected: [...376] [ip4][..udp] [.27.134.169.220][38445] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...375] [ip4][..udp] [208.123.176.154][58457] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...377] [ip4][..udp] [239.100.141.153][47597] -> [..74.111.203.55][..427] + new: [...377] [ip4][..udp] [239.100.141.153][47597] -> [..74.111.203.55][..427] detected: [...377] [ip4][..udp] [239.100.141.153][47597] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...376] [ip4][..udp] [.27.134.169.220][38445] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 383 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 377|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...378] [ip4][..udp] [157.121.130.117][.7470] -> [..165.144.84.62][..427] + new: [...378] [ip4][..udp] [157.121.130.117][.7470] -> [..165.144.84.62][..427] detected: [...378] [ip4][..udp] [157.121.130.117][.7470] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...377] [ip4][..udp] [239.100.141.153][47597] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 384 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 378|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...379] [ip4][..udp] [.36.231.109.217][49319] -> [..90.111.212.50][..427] + new: [...379] [ip4][..udp] [.36.231.109.217][49319] -> [..90.111.212.50][..427] detected: [...379] [ip4][..udp] [.36.231.109.217][49319] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...378] [ip4][..udp] [157.121.130.117][.7470] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 385 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 379|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 60] - new: [...380] [ip4][..udp] [...209.44.167.7][53096] -> [..90.111.212.50][..427] + new: [...380] [ip4][..udp] [...209.44.167.7][53096] -> [..90.111.212.50][..427] detected: [...380] [ip4][..udp] [...209.44.167.7][53096] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...379] [ip4][..udp] [.36.231.109.217][49319] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...381] [ip4][..udp] [..99.199.77.211][45829] -> [..165.144.84.62][..427] + new: [...381] [ip4][..udp] [..99.199.77.211][45829] -> [..165.144.84.62][..427] detected: [...381] [ip4][..udp] [..99.199.77.211][45829] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...380] [ip4][..udp] [...209.44.167.7][53096] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 387 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 381|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 61] - new: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] + new: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] detected: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...381] [ip4][..udp] [..99.199.77.211][45829] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...380] [ip4][..udp] [...209.44.167.7][53096] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] + new: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] detected: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] + new: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] detected: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...385] [ip4][..udp] [.215.48.253.201][42457] -> [..90.147.171.51][..427] + new: [...385] [ip4][..udp] [.215.48.253.201][42457] -> [..90.147.171.51][..427] detected: [...385] [ip4][..udp] [.215.48.253.201][42457] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...386] [ip4][..udp] [.215.48.253.201][39194] -> [..69.109.187.54][..427] + new: [...386] [ip4][..udp] [.215.48.253.201][39194] -> [..69.109.187.54][..427] detected: [...386] [ip4][..udp] [.215.48.253.201][39194] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...387] [ip4][..udp] [.215.48.253.201][46653] -> [..90.145.180.58][..427] + new: [...387] [ip4][..udp] [.215.48.253.201][46653] -> [..90.145.180.58][..427] detected: [...387] [ip4][..udp] [.215.48.253.201][46653] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...388] [ip4][..udp] [.215.48.253.201][44352] -> [..165.144.84.62][..427] + new: [...388] [ip4][..udp] [.215.48.253.201][44352] -> [..165.144.84.62][..427] detected: [...388] [ip4][..udp] [.215.48.253.201][44352] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...389] [ip4][..udp] [.215.48.253.201][53506] -> [.165.114.202.61][..427] + new: [...389] [ip4][..udp] [.215.48.253.201][53506] -> [.165.114.202.61][..427] detected: [...389] [ip4][..udp] [.215.48.253.201][53506] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...388] [ip4][..udp] [.215.48.253.201][44352] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] @@ -1732,7 +1732,7 @@ update: [...385] [ip4][..udp] [.215.48.253.201][42457] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...390] [ip4][..udp] [.215.48.253.201][49672] -> [.186.112.202.53][..427] + new: [...390] [ip4][..udp] [.215.48.253.201][49672] -> [.186.112.202.53][..427] detected: [...390] [ip4][..udp] [.215.48.253.201][49672] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...382] [ip4][..udp] [.215.48.253.201][44733] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...383] [ip4][..udp] [.215.48.253.201][56846] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] @@ -1744,7 +1744,7 @@ update: [...389] [ip4][..udp] [.215.48.253.201][53506] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 396 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 390|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...391] [ip4][..udp] [..44.242.231.77][50261] -> [.186.112.202.53][..427] + new: [...391] [ip4][..udp] [..44.242.231.77][50261] -> [.186.112.202.53][..427] detected: [...391] [ip4][..udp] [..44.242.231.77][50261] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...388] [ip4][..udp] [.215.48.253.201][44352] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...386] [ip4][..udp] [.215.48.253.201][39194] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] @@ -1753,1023 +1753,1023 @@ idle: [...390] [ip4][..udp] [.215.48.253.201][49672] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...384] [ip4][..udp] [.215.48.253.201][50630] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...389] [ip4][..udp] [.215.48.253.201][53506] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...392] [ip4][..udp] [..37.234.100.32][56813] -> [..90.145.180.58][..427] + new: [...392] [ip4][..udp] [..37.234.100.32][56813] -> [..90.145.180.58][..427] detected: [...392] [ip4][..udp] [..37.234.100.32][56813] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...391] [ip4][..udp] [..44.242.231.77][50261] -> [.186.112.202.53][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] DAEMON-EVENT: [Processed: 398 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 392|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...393] [ip4][..udp] [.27.134.169.220][44054] -> [...90.141.37.56][..427] + new: [...393] [ip4][..udp] [.27.134.169.220][44054] -> [...90.141.37.56][..427] detected: [...393] [ip4][..udp] [.27.134.169.220][44054] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...392] [ip4][..udp] [..37.234.100.32][56813] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 399 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 393|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...394] [ip4][..udp] [..67.159.16.150][46249] -> [..74.111.203.55][..427] + new: [...394] [ip4][..udp] [..67.159.16.150][46249] -> [..74.111.203.55][..427] detected: [...394] [ip4][..udp] [..67.159.16.150][46249] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...393] [ip4][..udp] [.27.134.169.220][44054] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 400 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 394|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...395] [ip4][..udp] [.27.134.169.220][64251] -> [..74.111.203.55][..427] + new: [...395] [ip4][..udp] [.27.134.169.220][64251] -> [..74.111.203.55][..427] detected: [...395] [ip4][..udp] [.27.134.169.220][64251] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...394] [ip4][..udp] [..67.159.16.150][46249] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...396] [ip4][..udp] [....88.71.42.58][15464] -> [..165.144.84.62][..427] + new: [...396] [ip4][..udp] [....88.71.42.58][15464] -> [..165.144.84.62][..427] detected: [...396] [ip4][..udp] [....88.71.42.58][15464] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...395] [ip4][..udp] [.27.134.169.220][64251] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 402 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 396|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...397] [ip4][..udp] [..191.62.219.57][29227] -> [.186.112.202.53][..427] + new: [...397] [ip4][..udp] [..191.62.219.57][29227] -> [.186.112.202.53][..427] detected: [...397] [ip4][..udp] [..191.62.219.57][29227] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...396] [ip4][..udp] [....88.71.42.58][15464] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...398] [ip4][..udp] [...190.71.42.54][47364] -> [..69.109.187.54][..427] + new: [...398] [ip4][..udp] [...190.71.42.54][47364] -> [..69.109.187.54][..427] detected: [...398] [ip4][..udp] [...190.71.42.54][47364] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...397] [ip4][..udp] [..191.62.219.57][29227] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 404 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 398|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...399] [ip4][..udp] [..166.62.197.60][35606] -> [.165.114.202.61][..427] + new: [...399] [ip4][..udp] [..166.62.197.60][35606] -> [.165.114.202.61][..427] detected: [...399] [ip4][..udp] [..166.62.197.60][35606] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...398] [ip4][..udp] [...190.71.42.54][47364] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...400] [ip4][..udp] [..191.62.219.57][18685] -> [..90.111.212.50][..427] + new: [...400] [ip4][..udp] [..191.62.219.57][18685] -> [..90.111.212.50][..427] detected: [...400] [ip4][..udp] [..191.62.219.57][18685] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...399] [ip4][..udp] [..166.62.197.60][35606] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 406 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 400|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 78] - new: [...401] [ip4][..udp] [...88.70.212.56][65013] -> [...85.111.52.57][..427] + new: [...401] [ip4][..udp] [...88.70.212.56][65013] -> [...85.111.52.57][..427] detected: [...401] [ip4][..udp] [...88.70.212.56][65013] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...400] [ip4][..udp] [..191.62.219.57][18685] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...402] [ip4][..udp] [..184.199.42.59][42047] -> [...90.141.37.56][..427] + new: [...402] [ip4][..udp] [..184.199.42.59][42047] -> [...90.141.37.56][..427] detected: [...402] [ip4][..udp] [..184.199.42.59][42047] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...401] [ip4][..udp] [...88.70.212.56][65013] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...403] [ip4][..udp] [..161.199.58.19][64864] -> [..90.147.171.51][..427] + new: [...403] [ip4][..udp] [..161.199.58.19][64864] -> [..90.147.171.51][..427] detected: [...403] [ip4][..udp] [..161.199.58.19][64864] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...402] [ip4][..udp] [..184.199.42.59][42047] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...401] [ip4][..udp] [...88.70.212.56][65013] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 409 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 403|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 79] - new: [...404] [ip4][..udp] [..161.62.218.52][37093] -> [..74.111.203.55][..427] + new: [...404] [ip4][..udp] [..161.62.218.52][37093] -> [..74.111.203.55][..427] detected: [...404] [ip4][..udp] [..161.62.218.52][37093] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...403] [ip4][..udp] [..161.199.58.19][64864] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 410 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 404|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 79] - new: [...405] [ip4][..udp] [.194.43.223.106][55142] -> [.165.114.202.61][..427] + new: [...405] [ip4][..udp] [.194.43.223.106][55142] -> [.165.114.202.61][..427] detected: [...405] [ip4][..udp] [.194.43.223.106][55142] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...404] [ip4][..udp] [..161.62.218.52][37093] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 411 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 405|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 79] - new: [...406] [ip4][..udp] [226.158.252.127][33255] -> [...85.111.52.57][..427] + new: [...406] [ip4][..udp] [226.158.252.127][33255] -> [...85.111.52.57][..427] detected: [...406] [ip4][..udp] [226.158.252.127][33255] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...405] [ip4][..udp] [.194.43.223.106][55142] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 412 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 406|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 79] - new: [...407] [ip4][..udp] [.200.31.144.158][36149] -> [.186.112.202.53][..427] + new: [...407] [ip4][..udp] [.200.31.144.158][36149] -> [.186.112.202.53][..427] detected: [...407] [ip4][..udp] [.200.31.144.158][36149] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...406] [ip4][..udp] [226.158.252.127][33255] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 413 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 407|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 79] - new: [...408] [ip4][..udp] [.200.31.144.158][45294] -> [.165.114.202.61][..427] + new: [...408] [ip4][..udp] [.200.31.144.158][45294] -> [.165.114.202.61][..427] detected: [...408] [ip4][..udp] [.200.31.144.158][45294] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...407] [ip4][..udp] [.200.31.144.158][36149] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...409] [ip4][..udp] [.200.31.144.158][45056] -> [..90.145.180.58][..427] + new: [...409] [ip4][..udp] [.200.31.144.158][45056] -> [..90.145.180.58][..427] detected: [...409] [ip4][..udp] [.200.31.144.158][45056] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...408] [ip4][..udp] [.200.31.144.158][45294] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...410] [ip4][..udp] [.93.102.124.112][10968] -> [..90.147.171.51][..427] + new: [...410] [ip4][..udp] [.93.102.124.112][10968] -> [..90.147.171.51][..427] detected: [...410] [ip4][..udp] [.93.102.124.112][10968] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...409] [ip4][..udp] [.200.31.144.158][45056] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 416 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 410|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 80] - new: [...411] [ip4][..udp] [.200.31.144.158][54431] -> [...90.141.37.56][..427] + new: [...411] [ip4][..udp] [.200.31.144.158][54431] -> [...90.141.37.56][..427] detected: [...411] [ip4][..udp] [.200.31.144.158][54431] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...409] [ip4][..udp] [.200.31.144.158][45056] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...410] [ip4][..udp] [.93.102.124.112][10968] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...412] [ip4][..udp] [.200.31.144.158][59262] -> [..90.147.171.51][..427] + new: [...412] [ip4][..udp] [.200.31.144.158][59262] -> [..90.147.171.51][..427] detected: [...412] [ip4][..udp] [.200.31.144.158][59262] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...411] [ip4][..udp] [.200.31.144.158][54431] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...413] [ip4][..udp] [.200.31.144.158][51675] -> [..69.109.187.54][..427] + new: [...413] [ip4][..udp] [.200.31.144.158][51675] -> [..69.109.187.54][..427] detected: [...413] [ip4][..udp] [.200.31.144.158][51675] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...412] [ip4][..udp] [.200.31.144.158][59262] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 419 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 413|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...414] [ip4][..udp] [.174.237.64.176][49218] -> [...90.141.37.56][..427] + new: [...414] [ip4][..udp] [.174.237.64.176][49218] -> [...90.141.37.56][..427] detected: [...414] [ip4][..udp] [.174.237.64.176][49218] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...413] [ip4][..udp] [.200.31.144.158][51675] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...412] [ip4][..udp] [.200.31.144.158][59262] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...415] [ip4][..udp] [.200.31.144.158][57345] -> [..165.144.84.62][..427] + new: [...415] [ip4][..udp] [.200.31.144.158][57345] -> [..165.144.84.62][..427] detected: [...415] [ip4][..udp] [.200.31.144.158][57345] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...414] [ip4][..udp] [.174.237.64.176][49218] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...416] [ip4][..udp] [.200.31.144.158][57245] -> [...85.111.52.57][..427] + new: [...416] [ip4][..udp] [.200.31.144.158][57245] -> [...85.111.52.57][..427] detected: [...416] [ip4][..udp] [.200.31.144.158][57245] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 422 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 416|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...417] [ip4][..udp] [193.219.252.221][51650] -> [..90.147.171.51][..427] + new: [...417] [ip4][..udp] [193.219.252.221][51650] -> [..90.147.171.51][..427] detected: [...417] [ip4][..udp] [193.219.252.221][51650] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...416] [ip4][..udp] [.200.31.144.158][57245] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...415] [ip4][..udp] [.200.31.144.158][57345] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 423 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 417|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...418] [ip4][..udp] [.200.31.144.158][41180] -> [..74.111.203.55][..427] + new: [...418] [ip4][..udp] [.200.31.144.158][41180] -> [..74.111.203.55][..427] detected: [...418] [ip4][..udp] [.200.31.144.158][41180] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...417] [ip4][..udp] [193.219.252.221][51650] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 424 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 418|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...419] [ip4][..udp] [.200.31.144.158][40785] -> [..90.111.212.50][..427] + new: [...419] [ip4][..udp] [.200.31.144.158][40785] -> [..90.111.212.50][..427] detected: [...419] [ip4][..udp] [.200.31.144.158][40785] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...418] [ip4][..udp] [.200.31.144.158][41180] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 425 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 419|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...420] [ip4][..udp] [..174.18.32.224][53272] -> [..74.111.203.55][..427] + new: [...420] [ip4][..udp] [..174.18.32.224][53272] -> [..74.111.203.55][..427] detected: [...420] [ip4][..udp] [..174.18.32.224][53272] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...419] [ip4][..udp] [.200.31.144.158][40785] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...421] [ip4][..udp] [237.132.176.136][59095] -> [..69.109.187.54][..427] + new: [...421] [ip4][..udp] [237.132.176.136][59095] -> [..69.109.187.54][..427] detected: [...421] [ip4][..udp] [237.132.176.136][59095] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...420] [ip4][..udp] [..174.18.32.224][53272] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 427 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 421|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...422] [ip4][..udp] [...37.36.31.210][53791] -> [..165.144.84.62][..427] + new: [...422] [ip4][..udp] [...37.36.31.210][53791] -> [..165.144.84.62][..427] detected: [...422] [ip4][..udp] [...37.36.31.210][53791] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...421] [ip4][..udp] [237.132.176.136][59095] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 428 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 422|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...423] [ip4][..udp] [.91.255.107.116][34976] -> [...85.111.52.57][..427] + new: [...423] [ip4][..udp] [.91.255.107.116][34976] -> [...85.111.52.57][..427] detected: [...423] [ip4][..udp] [.91.255.107.116][34976] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...422] [ip4][..udp] [...37.36.31.210][53791] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 429 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 423|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...424] [ip4][..udp] [....47.51.0.222][53190] -> [..69.109.187.54][..427] + new: [...424] [ip4][..udp] [....47.51.0.222][53190] -> [..69.109.187.54][..427] detected: [...424] [ip4][..udp] [....47.51.0.222][53190] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...423] [ip4][..udp] [.91.255.107.116][34976] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 430 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 424|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...425] [ip4][..udp] [.238.156.97.151][35769] -> [..74.111.203.55][..427] + new: [...425] [ip4][..udp] [.238.156.97.151][35769] -> [..74.111.203.55][..427] detected: [...425] [ip4][..udp] [.238.156.97.151][35769] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...424] [ip4][..udp] [....47.51.0.222][53190] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...426] [ip4][..udp] [134.180.144.149][33745] -> [...85.111.52.57][..427] + new: [...426] [ip4][..udp] [134.180.144.149][33745] -> [...85.111.52.57][..427] detected: [...426] [ip4][..udp] [134.180.144.149][33745] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...425] [ip4][..udp] [.238.156.97.151][35769] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 432 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 426|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...427] [ip4][..udp] [.246.75.104.115][37012] -> [..90.147.171.51][..427] + new: [...427] [ip4][..udp] [.246.75.104.115][37012] -> [..90.147.171.51][..427] detected: [...427] [ip4][..udp] [.246.75.104.115][37012] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...426] [ip4][..udp] [134.180.144.149][33745] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 433 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 427|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...428] [ip4][..udp] [.70.180.111.241][54319] -> [.165.114.202.61][..427] + new: [...428] [ip4][..udp] [.70.180.111.241][54319] -> [.165.114.202.61][..427] detected: [...428] [ip4][..udp] [.70.180.111.241][54319] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...427] [ip4][..udp] [.246.75.104.115][37012] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 434 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 428|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...429] [ip4][..udp] [..19.99.146.156][59479] -> [..90.111.212.50][..427] + new: [...429] [ip4][..udp] [..19.99.146.156][59479] -> [..90.111.212.50][..427] detected: [...429] [ip4][..udp] [..19.99.146.156][59479] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...428] [ip4][..udp] [.70.180.111.241][54319] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...430] [ip4][..udp] [.246.75.104.115][46227] -> [..90.145.180.58][..427] + new: [...430] [ip4][..udp] [.246.75.104.115][46227] -> [..90.145.180.58][..427] detected: [...430] [ip4][..udp] [.246.75.104.115][46227] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...431] [ip4][..udp] [..227.7.178.223][16085] -> [..74.111.203.55][..427] + new: [...431] [ip4][..udp] [..227.7.178.223][16085] -> [..74.111.203.55][..427] detected: [...431] [ip4][..udp] [..227.7.178.223][16085] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...430] [ip4][..udp] [.246.75.104.115][46227] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...429] [ip4][..udp] [..19.99.146.156][59479] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 437 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 431|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...432] [ip4][..udp] [.246.75.104.115][37571] -> [...90.141.37.56][..427] + new: [...432] [ip4][..udp] [.246.75.104.115][37571] -> [...90.141.37.56][..427] detected: [...432] [ip4][..udp] [.246.75.104.115][37571] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...431] [ip4][..udp] [..227.7.178.223][16085] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 438 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 432|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...433] [ip4][..udp] [.70.180.111.241][52184] -> [..69.109.187.54][..427] + new: [...433] [ip4][..udp] [.70.180.111.241][52184] -> [..69.109.187.54][..427] detected: [...433] [ip4][..udp] [.70.180.111.241][52184] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...432] [ip4][..udp] [.246.75.104.115][37571] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 439 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 433|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...434] [ip4][..udp] [.246.75.104.115][40378] -> [..165.144.84.62][..427] + new: [...434] [ip4][..udp] [.246.75.104.115][40378] -> [..165.144.84.62][..427] detected: [...434] [ip4][..udp] [.246.75.104.115][40378] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...433] [ip4][..udp] [.70.180.111.241][52184] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 440 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 434|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...435] [ip4][..udp] [.138.18.252.120][11561] -> [.165.114.202.61][..427] + new: [...435] [ip4][..udp] [.138.18.252.120][11561] -> [.165.114.202.61][..427] detected: [...435] [ip4][..udp] [.138.18.252.120][11561] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...434] [ip4][..udp] [.246.75.104.115][40378] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 441 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 435|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...436] [ip4][..udp] [219.160.101.209][55022] -> [...90.141.37.56][..427] + new: [...436] [ip4][..udp] [219.160.101.209][55022] -> [...90.141.37.56][..427] detected: [...436] [ip4][..udp] [219.160.101.209][55022] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...435] [ip4][..udp] [.138.18.252.120][11561] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 442 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 436|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...437] [ip4][..udp] [..66.228.166.55][51471] -> [..69.109.187.54][..427] + new: [...437] [ip4][..udp] [..66.228.166.55][51471] -> [..69.109.187.54][..427] detected: [...437] [ip4][..udp] [..66.228.166.55][51471] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...436] [ip4][..udp] [219.160.101.209][55022] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 443 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 437|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...438] [ip4][..udp] [172.237.152.209][53093] -> [..90.147.171.51][..427] + new: [...438] [ip4][..udp] [172.237.152.209][53093] -> [..90.147.171.51][..427] detected: [...438] [ip4][..udp] [172.237.152.209][53093] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...437] [ip4][..udp] [..66.228.166.55][51471] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 444 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 438|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...439] [ip4][..udp] [...82.19.88.220][49990] -> [.186.112.202.53][..427] + new: [...439] [ip4][..udp] [...82.19.88.220][49990] -> [.186.112.202.53][..427] detected: [...439] [ip4][..udp] [...82.19.88.220][49990] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...438] [ip4][..udp] [172.237.152.209][53093] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 445 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 439|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...440] [ip4][..udp] [..167.7.154.125][.2538] -> [...90.141.37.56][..427] + new: [...440] [ip4][..udp] [..167.7.154.125][.2538] -> [...90.141.37.56][..427] detected: [...440] [ip4][..udp] [..167.7.154.125][.2538] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...439] [ip4][..udp] [...82.19.88.220][49990] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 446 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 440|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...441] [ip4][..udp] [..206.204.24.90][54057] -> [..90.111.212.50][..427] + new: [...441] [ip4][..udp] [..206.204.24.90][54057] -> [..90.111.212.50][..427] detected: [...441] [ip4][..udp] [..206.204.24.90][54057] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...440] [ip4][..udp] [..167.7.154.125][.2538] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 447 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 441|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...442] [ip4][..udp] [..185.33.65.208][52802] -> [..74.111.203.55][..427] + new: [...442] [ip4][..udp] [..185.33.65.208][52802] -> [..74.111.203.55][..427] detected: [...442] [ip4][..udp] [..185.33.65.208][52802] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...441] [ip4][..udp] [..206.204.24.90][54057] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 448 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 442|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...443] [ip4][..udp] [..35.252.69.113][28374] -> [.186.112.202.53][..427] + new: [...443] [ip4][..udp] [..35.252.69.113][28374] -> [.186.112.202.53][..427] detected: [...443] [ip4][..udp] [..35.252.69.113][28374] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...442] [ip4][..udp] [..185.33.65.208][52802] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 449 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 443|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...444] [ip4][..udp] [.47.236.248.231][52985] -> [...90.141.37.56][..427] + new: [...444] [ip4][..udp] [.47.236.248.231][52985] -> [...90.141.37.56][..427] detected: [...444] [ip4][..udp] [.47.236.248.231][52985] -> [...90.141.37.56][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] idle: [...443] [ip4][..udp] [..35.252.69.113][28374] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 450 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 444|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 81] - new: [...445] [ip4][..udp] [.173.161.10.173][43924] -> [..90.111.212.50][..427] + new: [...445] [ip4][..udp] [.173.161.10.173][43924] -> [..90.111.212.50][..427] detected: [...445] [ip4][..udp] [.173.161.10.173][43924] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...444] [ip4][..udp] [.47.236.248.231][52985] -> [...90.141.37.56][..427] [Service_Location_Protocol][Alibaba][RPC][Acceptable] - new: [...446] [ip4][..udp] [185.213.154.138][52528] -> [.165.114.202.61][..427] + new: [...446] [ip4][..udp] [185.213.154.138][52528] -> [.165.114.202.61][..427] detected: [...446] [ip4][..udp] [185.213.154.138][52528] -> [.165.114.202.61][..427] [Service_Location_Protocol][Mullvad][RPC][Acceptable] update: [...445] [ip4][..udp] [.173.161.10.173][43924] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...447] [ip4][..udp] [..191.184.52.78][64609] -> [..90.111.212.50][..427] + new: [...447] [ip4][..udp] [..191.184.52.78][64609] -> [..90.111.212.50][..427] detected: [...447] [ip4][..udp] [..191.184.52.78][64609] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...445] [ip4][..udp] [.173.161.10.173][43924] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...446] [ip4][..udp] [185.213.154.138][52528] -> [.165.114.202.61][..427] [Service_Location_Protocol][Mullvad][RPC][Acceptable] DAEMON-EVENT: [Processed: 453 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 447|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 82] - new: [...448] [ip4][..udp] [..167.65.212.80][.3597] -> [..165.144.84.62][..427] + new: [...448] [ip4][..udp] [..167.65.212.80][.3597] -> [..165.144.84.62][..427] detected: [...448] [ip4][..udp] [..167.65.212.80][.3597] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...447] [ip4][..udp] [..191.184.52.78][64609] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...449] [ip4][..udp] [..185.62.196.74][50485] -> [.165.114.202.61][..427] + new: [...449] [ip4][..udp] [..185.62.196.74][50485] -> [.165.114.202.61][..427] detected: [...449] [ip4][..udp] [..185.62.196.74][50485] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...448] [ip4][..udp] [..167.65.212.80][.3597] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 455 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 449|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 82] - new: [...450] [ip4][..udp] [..167.65.212.80][.8856] -> [..90.145.180.58][..427] + new: [...450] [ip4][..udp] [..167.65.212.80][.8856] -> [..90.145.180.58][..427] detected: [...450] [ip4][..udp] [..167.65.212.80][.8856] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...449] [ip4][..udp] [..185.62.196.74][50485] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...451] [ip4][..udp] [....65.70.43.75][46615] -> [..74.111.203.55][..427] + new: [...451] [ip4][..udp] [....65.70.43.75][46615] -> [..74.111.203.55][..427] detected: [...451] [ip4][..udp] [....65.70.43.75][46615] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...452] [ip4][..udp] [....64.64.43.81][58560] -> [...90.141.37.56][..427] + new: [...452] [ip4][..udp] [....64.64.43.81][58560] -> [...90.141.37.56][..427] detected: [...452] [ip4][..udp] [....64.64.43.81][58560] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...451] [ip4][..udp] [....65.70.43.75][46615] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...450] [ip4][..udp] [..167.65.212.80][.8856] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 458 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 452|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 82] - new: [...453] [ip4][..udp] [....65.70.43.75][24868] -> [...85.111.52.57][..427] + new: [...453] [ip4][..udp] [....65.70.43.75][24868] -> [...85.111.52.57][..427] detected: [...453] [ip4][..udp] [....65.70.43.75][24868] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...452] [ip4][..udp] [....64.64.43.81][58560] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...454] [ip4][..udp] [..167.65.212.80][16286] -> [..69.109.187.54][..427] + new: [...454] [ip4][..udp] [..167.65.212.80][16286] -> [..69.109.187.54][..427] detected: [...454] [ip4][..udp] [..167.65.212.80][16286] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...453] [ip4][..udp] [....65.70.43.75][24868] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 460 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 454|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 83] - new: [...455] [ip4][..udp] [.34.119.122.126][.2631] -> [..74.111.203.55][..427] + new: [...455] [ip4][..udp] [.34.119.122.126][.2631] -> [..74.111.203.55][..427] detected: [...455] [ip4][..udp] [.34.119.122.126][.2631] -> [..74.111.203.55][..427] [Service_Location_Protocol][Google][RPC][Acceptable] idle: [...454] [ip4][..udp] [..167.65.212.80][16286] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...453] [ip4][..udp] [....65.70.43.75][24868] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...456] [ip4][..udp] [..211.50.152.79][55356] -> [..165.144.84.62][..427] + new: [...456] [ip4][..udp] [..211.50.152.79][55356] -> [..165.144.84.62][..427] detected: [...456] [ip4][..udp] [..211.50.152.79][55356] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...455] [ip4][..udp] [.34.119.122.126][.2631] -> [..74.111.203.55][..427] [Service_Location_Protocol][Google][RPC][Acceptable] DAEMON-EVENT: [Processed: 462 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 456|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 84] - new: [...457] [ip4][..udp] [.173.161.10.173][45539] -> [.186.112.202.53][..427] + new: [...457] [ip4][..udp] [.173.161.10.173][45539] -> [.186.112.202.53][..427] detected: [...457] [ip4][..udp] [.173.161.10.173][45539] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...455] [ip4][..udp] [.34.119.122.126][.2631] -> [..74.111.203.55][..427] [Service_Location_Protocol][Google][RPC][Acceptable] idle: [...456] [ip4][..udp] [..211.50.152.79][55356] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] + new: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] detected: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...457] [ip4][..udp] [.173.161.10.173][45539] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...459] [ip4][..udp] [...94.64.218.76][16452] -> [.186.112.202.53][..427] + new: [...459] [ip4][..udp] [...94.64.218.76][16452] -> [.186.112.202.53][..427] detected: [...459] [ip4][..udp] [...94.64.218.76][16452] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...460] [ip4][..udp] [209.239.135.211][55124] -> [...85.111.52.57][..427] + new: [...460] [ip4][..udp] [209.239.135.211][55124] -> [...85.111.52.57][..427] detected: [...460] [ip4][..udp] [209.239.135.211][55124] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...459] [ip4][..udp] [...94.64.218.76][16452] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 466 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 460|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 87] - new: [...461] [ip4][..udp] [226.128.122.118][58464] -> [..90.145.180.58][..427] + new: [...461] [ip4][..udp] [226.128.122.118][58464] -> [..90.145.180.58][..427] detected: [...461] [ip4][..udp] [226.128.122.118][58464] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...460] [ip4][..udp] [209.239.135.211][55124] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...458] [ip4][..udp] [...88.185.36.86][.4763] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...459] [ip4][..udp] [...94.64.218.76][16452] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 467 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 461|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 87] - new: [...462] [ip4][..udp] [.34.102.125.120][51324] -> [.165.114.202.61][..427] + new: [...462] [ip4][..udp] [.34.102.125.120][51324] -> [.165.114.202.61][..427] detected: [...462] [ip4][..udp] [.34.102.125.120][51324] -> [.165.114.202.61][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] idle: [...461] [ip4][..udp] [226.128.122.118][58464] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...463] [ip4][..udp] [.173.161.10.173][42304] -> [..165.144.84.62][..427] + new: [...463] [ip4][..udp] [.173.161.10.173][42304] -> [..165.144.84.62][..427] detected: [...463] [ip4][..udp] [.173.161.10.173][42304] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...462] [ip4][..udp] [.34.102.125.120][51324] -> [.165.114.202.61][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] DAEMON-EVENT: [Processed: 469 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 463|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...464] [ip4][..udp] [.173.161.10.173][53096] -> [..90.145.180.58][..427] + new: [...464] [ip4][..udp] [.173.161.10.173][53096] -> [..90.145.180.58][..427] detected: [...464] [ip4][..udp] [.173.161.10.173][53096] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...463] [ip4][..udp] [.173.161.10.173][42304] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...462] [ip4][..udp] [.34.102.125.120][51324] -> [.165.114.202.61][..427] [Service_Location_Protocol][GoogleCloud][RPC][Acceptable] DAEMON-EVENT: [Processed: 470 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 464|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...465] [ip4][..udp] [134.180.144.149][51824] -> [...85.111.52.57][..427] + new: [...465] [ip4][..udp] [134.180.144.149][51824] -> [...85.111.52.57][..427] detected: [...465] [ip4][..udp] [134.180.144.149][51824] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...464] [ip4][..udp] [.173.161.10.173][53096] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...466] [ip4][..udp] [236.131.162.157][35531] -> [..90.147.171.51][..427] + new: [...466] [ip4][..udp] [236.131.162.157][35531] -> [..90.147.171.51][..427] detected: [...466] [ip4][..udp] [236.131.162.157][35531] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...465] [ip4][..udp] [134.180.144.149][51824] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...467] [ip4][..udp] [.45.131.161.152][57860] -> [..90.111.212.50][..427] + new: [...467] [ip4][..udp] [.45.131.161.152][57860] -> [..90.111.212.50][..427] detected: [...467] [ip4][..udp] [.45.131.161.152][57860] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...466] [ip4][..udp] [236.131.162.157][35531] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 473 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 467|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...468] [ip4][..udp] [.173.161.10.173][60345] -> [...90.141.37.56][..427] + new: [...468] [ip4][..udp] [.173.161.10.173][60345] -> [...90.141.37.56][..427] detected: [...468] [ip4][..udp] [.173.161.10.173][60345] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...467] [ip4][..udp] [.45.131.161.152][57860] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 474 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 468|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...469] [ip4][..udp] [..16.99.147.146][60624] -> [...90.141.37.56][..427] + new: [...469] [ip4][..udp] [..16.99.147.146][60624] -> [...90.141.37.56][..427] detected: [...469] [ip4][..udp] [..16.99.147.146][60624] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...468] [ip4][..udp] [.173.161.10.173][60345] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 475 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 469|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...470] [ip4][..udp] [182.180.120.139][50595] -> [..165.144.84.62][..427] + new: [...470] [ip4][..udp] [182.180.120.139][50595] -> [..165.144.84.62][..427] detected: [...470] [ip4][..udp] [182.180.120.139][50595] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...469] [ip4][..udp] [..16.99.147.146][60624] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...471] [ip4][..udp] [..19.99.147.148][58452] -> [.165.114.202.61][..427] + new: [...471] [ip4][..udp] [..19.99.147.148][58452] -> [.165.114.202.61][..427] detected: [...471] [ip4][..udp] [..19.99.147.148][58452] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...470] [ip4][..udp] [182.180.120.139][50595] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 477 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 471|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...472] [ip4][..udp] [210.124.156.149][52931] -> [..69.109.187.54][..427] + new: [...472] [ip4][..udp] [210.124.156.149][52931] -> [..69.109.187.54][..427] detected: [...472] [ip4][..udp] [210.124.156.149][52931] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...471] [ip4][..udp] [..19.99.147.148][58452] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 478 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 472|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...473] [ip4][..udp] [134.180.144.149][57887] -> [.186.112.202.53][..427] + new: [...473] [ip4][..udp] [134.180.144.149][57887] -> [.186.112.202.53][..427] detected: [...473] [ip4][..udp] [134.180.144.149][57887] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...472] [ip4][..udp] [210.124.156.149][52931] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 479 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 473|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...474] [ip4][..udp] [184.180.168.240][56968] -> [..74.111.203.55][..427] + new: [...474] [ip4][..udp] [184.180.168.240][56968] -> [..74.111.203.55][..427] detected: [...474] [ip4][..udp] [184.180.168.240][56968] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...473] [ip4][..udp] [134.180.144.149][57887] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 480 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 474|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...475] [ip4][..udp] [.16.131.191.144][57563] -> [..90.145.180.58][..427] + new: [...475] [ip4][..udp] [.16.131.191.144][57563] -> [..90.145.180.58][..427] detected: [...475] [ip4][..udp] [.16.131.191.144][57563] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...474] [ip4][..udp] [184.180.168.240][56968] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...476] [ip4][..udp] [.173.161.10.173][33195] -> [.165.114.202.61][..427] + new: [...476] [ip4][..udp] [.173.161.10.173][33195] -> [.165.114.202.61][..427] detected: [...476] [ip4][..udp] [.173.161.10.173][33195] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...475] [ip4][..udp] [.16.131.191.144][57563] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 482 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 476|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...477] [ip4][..udp] [.173.161.10.173][48688] -> [..90.147.171.51][..427] + new: [...477] [ip4][..udp] [.173.161.10.173][48688] -> [..90.147.171.51][..427] detected: [...477] [ip4][..udp] [.173.161.10.173][48688] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...476] [ip4][..udp] [.173.161.10.173][33195] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 483 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 477|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...478] [ip4][..udp] [..231.38.82.221][41269] -> [..165.144.84.62][..427] + new: [...478] [ip4][..udp] [..231.38.82.221][41269] -> [..165.144.84.62][..427] detected: [...478] [ip4][..udp] [..231.38.82.221][41269] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...477] [ip4][..udp] [.173.161.10.173][48688] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 484 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 478|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...479] [ip4][..udp] [..35.252.69.113][14173] -> [..69.109.187.54][..427] + new: [...479] [ip4][..udp] [..35.252.69.113][14173] -> [..69.109.187.54][..427] detected: [...479] [ip4][..udp] [..35.252.69.113][14173] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...478] [ip4][..udp] [..231.38.82.221][41269] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 485 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 479|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...480] [ip4][..udp] [.173.19.223.218][54527] -> [...85.111.52.57][..427] + new: [...480] [ip4][..udp] [.173.19.223.218][54527] -> [...85.111.52.57][..427] detected: [...480] [ip4][..udp] [.173.19.223.218][54527] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...479] [ip4][..udp] [..35.252.69.113][14173] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 486 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 480|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...481] [ip4][..udp] [208.243.248.212][52104] -> [..90.145.180.58][..427] + new: [...481] [ip4][..udp] [208.243.248.212][52104] -> [..90.145.180.58][..427] detected: [...481] [ip4][..udp] [208.243.248.212][52104] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...480] [ip4][..udp] [.173.19.223.218][54527] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...482] [ip4][..udp] [..39.59.139.121][18087] -> [.165.114.202.61][..427] + new: [...482] [ip4][..udp] [..39.59.139.121][18087] -> [.165.114.202.61][..427] detected: [...482] [ip4][..udp] [..39.59.139.121][18087] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...481] [ip4][..udp] [208.243.248.212][52104] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 488 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 482|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...483] [ip4][..udp] [.173.161.10.173][33095] -> [..69.109.187.54][..427] + new: [...483] [ip4][..udp] [.173.161.10.173][33095] -> [..69.109.187.54][..427] detected: [...483] [ip4][..udp] [.173.161.10.173][33095] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...482] [ip4][..udp] [..39.59.139.121][18087] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 489 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 483|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...484] [ip4][..udp] [.173.161.10.173][42481] -> [...85.111.52.57][..427] + new: [...484] [ip4][..udp] [.173.161.10.173][42481] -> [...85.111.52.57][..427] detected: [...484] [ip4][..udp] [.173.161.10.173][42481] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...483] [ip4][..udp] [.173.161.10.173][33095] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...485] [ip4][..udp] [..70.210.68.170][50121] -> [..90.111.212.50][..427] + new: [...485] [ip4][..udp] [..70.210.68.170][50121] -> [..90.111.212.50][..427] detected: [...485] [ip4][..udp] [..70.210.68.170][50121] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...484] [ip4][..udp] [.173.161.10.173][42481] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 491 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 485|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...486] [ip4][..udp] [.227.199.90.122][51729] -> [..90.145.180.58][..427] + new: [...486] [ip4][..udp] [.227.199.90.122][51729] -> [..90.145.180.58][..427] detected: [...486] [ip4][..udp] [.227.199.90.122][51729] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...485] [ip4][..udp] [..70.210.68.170][50121] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 492 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 486|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...487] [ip4][..udp] [161.231.128.245][56820] -> [..74.111.203.55][..427] + new: [...487] [ip4][..udp] [161.231.128.245][56820] -> [..74.111.203.55][..427] detected: [...487] [ip4][..udp] [161.231.128.245][56820] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...486] [ip4][..udp] [.227.199.90.122][51729] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...488] [ip4][..udp] [.173.161.10.173][55131] -> [..74.111.203.55][..427] + new: [...488] [ip4][..udp] [.173.161.10.173][55131] -> [..74.111.203.55][..427] detected: [...488] [ip4][..udp] [.173.161.10.173][55131] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...487] [ip4][..udp] [161.231.128.245][56820] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 494 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 488|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...489] [ip4][..udp] [..99.199.77.211][14222] -> [.165.114.202.61][..427] + new: [...489] [ip4][..udp] [..99.199.77.211][14222] -> [.165.114.202.61][..427] detected: [...489] [ip4][..udp] [..99.199.77.211][14222] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...488] [ip4][..udp] [.173.161.10.173][55131] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 495 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 489|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...490] [ip4][..udp] [...222.41.7.222][55970] -> [..90.147.171.51][..427] + new: [...490] [ip4][..udp] [...222.41.7.222][55970] -> [..90.147.171.51][..427] detected: [...490] [ip4][..udp] [...222.41.7.222][55970] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...489] [ip4][..udp] [..99.199.77.211][14222] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 496 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 490|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...491] [ip4][..udp] [...89.28.95.249][56710] -> [..165.144.84.62][..427] + new: [...491] [ip4][..udp] [...89.28.95.249][56710] -> [..165.144.84.62][..427] detected: [...491] [ip4][..udp] [...89.28.95.249][56710] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...490] [ip4][..udp] [...222.41.7.222][55970] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 497 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 491|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...492] [ip4][..udp] [..85.47.224.171][16312] -> [..74.111.203.55][..427] + new: [...492] [ip4][..udp] [..85.47.224.171][16312] -> [..74.111.203.55][..427] detected: [...492] [ip4][..udp] [..85.47.224.171][16312] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...491] [ip4][..udp] [...89.28.95.249][56710] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...493] [ip4][..udp] [..85.47.224.171][46040] -> [..165.144.84.62][..427] + new: [...493] [ip4][..udp] [..85.47.224.171][46040] -> [..165.144.84.62][..427] detected: [...493] [ip4][..udp] [..85.47.224.171][46040] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...492] [ip4][..udp] [..85.47.224.171][16312] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...494] [ip4][..udp] [..74.142.40.174][10528] -> [...90.141.37.56][..427] + new: [...494] [ip4][..udp] [..74.142.40.174][10528] -> [...90.141.37.56][..427] detected: [...494] [ip4][..udp] [..74.142.40.174][10528] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...493] [ip4][..udp] [..85.47.224.171][46040] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 500 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 494|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...495] [ip4][..udp] [..85.174.88.154][20504] -> [..69.109.187.54][..427] + new: [...495] [ip4][..udp] [..85.174.88.154][20504] -> [..69.109.187.54][..427] detected: [...495] [ip4][..udp] [..85.174.88.154][20504] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...494] [ip4][..udp] [..74.142.40.174][10528] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 501 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 495|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 88] - new: [...496] [ip4][..udp] [170.238.168.143][62476] -> [...85.111.52.57][..427] + new: [...496] [ip4][..udp] [170.238.168.143][62476] -> [...85.111.52.57][..427] detected: [...496] [ip4][..udp] [170.238.168.143][62476] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...495] [ip4][..udp] [..85.174.88.154][20504] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...497] [ip4][..udp] [..170.18.87.162][58469] -> [.186.112.202.53][..427] + new: [...497] [ip4][..udp] [..170.18.87.162][58469] -> [.186.112.202.53][..427] detected: [...497] [ip4][..udp] [..170.18.87.162][58469] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...496] [ip4][..udp] [170.238.168.143][62476] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...498] [ip4][..udp] [..85.47.224.171][16312] -> [..90.111.212.50][..427] + new: [...498] [ip4][..udp] [..85.47.224.171][16312] -> [..90.111.212.50][..427] detected: [...498] [ip4][..udp] [..85.47.224.171][16312] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...499] [ip4][..udp] [.170.243.40.186][35528] -> [.165.114.202.61][..427] + new: [...499] [ip4][..udp] [.170.243.40.186][35528] -> [.165.114.202.61][..427] detected: [...499] [ip4][..udp] [.170.243.40.186][35528] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...497] [ip4][..udp] [..170.18.87.162][58469] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 505 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 499|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...500] [ip4][..udp] [..74.239.16.156][46464] -> [..90.145.180.58][..427] + new: [...500] [ip4][..udp] [..74.239.16.156][46464] -> [..90.145.180.58][..427] detected: [...500] [ip4][..udp] [..74.239.16.156][46464] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...498] [ip4][..udp] [..85.47.224.171][16312] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...497] [ip4][..udp] [..170.18.87.162][58469] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...499] [ip4][..udp] [.170.243.40.186][35528] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 506 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 500|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...501] [ip4][..udp] [...35.0.100.115][46588] -> [..165.144.84.62][..427] + new: [...501] [ip4][..udp] [...35.0.100.115][46588] -> [..165.144.84.62][..427] detected: [...501] [ip4][..udp] [...35.0.100.115][46588] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...500] [ip4][..udp] [..74.239.16.156][46464] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 507 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 501|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...502] [ip4][..udp] [.227.134.81.212][17542] -> [..90.147.171.51][..427] + new: [...502] [ip4][..udp] [.227.134.81.212][17542] -> [..90.147.171.51][..427] detected: [...502] [ip4][..udp] [.227.134.81.212][17542] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...501] [ip4][..udp] [...35.0.100.115][46588] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 508 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 502|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...503] [ip4][..udp] [...93.36.35.136][56600] -> [.165.114.202.61][..427] + new: [...503] [ip4][..udp] [...93.36.35.136][56600] -> [.165.114.202.61][..427] detected: [...503] [ip4][..udp] [...93.36.35.136][56600] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...502] [ip4][..udp] [.227.134.81.212][17542] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 509 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 503|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...504] [ip4][..udp] [..76.50.135.245][51836] -> [...90.141.37.56][..427] + new: [...504] [ip4][..udp] [..76.50.135.245][51836] -> [...90.141.37.56][..427] detected: [...504] [ip4][..udp] [..76.50.135.245][51836] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...503] [ip4][..udp] [...93.36.35.136][56600] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...505] [ip4][..udp] [..69.36.231.230][55374] -> [..69.109.187.54][..427] + new: [...505] [ip4][..udp] [..69.36.231.230][55374] -> [..69.109.187.54][..427] detected: [...505] [ip4][..udp] [..69.36.231.230][55374] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...504] [ip4][..udp] [..76.50.135.245][51836] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 511 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 505|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...506] [ip4][..udp] [..122.122.167.9][43646] -> [...90.141.37.56][..427] + new: [...506] [ip4][..udp] [..122.122.167.9][43646] -> [...90.141.37.56][..427] detected: [...506] [ip4][..udp] [..122.122.167.9][43646] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...505] [ip4][..udp] [..69.36.231.230][55374] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 512 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 506|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...507] [ip4][..udp] [.200.31.144.158][48498] -> [.165.114.202.61][..427] + new: [...507] [ip4][..udp] [.200.31.144.158][48498] -> [.165.114.202.61][..427] detected: [...507] [ip4][..udp] [.200.31.144.158][48498] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...506] [ip4][..udp] [..122.122.167.9][43646] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 513 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 507|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 89] - new: [...508] [ip4][..udp] [.200.31.144.158][35848] -> [..90.145.180.58][..427] + new: [...508] [ip4][..udp] [.200.31.144.158][35848] -> [..90.145.180.58][..427] detected: [...508] [ip4][..udp] [.200.31.144.158][35848] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...507] [ip4][..udp] [.200.31.144.158][48498] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...509] [ip4][..udp] [.200.31.144.158][38264] -> [..69.109.187.54][..427] + new: [...509] [ip4][..udp] [.200.31.144.158][38264] -> [..69.109.187.54][..427] detected: [...509] [ip4][..udp] [.200.31.144.158][38264] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...508] [ip4][..udp] [.200.31.144.158][35848] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 515 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 509|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 90] - new: [...510] [ip4][..udp] [.200.31.144.158][49404] -> [...85.111.52.57][..427] + new: [...510] [ip4][..udp] [.200.31.144.158][49404] -> [...85.111.52.57][..427] detected: [...510] [ip4][..udp] [.200.31.144.158][49404] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...509] [ip4][..udp] [.200.31.144.158][38264] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...508] [ip4][..udp] [.200.31.144.158][35848] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...511] [ip4][..udp] [239.131.160.152][40653] -> [..90.147.171.51][..427] + new: [...511] [ip4][..udp] [239.131.160.152][40653] -> [..90.147.171.51][..427] detected: [...511] [ip4][..udp] [239.131.160.152][40653] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...510] [ip4][..udp] [.200.31.144.158][49404] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 517 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 511|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 91] - new: [...512] [ip4][..udp] [.200.31.144.158][33216] -> [..165.144.84.62][..427] + new: [...512] [ip4][..udp] [.200.31.144.158][33216] -> [..165.144.84.62][..427] detected: [...512] [ip4][..udp] [.200.31.144.158][33216] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...510] [ip4][..udp] [.200.31.144.158][49404] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...511] [ip4][..udp] [239.131.160.152][40653] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...513] [ip4][..udp] [.200.31.144.158][42236] -> [..90.147.171.51][..427] + new: [...513] [ip4][..udp] [.200.31.144.158][42236] -> [..90.147.171.51][..427] detected: [...513] [ip4][..udp] [.200.31.144.158][42236] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...512] [ip4][..udp] [.200.31.144.158][33216] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...514] [ip4][..udp] [237.132.176.136][51278] -> [..74.111.203.55][..427] + new: [...514] [ip4][..udp] [237.132.176.136][51278] -> [..74.111.203.55][..427] detected: [...514] [ip4][..udp] [237.132.176.136][51278] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 520 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 514|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 91] - new: [...515] [ip4][..udp] [.246.75.104.115][50377] -> [.186.112.202.53][..427] + new: [...515] [ip4][..udp] [.246.75.104.115][50377] -> [.186.112.202.53][..427] detected: [...515] [ip4][..udp] [.246.75.104.115][50377] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...513] [ip4][..udp] [.200.31.144.158][42236] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...514] [ip4][..udp] [237.132.176.136][51278] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...516] [ip4][..udp] [.70.180.111.241][51457] -> [..165.144.84.62][..427] + new: [...516] [ip4][..udp] [.70.180.111.241][51457] -> [..165.144.84.62][..427] detected: [...516] [ip4][..udp] [.70.180.111.241][51457] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...515] [ip4][..udp] [.246.75.104.115][50377] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...517] [ip4][..udp] [.200.31.144.158][48231] -> [.186.112.202.53][..427] + new: [...517] [ip4][..udp] [.200.31.144.158][48231] -> [.186.112.202.53][..427] detected: [...517] [ip4][..udp] [.200.31.144.158][48231] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...516] [ip4][..udp] [.70.180.111.241][51457] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 523 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 517|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 92] - new: [...518] [ip4][..udp] [.200.31.144.158][55658] -> [..74.111.203.55][..427] + new: [...518] [ip4][..udp] [.200.31.144.158][55658] -> [..74.111.203.55][..427] detected: [...518] [ip4][..udp] [.200.31.144.158][55658] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...517] [ip4][..udp] [.200.31.144.158][48231] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...516] [ip4][..udp] [.70.180.111.241][51457] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...519] [ip4][..udp] [.70.180.111.241][58316] -> [..90.111.212.50][..427] + new: [...519] [ip4][..udp] [.70.180.111.241][58316] -> [..90.111.212.50][..427] detected: [...519] [ip4][..udp] [.70.180.111.241][58316] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...518] [ip4][..udp] [.200.31.144.158][55658] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 525 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 519|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 92] - new: [...520] [ip4][..udp] [.200.31.144.158][45270] -> [..90.111.212.50][..427] + new: [...520] [ip4][..udp] [.200.31.144.158][45270] -> [..90.111.212.50][..427] detected: [...520] [ip4][..udp] [.200.31.144.158][45270] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...519] [ip4][..udp] [.70.180.111.241][58316] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 526 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 520|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 92] - new: [...521] [ip4][..udp] [200.180.144.114][54554] -> [..69.109.187.54][..427] + new: [...521] [ip4][..udp] [200.180.144.114][54554] -> [..69.109.187.54][..427] detected: [...521] [ip4][..udp] [200.180.144.114][54554] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...520] [ip4][..udp] [.200.31.144.158][45270] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...522] [ip4][..udp] [208.123.176.154][56229] -> [...85.111.52.57][..427] + new: [...522] [ip4][..udp] [208.123.176.154][56229] -> [...85.111.52.57][..427] detected: [...522] [ip4][..udp] [208.123.176.154][56229] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...521] [ip4][..udp] [200.180.144.114][54554] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...523] [ip4][..udp] [.246.75.104.115][57365] -> [...90.141.37.56][..427] + new: [...523] [ip4][..udp] [.246.75.104.115][57365] -> [...90.141.37.56][..427] detected: [...523] [ip4][..udp] [.246.75.104.115][57365] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...522] [ip4][..udp] [208.123.176.154][56229] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 529 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 523|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...524] [ip4][..udp] [.194.23.249.243][54741] -> [..74.111.203.55][..427] + new: [...524] [ip4][..udp] [.194.23.249.243][54741] -> [..74.111.203.55][..427] detected: [...524] [ip4][..udp] [.194.23.249.243][54741] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...522] [ip4][..udp] [208.123.176.154][56229] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...523] [ip4][..udp] [.246.75.104.115][57365] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 530 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 524|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...525] [ip4][..udp] [165.128.253.116][53358] -> [..165.144.84.62][..427] + new: [...525] [ip4][..udp] [165.128.253.116][53358] -> [..165.144.84.62][..427] detected: [...525] [ip4][..udp] [165.128.253.116][53358] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...524] [ip4][..udp] [.194.23.249.243][54741] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 531 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 525|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...526] [ip4][..udp] [157.120.252.123][11982] -> [.186.112.202.53][..427] + new: [...526] [ip4][..udp] [157.120.252.123][11982] -> [.186.112.202.53][..427] detected: [...526] [ip4][..udp] [157.120.252.123][11982] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...525] [ip4][..udp] [165.128.253.116][53358] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 532 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 526|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...527] [ip4][..udp] [..79.210.95.146][54728] -> [.165.114.202.61][..427] + new: [...527] [ip4][..udp] [..79.210.95.146][54728] -> [.165.114.202.61][..427] detected: [...527] [ip4][..udp] [..79.210.95.146][54728] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...526] [ip4][..udp] [157.120.252.123][11982] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 533 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 527|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...528] [ip4][..udp] [..185.31.153.50][50851] -> [.186.112.202.53][..427] + new: [...528] [ip4][..udp] [..185.31.153.50][50851] -> [.186.112.202.53][..427] detected: [...528] [ip4][..udp] [..185.31.153.50][50851] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...527] [ip4][..udp] [..79.210.95.146][54728] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 534 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 528|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...529] [ip4][..udp] [.34.119.122.126][34795] -> [...90.141.37.56][..427] + new: [...529] [ip4][..udp] [.34.119.122.126][34795] -> [...90.141.37.56][..427] detected: [...529] [ip4][..udp] [.34.119.122.126][34795] -> [...90.141.37.56][..427] [Service_Location_Protocol][Google][RPC][Acceptable] idle: [...528] [ip4][..udp] [..185.31.153.50][50851] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 535 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 529|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...530] [ip4][..udp] [.253.112.232.91][40051] -> [..69.109.187.54][..427] + new: [...530] [ip4][..udp] [.253.112.232.91][40051] -> [..69.109.187.54][..427] detected: [...530] [ip4][..udp] [.253.112.232.91][40051] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...529] [ip4][..udp] [.34.119.122.126][34795] -> [...90.141.37.56][..427] [Service_Location_Protocol][Google][RPC][Acceptable] DAEMON-EVENT: [Processed: 536 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 530|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...531] [ip4][..udp] [.98.103.253.115][47719] -> [..90.111.212.50][..427] + new: [...531] [ip4][..udp] [.98.103.253.115][47719] -> [..90.111.212.50][..427] detected: [...531] [ip4][..udp] [.98.103.253.115][47719] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...530] [ip4][..udp] [.253.112.232.91][40051] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...532] [ip4][..udp] [.228.255.84.119][61523] -> [..74.111.203.55][..427] + new: [...532] [ip4][..udp] [.228.255.84.119][61523] -> [..74.111.203.55][..427] detected: [...532] [ip4][..udp] [.228.255.84.119][61523] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...531] [ip4][..udp] [.98.103.253.115][47719] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 538 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 532|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...533] [ip4][..udp] [.178.240.255.34][54964] -> [..69.109.187.54][..427] + new: [...533] [ip4][..udp] [.178.240.255.34][54964] -> [..69.109.187.54][..427] detected: [...533] [ip4][..udp] [.178.240.255.34][54964] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...532] [ip4][..udp] [.228.255.84.119][61523] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...534] [ip4][..udp] [.89.236.122.100][51926] -> [..90.145.180.58][..427] + new: [...534] [ip4][..udp] [.89.236.122.100][51926] -> [..90.145.180.58][..427] detected: [...534] [ip4][..udp] [.89.236.122.100][51926] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...533] [ip4][..udp] [.178.240.255.34][54964] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 540 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 534|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...535] [ip4][..udp] [154.129.123.124][35057] -> [..69.109.187.54][..427] + new: [...535] [ip4][..udp] [154.129.123.124][35057] -> [..69.109.187.54][..427] detected: [...535] [ip4][..udp] [154.129.123.124][35057] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...534] [ip4][..udp] [.89.236.122.100][51926] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 541 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 535|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...536] [ip4][..udp] [..35.252.69.113][61013] -> [..90.111.212.50][..427] + new: [...536] [ip4][..udp] [..35.252.69.113][61013] -> [..90.111.212.50][..427] detected: [...536] [ip4][..udp] [..35.252.69.113][61013] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...535] [ip4][..udp] [154.129.123.124][35057] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...537] [ip4][..udp] [..94.210.194.31][53432] -> [...85.111.52.57][..427] + new: [...537] [ip4][..udp] [..94.210.194.31][53432] -> [...85.111.52.57][..427] detected: [...537] [ip4][..udp] [..94.210.194.31][53432] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...536] [ip4][..udp] [..35.252.69.113][61013] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 543 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 537|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...538] [ip4][..udp] [..231.38.82.221][16953] -> [..90.111.212.50][..427] + new: [...538] [ip4][..udp] [..231.38.82.221][16953] -> [..90.111.212.50][..427] detected: [...538] [ip4][..udp] [..231.38.82.221][16953] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...537] [ip4][..udp] [..94.210.194.31][53432] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...539] [ip4][..udp] [..88.31.110.219][39592] -> [...85.111.52.57][..427] + new: [...539] [ip4][..udp] [..88.31.110.219][39592] -> [...85.111.52.57][..427] detected: [...539] [ip4][..udp] [..88.31.110.219][39592] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...538] [ip4][..udp] [..231.38.82.221][16953] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 545 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 539|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...540] [ip4][..udp] [231.223.121.213][.4034] -> [..69.109.187.54][..427] + new: [...540] [ip4][..udp] [231.223.121.213][.4034] -> [..69.109.187.54][..427] detected: [...540] [ip4][..udp] [231.223.121.213][.4034] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...539] [ip4][..udp] [..88.31.110.219][39592] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 546 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 540|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 93] - new: [...541] [ip4][..udp] [...64.63.36.139][49841] -> [.165.114.202.61][..427] + new: [...541] [ip4][..udp] [...64.63.36.139][49841] -> [.165.114.202.61][..427] detected: [...541] [ip4][..udp] [...64.63.36.139][49841] -> [.165.114.202.61][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...540] [ip4][..udp] [231.223.121.213][.4034] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...542] [ip4][..udp] [..71.191.53.138][45513] -> [..90.111.212.50][..427] + new: [...542] [ip4][..udp] [..71.191.53.138][45513] -> [..90.111.212.50][..427] detected: [...542] [ip4][..udp] [..71.191.53.138][45513] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...541] [ip4][..udp] [...64.63.36.139][49841] -> [.165.114.202.61][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] - new: [...543] [ip4][..udp] [...64.63.52.142][14637] -> [..90.147.171.51][..427] + new: [...543] [ip4][..udp] [...64.63.52.142][14637] -> [..90.147.171.51][..427] detected: [...543] [ip4][..udp] [...64.63.52.142][14637] -> [..90.147.171.51][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...542] [ip4][..udp] [..71.191.53.138][45513] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...541] [ip4][..udp] [...64.63.36.139][49841] -> [.165.114.202.61][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] - new: [...544] [ip4][..udp] [...64.63.36.139][49841] -> [..69.109.187.54][..427] + new: [...544] [ip4][..udp] [...64.63.36.139][49841] -> [..69.109.187.54][..427] detected: [...544] [ip4][..udp] [...64.63.36.139][49841] -> [..69.109.187.54][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...543] [ip4][..udp] [...64.63.52.142][14637] -> [..90.147.171.51][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] DAEMON-EVENT: [Processed: 550 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 544|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 94] - new: [...545] [ip4][..udp] [..191.57.36.135][30888] -> [..165.144.84.62][..427] + new: [...545] [ip4][..udp] [..191.57.36.135][30888] -> [..165.144.84.62][..427] detected: [...545] [ip4][..udp] [..191.57.36.135][30888] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...544] [ip4][..udp] [...64.63.36.139][49841] -> [..69.109.187.54][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] - new: [...546] [ip4][..udp] [.184.193.58.134][21356] -> [..74.111.203.55][..427] + new: [...546] [ip4][..udp] [.184.193.58.134][21356] -> [..74.111.203.55][..427] detected: [...546] [ip4][..udp] [.184.193.58.134][21356] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...544] [ip4][..udp] [...64.63.36.139][49841] -> [..69.109.187.54][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] update: [...545] [ip4][..udp] [..191.57.36.135][30888] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...547] [ip4][..udp] [...64.63.52.142][45266] -> [...85.111.52.57][..427] + new: [...547] [ip4][..udp] [...64.63.52.142][45266] -> [...85.111.52.57][..427] detected: [...547] [ip4][..udp] [...64.63.52.142][45266] -> [...85.111.52.57][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...545] [ip4][..udp] [..191.57.36.135][30888] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...546] [ip4][..udp] [.184.193.58.134][21356] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...548] [ip4][..udp] [.184.193.58.134][.6016] -> [..90.145.180.58][..427] + new: [...548] [ip4][..udp] [.184.193.58.134][.6016] -> [..90.145.180.58][..427] detected: [...548] [ip4][..udp] [.184.193.58.134][.6016] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...547] [ip4][..udp] [...64.63.52.142][45266] -> [...85.111.52.57][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...546] [ip4][..udp] [.184.193.58.134][21356] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 554 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 548|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...549] [ip4][..udp] [.184.193.58.134][21356] -> [...90.141.37.56][..427] + new: [...549] [ip4][..udp] [.184.193.58.134][21356] -> [...90.141.37.56][..427] detected: [...549] [ip4][..udp] [.184.193.58.134][21356] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...548] [ip4][..udp] [.184.193.58.134][.6016] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 555 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 549|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...550] [ip4][..udp] [..51.242.192.58][51989] -> [..165.144.84.62][..427] + new: [...550] [ip4][..udp] [..51.242.192.58][51989] -> [..165.144.84.62][..427] detected: [...550] [ip4][..udp] [..51.242.192.58][51989] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...549] [ip4][..udp] [.184.193.58.134][21356] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 556 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 550|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...551] [ip4][..udp] [.64.193.196.133][45764] -> [.186.112.202.53][..427] + new: [...551] [ip4][..udp] [.64.193.196.133][45764] -> [.186.112.202.53][..427] detected: [...551] [ip4][..udp] [.64.193.196.133][45764] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...550] [ip4][..udp] [..51.242.192.58][51989] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 557 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 551|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...552] [ip4][..udp] [.185.29.253.207][55308] -> [...90.141.37.56][..427] + new: [...552] [ip4][..udp] [.185.29.253.207][55308] -> [...90.141.37.56][..427] detected: [...552] [ip4][..udp] [.185.29.253.207][55308] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...551] [ip4][..udp] [.64.193.196.133][45764] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 558 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 552|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...553] [ip4][..udp] [...49.49.71.169][56940] -> [..90.147.171.51][..427] + new: [...553] [ip4][..udp] [...49.49.71.169][56940] -> [..90.147.171.51][..427] detected: [...553] [ip4][..udp] [...49.49.71.169][56940] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...552] [ip4][..udp] [.185.29.253.207][55308] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 559 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 553|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...554] [ip4][..udp] [...198.23.89.28][55179] -> [..90.111.212.50][..427] + new: [...554] [ip4][..udp] [...198.23.89.28][55179] -> [..90.111.212.50][..427] detected: [...554] [ip4][..udp] [...198.23.89.28][55179] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...553] [ip4][..udp] [...49.49.71.169][56940] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 560 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 554|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...555] [ip4][..udp] [..231.38.82.221][33154] -> [.186.112.202.53][..427] + new: [...555] [ip4][..udp] [..231.38.82.221][33154] -> [.186.112.202.53][..427] detected: [...555] [ip4][..udp] [..231.38.82.221][33154] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...554] [ip4][..udp] [...198.23.89.28][55179] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 561 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 555|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...556] [ip4][..udp] [...43.95.195.22][50287] -> [...85.111.52.57][..427] + new: [...556] [ip4][..udp] [...43.95.195.22][50287] -> [...85.111.52.57][..427] detected: [...556] [ip4][..udp] [...43.95.195.22][50287] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...555] [ip4][..udp] [..231.38.82.221][33154] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 563 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 556|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...557] [ip4][..udp] [..235.98.65.133][26337] -> [.165.114.202.61][..427] + new: [...557] [ip4][..udp] [..235.98.65.133][26337] -> [.165.114.202.61][..427] detected: [...557] [ip4][..udp] [..235.98.65.133][26337] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...556] [ip4][..udp] [...43.95.195.22][50287] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 565 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 557|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...558] [ip4][..udp] [.159.60.180.118][39471] -> [.165.114.202.61][..427] + new: [...558] [ip4][..udp] [.159.60.180.118][39471] -> [.165.114.202.61][..427] detected: [...558] [ip4][..udp] [.159.60.180.118][39471] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...557] [ip4][..udp] [..235.98.65.133][26337] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 566 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 558|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...559] [ip4][..udp] [.164.192.91.117][41275] -> [..165.144.84.62][..427] + new: [...559] [ip4][..udp] [.164.192.91.117][41275] -> [..165.144.84.62][..427] detected: [...559] [ip4][..udp] [.164.192.91.117][41275] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...558] [ip4][..udp] [.159.60.180.118][39471] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 567 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 559|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...560] [ip4][..udp] [155.160.165.208][51124] -> [..69.109.187.54][..427] + new: [...560] [ip4][..udp] [155.160.165.208][51124] -> [..69.109.187.54][..427] detected: [...560] [ip4][..udp] [155.160.165.208][51124] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...559] [ip4][..udp] [.164.192.91.117][41275] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 568 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 560|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...561] [ip4][..udp] [...35.0.100.115][65092] -> [.186.112.202.53][..427] + new: [...561] [ip4][..udp] [...35.0.100.115][65092] -> [.186.112.202.53][..427] detected: [...561] [ip4][..udp] [...35.0.100.115][65092] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...560] [ip4][..udp] [155.160.165.208][51124] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 569 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 561|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...562] [ip4][..udp] [231.223.121.213][15170] -> [..90.147.171.51][..427] + new: [...562] [ip4][..udp] [231.223.121.213][15170] -> [..90.147.171.51][..427] detected: [...562] [ip4][..udp] [231.223.121.213][15170] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...561] [ip4][..udp] [...35.0.100.115][65092] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 570 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 562|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...563] [ip4][..udp] [...65.218.6.160][55146] -> [.165.114.202.61][..427] + new: [...563] [ip4][..udp] [...65.218.6.160][55146] -> [.165.114.202.61][..427] detected: [...563] [ip4][..udp] [...65.218.6.160][55146] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...562] [ip4][..udp] [231.223.121.213][15170] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 571 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 563|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...564] [ip4][..udp] [.93.102.124.112][64449] -> [...85.111.52.57][..427] + new: [...564] [ip4][..udp] [.93.102.124.112][64449] -> [...85.111.52.57][..427] detected: [...564] [ip4][..udp] [.93.102.124.112][64449] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...563] [ip4][..udp] [...65.218.6.160][55146] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 572 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 564|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...565] [ip4][..udp] [..32.248.84.127][45264] -> [...90.141.37.56][..427] + new: [...565] [ip4][..udp] [..32.248.84.127][45264] -> [...90.141.37.56][..427] detected: [...565] [ip4][..udp] [..32.248.84.127][45264] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...564] [ip4][..udp] [.93.102.124.112][64449] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 573 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 565|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...566] [ip4][..udp] [....69.24.27.60][56117] -> [..90.111.212.50][..427] + new: [...566] [ip4][..udp] [....69.24.27.60][56117] -> [..90.111.212.50][..427] detected: [...566] [ip4][..udp] [....69.24.27.60][56117] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...565] [ip4][..udp] [..32.248.84.127][45264] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 574 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 566|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...567] [ip4][..udp] [..64.62.219.130][17454] -> [...85.111.52.57][..427] + new: [...567] [ip4][..udp] [..64.62.219.130][17454] -> [...85.111.52.57][..427] detected: [...567] [ip4][..udp] [..64.62.219.130][17454] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...566] [ip4][..udp] [....69.24.27.60][56117] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...568] [ip4][..udp] [...64.63.52.142][21065] -> [..90.111.212.50][..427] + new: [...568] [ip4][..udp] [...64.63.52.142][21065] -> [..90.111.212.50][..427] detected: [...568] [ip4][..udp] [...64.63.52.142][21065] -> [..90.111.212.50][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] - new: [...569] [ip4][..udp] [...64.63.52.142][50624] -> [..69.109.187.54][..427] + new: [...569] [ip4][..udp] [...64.63.52.142][50624] -> [..69.109.187.54][..427] detected: [...569] [ip4][..udp] [...64.63.52.142][50624] -> [..69.109.187.54][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...568] [ip4][..udp] [...64.63.52.142][21065] -> [..90.111.212.50][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] idle: [...567] [ip4][..udp] [..64.62.219.130][17454] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...570] [ip4][..udp] [...9.160.170.26][53573] -> [..69.109.187.54][..427] + new: [...570] [ip4][..udp] [...9.160.170.26][53573] -> [..69.109.187.54][..427] detected: [...570] [ip4][..udp] [...9.160.170.26][53573] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 578 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 570|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 97] - new: [...571] [ip4][..udp] [.64.193.196.133][51380] -> [..90.145.180.58][..427] + new: [...571] [ip4][..udp] [.64.193.196.133][51380] -> [..90.145.180.58][..427] detected: [...571] [ip4][..udp] [.64.193.196.133][51380] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...570] [ip4][..udp] [...9.160.170.26][53573] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...569] [ip4][..udp] [...64.63.52.142][50624] -> [..69.109.187.54][..427] [Service_Location_Protocol][Twitter][RPC][Acceptable] - new: [...572] [ip4][..udp] [...80.51.127.74][51252] -> [...90.141.37.56][..427] + new: [...572] [ip4][..udp] [...80.51.127.74][51252] -> [...90.141.37.56][..427] detected: [...572] [ip4][..udp] [...80.51.127.74][51252] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...573] [ip4][..udp] [.160.71.213.140][41896] -> [.186.112.202.53][..427] + new: [...573] [ip4][..udp] [.160.71.213.140][41896] -> [.186.112.202.53][..427] detected: [...573] [ip4][..udp] [.160.71.213.140][41896] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...572] [ip4][..udp] [...80.51.127.74][51252] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...571] [ip4][..udp] [.64.193.196.133][51380] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 581 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 573|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 99] - new: [...574] [ip4][..udp] [..191.57.36.135][38472] -> [..165.144.84.62][..427] + new: [...574] [ip4][..udp] [..191.57.36.135][38472] -> [..165.144.84.62][..427] detected: [...574] [ip4][..udp] [..191.57.36.135][38472] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...572] [ip4][..udp] [...80.51.127.74][51252] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...571] [ip4][..udp] [.64.193.196.133][51380] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...573] [ip4][..udp] [.160.71.213.140][41896] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...575] [ip4][..udp] [.65.193.203.129][63990] -> [...90.141.37.56][..427] + new: [...575] [ip4][..udp] [.65.193.203.129][63990] -> [...90.141.37.56][..427] detected: [...575] [ip4][..udp] [.65.193.203.129][63990] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...574] [ip4][..udp] [..191.57.36.135][38472] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 583 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 575|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 99] - new: [...576] [ip4][..udp] [..71.191.53.138][59582] -> [.165.114.202.61][..427] + new: [...576] [ip4][..udp] [..71.191.53.138][59582] -> [.165.114.202.61][..427] detected: [...576] [ip4][..udp] [..71.191.53.138][59582] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...575] [ip4][..udp] [.65.193.203.129][63990] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 584 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 576|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 99] - new: [...577] [ip4][..udp] [.160.71.213.140][32482] -> [..74.111.203.55][..427] + new: [...577] [ip4][..udp] [.160.71.213.140][32482] -> [..74.111.203.55][..427] detected: [...577] [ip4][..udp] [.160.71.213.140][32482] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...576] [ip4][..udp] [..71.191.53.138][59582] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 585 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 577|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 99] - new: [...578] [ip4][..udp] [.98.103.253.115][41415] -> [..74.111.203.55][..427] + new: [...578] [ip4][..udp] [.98.103.253.115][41415] -> [..74.111.203.55][..427] detected: [...578] [ip4][..udp] [.98.103.253.115][41415] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...577] [ip4][..udp] [.160.71.213.140][32482] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 586 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 578|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 99] - new: [...579] [ip4][..udp] [...33.216.90.56][56415] -> [..165.144.84.62][..427] + new: [...579] [ip4][..udp] [...33.216.90.56][56415] -> [..165.144.84.62][..427] detected: [...579] [ip4][..udp] [...33.216.90.56][56415] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...578] [ip4][..udp] [.98.103.253.115][41415] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...580] [ip4][..udp] [154.129.123.124][.6873] -> [.186.112.202.53][..427] + new: [...580] [ip4][..udp] [154.129.123.124][.6873] -> [.186.112.202.53][..427] detected: [...580] [ip4][..udp] [154.129.123.124][.6873] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...579] [ip4][..udp] [...33.216.90.56][56415] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...581] [ip4][..udp] [.210.12.216.151][55745] -> [..90.145.180.58][..427] + new: [...581] [ip4][..udp] [.210.12.216.151][55745] -> [..90.145.180.58][..427] detected: [...581] [ip4][..udp] [.210.12.216.151][55745] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...580] [ip4][..udp] [154.129.123.124][.6873] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 589 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 581|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...582] [ip4][..udp] [..65.20.223.151][51977] -> [..90.147.171.51][..427] + new: [...582] [ip4][..udp] [..65.20.223.151][51977] -> [..90.147.171.51][..427] detected: [...582] [ip4][..udp] [..65.20.223.151][51977] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...581] [ip4][..udp] [.210.12.216.151][55745] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...580] [ip4][..udp] [154.129.123.124][.6873] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 590 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 582|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...583] [ip4][..udp] [..88.31.110.219][54342] -> [.165.114.202.61][..427] + new: [...583] [ip4][..udp] [..88.31.110.219][54342] -> [.165.114.202.61][..427] detected: [...583] [ip4][..udp] [..88.31.110.219][54342] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...582] [ip4][..udp] [..65.20.223.151][51977] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 591 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 583|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...584] [ip4][..udp] [206.206.184.241][50350] -> [..69.109.187.54][..427] + new: [...584] [ip4][..udp] [206.206.184.241][50350] -> [..69.109.187.54][..427] detected: [...584] [ip4][..udp] [206.206.184.241][50350] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...583] [ip4][..udp] [..88.31.110.219][54342] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...585] [ip4][..udp] [..190.35.225.89][52867] -> [...85.111.52.57][..427] + new: [...585] [ip4][..udp] [..190.35.225.89][52867] -> [...85.111.52.57][..427] detected: [...585] [ip4][..udp] [..190.35.225.89][52867] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 593 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 585|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...586] [ip4][..udp] [..227.7.178.223][63301] -> [..165.144.84.62][..427] + new: [...586] [ip4][..udp] [..227.7.178.223][63301] -> [..165.144.84.62][..427] detected: [...586] [ip4][..udp] [..227.7.178.223][63301] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...584] [ip4][..udp] [206.206.184.241][50350] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...585] [ip4][..udp] [..190.35.225.89][52867] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 594 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 586|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...587] [ip4][..udp] [.34.214.128.211][50699] -> [..74.111.203.55][..427] + new: [...587] [ip4][..udp] [.34.214.128.211][50699] -> [..74.111.203.55][..427] detected: [...587] [ip4][..udp] [.34.214.128.211][50699] -> [..74.111.203.55][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] idle: [...586] [ip4][..udp] [..227.7.178.223][63301] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 595 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 587|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...588] [ip4][..udp] [..67.159.16.150][44047] -> [...85.111.52.57][..427] + new: [...588] [ip4][..udp] [..67.159.16.150][44047] -> [...85.111.52.57][..427] detected: [...588] [ip4][..udp] [..67.159.16.150][44047] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...587] [ip4][..udp] [.34.214.128.211][50699] -> [..74.111.203.55][..427] [Service_Location_Protocol][AmazonAWS][RPC][Acceptable] DAEMON-EVENT: [Processed: 596 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 588|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...589] [ip4][..udp] [231.223.121.213][38016] -> [..74.111.203.55][..427] + new: [...589] [ip4][..udp] [231.223.121.213][38016] -> [..74.111.203.55][..427] detected: [...589] [ip4][..udp] [231.223.121.213][38016] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...588] [ip4][..udp] [..67.159.16.150][44047] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 597 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 589|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...590] [ip4][..udp] [.218.225.124.29][52381] -> [..69.109.187.54][..427] + new: [...590] [ip4][..udp] [.218.225.124.29][52381] -> [..69.109.187.54][..427] detected: [...590] [ip4][..udp] [.218.225.124.29][52381] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...589] [ip4][..udp] [231.223.121.213][38016] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 598 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 590|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...591] [ip4][..udp] [.200.31.144.158][47273] -> [..74.111.203.55][..427] + new: [...591] [ip4][..udp] [.200.31.144.158][47273] -> [..74.111.203.55][..427] detected: [...591] [ip4][..udp] [.200.31.144.158][47273] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...590] [ip4][..udp] [.218.225.124.29][52381] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...592] [ip4][..udp] [..49.45.160.215][52110] -> [.165.114.202.61][..427] + new: [...592] [ip4][..udp] [..49.45.160.215][52110] -> [.165.114.202.61][..427] detected: [...592] [ip4][..udp] [..49.45.160.215][52110] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...591] [ip4][..udp] [.200.31.144.158][47273] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 600 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 592|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...593] [ip4][..udp] [.200.31.144.158][56053] -> [..69.109.187.54][..427] + new: [...593] [ip4][..udp] [.200.31.144.158][56053] -> [..69.109.187.54][..427] detected: [...593] [ip4][..udp] [.200.31.144.158][56053] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...592] [ip4][..udp] [..49.45.160.215][52110] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 601 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 593|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...594] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] + new: [...594] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] detected: [...594] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...593] [ip4][..udp] [.200.31.144.158][56053] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 602 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 594|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...595] [ip4][..udp] [.200.31.144.158][54403] -> [...90.141.37.56][..427] + new: [...595] [ip4][..udp] [.200.31.144.158][54403] -> [...90.141.37.56][..427] detected: [...595] [ip4][..udp] [.200.31.144.158][54403] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...594] [ip4][..udp] [.200.31.144.158][44785] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...596] [ip4][..udp] [152.255.170.124][.5941] -> [...85.111.52.57][..427] + new: [...596] [ip4][..udp] [152.255.170.124][.5941] -> [...85.111.52.57][..427] detected: [...596] [ip4][..udp] [152.255.170.124][.5941] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...595] [ip4][..udp] [.200.31.144.158][54403] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 604 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 596|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...597] [ip4][..udp] [.200.31.144.158][41849] -> [..90.111.212.50][..427] + new: [...597] [ip4][..udp] [.200.31.144.158][41849] -> [..90.111.212.50][..427] detected: [...597] [ip4][..udp] [.200.31.144.158][41849] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...596] [ip4][..udp] [152.255.170.124][.5941] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 605 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 597|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...598] [ip4][..udp] [.200.31.144.158][55801] -> [.165.114.202.61][..427] + new: [...598] [ip4][..udp] [.200.31.144.158][55801] -> [.165.114.202.61][..427] detected: [...598] [ip4][..udp] [.200.31.144.158][55801] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...597] [ip4][..udp] [.200.31.144.158][41849] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 606 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 598|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...599] [ip4][..udp] [.200.31.144.158][59938] -> [..165.144.84.62][..427] + new: [...599] [ip4][..udp] [.200.31.144.158][59938] -> [..165.144.84.62][..427] detected: [...599] [ip4][..udp] [.200.31.144.158][59938] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...598] [ip4][..udp] [.200.31.144.158][55801] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 607 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 599|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...600] [ip4][..udp] [157.120.252.123][42800] -> [..90.147.171.51][..427] + new: [...600] [ip4][..udp] [157.120.252.123][42800] -> [..90.147.171.51][..427] detected: [...600] [ip4][..udp] [157.120.252.123][42800] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...599] [ip4][..udp] [.200.31.144.158][59938] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 608 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 600|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...601] [ip4][..udp] [.155.185.93.215][16031] -> [..165.144.84.62][..427] + new: [...601] [ip4][..udp] [.155.185.93.215][16031] -> [..165.144.84.62][..427] detected: [...601] [ip4][..udp] [.155.185.93.215][16031] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...600] [ip4][..udp] [157.120.252.123][42800] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 609 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 601|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...602] [ip4][..udp] [....174.50.7.11][49286] -> [.186.112.202.53][..427] + new: [...602] [ip4][..udp] [....174.50.7.11][49286] -> [.186.112.202.53][..427] detected: [...602] [ip4][..udp] [....174.50.7.11][49286] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...601] [ip4][..udp] [.155.185.93.215][16031] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 610 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 602|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...603] [ip4][..udp] [..89.214.56.129][54129] -> [..74.111.203.55][..427] + new: [...603] [ip4][..udp] [..89.214.56.129][54129] -> [..74.111.203.55][..427] detected: [...603] [ip4][..udp] [..89.214.56.129][54129] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...602] [ip4][..udp] [....174.50.7.11][49286] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 611 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 603|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...604] [ip4][..udp] [.166.209.36.168][54765] -> [...90.141.37.56][..427] + new: [...604] [ip4][..udp] [.166.209.36.168][54765] -> [...90.141.37.56][..427] detected: [...604] [ip4][..udp] [.166.209.36.168][54765] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...603] [ip4][..udp] [..89.214.56.129][54129] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 612 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 604|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 100] - new: [...605] [ip4][..udp] [..70.191.37.189][53867] -> [..90.145.180.58][..427] + new: [...605] [ip4][..udp] [..70.191.37.189][53867] -> [..90.145.180.58][..427] detected: [...605] [ip4][..udp] [..70.191.37.189][53867] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...604] [ip4][..udp] [.166.209.36.168][54765] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] + new: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] detected: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...605] [ip4][..udp] [..70.191.37.189][53867] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...607] [ip4][..udp] [.88.192.213.176][12807] -> [.165.114.202.61][..427] + new: [...607] [ip4][..udp] [.88.192.213.176][12807] -> [.165.114.202.61][..427] detected: [...607] [ip4][..udp] [.88.192.213.176][12807] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...608] [ip4][..udp] [.88.192.213.176][12807] -> [..165.144.84.62][..427] + new: [...608] [ip4][..udp] [.88.192.213.176][12807] -> [..165.144.84.62][..427] detected: [...608] [ip4][..udp] [.88.192.213.176][12807] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] update: [...607] [ip4][..udp] [.88.192.213.176][12807] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...609] [ip4][..udp] [..95.185.37.180][56601] -> [...85.111.52.57][..427] + new: [...609] [ip4][..udp] [..95.185.37.180][56601] -> [...85.111.52.57][..427] detected: [...609] [ip4][..udp] [..95.185.37.180][56601] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...608] [ip4][..udp] [.88.192.213.176][12807] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...606] [ip4][..udp] [..166.70.59.181][28945] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...607] [ip4][..udp] [.88.192.213.176][12807] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 617 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 609|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...610] [ip4][..udp] [..88.63.218.184][57760] -> [.186.112.202.53][..427] + new: [...610] [ip4][..udp] [..88.63.218.184][57760] -> [.186.112.202.53][..427] detected: [...610] [ip4][..udp] [..88.63.218.184][57760] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...609] [ip4][..udp] [..95.185.37.180][56601] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 618 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 610|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...611] [ip4][..udp] [.95.190.219.185][65399] -> [..90.111.212.50][..427] + new: [...611] [ip4][..udp] [.95.190.219.185][65399] -> [..90.111.212.50][..427] detected: [...611] [ip4][..udp] [.95.190.219.185][65399] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...610] [ip4][..udp] [..88.63.218.184][57760] -> [.186.112.202.53][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...612] [ip4][..udp] [...71.64.36.183][43664] -> [..90.147.171.51][..427] + new: [...612] [ip4][..udp] [...71.64.36.183][43664] -> [..90.147.171.51][..427] detected: [...612] [ip4][..udp] [...71.64.36.183][43664] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...611] [ip4][..udp] [.95.190.219.185][65399] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...613] [ip4][..udp] [..64.56.203.178][58318] -> [..74.111.203.55][..427] + new: [...613] [ip4][..udp] [..64.56.203.178][58318] -> [..74.111.203.55][..427] detected: [...613] [ip4][..udp] [..64.56.203.178][58318] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 621 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 613|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...614] [ip4][..udp] [.93.102.124.112][43680] -> [..69.109.187.54][..427] + new: [...614] [ip4][..udp] [.93.102.124.112][43680] -> [..69.109.187.54][..427] detected: [...614] [ip4][..udp] [.93.102.124.112][43680] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...613] [ip4][..udp] [..64.56.203.178][58318] -> [..74.111.203.55][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...612] [ip4][..udp] [...71.64.36.183][43664] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 622 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 614|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...615] [ip4][..udp] [..185.27.37.156][54712] -> [..90.145.180.58][..427] + new: [...615] [ip4][..udp] [..185.27.37.156][54712] -> [..90.145.180.58][..427] detected: [...615] [ip4][..udp] [..185.27.37.156][54712] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...614] [ip4][..udp] [.93.102.124.112][43680] -> [..69.109.187.54][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 623 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 615|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...616] [ip4][..udp] [186.213.158.225][53551] -> [..90.111.212.50][..427] + new: [...616] [ip4][..udp] [186.213.158.225][53551] -> [..90.111.212.50][..427] detected: [...616] [ip4][..udp] [186.213.158.225][53551] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...615] [ip4][..udp] [..185.27.37.156][54712] -> [..90.145.180.58][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 624 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 616|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...617] [ip4][..udp] [..167.7.154.125][55642] -> [...90.141.37.56][..427] + new: [...617] [ip4][..udp] [..167.7.154.125][55642] -> [...90.141.37.56][..427] detected: [...617] [ip4][..udp] [..167.7.154.125][55642] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...616] [ip4][..udp] [186.213.158.225][53551] -> [..90.111.212.50][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 625 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 617|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...618] [ip4][..udp] [.70.216.186.103][52251] -> [..90.147.171.51][..427] + new: [...618] [ip4][..udp] [.70.216.186.103][52251] -> [..90.147.171.51][..427] detected: [...618] [ip4][..udp] [.70.216.186.103][52251] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...617] [ip4][..udp] [..167.7.154.125][55642] -> [...90.141.37.56][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...619] [ip4][..udp] [..67.159.16.150][26319] -> [.165.114.202.61][..427] + new: [...619] [ip4][..udp] [..67.159.16.150][26319] -> [.165.114.202.61][..427] detected: [...619] [ip4][..udp] [..67.159.16.150][26319] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] DAEMON-EVENT: [Processed: 627 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 619|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 103] - new: [...620] [ip4][..udp] [....58.22.67.22][52092] -> [...85.111.52.57][..427] + new: [...620] [ip4][..udp] [....58.22.67.22][52092] -> [...85.111.52.57][..427] detected: [...620] [ip4][..udp] [....58.22.67.22][52092] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...618] [ip4][..udp] [.70.216.186.103][52251] -> [..90.147.171.51][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...619] [ip4][..udp] [..67.159.16.150][26319] -> [.165.114.202.61][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] - new: [...621] [ip4][..udp] [..217.39.155.99][51503] -> [..165.144.84.62][..427] + new: [...621] [ip4][..udp] [..217.39.155.99][51503] -> [..165.144.84.62][..427] detected: [...621] [ip4][..udp] [..217.39.155.99][51503] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...620] [ip4][..udp] [....58.22.67.22][52092] -> [...85.111.52.57][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] idle: [...621] [ip4][..udp] [..217.39.155.99][51503] -> [..165.144.84.62][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/ssdp-m-search-ua.pcap.out b/test/results/flow-info/default/ssdp-m-search-ua.pcap.out index b676c9b16..0298db23e 100644 --- a/test/results/flow-info/default/ssdp-m-search-ua.pcap.out +++ b/test/results/flow-info/default/ssdp-m-search-ua.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.242.50][56446] -> [239.255.255.250][.1900] + new: [.....1] [ip4][..udp] [.192.168.242.50][56446] -> [239.255.255.250][.1900] detected: [.....1] [ip4][..udp] [.192.168.242.50][56446] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] idle: [.....1] [ip4][..udp] [.192.168.242.50][56446] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/ssdp-m-search.pcap.out b/test/results/flow-info/default/ssdp-m-search.pcap.out index 2ae7e5961..3abfdc8d7 100644 --- a/test/results/flow-info/default/ssdp-m-search.pcap.out +++ b/test/results/flow-info/default/ssdp-m-search.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.242.8][42253] -> [192.168.242.255][32412] + new: [.....1] [ip4][..udp] [..192.168.242.8][42253] -> [192.168.242.255][32412] detected: [.....1] [ip4][..udp] [..192.168.242.8][42253] -> [192.168.242.255][32412] [SSDP][Unknown][System][Acceptable][] update: [.....1] [ip4][..udp] [..192.168.242.8][42253] -> [192.168.242.255][32412] [SSDP][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [..192.168.242.8][42253] -> [192.168.242.255][32412] [SSDP][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/ssh.pcap.out b/test/results/flow-info/default/ssh.pcap.out index 6b34663cb..17732fb82 100644 --- a/test/results/flow-info/default/ssh.pcap.out +++ b/test/results/flow-info/default/ssh.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...172.16.238.1][58395] -> [.172.16.238.168][...22] + new: [.....1] [ip4][..tcp] [...172.16.238.1][58395] -> [.172.16.238.168][...22] detected: [.....1] [ip4][..tcp] [...172.16.238.1][58395] -> [.172.16.238.168][...22] [SSH][Unknown][RemoteAccess][Acceptable] RISK: SSH Obsolete Cli Vers/Cipher detection-update: [.....1] [ip4][..tcp] [...172.16.238.1][58395] -> [.172.16.238.168][...22] [SSH][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/ssl-cert-name-mismatch.pcap.out b/test/results/flow-info/default/ssl-cert-name-mismatch.pcap.out index 869f0e2c6..859737875 100644 --- a/test/results/flow-info/default/ssl-cert-name-mismatch.pcap.out +++ b/test/results/flow-info/default/ssl-cert-name-mismatch.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.222][54772] -> [.104.154.89.105][..443] + new: [.....1] [ip4][..tcp] [..192.168.2.222][54772] -> [.104.154.89.105][..443] detected: [.....1] [ip4][..tcp] [..192.168.2.222][54772] -> [.104.154.89.105][..443] [TLS][GoogleCloud][Web][Safe][wrong.host.badssl.com] detection-update: [.....1] [ip4][..tcp] [..192.168.2.222][54772] -> [.104.154.89.105][..443] [TLS][GoogleCloud][Web][Safe][wrong.host.badssl.com] detection-update: [.....1] [ip4][..tcp] [..192.168.2.222][54772] -> [.104.154.89.105][..443] [TLS][GoogleCloud][Web][Safe][wrong.host.badssl.com] diff --git a/test/results/flow-info/default/starcraft_battle.pcap.out b/test/results/flow-info/default/starcraft_battle.pcap.out index 2076b4920..da8388ada 100644 --- a/test/results/flow-info/default/starcraft_battle.pcap.out +++ b/test/results/flow-info/default/starcraft_battle.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.30.252.91][..443] -> [..192.168.1.100][.3213] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.30.252.91][..443] -> [..192.168.1.100][.3213] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.30.252.91][..443] -> [..192.168.1.100][.3213] [TLS][Github][Web][Safe] - new: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] + new: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] detected: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][91.252.30.192.in-addr.arpa] detection-update: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][100.1.168.192.in-addr.arpa] RISK: Unidirectional Traffic detection-update: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][100.1.168.192.in-addr.arpa] RISK: Minor Issues - new: [.....3] [ip4][..tcp] [..80.239.186.26][..443] -> [..192.168.1.100][.3476] [MIDSTREAM] - new: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] + new: [.....3] [ip4][..tcp] [..80.239.186.26][..443] -> [..192.168.1.100][.3476] [MIDSTREAM] + new: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] detected: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][254.1.168.192.in-addr.arpa] detection-update: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][26.186.239.80.in-addr.arpa] RISK: Unidirectional Traffic @@ -18,32 +18,32 @@ RISK: Error Code detection-update: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][26.186.239.80.in-addr.arpa] RISK: Error Code - new: [.....5] [ip4][..tcp] [..80.239.186.40][..443] -> [..192.168.1.100][.3478] [MIDSTREAM] - new: [.....6] [ip4][..udp] [..173.194.40.22][..443] -> [..192.168.1.100][53568] - new: [.....7] [ip4][..udp] [..192.168.1.100][58844] -> [..192.168.1.254][...53] + new: [.....5] [ip4][..tcp] [..80.239.186.40][..443] -> [..192.168.1.100][.3478] [MIDSTREAM] + new: [.....6] [ip4][..udp] [..173.194.40.22][..443] -> [..192.168.1.100][53568] + new: [.....7] [ip4][..udp] [..192.168.1.100][58844] -> [..192.168.1.254][...53] detected: [.....7] [ip4][..udp] [..192.168.1.100][58844] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][40.186.239.80.in-addr.arpa] detection-update: [.....7] [ip4][..udp] [..192.168.1.100][58844] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][40.186.239.80.in-addr.arpa] - new: [.....8] [ip4][..tcp] [..192.168.1.100][.3052] -> [.216.58.212.110][..443] [MIDSTREAM] - new: [.....9] [ip4][..udp] [..192.168.1.100][58851] -> [..192.168.1.254][...53] + new: [.....8] [ip4][..tcp] [..192.168.1.100][.3052] -> [.216.58.212.110][..443] [MIDSTREAM] + new: [.....9] [ip4][..udp] [..192.168.1.100][58851] -> [..192.168.1.254][...53] detected: [.....9] [ip4][..udp] [..192.168.1.100][58851] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][22.40.194.173.in-addr.arpa] detection-update: [.....9] [ip4][..udp] [..192.168.1.100][58851] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][110.212.58.216.in-addr.arpa] RISK: Unidirectional Traffic detection-update: [.....9] [ip4][..udp] [..192.168.1.100][58851] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][110.212.58.216.in-addr.arpa] - new: [....10] [ip4][..tcp] [..192.168.1.100][.3427] -> [.80.239.208.193][.1119] [MIDSTREAM] - new: [....11] [ip4][..tcp] [..192.168.1.100][.2759] -> [.64.233.184.188][.5228] [MIDSTREAM] + new: [....10] [ip4][..tcp] [..192.168.1.100][.3427] -> [.80.239.208.193][.1119] [MIDSTREAM] + new: [....11] [ip4][..tcp] [..192.168.1.100][.2759] -> [.64.233.184.188][.5228] [MIDSTREAM] ERROR-EVENT: Unknown packet type [1/16] - new: [....12] [ip4][..udp] [..192.168.1.254][38605] -> [239.255.255.250][.1900] + new: [....12] [ip4][..udp] [..192.168.1.254][38605] -> [239.255.255.250][.1900] detected: [....12] [ip4][..udp] [..192.168.1.254][38605] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....13] [ip4][..tcp] [..192.168.1.100][.3506] -> [173.194.113.224][...80] + new: [....13] [ip4][..tcp] [..192.168.1.100][.3506] -> [173.194.113.224][...80] detected: [....13] [ip4][..tcp] [..192.168.1.100][.3506] -> [173.194.113.224][...80] [HTTP.Google][Google][Advertisement][Acceptable][www.google-analytics.com] - new: [....14] [ip4][..udp] [..192.168.1.100][60026] -> [..192.168.1.254][...53] + new: [....14] [ip4][..udp] [..192.168.1.100][60026] -> [..192.168.1.254][...53] detected: [....14] [ip4][..udp] [..192.168.1.100][60026] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][llnw.blizzard.com] RISK: Susp DGA Domain name detection-update: [....14] [ip4][..udp] [..192.168.1.100][60026] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][llnw.blizzard.com] RISK: Susp DGA Domain name, Unidirectional Traffic detection-update: [....14] [ip4][..udp] [..192.168.1.100][60026] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][llnw.blizzard.com] RISK: Susp DGA Domain name, Risky Domain Name - new: [....15] [ip4][..tcp] [..192.168.1.100][.3508] -> [.87.248.221.254][...80] + new: [....15] [ip4][..tcp] [..192.168.1.100][.3508] -> [.87.248.221.254][...80] detected: [....15] [ip4][..tcp] [..192.168.1.100][.3508] -> [.87.248.221.254][...80] [HTTP][Unknown][Web][Acceptable][llnw.blizzard.com] RISK: Susp DGA Domain name detection-update: [....15] [ip4][..tcp] [..192.168.1.100][.3508] -> [.87.248.221.254][...80] [HTTP][Unknown][Download][Acceptable][llnw.blizzard.com] @@ -58,21 +58,21 @@ [IATS(ms)....: 58.1,58.1,0.1,58.2,14.3,72.4,0.1,0.1,0.2,0.2,0.1,0.2,0.2,0.2,0.2,0.2,0.1,0.1,0.2,0.2,56.8,56.9,0.2,0.2,0.2,0.2,0.2,0.1,0.1,0.1,0.2] [PKTLENS.....: 52,52,40,227,46,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500,40,1500] [ENTROPIES...: 4.6,4.9,4.7,5.8,4.5,5.3,4.7,5.1,4.6,5.2,4.7,5.1,4.7,5.1,4.6,5.2,4.6,5.2,4.6,5.1,4.7,5.2,4.7,5.1,4.7,5.1,4.7,5.2,4.7,5.2,4.7,5.1] - new: [....16] [ip4][..tcp] [..192.168.1.100][.3512] -> [..12.129.222.54][...80] + new: [....16] [ip4][..tcp] [..192.168.1.100][.3512] -> [..12.129.222.54][...80] detected: [....16] [ip4][..tcp] [..192.168.1.100][.3512] -> [..12.129.222.54][...80] [HTTP.WorldOfWarcraft][Unknown][Game][Fun][us.scan.worldofwarcraft.com] RISK: HTTP Susp User-Agent detection-update: [....16] [ip4][..tcp] [..192.168.1.100][.3512] -> [..12.129.222.54][...80] [HTTP.WorldOfWarcraft][Unknown][Game][Fun][us.scan.worldofwarcraft.com] RISK: HTTP Susp User-Agent, HTTP Obsolete Server - new: [....17] [ip4][..tcp] [..192.168.1.100][.3492] -> [...2.228.46.104][..443] [MIDSTREAM] - new: [....18] [ip4][..tcp] [..192.168.1.100][.3489] -> [...2.228.46.104][..443] [MIDSTREAM] - new: [....19] [ip4][..tcp] [..192.168.1.100][.3490] -> [...2.228.46.104][..443] [MIDSTREAM] - new: [....20] [ip4][..tcp] [..192.168.1.100][.3491] -> [...2.228.46.104][..443] [MIDSTREAM] - new: [....21] [ip4][..tcp] [..192.168.1.100][.3482] -> [...2.228.46.114][..443] [MIDSTREAM] - new: [....22] [ip4][..tcp] [..192.168.1.100][.3480] -> [...2.228.46.114][..443] [MIDSTREAM] - new: [....23] [ip4][..tcp] [..192.168.1.100][.3481] -> [...2.228.46.114][..443] [MIDSTREAM] - new: [....24] [ip4][..tcp] [..192.168.1.100][.3479] -> [...2.228.46.114][..443] [MIDSTREAM] - new: [....25] [ip4][..tcp] [..192.168.1.100][.3486] -> [.199.38.164.156][..443] [MIDSTREAM] - new: [....26] [ip4][..tcp] [..192.168.1.100][.3484] -> [173.194.113.224][..443] [MIDSTREAM] + new: [....17] [ip4][..tcp] [..192.168.1.100][.3492] -> [...2.228.46.104][..443] [MIDSTREAM] + new: [....18] [ip4][..tcp] [..192.168.1.100][.3489] -> [...2.228.46.104][..443] [MIDSTREAM] + new: [....19] [ip4][..tcp] [..192.168.1.100][.3490] -> [...2.228.46.104][..443] [MIDSTREAM] + new: [....20] [ip4][..tcp] [..192.168.1.100][.3491] -> [...2.228.46.104][..443] [MIDSTREAM] + new: [....21] [ip4][..tcp] [..192.168.1.100][.3482] -> [...2.228.46.114][..443] [MIDSTREAM] + new: [....22] [ip4][..tcp] [..192.168.1.100][.3480] -> [...2.228.46.114][..443] [MIDSTREAM] + new: [....23] [ip4][..tcp] [..192.168.1.100][.3481] -> [...2.228.46.114][..443] [MIDSTREAM] + new: [....24] [ip4][..tcp] [..192.168.1.100][.3479] -> [...2.228.46.114][..443] [MIDSTREAM] + new: [....25] [ip4][..tcp] [..192.168.1.100][.3486] -> [.199.38.164.156][..443] [MIDSTREAM] + new: [....26] [ip4][..tcp] [..192.168.1.100][.3484] -> [173.194.113.224][..443] [MIDSTREAM] detected: [....21] [ip4][..tcp] [..192.168.1.100][.3482] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] detected: [....24] [ip4][..tcp] [..192.168.1.100][.3479] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] detected: [....23] [ip4][..tcp] [..192.168.1.100][.3481] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] @@ -81,21 +81,21 @@ detected: [....20] [ip4][..tcp] [..192.168.1.100][.3491] -> [...2.228.46.104][..443] [TLS][Unknown][Web][Safe] detected: [....22] [ip4][..tcp] [..192.168.1.100][.3480] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] detected: [....18] [ip4][..tcp] [..192.168.1.100][.3489] -> [...2.228.46.104][..443] [TLS][Unknown][Web][Safe] - new: [....27] [ip4][....2] [..192.168.1.107] -> [.....224.0.0.22] + new: [....27] [ip4][....2] [..192.168.1.107] -> [.....224.0.0.22] detected: [....27] [ip4][....2] [..192.168.1.107] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] + new: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] detected: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][nydus.battle.net] detection-update: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][nydus.battle.net] RISK: Unidirectional Traffic detection-update: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][nydus.battle.net] - new: [....29] [ip4][..tcp] [..192.168.1.100][.3515] -> [..80.239.186.26][...80] + new: [....29] [ip4][..tcp] [..192.168.1.100][.3515] -> [..80.239.186.26][...80] detected: [....29] [ip4][..tcp] [..192.168.1.100][.3515] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable][nydus.battle.net] - new: [....30] [ip4][..tcp] [..192.168.1.100][.3516] -> [..80.239.186.21][...80] + new: [....30] [ip4][..tcp] [..192.168.1.100][.3516] -> [..80.239.186.21][...80] detected: [....30] [ip4][..tcp] [..192.168.1.100][.3516] -> [..80.239.186.21][...80] [HTTP][Unknown][Web][Acceptable][eu.launcher.battle.net] - new: [....31] [ip4][..tcp] [..192.168.1.100][.3517] -> [213.248.127.130][.1119] - new: [....32] [ip4][..tcp] [..192.168.1.100][.3518] -> [..80.239.186.26][...80] + new: [....31] [ip4][..tcp] [..192.168.1.100][.3517] -> [213.248.127.130][.1119] + new: [....32] [ip4][..tcp] [..192.168.1.100][.3518] -> [..80.239.186.26][...80] detected: [....32] [ip4][..tcp] [..192.168.1.100][.3518] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable][nydus.battle.net] - new: [....33] [ip4][..tcp] [..192.168.1.100][.3519] -> [..80.239.186.21][...80] + new: [....33] [ip4][..tcp] [..192.168.1.100][.3519] -> [..80.239.186.21][...80] detected: [....31] [ip4][..tcp] [..192.168.1.100][.3517] -> [213.248.127.130][.1119] [Starcraft][Unknown][Game][Fun] detected: [....33] [ip4][..tcp] [..192.168.1.100][.3519] -> [..80.239.186.21][...80] [HTTP][Unknown][Web][Acceptable][eu.launcher.battle.net] analyse: [....31] [ip4][..tcp] [..192.168.1.100][.3517] -> [213.248.127.130][.1119] [Starcraft][Unknown][Game][Fun] @@ -108,40 +108,40 @@ [IATS(ms)....: 52.5,52.6,94.6,145.7,24.3,95.1,95.9,166.3,70.9,49.6,160.3,31.2,128.6,15.2,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 52,46,40,142,46,783,40,220,303,40,235,46,108,42,63,63,63,63,63,63,63,63,63,63,63,63,63,63,63,63,63,63] [ENTROPIES...: 4.5,4.6,4.7,5.4,4.5,7.8,5.0,7.1,7.2,4.9,6.2,4.7,5.0,4.8,5.6,5.5,5.6,5.6,5.6,5.7,5.5,5.5,5.5,5.7,5.7,5.7,5.5,5.6,5.6,5.7,5.6,5.6] - new: [....34] [ip4][..udp] [..192.168.1.100][53146] -> [...5.42.180.154][.1119] - new: [....35] [ip4][..udp] [..192.168.1.100][53146] -> [..62.115.246.51][.1119] - new: [....36] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.212][.1119] - new: [....37] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.166][.1119] - new: [....38] [ip4][..tcp] [..192.168.1.100][.3521] -> [..80.239.186.26][...80] + new: [....34] [ip4][..udp] [..192.168.1.100][53146] -> [...5.42.180.154][.1119] + new: [....35] [ip4][..udp] [..192.168.1.100][53146] -> [..62.115.246.51][.1119] + new: [....36] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.212][.1119] + new: [....37] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.166][.1119] + new: [....38] [ip4][..tcp] [..192.168.1.100][.3521] -> [..80.239.186.26][...80] detected: [....38] [ip4][..tcp] [..192.168.1.100][.3521] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable][nydus.battle.net] - new: [....39] [ip4][..tcp] [..192.168.1.100][.3522] -> [..80.239.186.21][...80] + new: [....39] [ip4][..tcp] [..192.168.1.100][.3522] -> [..80.239.186.21][...80] detected: [....39] [ip4][..tcp] [..192.168.1.100][.3522] -> [..80.239.186.21][...80] [HTTP][Unknown][Web][Acceptable][eu.launcher.battle.net] - new: [....40] [ip4][..tcp] [..192.168.1.100][.3523] -> [..80.239.186.26][...80] - new: [....41] [ip4][..tcp] [..192.168.1.100][.3524] -> [..80.239.186.26][...80] + new: [....40] [ip4][..tcp] [..192.168.1.100][.3523] -> [..80.239.186.26][...80] + new: [....41] [ip4][..tcp] [..192.168.1.100][.3524] -> [..80.239.186.26][...80] detected: [....40] [ip4][..tcp] [..192.168.1.100][.3523] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable][nydus.battle.net] detected: [....41] [ip4][..tcp] [..192.168.1.100][.3524] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable][nydus.battle.net] - new: [....42] [ip4][..tcp] [..192.168.1.100][.3525] -> [..80.239.186.40][...80] - new: [....43] [ip4][..tcp] [..192.168.1.100][.3526] -> [..80.239.186.40][...80] + new: [....42] [ip4][..tcp] [..192.168.1.100][.3525] -> [..80.239.186.40][...80] + new: [....43] [ip4][..tcp] [..192.168.1.100][.3526] -> [..80.239.186.40][...80] detected: [....42] [ip4][..tcp] [..192.168.1.100][.3525] -> [..80.239.186.40][...80] [HTTP][Unknown][Web][Acceptable][eu.battle.net] detected: [....43] [ip4][..tcp] [..192.168.1.100][.3526] -> [..80.239.186.40][...80] [HTTP][Unknown][Web][Acceptable][eu.battle.net] - new: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] + new: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] detected: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][bnetcmsus-a.akamaihd.net] detection-update: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][bnetcmsus-a.akamaihd.net] RISK: Unidirectional Traffic detection-update: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][bnetcmsus-a.akamaihd.net] - new: [....45] [ip4][..tcp] [..192.168.1.100][.3527] -> [...2.228.46.112][...80] - new: [....46] [ip4][..tcp] [..192.168.1.100][.3528] -> [...2.228.46.112][...80] - new: [....47] [ip4][..tcp] [..192.168.1.100][.3529] -> [...2.228.46.112][...80] - new: [....48] [ip4][..tcp] [..192.168.1.100][.3530] -> [...2.228.46.112][...80] - new: [....49] [ip4][..tcp] [..192.168.1.100][.3531] -> [...2.228.46.112][...80] + new: [....45] [ip4][..tcp] [..192.168.1.100][.3527] -> [...2.228.46.112][...80] + new: [....46] [ip4][..tcp] [..192.168.1.100][.3528] -> [...2.228.46.112][...80] + new: [....47] [ip4][..tcp] [..192.168.1.100][.3529] -> [...2.228.46.112][...80] + new: [....48] [ip4][..tcp] [..192.168.1.100][.3530] -> [...2.228.46.112][...80] + new: [....49] [ip4][..tcp] [..192.168.1.100][.3531] -> [...2.228.46.112][...80] detected: [....45] [ip4][..tcp] [..192.168.1.100][.3527] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] - new: [....50] [ip4][..tcp] [..192.168.1.100][.3532] -> [...2.228.46.112][...80] - new: [....51] [ip4][..tcp] [..192.168.1.100][.3533] -> [...2.228.46.112][...80] + new: [....50] [ip4][..tcp] [..192.168.1.100][.3532] -> [...2.228.46.112][...80] + new: [....51] [ip4][..tcp] [..192.168.1.100][.3533] -> [...2.228.46.112][...80] detected: [....47] [ip4][..tcp] [..192.168.1.100][.3529] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] detected: [....48] [ip4][..tcp] [..192.168.1.100][.3530] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] detected: [....46] [ip4][..tcp] [..192.168.1.100][.3528] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] detected: [....49] [ip4][..tcp] [..192.168.1.100][.3531] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] - new: [....52] [ip4][..tcp] [..192.168.1.100][.3534] -> [...2.228.46.112][...80] + new: [....52] [ip4][..tcp] [..192.168.1.100][.3534] -> [...2.228.46.112][...80] detected: [....50] [ip4][..tcp] [..192.168.1.100][.3532] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] detected: [....51] [ip4][..tcp] [..192.168.1.100][.3533] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][bnetcmsus-a.akamaihd.net] analyse: [....45] [ip4][..tcp] [..192.168.1.100][.3527] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable] @@ -155,19 +155,19 @@ [PKTLENS.....: 52,52,40,189,46,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40,1500,1500,40] [ENTROPIES...: 4.5,4.8,4.7,5.8,4.5,5.9,7.7,4.7,7.8,7.8,4.7,7.8,7.7,4.7,7.7,7.8,4.7,7.8,7.8,4.7,7.8,7.8,4.7,7.7,7.8,4.7,7.8,7.7,4.7,7.8,7.8,4.7] guessed: [....35] [ip4][..udp] [..192.168.1.100][53146] -> [..62.115.246.51][.1119] [Starcraft][Unknown][Game][Fun] - idle: [....35] [ip4][..udp] [..192.168.1.100][53146] -> [..62.115.246.51][.1119] + idle: [....35] [ip4][..udp] [..192.168.1.100][53146] -> [..62.115.246.51][.1119] guessed: [....11] [ip4][..tcp] [..192.168.1.100][.2759] -> [.64.233.184.188][.5228] [Google][Google][Web][Acceptable] - idle: [....11] [ip4][..tcp] [..192.168.1.100][.2759] -> [.64.233.184.188][.5228] + idle: [....11] [ip4][..tcp] [..192.168.1.100][.2759] -> [.64.233.184.188][.5228] guessed: [.....8] [ip4][..tcp] [..192.168.1.100][.3052] -> [.216.58.212.110][..443] [TLS][Google][Web][Safe] - idle: [.....8] [ip4][..tcp] [..192.168.1.100][.3052] -> [.216.58.212.110][..443] + idle: [.....8] [ip4][..tcp] [..192.168.1.100][.3052] -> [.216.58.212.110][..443] idle: [....28] [ip4][..udp] [..192.168.1.100][53145] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] end: [....13] [ip4][..tcp] [..192.168.1.100][.3506] -> [173.194.113.224][...80] [HTTP.Google][Google][Advertisement][Acceptable] idle: [....27] [ip4][....2] [..192.168.1.107] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] guessed: [....10] [ip4][..tcp] [..192.168.1.100][.3427] -> [.80.239.208.193][.1119] [Starcraft][Unknown][Game][Fun] - end: [....10] [ip4][..tcp] [..192.168.1.100][.3427] -> [.80.239.208.193][.1119] + end: [....10] [ip4][..tcp] [..192.168.1.100][.3427] -> [.80.239.208.193][.1119] idle: [....44] [ip4][..udp] [..192.168.1.100][55468] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] guessed: [....26] [ip4][..tcp] [..192.168.1.100][.3484] -> [173.194.113.224][..443] [TLS][Google][Web][Safe] - end: [....26] [ip4][..tcp] [..192.168.1.100][.3484] -> [173.194.113.224][..443] + end: [....26] [ip4][..tcp] [..192.168.1.100][.3484] -> [173.194.113.224][..443] idle: [....45] [ip4][..tcp] [..192.168.1.100][.3527] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable] idle: [....46] [ip4][..tcp] [..192.168.1.100][.3528] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable] idle: [....47] [ip4][..tcp] [..192.168.1.100][.3529] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable] @@ -177,7 +177,7 @@ idle: [....51] [ip4][..tcp] [..192.168.1.100][.3533] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable] guessed: [....52] [ip4][..tcp] [..192.168.1.100][.3534] -> [...2.228.46.112][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....52] [ip4][..tcp] [..192.168.1.100][.3534] -> [...2.228.46.112][...80] + idle: [....52] [ip4][..tcp] [..192.168.1.100][.3534] -> [...2.228.46.112][...80] idle: [....31] [ip4][..tcp] [..192.168.1.100][.3517] -> [213.248.127.130][.1119] [Starcraft][Unknown][Game][Fun] end: [....24] [ip4][..tcp] [..192.168.1.100][.3479] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] end: [....22] [ip4][..tcp] [..192.168.1.100][.3480] -> [...2.228.46.114][..443] [TLS][Unknown][Web][Safe] @@ -191,9 +191,9 @@ RISK: Susp DGA Domain name, Risky Domain Name idle: [.....1] [ip4][..tcp] [..192.30.252.91][..443] -> [..192.168.1.100][.3213] [TLS][Github][Web][Safe] guessed: [....37] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.166][.1119] [Starcraft][Unknown][Game][Fun] - idle: [....37] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.166][.1119] + idle: [....37] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.166][.1119] guessed: [....36] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.212][.1119] [Starcraft][Unknown][Game][Fun] - idle: [....36] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.212][.1119] + idle: [....36] [ip4][..udp] [..192.168.1.100][.6113] -> [213.248.127.212][.1119] end: [....29] [ip4][..tcp] [..192.168.1.100][.3515] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable] end: [....30] [ip4][..tcp] [..192.168.1.100][.3516] -> [..80.239.186.21][...80] [HTTP][Unknown][Web][Acceptable] end: [....32] [ip4][..tcp] [..192.168.1.100][.3518] -> [..80.239.186.26][...80] [HTTP][Unknown][Web][Acceptable] @@ -205,20 +205,20 @@ end: [....42] [ip4][..tcp] [..192.168.1.100][.3525] -> [..80.239.186.40][...80] [HTTP][Unknown][Web][Acceptable] end: [....43] [ip4][..tcp] [..192.168.1.100][.3526] -> [..80.239.186.40][...80] [HTTP][Unknown][Web][Acceptable] guessed: [.....6] [ip4][..udp] [..173.194.40.22][..443] -> [..192.168.1.100][53568] [QUIC][Google][Web][Acceptable] - idle: [.....6] [ip4][..udp] [..173.194.40.22][..443] -> [..192.168.1.100][53568] + idle: [.....6] [ip4][..udp] [..173.194.40.22][..443] -> [..192.168.1.100][53568] guessed: [....34] [ip4][..udp] [..192.168.1.100][53146] -> [...5.42.180.154][.1119] [Starcraft][Unknown][Game][Fun] - idle: [....34] [ip4][..udp] [..192.168.1.100][53146] -> [...5.42.180.154][.1119] + idle: [....34] [ip4][..udp] [..192.168.1.100][53146] -> [...5.42.180.154][.1119] guessed: [....25] [ip4][..tcp] [..192.168.1.100][.3486] -> [.199.38.164.156][..443] [TLS][Unknown][Web][Safe] - end: [....25] [ip4][..tcp] [..192.168.1.100][.3486] -> [.199.38.164.156][..443] + end: [....25] [ip4][..tcp] [..192.168.1.100][.3486] -> [.199.38.164.156][..443] idle: [....12] [ip4][..udp] [..192.168.1.254][38605] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] end: [....15] [ip4][..tcp] [..192.168.1.100][.3508] -> [.87.248.221.254][...80] [HTTP][Unknown][Download][Acceptable] RISK: Binary App Transfer, Susp DGA Domain name guessed: [.....3] [ip4][..tcp] [..80.239.186.26][..443] -> [..192.168.1.100][.3476] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic, TCP Connection Issues - end: [.....3] [ip4][..tcp] [..80.239.186.26][..443] -> [..192.168.1.100][.3476] + end: [.....3] [ip4][..tcp] [..80.239.186.26][..443] -> [..192.168.1.100][.3476] guessed: [.....5] [ip4][..tcp] [..80.239.186.40][..443] -> [..192.168.1.100][.3478] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic, TCP Connection Issues - end: [.....5] [ip4][..tcp] [..80.239.186.40][..443] -> [..192.168.1.100][.3478] + end: [.....5] [ip4][..tcp] [..80.239.186.40][..443] -> [..192.168.1.100][.3478] idle: [.....2] [ip4][..udp] [..192.168.1.100][58818] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] RISK: Minor Issues idle: [.....4] [ip4][..udp] [..192.168.1.100][58831] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/steam.pcap.out b/test/results/flow-info/default/steam.pcap.out index f42b382f6..268344602 100644 --- a/test/results/flow-info/default/steam.pcap.out +++ b/test/results/flow-info/default/steam.pcap.out @@ -1,119 +1,119 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27018] + new: [.....1] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27018] detected: [.....1] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27018] [Steam][Steam][Game][Fun] - new: [.....2] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27019] + new: [.....2] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27019] detected: [.....2] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27019] [Steam][Steam][Game][Fun] - new: [.....3] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27018] + new: [.....3] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27018] detected: [.....3] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27018] [Steam][Unknown][Game][Fun] - new: [.....4] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27017] + new: [.....4] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27017] detected: [.....4] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27017] [Steam][Unknown][Game][Fun] - new: [.....5] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27018] + new: [.....5] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27018] detected: [.....5] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27018] [Steam][Unknown][Game][Fun] - new: [.....6] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27017] + new: [.....6] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27017] detected: [.....6] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27017] [Steam][Unknown][Game][Fun] - new: [.....7] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.36][27017] + new: [.....7] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.36][27017] detected: [.....7] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.36][27017] [Steam][Unknown][Game][Fun] - new: [.....8] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27018] + new: [.....8] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27018] detected: [.....8] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27018] [Steam][Steam][Game][Fun] - new: [.....9] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27018] + new: [.....9] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27018] detected: [.....9] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27018] [Steam][Unknown][Game][Fun] - new: [....10] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.83][27017] + new: [....10] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.83][27017] detected: [....10] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.83][27017] [Steam][Unknown][Game][Fun] - new: [....11] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27019] + new: [....11] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27019] detected: [....11] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27019] [Steam][Unknown][Game][Fun] - new: [....12] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27017] + new: [....12] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27017] detected: [....12] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27017] [Steam][Unknown][Game][Fun] - new: [....13] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27019] + new: [....13] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27019] detected: [....13] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27019] [Steam][Steam][Game][Fun] - new: [....14] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27018] + new: [....14] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27018] detected: [....14] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27018] [Steam][Unknown][Game][Fun] - new: [....15] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27017] + new: [....15] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27017] detected: [....15] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.172][27017] [Steam][Unknown][Game][Fun] - new: [....16] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27019] + new: [....16] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27019] detected: [....16] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27019] [Steam][Unknown][Game][Fun] - new: [....17] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.34][27017] + new: [....17] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.34][27017] detected: [....17] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.34][27017] [Steam][Unknown][Game][Fun] - new: [....18] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.4][27017] + new: [....18] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.4][27017] detected: [....18] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.4][27017] [Steam][Unknown][Game][Fun] - new: [....19] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.179][27017] + new: [....19] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.179][27017] detected: [....19] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.179][27017] [Steam][Unknown][Game][Fun] - new: [....20] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27017] + new: [....20] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27017] detected: [....20] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27017] [Steam][Unknown][Game][Fun] - new: [....21] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.82][27017] + new: [....21] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.82][27017] detected: [....21] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.171.82][27017] [Steam][Unknown][Game][Fun] - new: [....22] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27018] + new: [....22] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27018] detected: [....22] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27018] [Steam][Unknown][Game][Fun] - new: [....23] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27019] + new: [....23] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27019] detected: [....23] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27019] [Steam][Unknown][Game][Fun] - new: [....24] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27017] + new: [....24] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27017] detected: [....24] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27017] [Steam][Steam][Game][Fun] - new: [....25] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27017] + new: [....25] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27017] detected: [....25] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27017] [Steam][Steam][Game][Fun] - new: [....26] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27017] + new: [....26] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27017] detected: [....26] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27017] [Steam][Unknown][Game][Fun] - new: [....27] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27017] + new: [....27] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27017] detected: [....27] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27017] [Steam][Unknown][Game][Fun] - new: [....28] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27018] + new: [....28] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27018] detected: [....28] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27018] [Steam][Unknown][Game][Fun] - new: [....29] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27018] + new: [....29] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27018] detected: [....29] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27018] [Steam][Unknown][Game][Fun] - new: [....30] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27017] + new: [....30] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27017] detected: [....30] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27017] [Steam][Unknown][Game][Fun] - new: [....31] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.5][27017] + new: [....31] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.5][27017] detected: [....31] [ip4][..udp] [192.168.188.149][45665] -> [...203.77.185.5][27017] [Steam][Unknown][Game][Fun] - new: [....32] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27018] + new: [....32] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27018] detected: [....32] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27018] [Steam][Steam][Game][Fun] - new: [....33] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27019] + new: [....33] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27019] detected: [....33] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27019] [Steam][Steam][Game][Fun] - new: [....34] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27018] + new: [....34] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27018] detected: [....34] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.174][27018] [Steam][Unknown][Game][Fun] - new: [....35] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27017] + new: [....35] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27017] detected: [....35] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27017] [Steam][Unknown][Game][Fun] - new: [....36] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27017] + new: [....36] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27017] detected: [....36] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27017] [Steam][Steam][Game][Fun] - new: [....37] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27017] + new: [....37] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27017] detected: [....37] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27017] [Steam][Unknown][Game][Fun] - new: [....38] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27017] + new: [....38] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27017] detected: [....38] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.187][27017] [Steam][Unknown][Game][Fun] - new: [....39] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27017] + new: [....39] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27017] detected: [....39] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.5][27017] [Steam][Unknown][Game][Fun] - new: [....40] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27018] + new: [....40] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27018] detected: [....40] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.84][27018] [Steam][Unknown][Game][Fun] - new: [....41] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27017] + new: [....41] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27017] detected: [....41] [ip4][..udp] [192.168.188.149][45665] -> [.208.111.133.85][27017] [Steam][Unknown][Game][Fun] - new: [....42] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27018] + new: [....42] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27018] detected: [....42] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27018] [Steam][Unknown][Game][Fun] - new: [....43] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27017] + new: [....43] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27017] detected: [....43] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.185][27017] [Steam][Unknown][Game][Fun] - new: [....44] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.35][27017] + new: [....44] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.35][27017] detected: [....44] [ip4][..udp] [192.168.188.149][45665] -> [...68.142.91.35][27017] [Steam][Unknown][Game][Fun] - new: [....45] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27019] + new: [....45] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27019] detected: [....45] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.13][27019] [Steam][Steam][Game][Fun] - new: [....46] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27018] + new: [....46] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27018] detected: [....46] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.170][27018] [Steam][Unknown][Game][Fun] - new: [....47] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27017] + new: [....47] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27017] detected: [....47] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.15][27017] [Steam][Steam][Game][Fun] - new: [....48] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27018] + new: [....48] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27018] detected: [....48] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.175][27018] [Steam][Unknown][Game][Fun] - new: [....49] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27019] + new: [....49] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27019] detected: [....49] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27019] [Steam][Unknown][Game][Fun] - new: [....50] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27018] + new: [....50] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27018] detected: [....50] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.188][27018] [Steam][Unknown][Game][Fun] - new: [....51] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.178][27017] + new: [....51] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.178][27017] detected: [....51] [ip4][..udp] [192.168.188.149][45665] -> [.68.142.116.178][27017] [Steam][Unknown][Game][Fun] - new: [....52] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27018] + new: [....52] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27018] detected: [....52] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.6][27018] [Steam][Unknown][Game][Fun] - new: [....53] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27018] + new: [....53] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27018] detected: [....53] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.14][27018] [Steam][Steam][Game][Fun] - new: [....54] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27018] + new: [....54] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27018] detected: [....54] [ip4][..udp] [192.168.188.149][45665] -> [..69.28.145.171][27018] [Steam][Unknown][Game][Fun] - new: [....55] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27017] + new: [....55] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27017] detected: [....55] [ip4][..udp] [192.168.188.149][45665] -> [..72.165.61.176][27017] [Steam][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 104 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 55 / 55|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....56] [ip4][..udp] [...118.105.60.5][14963] -> [....2.95.26.169][27036] + new: [....56] [ip4][..udp] [...118.105.60.5][14963] -> [....2.95.26.169][27036] detected: [....56] [ip4][..udp] [...118.105.60.5][14963] -> [....2.95.26.169][27036] [Steam][Unknown][Game][Fun] idle: [....37] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.7][27017] [Steam][Unknown][Game][Fun] idle: [.....6] [ip4][..udp] [192.168.188.149][45665] -> [...81.171.115.8][27017] [Steam][Unknown][Game][Fun] @@ -172,12 +172,12 @@ idle: [.....2] [ip4][..udp] [192.168.188.149][45665] -> [..146.66.152.12][27019] [Steam][Steam][Game][Fun] DAEMON-EVENT: [Processed: 105 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 56|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....57] [ip4][..udp] [245.111.219.147][27380] -> [104.191.198.151][27036] + new: [....57] [ip4][..udp] [245.111.219.147][27380] -> [104.191.198.151][27036] detected: [....57] [ip4][..udp] [245.111.219.147][27380] -> [104.191.198.151][27036] [Steam][Unknown][Game][Fun] idle: [....56] [ip4][..udp] [...118.105.60.5][14963] -> [....2.95.26.169][27036] [Steam][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 106 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 57|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....58] [ip4][..udp] [...98.10.157.76][10595] -> [164.144.140.184][27036] + new: [....58] [ip4][..udp] [...98.10.157.76][10595] -> [164.144.140.184][27036] detected: [....58] [ip4][..udp] [...98.10.157.76][10595] -> [164.144.140.184][27036] [Steam][Unknown][Game][Fun] idle: [....57] [ip4][..udp] [245.111.219.147][27380] -> [104.191.198.151][27036] [Steam][Unknown][Game][Fun] idle: [....58] [ip4][..udp] [...98.10.157.76][10595] -> [164.144.140.184][27036] [Steam][Unknown][Game][Fun] diff --git a/test/results/flow-info/default/steam_datagram_relay_ping.pcapng.out b/test/results/flow-info/default/steam_datagram_relay_ping.pcapng.out index 58171cc0b..9a3b607b0 100644 --- a/test/results/flow-info/default/steam_datagram_relay_ping.pcapng.out +++ b/test/results/flow-info/default/steam_datagram_relay_ping.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][52157] -> [..139.45.193.10][27018] + new: [.....1] [ip4][..udp] [..192.168.2.100][52157] -> [..139.45.193.10][27018] detected: [.....1] [ip4][..udp] [..192.168.2.100][52157] -> [..139.45.193.10][27018] [Steam][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][52157] -> [..139.45.193.10][27018] [Steam][Unknown][Game][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/stun.pcap.out b/test/results/flow-info/default/stun.pcap.out index c7f95417e..ac88606a3 100644 --- a/test/results/flow-info/default/stun.pcap.out +++ b/test/results/flow-info/default/stun.pcap.out @@ -1,16 +1,28 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.77.110.51][41588] -> [..10.206.50.239][42000] + new: [.....1] [ip4][..tcp] [...10.77.110.51][41588] -> [..10.206.50.239][42000] detected: [.....1] [ip4][..tcp] [...10.77.110.51][41588] -> [..10.206.50.239][42000] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] - detected: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable][] + new: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] + detected: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] [STUN][Google][Network][Acceptable][] + detection-update: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] [STUN][Google][Network][Acceptable][] + RISK: Unidirectional Traffic + detection-update: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] [STUN][Google][Network][Acceptable][] + detection-update: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][turn.l.google.com] + new: [.....3] [ip4][.icmp] [.192.168.12.169] -> [.74.125.247.128] + detected: [.....3] [ip4][.icmp] [.192.168.12.169] -> [.74.125.247.128] [ICMP][Google][Network][Acceptable] end: [.....1] [ip4][..tcp] [...10.77.110.51][41588] -> [..10.206.50.239][42000] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable] - update: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] - update: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] - analyse: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] + DAEMON-EVENT: [Processed: 24 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 3|updates: 0] + new: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] + detected: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable][] + idle: [.....2] [ip4][..udp] [.192.168.12.169][43016] -> [.74.125.247.128][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] + idle: [.....3] [ip4][.icmp] [.192.168.12.169] -> [.74.125.247.128] [ICMP][Google][Network][Acceptable] + update: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] + update: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] + analyse: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.003| 10.359| 9.105| 2.980| 8880623.976| 4.800] [PKTLEN......: 68.000| 92.000| 80.000| 12.000| 144.000| 5.000] @@ -20,15 +32,15 @@ [IATS(ms)....: 6.9,10132.2,10132.3,10358.5,2.9,10358.5,2.9,10055.4,10055.5,10056.9,10056.9,10057.2,10057.2,10053.9,10054.0,10069.5,10069.5,10027.1,10027.1,10027.3,10027.3,10064.0,10063.9,10098.3,10098.4,10035.5,10035.4,10061.4,10061.4,10028.4,10028.3] [PKTLENS.....: 68,92,68,92,68,68,92,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92,68,92] [ENTROPIES...: 5.4,5.5,5.4,5.5,5.5,5.5,5.5,5.5,5.5,5.6,5.5,5.6,5.4,5.6,5.5,5.6,5.4,5.5,5.5,5.5,5.4,5.6,5.4,5.5,5.5,5.6,5.5,5.6,5.5,5.5,5.4,5.5] - update: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] - DAEMON-EVENT: [Processed: 57 pkts][ZLib][compressions: 0|diff: 0 / 0] - DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....3] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] - detected: [.....3] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN][Facebook][Network][Acceptable][] + update: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] + DAEMON-EVENT: [Processed: 66 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 3|updates: 3] + new: [.....5] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] + detected: [.....5] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN][Facebook][Network][Acceptable][] RISK: Known Proto on Non Std Port - detection-update: [.....3] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable][turner.facebook] + detection-update: [.....5] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable][turner.facebook] RISK: Known Proto on Non Std Port - analyse: [.....3] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable] + analyse: [.....5] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 6.004| 0.447| 1.463| 2139022.033| 1.900] [PKTLEN......: 56.000| 168.000| 139.600| 32.100| 1033.400| 5.000] @@ -38,19 +50,19 @@ [IATS(ms)....: 11.5,15.6,15.9,6004.4,4.7,5997.4,4.5,7.5,7.1,108.4,344.5,499.2,68.5,0.2,19.7,29.0,92.2,23.6,96.4,1.6,50.3,48.3,0.3,50.1,3.3,0.0,52.9,0.4,9.7,44.9,232.2] [PKTLENS.....: 56,132,164,104,168,168,140,168,140,72,164,164,160,168,128,72,164,128,160,128,164,160,128,164,128,160,128,168,128,72,160,160] [ENTROPIES...: 4.9,5.6,5.9,5.8,5.9,6.0,5.6,5.8,5.5,5.6,5.9,6.0,6.0,5.9,5.8,5.5,6.0,5.9,6.0,5.9,5.9,6.0,5.8,6.0,5.9,6.0,5.9,5.9,5.8,5.6,6.1,6.0] - idle: [.....2] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] - DAEMON-EVENT: [Processed: 132 pkts][ZLib][compressions: 0|diff: 0 / 0] - DAEMON-EVENT: [Flows][active: 1 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 3] - new: [.....4] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] - detected: [.....4] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable][] - detection-update: [.....4] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable][apps-host.com] - idle: [.....3] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable] + idle: [.....4] [ip6][..udp] [3516:bf0b:fc53:75e7:70af:f67f:8e49:f603][56880] -> [....2a38:e156:8167:a333:face:b00c::24d9][.3478] [STUN][Unknown][Network][Acceptable] + DAEMON-EVENT: [Processed: 141 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 4|updates: 3] + new: [.....6] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] + detected: [.....6] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable][] + detection-update: [.....6] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable][apps-host.com] + idle: [.....5] [ip4][..udp] [.192.168.12.169][38123] -> [....31.13.86.54][40003] [STUN.FacebookVoip][Facebook][VoIP][Acceptable] RISK: Known Proto on Non Std Port - DAEMON-EVENT: [Processed: 152 pkts][ZLib][compressions: 0|diff: 0 / 0] - DAEMON-EVENT: [Flows][active: 1 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 3] - new: [.....5] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] - detected: [.....5] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] - analyse: [.....5] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] + DAEMON-EVENT: [Processed: 161 pkts][ZLib][compressions: 0|diff: 0 / 0] + DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 5|updates: 3] + new: [.....7] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] + detected: [.....7] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] + analyse: [.....7] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.836| 0.131| 0.227| 51553.292| 3.400] [PKTLEN......: 62.000| 1226.000| 179.200| 221.300| 48965.100| 4.400] @@ -60,6 +72,6 @@ [IATS(ms)....: 22.9,25.6,18.8,27.0,9.0,16.5,8.2,0.0,96.0,9.4,96.1,13.9,9.7,14.0,0.0,0.0,28.4,12.0,233.2,17.4,835.9,625.3,352.7,699.8,203.7,550.7,72.1,9.0,20.6,28.1,14.7] [PKTLENS.....: 136,120,181,140,1226,574,120,109,598,109,140,145,161,120,141,93,97,93,113,62,93,140,120,62,110,140,120,94,94,95,95,95] [ENTROPIES...: 5.9,5.9,5.0,5.9,7.3,6.7,5.8,5.7,7.4,5.7,6.0,6.2,6.4,5.9,6.1,5.4,5.4,5.6,5.9,5.3,5.2,5.9,5.8,5.2,6.1,5.9,6.0,6.1,6.0,5.9,6.1,5.9] - idle: [.....5] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] - idle: [.....4] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable] + idle: [.....7] [ip4][..udp] [.192.168.12.169][49153] -> [..142.250.82.99][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] + idle: [.....6] [ip4][..tcp] [...87.47.100.17][.3478] -> [....54.1.57.155][37257] [STUN][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/stun_classic.pcap.out b/test/results/flow-info/default/stun_classic.pcap.out index 929ad22e2..7ff6b2927 100644 --- a/test/results/flow-info/default/stun_classic.pcap.out +++ b/test/results/flow-info/default/stun_classic.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..172.16.63.224][55050] -> [...172.16.63.21][13958] + new: [.....1] [ip4][..udp] [..172.16.63.224][55050] -> [...172.16.63.21][13958] detected: [.....1] [ip4][..udp] [..172.16.63.224][55050] -> [...172.16.63.21][13958] [STUN][Unknown][Network][Acceptable][] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..udp] [..172.16.63.224][55050] -> [...172.16.63.21][13958] [STUN.RTP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/stun_dtls_unidirectional_client.pcap.out b/test/results/flow-info/default/stun_dtls_unidirectional_client.pcap.out index 09cd7b748..fd995d58c 100644 --- a/test/results/flow-info/default/stun_dtls_unidirectional_client.pcap.out +++ b/test/results/flow-info/default/stun_dtls_unidirectional_client.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.....26.83.9.81][57567] -> [..33.35.223.103][..540] + new: [.....1] [ip4][..udp] [.....26.83.9.81][57567] -> [..33.35.223.103][..540] detected: [.....1] [ip4][..udp] [.....26.83.9.81][57567] -> [..33.35.223.103][..540] [STUN][Unknown][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [.....26.83.9.81][57567] -> [..33.35.223.103][..540] [STUN][Unknown][Network][Acceptable][] diff --git a/test/results/flow-info/default/stun_dtls_unidirectional_server.pcap.out b/test/results/flow-info/default/stun_dtls_unidirectional_server.pcap.out index dac2d001e..073b7c8ea 100644 --- a/test/results/flow-info/default/stun_dtls_unidirectional_server.pcap.out +++ b/test/results/flow-info/default/stun_dtls_unidirectional_server.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..33.35.223.103][..540] -> [.....26.83.9.81][57567] + new: [.....1] [ip4][..udp] [..33.35.223.103][..540] -> [.....26.83.9.81][57567] detected: [.....1] [ip4][..udp] [..33.35.223.103][..540] -> [.....26.83.9.81][57567] [STUN][Unknown][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [..33.35.223.103][..540] -> [.....26.83.9.81][57567] [STUN][Unknown][Network][Acceptable][] diff --git a/test/results/flow-info/default/stun_google_meet.pcapng.out b/test/results/flow-info/default/stun_google_meet.pcapng.out index ab4ab0196..91da428d4 100644 --- a/test/results/flow-info/default/stun_google_meet.pcapng.out +++ b/test/results/flow-info/default/stun_google_meet.pcapng.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.156][38152] -> [.74.125.128.127][19302] + new: [.....1] [ip4][..udp] [.192.168.12.156][38152] -> [.74.125.128.127][19302] detected: [.....1] [ip4][..udp] [.192.168.12.156][38152] -> [.74.125.128.127][19302] [STUN][Google][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [.192.168.12.156][45400] -> [.74.125.128.127][19302] + new: [.....2] [ip4][..udp] [.192.168.12.156][45400] -> [.74.125.128.127][19302] detected: [.....2] [ip4][..udp] [.192.168.12.156][45400] -> [.74.125.128.127][19302] [STUN][Google][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][19305] + new: [.....3] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][19305] detected: [.....3] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][19305] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][19305] + new: [.....4] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][19305] detected: [.....4] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][19305] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [.....3] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][19305] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] @@ -23,9 +23,9 @@ [IATS(ms)....: 27.7,164.3,5.3,154.4,6.7,36.4,35.4,0.1,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,27.3,18.9,0.0,0.0,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 152,92,148,185,92,1231,573,598,65,288,288,288,288,288,288,288,288,288,288,288,288,288,109,109,288,288,288,165,288,288,288,288] [ENTROPIES...: 5.9,5.7,5.9,5.0,5.7,7.3,6.8,7.4,4.6,7.1,7.1,7.2,7.1,7.0,7.0,7.1,7.1,7.0,7.1,7.1,7.1,7.1,5.7,5.7,7.0,7.1,7.0,6.4,7.2,7.1,7.1,7.1] - new: [.....5] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][.3478] + new: [.....5] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][.3478] detected: [.....5] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] - new: [.....6] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][.3478] + new: [.....6] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][.3478] detected: [.....6] [ip4][..udp] [.192.168.12.156][45400] -> [..142.250.82.76][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable][] analyse: [.....5] [ip4][..udp] [.192.168.12.156][38152] -> [..142.250.82.76][.3478] [STUN.GoogleHangoutDuo][Google][VoIP][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/stun_msteams_unidir.pcapng.out b/test/results/flow-info/default/stun_msteams_unidir.pcapng.out index e4453a3c4..ee06868f3 100644 --- a/test/results/flow-info/default/stun_msteams_unidir.pcapng.out +++ b/test/results/flow-info/default/stun_msteams_unidir.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..52.115.136.55][.3479] -> [.......10.0.0.1][50006] + new: [.....1] [ip4][..udp] [..52.115.136.55][.3479] -> [.......10.0.0.1][50006] detected: [.....1] [ip4][..udp] [..52.115.136.55][.3479] -> [.......10.0.0.1][50006] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port idle: [.....1] [ip4][..udp] [..52.115.136.55][.3479] -> [.......10.0.0.1][50006] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable] diff --git a/test/results/flow-info/default/stun_signal.pcapng.out b/test/results/flow-info/default/stun_signal.pcapng.out index 4253b1833..4219c2f2c 100644 --- a/test/results/flow-info/default/stun_signal.pcapng.out +++ b/test/results/flow-info/default/stun_signal.pcapng.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.169][39518] -> [172.253.121.127][19302] + new: [.....1] [ip4][..udp] [.192.168.12.169][39518] -> [172.253.121.127][19302] detected: [.....1] [ip4][..udp] [.192.168.12.169][39518] -> [172.253.121.127][19302] [STUN][Google][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [.192.168.12.169][47204] -> [172.253.121.127][19302] + new: [.....2] [ip4][..udp] [.192.168.12.169][47204] -> [172.253.121.127][19302] detected: [.....2] [ip4][..udp] [.192.168.12.169][47204] -> [172.253.121.127][19302] [STUN][Google][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][..443] + new: [.....3] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][..443] detected: [.....3] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][..443] [STUN][AmazonAWS][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][.3478] + new: [.....4] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][.3478] detected: [.....4] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][.3478] [STUN][AmazonAWS][Network][Acceptable][] - new: [.....5] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][.3478] + new: [.....5] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][.3478] detected: [.....5] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][.3478] [STUN][AmazonAWS][Network][Acceptable][] - new: [.....6] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][..443] + new: [.....6] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][..443] detected: [.....6] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][..443] [STUN][AmazonAWS][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [.....7] [ip4][.icmp] [.35.158.183.167] -> [.192.168.12.169] + new: [.....7] [ip4][.icmp] [.35.158.183.167] -> [.192.168.12.169] detected: [.....7] [ip4][.icmp] [.35.158.183.167] -> [.192.168.12.169] [ICMP][AmazonAWS][Network][Acceptable] detection-update: [.....3] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][..443] [STUN][AmazonAWS][Network][Acceptable][] RISK: Known Proto on Non Std Port, Unidirectional Traffic @@ -33,23 +33,23 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [.....6] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][..443] [STUN.SignalVoip][AmazonAWS][Network][Acceptable][] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [.....8] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][.3478] + new: [.....8] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][.3478] detected: [.....8] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][.3478] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] - new: [.....9] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][..443] + new: [.....9] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][..443] detected: [.....9] [ip4][..udp] [.192.168.12.169][43068] -> [.35.158.183.167][..443] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....10] [ip4][..udp] [.192.168.12.169][43068] -> [172.253.121.127][19302] + new: [....10] [ip4][..udp] [.192.168.12.169][43068] -> [172.253.121.127][19302] detected: [....10] [ip4][..udp] [.192.168.12.169][43068] -> [172.253.121.127][19302] [STUN.SignalVoip][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....11] [ip4][..udp] [.192.168.12.169][39950] -> [172.253.121.127][19302] + new: [....11] [ip4][..udp] [.192.168.12.169][39950] -> [172.253.121.127][19302] detected: [....11] [ip4][..udp] [.192.168.12.169][39950] -> [172.253.121.127][19302] [STUN.SignalVoip][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....12] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][..443] + new: [....12] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][..443] detected: [....12] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][..443] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....13] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][.3478] + new: [....13] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][.3478] detected: [....13] [ip4][..udp] [.192.168.12.169][39950] -> [.35.158.183.167][.3478] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] - new: [....14] [ip4][..udp] [.192.168.12.169][43068] -> [.18.195.131.143][61156] + new: [....14] [ip4][..udp] [.192.168.12.169][43068] -> [.18.195.131.143][61156] detected: [....14] [ip4][..udp] [.192.168.12.169][43068] -> [.18.195.131.143][61156] [STUN][AmazonAWS][Network][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....14] [ip4][..udp] [.192.168.12.169][43068] -> [.18.195.131.143][61156] [STUN][AmazonAWS][Network][Acceptable] @@ -83,28 +83,28 @@ RISK: Known Proto on Non Std Port, Unidirectional Traffic update: [.....4] [ip4][..udp] [.192.168.12.169][47204] -> [.35.158.183.167][.3478] [STUN.SignalVoip][AmazonAWS][Network][Acceptable] update: [.....5] [ip4][..udp] [.192.168.12.169][39518] -> [.35.158.183.167][.3478] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable] - new: [....15] [ip4][..udp] [.192.168.12.169][47767] -> [172.253.121.127][19302] + new: [....15] [ip4][..udp] [.192.168.12.169][47767] -> [172.253.121.127][19302] detected: [....15] [ip4][..udp] [.192.168.12.169][47767] -> [172.253.121.127][19302] [STUN.SignalVoip][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....16] [ip4][..udp] [.192.168.12.169][37970] -> [172.253.121.127][19302] + new: [....16] [ip4][..udp] [.192.168.12.169][37970] -> [172.253.121.127][19302] detected: [....16] [ip4][..udp] [.192.168.12.169][37970] -> [172.253.121.127][19302] [STUN.SignalVoip][Google][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....17] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][..443] + new: [....17] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][..443] detected: [....17] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][..443] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....18] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][..443] + new: [....18] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][..443] detected: [....18] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][..443] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....19] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][.3478] + new: [....19] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][.3478] detected: [....19] [ip4][..udp] [.192.168.12.169][47767] -> [.35.158.122.211][.3478] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] - new: [....20] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][.3478] + new: [....20] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][.3478] detected: [....20] [ip4][..udp] [.192.168.12.169][37970] -> [.35.158.122.211][.3478] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] - new: [....21] [ip4][.icmp] [.35.158.122.211] -> [.192.168.12.169] + new: [....21] [ip4][.icmp] [.35.158.122.211] -> [.192.168.12.169] detected: [....21] [ip4][.icmp] [.35.158.122.211] -> [.192.168.12.169] [ICMP][AmazonAWS][Network][Acceptable] - new: [....22] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][54054] + new: [....22] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][54054] detected: [....22] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][54054] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....23] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][61498] + new: [....23] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][61498] detected: [....23] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][61498] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....23] [ip4][..udp] [.192.168.12.169][47767] -> [.18.195.131.143][61498] [STUN.SignalVoip][AmazonAWS][VoIP][Acceptable] diff --git a/test/results/flow-info/default/stun_tcp_multiple_msgs_same_pkt.pcap.out b/test/results/flow-info/default/stun_tcp_multiple_msgs_same_pkt.pcap.out index aeffac795..e807f682d 100644 --- a/test/results/flow-info/default/stun_tcp_multiple_msgs_same_pkt.pcap.out +++ b/test/results/flow-info/default/stun_tcp_multiple_msgs_same_pkt.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [166.172.142.131][.3479] -> [..23.183.197.71][42849] + new: [.....1] [ip4][..tcp] [166.172.142.131][.3479] -> [..23.183.197.71][42849] detected: [.....1] [ip4][..tcp] [166.172.142.131][.3479] -> [..23.183.197.71][42849] [STUN][Unknown][Network][Acceptable][] end: [.....1] [ip4][..tcp] [166.172.142.131][.3479] -> [..23.183.197.71][42849] [STUN][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/stun_wa_call.pcapng.out b/test/results/flow-info/default/stun_wa_call.pcapng.out index c7bbf6b48..0ccc80598 100644 --- a/test/results/flow-info/default/stun_wa_call.pcapng.out +++ b/test/results/flow-info/default/stun_wa_call.pcapng.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.12.156][46652] -> [..93.57.123.227][.3478] + new: [.....1] [ip4][..udp] [.192.168.12.156][46652] -> [..93.57.123.227][.3478] detected: [.....1] [ip4][..udp] [.192.168.12.156][46652] -> [..93.57.123.227][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] - new: [.....2] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.203.62][.3478] + new: [.....2] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.203.62][.3478] detected: [.....2] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.203.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....3] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.231.62][.3478] + new: [.....3] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.231.62][.3478] detected: [.....3] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.231.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....4] [ip4][..udp] [.192.168.12.156][46652] -> [..157.240.21.51][.3478] + new: [.....4] [ip4][..udp] [.192.168.12.156][46652] -> [..157.240.21.51][.3478] detected: [.....4] [ip4][..udp] [.192.168.12.156][46652] -> [..157.240.21.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....5] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.195.48][.3478] + new: [.....5] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.195.48][.3478] detected: [.....5] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.195.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] analyse: [.....1] [ip4][..udp] [.192.168.12.156][46652] -> [..93.57.123.227][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -21,15 +21,15 @@ [IATS(ms)....: 0.2,8.4,0.0,2463.7,2505.3,0.2,3.6,0.3,39.5,0.1,6.1,4.8,0.0,25.9,31.6,82.0,37.7,1.7,120.9,0.0,78.6,59.9,292.8,130.0,59.7,381.6,376.4,412.4,0.0,227.9,362.0] [PKTLENS.....: 240,240,96,96,74,300,300,300,300,96,96,74,96,96,48,48,98,300,300,96,96,89,53,107,108,53,77,86,150,73,227,273] [ENTROPIES...: 7.0,7.0,5.8,5.8,5.8,7.0,7.0,7.0,7.0,5.7,5.8,5.7,5.7,5.7,5.2,5.2,5.8,7.0,7.0,5.7,5.8,5.8,4.9,6.0,6.1,5.0,5.5,5.7,6.6,5.5,6.9,7.2] - new: [.....6] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.203.62][.3478] + new: [.....6] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.203.62][.3478] detected: [.....6] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.203.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....7] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.231.62][.3478] + new: [.....7] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.231.62][.3478] detected: [.....7] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.231.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....8] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.196.62][.3478] + new: [.....8] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.196.62][.3478] detected: [.....8] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.196.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....9] [ip4][..udp] [.192.168.12.156][49526] -> [..179.60.192.48][.3478] + new: [.....9] [ip4][..udp] [.192.168.12.156][49526] -> [..179.60.192.48][.3478] detected: [.....9] [ip4][..udp] [.192.168.12.156][49526] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....10] [ip4][..udp] [.192.168.12.156][49526] -> [..185.60.216.51][.3478] + new: [....10] [ip4][..udp] [.192.168.12.156][49526] -> [..185.60.216.51][.3478] detected: [....10] [ip4][..udp] [.192.168.12.156][49526] -> [..185.60.216.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] analyse: [.....6] [ip4][..udp] [.192.168.12.156][49526] -> [.157.240.203.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -41,13 +41,13 @@ [IATS(ms)....: 0.1,8.3,0.0,10.1,8.1,24.5,25.3,11.6,10.1,12.8,14.4,10.6,10.6,10.6,10.5,16.3,6.1,16.2,5.9,10.0,9.7,10.6,11.3,10.7,10.5,10.8,10.6,10.2,10.7,11.3,11.5] [PKTLENS.....: 300,300,96,96,92,540,92,540,92,540,92,540,92,540,92,540,48,92,48,540,92,540,92,540,92,540,92,540,92,540,92,540] [ENTROPIES...: 7.0,7.0,5.8,5.7,5.7,1.5,5.8,1.5,5.6,1.5,5.6,1.5,5.7,1.5,5.6,1.5,5.2,5.7,5.1,1.5,5.7,1.5,5.7,1.5,5.6,1.5,5.7,1.5,5.8,1.5,5.7,1.5] - new: [....11] [ip4][..udp] [.192.168.12.156][49526] -> [...10.82.40.241][40436] + new: [....11] [ip4][..udp] [.192.168.12.156][49526] -> [...10.82.40.241][40436] detected: [....11] [ip4][..udp] [.192.168.12.156][49526] -> [...10.82.40.241][40436] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....12] [ip4][..udp] [.192.168.12.156][49526] -> [...93.33.118.87][41107] + new: [....12] [ip4][..udp] [.192.168.12.156][49526] -> [...93.33.118.87][41107] detected: [....12] [ip4][..udp] [.192.168.12.156][49526] -> [...93.33.118.87][41107] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....13] [ip4][.icmp] [..93.63.100.129] -> [.192.168.12.156] + new: [....13] [ip4][.icmp] [..93.63.100.129] -> [.192.168.12.156] detected: [....13] [ip4][.icmp] [..93.63.100.129] -> [.192.168.12.156] [ICMP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [.192.168.12.156][46652] -> [.157.240.203.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [.....4] [ip4][..udp] [.192.168.12.156][46652] -> [..157.240.21.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] diff --git a/test/results/flow-info/default/stun_zoom.pcapng.out b/test/results/flow-info/default/stun_zoom.pcapng.out index 11510e7e6..396e027d3 100644 --- a/test/results/flow-info/default/stun_zoom.pcapng.out +++ b/test/results/flow-info/default/stun_zoom.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.43.169][48854] -> [.134.224.90.111][.8801] + new: [.....1] [ip4][..udp] [.192.168.43.169][48854] -> [.134.224.90.111][.8801] detected: [.....1] [ip4][..udp] [.192.168.43.169][48854] -> [.134.224.90.111][.8801] [STUN][Zoom][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [.192.168.43.169][48854] -> [.134.224.90.111][.8801] [STUN][Zoom][Network][Acceptable][] @@ -10,7 +10,7 @@ RISK: Known Proto on Non Std Port detection-update: [.....1] [ip4][..udp] [.192.168.43.169][48854] -> [.134.224.90.111][.8801] [DTLS][Zoom][Safe] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn - new: [.....2] [ip4][..udp] [.192.168.43.169][53065] -> [.134.224.90.111][.8801] + new: [.....2] [ip4][..udp] [.192.168.43.169][53065] -> [.134.224.90.111][.8801] detected: [.....2] [ip4][..udp] [.192.168.43.169][53065] -> [.134.224.90.111][.8801] [STUN][Zoom][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [.....2] [ip4][..udp] [.192.168.43.169][53065] -> [.134.224.90.111][.8801] [STUN][Zoom][Network][Acceptable][] diff --git a/test/results/flow-info/default/syncthing.pcap.out b/test/results/flow-info/default/syncthing.pcap.out index 22f5aee55..4a03025da 100644 --- a/test/results/flow-info/default/syncthing.pcap.out +++ b/test/results/flow-info/default/syncthing.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][42370] -> [.............................ff12::8384][21027] + new: [.....1] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][42370] -> [.............................ff12::8384][21027] detected: [.....1] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][42370] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] - new: [.....2] [ip4][..udp] [..192.168.2.100][33927] -> [..192.168.2.255][21027] + new: [.....2] [ip4][..udp] [..192.168.2.100][33927] -> [..192.168.2.255][21027] detected: [.....2] [ip4][..udp] [..192.168.2.100][33927] -> [..192.168.2.255][21027] [Syncthing][Unknown][Download][Fun] - new: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] + new: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] detected: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] update: [.....1] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][42370] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] update: [.....2] [ip4][..udp] [..192.168.2.100][33927] -> [..192.168.2.255][21027] [Syncthing][Unknown][Download][Fun] @@ -20,7 +20,7 @@ update: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] update: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] update: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] - new: [.....4] [ip4][..udp] [..192.168.2.100][54977] -> [..192.168.2.255][21027] + new: [.....4] [ip4][..udp] [..192.168.2.100][54977] -> [..192.168.2.255][21027] detected: [.....4] [ip4][..udp] [..192.168.2.100][54977] -> [..192.168.2.255][21027] [Syncthing][Unknown][Download][Fun] idle: [.....4] [ip4][..udp] [..192.168.2.100][54977] -> [..192.168.2.255][21027] [Syncthing][Unknown][Download][Fun] idle: [.....3] [ip6][..udp] [..............fe80::6238:e0ff:fec5:35a0][47077] -> [.............................ff12::8384][21027] [Syncthing][Unknown][Download][Fun] diff --git a/test/results/flow-info/default/synscan.pcap.out b/test/results/flow-info/default/synscan.pcap.out index 7066e47b3..41e02f436 100644 --- a/test/results/flow-info/default/synscan.pcap.out +++ b/test/results/flow-info/default/synscan.pcap.out @@ -1,7977 +1,7977 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..443] - new: [.....2] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..143] - new: [.....3] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3306] - new: [.....4] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..199] - new: [.....5] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..111] - new: [.....6] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1025] - new: [.....7] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..995] - new: [.....8] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..587] - new: [.....9] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...53] - new: [....10] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5900] - new: [....11] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...21] - new: [....12] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..113] - new: [....13] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...80] - new: [....14] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..139] - new: [....15] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3389] - new: [....16] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...23] - new: [....17] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...23] - new: [....18] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3389] - new: [....19] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..139] - new: [....20] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...21] - new: [....21] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5900] - new: [....22] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..587] - new: [....23] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..995] - new: [....24] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1025] - new: [....25] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..111] - new: [....26] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..199] - new: [....27] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3306] - new: [....28] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..143] - new: [....29] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..443] - new: [....30] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1723] - new: [....31] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..993] - new: [....32] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..110] - new: [....33] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8080] - new: [....34] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1720] - new: [....35] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...25] - new: [....36] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..445] - new: [....37] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..256] - new: [....38] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..554] - new: [....39] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..135] - new: [....40] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...22] - new: [....41] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8888] - new: [....42] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..548] - new: [....43] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1056] - new: [....44] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10629] - new: [....45] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2605] - new: [....46] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10621] - new: [....47] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..990] - new: [....48] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5414] - new: [....49] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2222] - new: [....50] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6000] - new: [....51] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1687] - new: [....52] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1233] - new: [....53] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2030] - new: [....54] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....6] - new: [....55] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1417] - new: [....56] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8222] - new: [....57] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..683] - new: [....58] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3050] - new: [....59] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..548] - new: [....60] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8888] - new: [....61] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..135] - new: [....62] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..554] - new: [....63] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..256] - new: [....64] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..445] - new: [....65] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1720] - new: [....66] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8080] - new: [....67] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..110] - new: [....68] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..993] - new: [....69] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1723] - new: [....70] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3050] - new: [....71] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..683] - new: [....72] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8222] - new: [....73] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1417] - new: [....74] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....6] - new: [....75] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2030] - new: [....76] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1233] - new: [....77] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1687] - new: [....78] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6000] - new: [....79] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2222] - new: [....80] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5414] - new: [....81] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..990] - new: [....82] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10621] - new: [....83] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2605] - new: [....84] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10629] - new: [....85] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1056] - new: [....86] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2038] - new: [....87] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14238] - new: [....88] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..514] - new: [....89] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3880] - new: [....90] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17877] - new: [....91] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7777] - new: [....92] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4848] - new: [....93] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32778] - new: [....94] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16080] - new: [....95] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1594] - new: [....96] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65000] - new: [....97] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1075] - new: [....98] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1300] - new: [....99] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2701] - new: [...100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..843] - new: [...101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2005] - new: [...102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9200] - new: [...103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5903] - new: [...104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1067] - new: [...105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4003] - new: [...106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33899] - new: [...107] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7676] - new: [...108] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14442] - new: [...109] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31337] - new: [...110] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1247] - new: [...111] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1311] - new: [...112] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9917] - new: [...113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65000] - new: [...114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1594] - new: [...115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16080] - new: [...116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32778] - new: [...117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4848] - new: [...118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7777] - new: [...119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17877] - new: [...120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3880] - new: [...121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..514] - new: [...122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14238] - new: [...123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2038] - new: [...124] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8291] - new: [...125] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3826] - new: [...126] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3077] - new: [...127] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1187] - new: [...128] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7200] - new: [...129] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5822] - new: [...130] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1024] - new: [...131] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10626] - new: [...132] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...32] - new: [...133] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15004] - new: [...134] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52848] - new: [...135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...24] - new: [...136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5101] - new: [...137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1296] - new: [...138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9102] - new: [...139] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9917] - new: [...140] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1311] - new: [...141] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1247] - new: [...142] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14442] - new: [...143] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7676] - new: [...144] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33899] - new: [...145] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4003] - new: [...146] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1067] - new: [...147] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5903] - new: [...148] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9200] - new: [...149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2005] - new: [...150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..843] - new: [...151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2701] - new: [...152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1300] - new: [...153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1075] - new: [...154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9102] - new: [...155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1296] - new: [...156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5101] - new: [...157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...24] - new: [...158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52848] - new: [...159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15004] - new: [...160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...32] - new: [...161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10626] - new: [...162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1024] - new: [...163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5822] - new: [...164] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7200] - new: [...165] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1187] - new: [...166] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3077] - new: [...167] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3826] - new: [...168] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8291] - new: [...169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5959] - new: [...170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..425] - new: [...171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9500] - new: [...172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14000] - new: [...173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15660] - new: [...174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13456] - new: [...175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1073] - new: [...176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2106] - new: [...177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61532] - new: [...178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..497] - new: [...179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2869] - new: [...180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6669] - new: [...181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1433] - new: [...182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4000] - new: [...183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1043] - new: [...184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9575] - new: [...185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32768] - new: [...186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1641] - new: [...187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5825] - new: [...188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9898] - new: [...189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27355] - new: [...190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1583] - new: [...191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6580] - new: [...192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3001] - new: [...193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2190] - new: [...194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49155] - new: [...195] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2869] - new: [...196] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..497] - new: [...197] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61532] - new: [...198] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2106] - new: [...199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1073] - new: [...200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13456] - new: [...201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15660] - new: [...202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14000] - new: [...203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9500] - new: [...204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..425] - new: [...205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5959] - new: [...206] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7496] - new: [...207] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1071] - new: [...208] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30718] - new: [...209] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..808] - new: [...210] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6543] - new: [...211] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3071] - new: [...212] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5033] - new: [...213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1095] - new: [...214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1064] - new: [...215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1111] - new: [...216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8649] - new: [...217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2099] - new: [...218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..765] - new: [...219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9010] - new: [...220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9071] - new: [...221] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49155] - new: [...222] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2190] - new: [...223] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3001] - new: [...224] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6580] - new: [...225] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1583] - new: [...226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27355] - new: [...227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9898] - new: [...228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5825] - new: [...229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1641] - new: [...230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32768] - new: [...231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9575] - new: [...232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1043] - new: [...233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4000] - new: [...234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1433] - new: [...235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6669] - new: [...236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9071] - new: [...237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9010] - new: [...238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..765] - new: [...239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2099] - new: [...240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8649] - new: [...241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1111] - new: [...242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1064] - new: [...243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1095] - new: [...244] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5033] - new: [...245] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3071] - new: [...246] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6543] - new: [...247] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..808] - new: [...248] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30718] - new: [...249] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1071] - new: [...250] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7496] - new: [...251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44176] - new: [...252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1183] - new: [...253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49999] - new: [...254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8300] - new: [...255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11967] - new: [...256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3945] - new: [...257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5431] - new: [...258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8045] - new: [...259] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6788] - new: [...260] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5190] - new: [...261] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1084] - new: [...262] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6839] - new: [...263] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40911] - new: [...264] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9666] - new: [...265] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1123] - new: [...266] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6389] - new: [...267] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2525] - new: [...268] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7000] - new: [...269] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1840] - new: [...270] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..280] - new: [...271] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1131] - new: [...272] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10002] - new: [...273] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3017] - new: [...274] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..700] - new: [...275] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5500] - new: [...276] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32781] - new: [...277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1084] - new: [...278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5190] - new: [...279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6788] - new: [...280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8045] - new: [...281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5431] - new: [...282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3945] - new: [...283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11967] - new: [...284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8300] - new: [...285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49999] - new: [...286] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1183] - new: [...287] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44176] - new: [...288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5214] - new: [...289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...17] - new: [...290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6699] - new: [...291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3814] - new: [...292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24444] - new: [...293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...26] - new: [...294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3369] - new: [...295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2382] - new: [...296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..666] - new: [...297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1244] - new: [...298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3052] - new: [...299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][62078] - new: [...300] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3918] - new: [...301] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..801] - new: [...302] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19101] - new: [...303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32781] - new: [...304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5500] - new: [...305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..700] - new: [...306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3017] - new: [...307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10002] - new: [...308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1131] - new: [...309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..280] - new: [...310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1840] - new: [...311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7000] - new: [...312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2525] - new: [...313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6389] - new: [...314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1123] - new: [...315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9666] - new: [...316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40911] - new: [...317] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6839] - new: [...318] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19101] - new: [...319] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..801] - new: [...320] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3918] - new: [...321] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][62078] - new: [...322] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3052] - new: [...323] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1244] - new: [...324] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..666] - new: [...325] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2382] - new: [...326] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3369] - new: [...327] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...26] - new: [...328] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24444] - new: [...329] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3814] - new: [...330] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6699] - new: [...331] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...17] - new: [...332] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5214] - new: [...333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4899] - new: [...334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52869] - new: [...335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4006] - new: [...336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3493] - new: [...337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3737] - new: [...338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5221] - new: [...339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5080] - new: [...340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2020] - new: [...341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][48080] - new: [...342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20222] - new: [...343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5963] - new: [...344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1524] - new: [...345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1154] - new: [...346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8086] - new: [...347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1047] - new: [...348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1060] - new: [...349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2522] - new: [...350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2046] - new: [...351] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3476] - new: [...352] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2811] - new: [...353] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4129] - new: [...354] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16001] - new: [...355] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2001] - new: [...356] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5631] - new: [...357] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3827] - new: [...358] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3809] - new: [...359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5963] - new: [...360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20222] - new: [...361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][48080] - new: [...362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2020] - new: [...363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5080] - new: [...364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5221] - new: [...365] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3737] - new: [...366] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3493] - new: [...367] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4006] - new: [...368] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52869] - new: [...369] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4899] - new: [...370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44501] - new: [...371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....9] - new: [...372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1328] - new: [...373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1166] - new: [...374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4005] - new: [...375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5800] - new: [...376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1040] - new: [...377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...99] - new: [...378] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5440] - new: [...379] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27356] - new: [...380] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4111] - new: [...381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19780] - new: [...382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7800] - new: [...383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1087] - new: [...384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1666] - new: [...385] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3809] - new: [...386] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3827] - new: [...387] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5631] - new: [...388] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2001] - new: [...389] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16001] - new: [...390] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4129] - new: [...391] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2811] - new: [...392] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3476] - new: [...393] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2046] - new: [...394] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2522] - new: [...395] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1060] - new: [...396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1047] - new: [...397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8086] - new: [...398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1154] - new: [...399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1524] - new: [...400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1666] - new: [...401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1087] - new: [...402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7800] - new: [...403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19780] - new: [...404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4111] - new: [...405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27356] - new: [...406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5440] - new: [...407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...99] - new: [...408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1040] - new: [...409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5800] - new: [...410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4005] - new: [...411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1166] - new: [...412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1328] - new: [...413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....9] - new: [...414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44501] - new: [...415] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2968] - new: [...416] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2909] - new: [...417] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2393] - new: [...418] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1070] - new: [...419] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..254] - new: [...420] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3784] - new: [...421] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10009] - new: [...422] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1097] - new: [...423] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9593] - new: [...424] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1151] - new: [...425] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4224] - new: [...426] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49176] - new: [...427] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8000] - new: [...428] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1027] - new: [...429] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...30] - new: [...430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5811] - new: [...431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2260] - new: [...432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1461] - new: [...433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3000] - new: [...434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60443] - new: [...435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8400] - new: [...436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32785] - new: [...437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9110] - new: [...438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5200] - new: [...439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1048] - new: [...440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1688] - new: [...441] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4224] - new: [...442] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1151] - new: [...443] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9593] - new: [...444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1097] - new: [...445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10009] - new: [...446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3784] - new: [...447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..254] - new: [...448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1070] - new: [...449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2393] - new: [...450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2909] - new: [...451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2968] - new: [...452] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8651] - new: [...453] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1805] - new: [...454] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25734] - new: [...455] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15742] - new: [...456] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..912] - new: [...457] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..726] - new: [...458] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7741] - new: [...459] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4662] - new: [...460] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2800] - new: [...461] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6346] - new: [...462] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57797] - new: [...463] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4126] - new: [...464] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9415] - new: [...465] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2161] - new: [...466] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...82] - new: [...467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1688] - new: [...468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1048] - new: [...469] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5200] - new: [...470] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9110] - new: [...471] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32785] - new: [...472] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8400] - new: [...473] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60443] - new: [...474] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3000] - new: [...475] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1461] - new: [...476] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2260] - new: [...477] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5811] - new: [...478] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...30] - new: [...479] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1027] - new: [...480] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8000] - new: [...481] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49176] - new: [...482] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...82] - new: [...483] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2161] - new: [...484] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9415] - new: [...485] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4126] - new: [...486] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57797] - new: [...487] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6346] - new: [...488] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2800] - new: [...489] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4662] - new: [...490] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7741] - new: [...491] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..726] - new: [...492] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..912] - new: [...493] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15742] - new: [...494] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25734] - new: [...495] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1805] - new: [...496] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8651] - new: [...497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..646] - new: [...498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11111] - new: [...499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9944] - new: [...500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1862] - new: [...501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8100] - new: [...502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7911] - new: [...503] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32780] - new: [...504] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..163] - new: [...505] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3301] - new: [...506] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2200] - new: [...507] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7070] - new: [...508] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1065] - new: [...509] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32776] - new: [...510] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1259] - new: [...511] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9595] - new: [...512] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][35500] - new: [...513] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10082] - new: [...514] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....7] - new: [...515] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2013] - new: [...516] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..464] - new: [...517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6025] - new: [...518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5730] - new: [...519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8021] - new: [...520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3517] - new: [...521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1088] - new: [...522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..999] - new: [...523] [ip4][..tcp] [.....172.16.0.8][36061] -> [...64.13.134.52][..113] - new: [...524] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7070] - new: [...525] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2200] - new: [...526] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3301] - new: [...527] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..163] - new: [...528] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32780] - new: [...529] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7911] - new: [...530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8100] - new: [...531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1862] - new: [...532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9944] - new: [...533] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11111] - new: [...534] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..646] - new: [...535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5906] - new: [...536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2288] - new: [...537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1719] - new: [...538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9418] - new: [...539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10000] - new: [...540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20031] - new: [...541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4567] - new: [...542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8193] - new: [...543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1322] - new: [...544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....3] - new: [...545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1761] - new: [...546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10566] - new: [...547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1169] - new: [...548] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9220] - new: [...549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..999] - new: [...550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1088] - new: [...551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3517] - new: [...552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8021] - new: [...553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5730] - new: [...554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6025] - new: [...555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..464] - new: [...556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2013] - new: [...557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....7] - new: [...558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10082] - new: [...559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][35500] - new: [...560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9595] - new: [...561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1259] - new: [...562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32776] - new: [...563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1065] - new: [...564] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..212] - new: [...565] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65129] - new: [...566] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1185] - new: [...567] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9009] - new: [...568] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1248] - new: [...569] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1058] - new: [...570] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5988] - new: [...571] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1277] - new: [...572] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2126] - new: [...573] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1216] - new: [...574] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9091] - new: [...575] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1455] - new: [...576] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1009] - new: [...577] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10001] - new: [...578] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8292] - new: [...579] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55600] - new: [...580] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20005] - new: [...581] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1036] - new: [...582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6106] - new: [...583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7201] - new: [...584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1053] - new: [...585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32774] - new: [...586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2998] - new: [...587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2047] - new: [...588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8200] - new: [...589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..888] - new: [...590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34572] - new: [...591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1201] - new: [...592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9003] - new: [...593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3367] - new: [...594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2196] - new: [...595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2121] - new: [...596] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5850] - new: [...597] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7512] - new: [...598] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1096] - new: [...599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9220] - new: [...600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1169] - new: [...601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10566] - new: [...602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1761] - new: [...603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....3] - new: [...604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1322] - new: [...605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8193] - new: [...606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4567] - new: [...607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20031] - new: [...608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10000] - new: [...609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9418] - new: [...610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1719] - new: [...611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2288] - new: [...612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5906] - new: [...613] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7100] - new: [...614] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3851] - new: [...615] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10180] - new: [...616] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7001] - new: [...617] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4449] - new: [...618] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54328] - new: [...619] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...83] - new: [...620] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1309] - new: [...621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8009] - new: [...622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4343] - new: [...623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9050] - new: [...624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3905] - new: [...625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7625] - new: [...626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10004] - new: [...627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6779] - new: [...628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5999] - new: [...629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5810] - new: [...630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9101] - new: [...631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..749] - new: [...632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1301] - new: [...633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8002] - new: [...634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8099] - new: [...635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3030] - new: [...636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1031] - new: [...637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2048] - new: [...638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6547] - new: [...639] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1036] - new: [...640] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20005] - new: [...641] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55600] - new: [...642] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8292] - new: [...643] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10001] - new: [...644] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1009] - new: [...645] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1455] - new: [...646] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9091] - new: [...647] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1216] - new: [...648] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2126] - new: [...649] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1277] - new: [...650] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5988] - new: [...651] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1058] - new: [...652] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1248] - new: [...653] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9009] - new: [...654] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1185] - new: [...655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65129] - new: [...656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..212] - new: [...657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1096] - new: [...658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7512] - new: [...659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5850] - new: [...660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2121] - new: [...661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2196] - new: [...662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3367] - new: [...663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9003] - new: [...664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1201] - new: [...665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34572] - new: [...666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..888] - new: [...667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8200] - new: [...668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2047] - new: [...669] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2998] - new: [...670] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32774] - new: [...671] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1053] - new: [...672] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7201] - new: [...673] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6106] - new: [...674] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9050] - new: [...675] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4343] - new: [...676] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8009] - new: [...677] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1309] - new: [...678] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...83] - new: [...679] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54328] - new: [...680] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4449] - new: [...681] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7001] - new: [...682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10180] - new: [...683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3851] - new: [...684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7100] - new: [...685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1218] - new: [...686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19315] - new: [...687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19842] - new: [...688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3546] - new: [...689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1086] - new: [...690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1052] - new: [...691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3995] - new: [...692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4900] - new: [...693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30000] - new: [...694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...42] - new: [...695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51493] - new: [...696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8192] - new: [...697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1271] - new: [...698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16016] - new: [...699] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6547] - new: [...700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2048] - new: [...701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1031] - new: [...702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3030] - new: [...703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8099] - new: [...704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8002] - new: [...705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1301] - new: [...706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..749] - new: [...707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9101] - new: [...708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5810] - new: [...709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5999] - new: [...710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6779] - new: [...711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10004] - new: [...712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7625] - new: [...713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3905] - new: [...714] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1083] - new: [...715] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8701] - new: [...716] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3390] - new: [...717] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1875] - new: [...718] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1199] - new: [...719] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1721] - new: [...720] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10778] - new: [...721] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1718] - new: [...722] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16000] - new: [...723] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..125] - new: [...724] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1658] - new: [...725] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1148] - new: [...726] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..366] - new: [...727] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49165] - new: [...728] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1839] - new: [...729] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9943] - new: [...730] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2107] - new: [...731] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10617] - new: [...732] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2717] - new: [...733] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10003] - new: [...734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1041] - new: [...735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1042] - new: [...736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8082] - new: [...737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1165] - new: [...738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5405] - new: [...739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5051] - new: [...740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2383] - new: [...741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2022] - new: [...742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6510] - new: [...743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9876] - new: [...744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1072] - new: [...745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5001] - new: [...746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8181] - new: [...747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..301] - new: [...748] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1078] - new: [...749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16016] - new: [...750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1271] - new: [...751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8192] - new: [...752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51493] - new: [...753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...42] - new: [...754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30000] - new: [...755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4900] - new: [...756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3995] - new: [...757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1052] - new: [...758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1086] - new: [...759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3546] - new: [...760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19842] - new: [...761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19315] - new: [...762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1218] - new: [...763] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..109] - new: [...764] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1999] - new: [...765] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4125] - new: [...766] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12265] - new: [...767] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49163] - new: [...768] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1085] - new: [...769] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5922] - new: [...770] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32782] - new: [...771] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1079] - new: [...772] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1141] - new: [...773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..617] - new: [...774] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10617] - new: [...775] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2107] - new: [...776] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9943] - new: [...777] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1839] - new: [...778] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49165] - new: [...779] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..366] - new: [...780] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1148] - new: [...781] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1658] - new: [...782] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..125] - new: [...783] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16000] - new: [...784] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1718] - new: [...785] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10778] - new: [...786] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1721] - new: [...787] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1199] - new: [...788] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1875] - new: [...789] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3390] - new: [...790] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8701] - new: [...791] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1083] - new: [...792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32779] - new: [...793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49156] - new: [...794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5510] - new: [...795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5566] - new: [...796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9999] - new: [...797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9485] - new: [...798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3878] - new: [...799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...84] - new: [...800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3801] - new: [...801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17988] - new: [...802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49154] - new: [...803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10010] - new: [...804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5718] - new: [...805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3168] - new: [...806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3006] - new: [...807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1078] - new: [...808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..301] - new: [...809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8181] - new: [...810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5001] - new: [...811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1072] - new: [...812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9876] - new: [...813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6510] - new: [...814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2022] - new: [...815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2383] - new: [...816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5051] - new: [...817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5405] - new: [...818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1165] - new: [...819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8082] - new: [...820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1042] - new: [...821] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1041] - new: [...822] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10003] - new: [...823] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2717] - new: [...824] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..617] - new: [...825] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1141] - new: [...826] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1079] - new: [...827] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32782] - new: [...828] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5922] - new: [...829] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1085] - new: [...830] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49163] - new: [...831] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12265] - new: [...832] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4125] - new: [...833] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1999] - new: [...834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..109] - new: [...835] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5280] - new: [...836] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1066] - new: [...837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..481] - new: [...838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5901] - new: [...839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8042] - new: [...840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2967] - new: [...841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....4] - new: [...842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1082] - new: [...843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1521] - new: [...844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2100] - new: [...845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1001] - new: [...846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8090] - new: [...847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1914] - new: [...848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7937] - new: [...849] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3006] - new: [...850] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3168] - new: [...851] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5718] - new: [...852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10010] - new: [...853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49154] - new: [...854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17988] - new: [...855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3801] - new: [...856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...84] - new: [...857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3878] - new: [...858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9485] - new: [...859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9999] - new: [...860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5566] - new: [...861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5510] - new: [...862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49156] - new: [...863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32779] - new: [...864] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1029] - new: [...865] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1864] - new: [...866] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..901] - new: [...867] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..981] - new: [...868] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5560] - new: [...869] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3007] - new: [...870] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1119] - new: [...871] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55555] - new: [...872] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3766] - new: [...873] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1600] - new: [...874] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1192] - new: [...875] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12174] - new: [...876] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11110] - new: [...877] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15002] - new: [...878] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12345] - new: [...879] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9968] - new: [...880] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1974] - new: [...881] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9900] - new: [...882] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1164] - new: [...883] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..898] - new: [...884] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6881] - new: [...885] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34571] - new: [...886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..500] - new: [...887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5120] - new: [...888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18040] - new: [...889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5060] - new: [...890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3659] - new: [...891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1051] - new: [...892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..545] - new: [...893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2004] - new: [...894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1002] - new: [...895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2601] - new: [...896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1093] - new: [...897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5989] - new: [...898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4550] - new: [...899] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7937] - new: [...900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1914] - new: [...901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8090] - new: [...902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1001] - new: [...903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2100] - new: [...904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1521] - new: [...905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1082] - new: [...906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....4] - new: [...907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2967] - new: [...908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8042] - new: [...909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5901] - new: [...910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..481] - new: [...911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1066] - new: [...912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5280] - new: [...913] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7778] - new: [...914] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..987] - new: [...915] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5679] - new: [...916] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8180] - new: [...917] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4279] - new: [...918] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14441] - new: [...919] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44443] - new: [...920] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9618] - new: [...921] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2301] - new: [...922] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50800] - new: [...923] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8010] - new: [...924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9900] - new: [...925] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1974] - new: [...926] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9968] - new: [...927] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12345] - new: [...928] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15002] - new: [...929] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11110] - new: [...930] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12174] - new: [...931] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1192] - new: [...932] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1600] - new: [...933] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3766] - new: [...934] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55555] - new: [...935] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1119] - new: [...936] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3007] - new: [...937] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5560] - new: [...938] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..981] - new: [...939] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..901] - new: [...940] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1864] - new: [...941] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1029] - new: [...942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5987] - new: [...943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9502] - new: [...944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....1] - new: [...945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1046] - new: [...946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27715] - new: [...947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7002] - new: [...948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][28201] - new: [...949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1186] - new: [...950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..705] - new: [...951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2009] - new: [...952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64680] - new: [...953] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18101] - new: [...954] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49158] - new: [...955] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3971] - new: [...956] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6689] - new: [...957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4550] - new: [...958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5989] - new: [...959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1093] - new: [...960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2601] - new: [...961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1002] - new: [...962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2004] - new: [...963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..545] - new: [...964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1051] - new: [...965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3659] - new: [...966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5060] - new: [...967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18040] - new: [...968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5120] - new: [...969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..500] - new: [...970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34571] - new: [...971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6881] - new: [...972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..898] - new: [...973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1164] - new: [...974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8010] - new: [...975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50800] - new: [...976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2301] - new: [...977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9618] - new: [...978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44443] - new: [...979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14441] - new: [...980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4279] - new: [...981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8180] - new: [...982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5679] - new: [...983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..987] - new: [...984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7778] - new: [...985] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31038] - new: [...986] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12000] - new: [...987] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10616] - new: [...988] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1059] - new: [...989] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2604] - new: [...990] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50500] - new: [...991] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4443] - new: [...992] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1900] - new: [...993] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1137] - new: [...994] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9081] - new: [...995] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5802] - new: [...996] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19801] - new: [...997] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1443] - new: [...998] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32783] - new: [...999] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6689] - new: [..1000] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3971] - new: [..1001] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49158] - new: [..1002] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18101] - new: [..1003] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64680] - new: [..1004] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2009] - new: [..1005] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..705] - new: [..1006] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1186] - new: [..1007] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][28201] - new: [..1008] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7002] - new: [..1009] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27715] - new: [..1010] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1046] - new: [..1011] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....1] - new: [..1012] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9502] - new: [..1013] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5987] - new: [..1014] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1783] - new: [..1015] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4445] - new: [..1016] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2381] - new: [..1017] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][45100] - new: [..1018] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7019] - new: [..1019] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16992] - new: [..1020] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1174] - new: [..1021] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13782] - new: [..1022] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5902] - new: [..1023] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9878] - new: [..1024] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..667] - new: [..1025] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9080] - new: [..1026] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5102] - new: [..1027] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5877] - new: [..1028] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1037] - new: [..1029] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5907] - new: [..1030] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..211] - new: [..1031] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2035] - new: [..1032] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..144] - new: [..1033] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1112] - new: [..1034] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2170] - new: [..1035] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6101] - new: [..1036] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..800] - new: [..1037] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8994] - new: [..1038] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2399] - new: [..1039] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3580] - new: [..1040] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...89] - new: [..1041] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8873] - new: [..1042] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7106] - new: [..1043] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8087] - new: [..1044] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9594] - new: [..1045] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1099] - new: [..1046] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34573] - new: [..1047] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5030] - new: [..1048] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2702] - new: [..1049] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32783] - new: [..1050] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1443] - new: [..1051] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19801] - new: [..1052] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5802] - new: [..1053] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9081] - new: [..1054] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1137] - new: [..1055] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1900] - new: [..1056] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4443] - new: [..1057] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50500] - new: [..1058] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2604] - new: [..1059] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1059] - new: [..1060] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10616] - new: [..1061] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12000] - new: [..1062] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][31038] - new: [..1063] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9002] - new: [..1064] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5998] - new: [..1065] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9503] - new: [..1066] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1062] - new: [..1067] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1217] - new: [..1068] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50001] - new: [..1069] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3325] - new: [..1070] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1011] - new: [..1071] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1117] - new: [..1072] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1533] - new: [..1073] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3404] - new: [..1074] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2035] - new: [..1075] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..211] - new: [..1076] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5907] - new: [..1077] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1037] - new: [..1078] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5877] - new: [..1079] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5102] - new: [..1080] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9080] - new: [..1081] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..667] - new: [..1082] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9878] - new: [..1083] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5902] - new: [..1084] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13782] - new: [..1085] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1174] - new: [..1086] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16992] - new: [..1087] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7019] - new: [..1088] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][45100] - new: [..1089] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2381] - new: [..1090] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4445] - new: [..1091] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1783] - new: [..1092] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..902] - new: [..1093] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3690] - new: [..1094] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8089] - new: [..1095] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1010] - new: [..1096] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8402] - new: [..1097] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9090] - new: [..1098] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3527] - new: [..1099] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..992] - new: [..1100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8652] - new: [..1101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..255] - new: [..1102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33354] - new: [..1103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1050] - new: [..1104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1782] - new: [..1105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..406] - new: [..1106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][22939] - new: [..1107] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2702] - new: [..1108] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5030] - new: [..1109] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34573] - new: [..1110] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1099] - new: [..1111] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9594] - new: [..1112] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8087] - new: [..1113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7106] - new: [..1114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8873] - new: [..1115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...89] - new: [..1116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3580] - new: [..1117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2399] - new: [..1118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8994] - new: [..1119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..800] - new: [..1120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6101] - new: [..1121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2170] - new: [..1122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1112] - new: [..1123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..144] - new: [..1124] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3404] - new: [..1125] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1533] - new: [..1126] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1117] - new: [..1127] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1011] - new: [..1128] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3325] - new: [..1129] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50001] - new: [..1130] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1217] - new: [..1131] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1062] - new: [..1132] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9503] - new: [..1133] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5998] - new: [..1134] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9002] - new: [..1135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..524] - new: [..1136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5100] - new: [..1137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1091] - new: [..1138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15000] - new: [..1139] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...19] - new: [..1140] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2042] - new: [..1141] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1138] - new: [..1142] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5960] - new: [..1143] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2144] - new: [..1144] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1106] - new: [..1145] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4446] - new: [..1146] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5432] - new: [..1147] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8085] - new: [..1148] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2119] - new: [..1149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][22939] - new: [..1150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..406] - new: [..1151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1782] - new: [..1152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1050] - new: [..1153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33354] - new: [..1154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..255] - new: [..1155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8652] - new: [..1156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..992] - new: [..1157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3527] - new: [..1158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9090] - new: [..1159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8402] - new: [..1160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1010] - new: [..1161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8089] - new: [..1162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3690] - new: [..1163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..902] - new: [..1164] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1971] - new: [..1165] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5222] - new: [..1166] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1100] - new: [..1167] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6668] - new: [..1168] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8600] - new: [..1169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5000] - new: [..1170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..714] - new: [..1171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7921] - new: [..1172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6112] - new: [..1173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50300] - new: [..1174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6156] - new: [..1175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13783] - new: [..1176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8007] - new: [..1177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32773] - new: [..1178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1105] - new: [..1179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5050] - new: [..1180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1175] - new: [..1181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3260] - new: [..1182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9001] - new: [..1183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15003] - new: [..1184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...70] - new: [..1185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2003] - new: [..1186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1030] - new: [..1187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..543] - new: [..1188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1132] - new: [..1189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64623] - new: [..1190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6007] - new: [..1191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3300] - new: [..1192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..222] - new: [..1193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8194] - new: [..1194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10628] - new: [..1195] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4444] - new: [..1196] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...79] - new: [..1197] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7938] - new: [..1198] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1032] - new: [..1199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2119] - new: [..1200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8085] - new: [..1201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5432] - new: [..1202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4446] - new: [..1203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1106] - new: [..1204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2144] - new: [..1205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5960] - new: [..1206] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1138] - new: [..1207] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2042] - new: [..1208] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...19] - new: [..1209] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15000] - new: [..1210] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1091] - new: [..1211] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5100] - new: [..1212] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..524] - new: [..1213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1272] - new: [..1214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8899] - new: [..1215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1121] - new: [..1216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10024] - new: [..1217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6003] - new: [..1218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8088] - new: [..1219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][41511] - new: [..1220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5298] - new: [..1221] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1717] - new: [..1222] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...43] - new: [..1223] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1122] - new: [..1224] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..711] - new: [..1225] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32769] - new: [..1226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3260] - new: [..1227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1175] - new: [..1228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5050] - new: [..1229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1105] - new: [..1230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32773] - new: [..1231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8007] - new: [..1232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13783] - new: [..1233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6156] - new: [..1234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50300] - new: [..1235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6112] - new: [..1236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7921] - new: [..1237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..714] - new: [..1238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5000] - new: [..1239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8600] - new: [..1240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6668] - new: [..1241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1100] - new: [..1242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5222] - new: [..1243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1971] - new: [..1244] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1501] - new: [..1245] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2602] - new: [..1246] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1163] - new: [..1247] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1045] - new: [..1248] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..106] - new: [..1249] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1061] - new: [..1250] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1972] - new: [..1251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3800] - new: [..1252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1124] - new: [..1253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27000] - new: [..1254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5544] - new: [..1255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7025] - new: [..1256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3551] - new: [..1257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1098] - new: [..1258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2041] - new: [..1259] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7938] - new: [..1260] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...79] - new: [..1261] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4444] - new: [..1262] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10628] - new: [..1263] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8194] - new: [..1264] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..222] - new: [..1265] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3300] - new: [..1266] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6007] - new: [..1267] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64623] - new: [..1268] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1132] - new: [..1269] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..543] - new: [..1270] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1030] - new: [..1271] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2003] - new: [..1272] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15003] - new: [..1273] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9001] - new: [..1274] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1032] - new: [..1275] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1122] - new: [..1276] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...43] - new: [..1277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1717] - new: [..1278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5298] - new: [..1279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][41511] - new: [..1280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8088] - new: [..1281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6003] - new: [..1282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10024] - new: [..1283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1121] - new: [..1284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8899] - new: [..1285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1272] - new: [..1286] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2179] - new: [..1287] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5087] - new: [..1288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44442] - new: [..1289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..427] - new: [..1290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4004] - new: [..1291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2394] - new: [..1292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5952] - new: [..1293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2608] - new: [..1294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..458] - new: [..1295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1068] - new: [..1296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1700] - new: [..1297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..691] - new: [..1298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5910] - new: [..1299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9103] - new: [..1300] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32769] - new: [..1301] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..711] - new: [..1302] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2041] - new: [..1303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1098] - new: [..1304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3551] - new: [..1305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7025] - new: [..1306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5544] - new: [..1307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27000] - new: [..1308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1124] - new: [..1309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3800] - new: [..1310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1972] - new: [..1311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1061] - new: [..1312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..106] - new: [..1313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1045] - new: [..1314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1163] - new: [..1315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2602] - new: [..1316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1501] - new: [..1317] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][38292] - new: [..1318] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..416] - new: [..1319] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1998] - new: [..1320] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...20] - new: [..1321] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1287] - new: [..1322] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57294] - new: [..1323] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..541] - new: [..1324] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1352] - new: [..1325] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3283] - new: [..1326] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1145] - new: [..1327] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2191] - new: [..1328] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20000] - new: [..1329] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1035] - new: [..1330] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...88] - new: [..1331] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1055] - new: [..1332] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32772] - new: [..1333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1077] - new: [..1334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6566] - new: [..1335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56737] - new: [..1336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5961] - new: [..1337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][58080] - new: [..1338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9207] - new: [..1339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1126] - new: [..1340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19283] - new: [..1341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..513] - new: [..1342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..722] - new: [..1343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49153] - new: [..1344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8001] - new: [..1345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3370] - new: [..1346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4242] - new: [..1347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6009] - new: [..1348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3869] - new: [..1349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1069] - new: [..1350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16113] - new: [..1351] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9103] - new: [..1352] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5910] - new: [..1353] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..691] - new: [..1354] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1700] - new: [..1355] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1068] - new: [..1356] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..458] - new: [..1357] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2608] - new: [..1358] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5952] - new: [..1359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2394] - new: [..1360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4004] - new: [..1361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..427] - new: [..1362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44442] - new: [..1363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5087] - new: [..1364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2179] - new: [..1365] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...81] - new: [..1366] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3221] - new: [..1367] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2557] - new: [..1368] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...37] - new: [..1369] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2135] - new: [..1370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2809] - new: [..1371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51103] - new: [..1372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3871] - new: [..1373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...13] - new: [..1374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5801] - new: [..1375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3322] - new: [..1376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2021] - new: [..1377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3333] - new: [..1378] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1998] - new: [..1379] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..416] - new: [..1380] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][38292] - new: [..1381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6100] - new: [..1382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..720] - new: [..1383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8031] - new: [..1384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..146] - new: [..1385] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..407] - new: [..1386] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3323] - new: [..1387] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24800] - new: [..1388] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7999] - new: [..1389] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19350] - new: [..1390] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61900] - new: [..1391] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..593] - new: [..1392] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6002] - new: [..1393] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1310] - new: [..1394] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8008] - new: [..1395] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1114] - new: [..1396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1069] - new: [..1397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3869] - new: [..1398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6009] - new: [..1399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4242] - new: [..1400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3370] - new: [..1401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8001] - new: [..1402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49153] - new: [..1403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..722] - new: [..1404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..513] - new: [..1405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19283] - new: [..1406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1126] - new: [..1407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9207] - new: [..1408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][58080] - new: [..1409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5961] - new: [..1410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56737] - new: [..1411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6566] - new: [..1412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1077] - new: [..1413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32772] - new: [..1414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1055] - new: [..1415] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...88] - new: [..1416] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1035] - new: [..1417] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20000] - new: [..1418] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2191] - new: [..1419] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1145] - new: [..1420] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3283] - new: [..1421] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1352] - new: [..1422] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..541] - new: [..1423] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57294] - new: [..1424] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1287] - new: [..1425] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...20] - new: [..1426] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16113] - new: [..1427] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2557] - new: [..1428] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3221] - new: [..1429] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...81] - new: [..1430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3889] - new: [..1431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6565] - new: [..1432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2007] - new: [..1433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3269] - new: [..1434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1000] - new: [..1435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2492] - new: [..1436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2710] - new: [..1437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5004] - new: [..1438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7443] - new: [..1439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27352] - new: [..1440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7004] - new: [..1441] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52673] - new: [..1442] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8081] - new: [..1443] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49175] - new: [..1444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3322] - new: [..1445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5801] - new: [..1446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...13] - new: [..1447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3871] - new: [..1448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51103] - new: [..1449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2809] - new: [..1450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2135] - new: [..1451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...37] - new: [..1452] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3333] - new: [..1453] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2021] - new: [..1454] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1114] - new: [..1455] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8008] - new: [..1456] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1310] - new: [..1457] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6002] - new: [..1458] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..593] - new: [..1459] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61900] - new: [..1460] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19350] - new: [..1461] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7999] - new: [..1462] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24800] - new: [..1463] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3323] - new: [..1464] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..407] - new: [..1465] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..146] - new: [..1466] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8031] - new: [..1467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..720] - new: [..1468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6100] - new: [..1469] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5815] - new: [..1470] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8500] - new: [..1471] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1026] - new: [..1472] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16012] - new: [..1473] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40193] - new: [..1474] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1947] - new: [..1475] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5666] - new: [..1476] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5226] - new: [..1477] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9040] - new: [..1478] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8011] - new: [..1479] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..417] - new: [..1480] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32771] - new: [..1481] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6001] - new: [..1482] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1503] - new: [..1483] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1076] - new: [..1484] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4002] - new: [..1485] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...49] - new: [..1486] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2111] - new: [..1487] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..264] - new: [..1488] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1500] - new: [..1489] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49161] - new: [..1490] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1081] - new: [..1491] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2500] - new: [..1492] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6567] - new: [..1493] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1033] - new: [..1494] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..631] - new: [..1495] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..648] - new: [..1496] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2002] - new: [..1497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..340] - new: [..1498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7435] - new: [..1499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6792] - new: [..1500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..783] - new: [..1501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1147] - new: [..1502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54045] - new: [..1503] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49175] - new: [..1504] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8081] - new: [..1505] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52673] - new: [..1506] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7004] - new: [..1507] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27352] - new: [..1508] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7443] - new: [..1509] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5004] - new: [..1510] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2710] - new: [..1511] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2492] - new: [..1512] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1000] - new: [..1513] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3269] - new: [..1514] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2007] - new: [..1515] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6565] - new: [..1516] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3889] - new: [..1517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1113] - new: [..1518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3986] - new: [..1519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8443] - new: [..1520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1054] - new: [..1521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][21571] - new: [..1522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5950] - new: [..1523] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9100] - new: [..1524] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49400] - new: [..1525] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1130] - new: [..1526] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2875] - new: [..1527] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32784] - new: [..1528] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1556] - new: [..1529] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1022] - new: [..1530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1026] - new: [..1531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8500] - new: [..1532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5815] - new: [..1533] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1102] - new: [..1534] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55055] - new: [..1535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3371] - new: [..1536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10025] - new: [..1537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..616] - new: [..1538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1039] - new: [..1539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7627] - new: [..1540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10215] - new: [..1541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6692] - new: [..1542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5009] - new: [..1543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2323] - new: [..1544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8290] - new: [..1545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2043] - new: [..1546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1034] - new: [..1547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1935] - new: [..1548] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1147] - new: [..1549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..783] - new: [..1550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6792] - new: [..1551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7435] - new: [..1552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..340] - new: [..1553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2002] - new: [..1554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..648] - new: [..1555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..631] - new: [..1556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1033] - new: [..1557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6567] - new: [..1558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2500] - new: [..1559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1081] - new: [..1560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49161] - new: [..1561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1500] - new: [..1562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..264] - new: [..1563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2111] - new: [..1564] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...49] - new: [..1565] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4002] - new: [..1566] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1076] - new: [..1567] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1503] - new: [..1568] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6001] - new: [..1569] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32771] - new: [..1570] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..417] - new: [..1571] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8011] - new: [..1572] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9040] - new: [..1573] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5226] - new: [..1574] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5666] - new: [..1575] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1947] - new: [..1576] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40193] - new: [..1577] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16012] - new: [..1578] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54045] - new: [..1579] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8443] - new: [..1580] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3986] - new: [..1581] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1113] - new: [..1582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1107] - new: [..1583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..636] - new: [..1584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5054] - new: [..1585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1334] - new: [..1586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1023] - new: [..1587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..903] - new: [..1588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..100] - new: [..1589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3703] - new: [..1590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1028] - new: [..1591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..900] - new: [..1592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..873] - new: [..1593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..119] - new: [..1594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][26214] - new: [..1595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20828] - new: [..1596] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32784] - new: [..1597] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2875] - new: [..1598] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1130] - new: [..1599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49400] - new: [..1600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9100] - new: [..1601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5950] - new: [..1602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][21571] - new: [..1603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1054] - new: [..1604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1022] - new: [..1605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1556] - new: [..1606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1935] - new: [..1607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1034] - new: [..1608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2043] - new: [..1609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8290] - new: [..1610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2323] - new: [..1611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5009] - new: [..1612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6692] - new: [..1613] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10215] - new: [..1614] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7627] - new: [..1615] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1039] - new: [..1616] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..616] - new: [..1617] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10025] - new: [..1618] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3371] - new: [..1619] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55055] - new: [..1620] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1102] - new: [..1621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5550] - new: [..1622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2638] - new: [..1623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..515] - new: [..1624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..555] - new: [..1625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..880] - new: [..1626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1755] - new: [..1627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49159] - new: [..1628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8254] - new: [..1629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1090] - new: [..1630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3324] - new: [..1631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2000] - new: [..1632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50003] - new: [..1633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9535] - new: [..1634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..161] - new: [..1635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9000] - new: [..1636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2105] - new: [..1637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1213] - new: [..1638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18988] - new: [..1639] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..668] - new: [..1640] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...33] - new: [..1641] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5859] - new: [..1642] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32777] - new: [..1643] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56738] - new: [..1644] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9099] - new: [..1645] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4045] - new: [..1646] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1094] - new: [..1647] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2068] - new: [..1648] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8083] - new: [..1649] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..777] - new: [..1650] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1074] - new: [..1651] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13722] - new: [..1652] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3920] - new: [..1653] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5904] - new: [..1654] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..787] - new: [..1655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20828] - new: [..1656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][26214] - new: [..1657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..119] - new: [..1658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..873] - new: [..1659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..900] - new: [..1660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1028] - new: [..1661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3703] - new: [..1662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..100] - new: [..1663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..903] - new: [..1664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1023] - new: [..1665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1334] - new: [..1666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5054] - new: [..1667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..636] - new: [..1668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1107] - new: [..1669] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8383] - new: [..1670] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..544] - new: [..1671] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9111] - new: [..1672] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..444] - new: [..1673] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3211] - new: [..1674] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20221] - new: [..1675] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6667] - new: [..1676] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7103] - new: [..1677] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2010] - new: [..1678] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30951] - new: [..1679] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1089] - new: [..1680] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2910] - new: [..1681] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5357] - new: [..1682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..515] - new: [..1683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2638] - new: [..1684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5550] - new: [..1685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6901] - new: [..1686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25735] - new: [..1687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6969] - new: [..1688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3003] - new: [..1689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3011] - new: [..1690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50002] - new: [..1691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9998] - new: [..1692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3998] - new: [..1693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2006] - new: [..1694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1080] - new: [..1695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6006] - new: [..1696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3005] - new: [..1697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5633] - new: [..1698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7402] - new: [..1699] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4321] - new: [..1700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5859] - new: [..1701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...33] - new: [..1702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..668] - new: [..1703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18988] - new: [..1704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1213] - new: [..1705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2105] - new: [..1706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9000] - new: [..1707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..161] - new: [..1708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9535] - new: [..1709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50003] - new: [..1710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2000] - new: [..1711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3324] - new: [..1712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1090] - new: [..1713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8254] - new: [..1714] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49159] - new: [..1715] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1755] - new: [..1716] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..880] - new: [..1717] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..555] - new: [..1718] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5904] - new: [..1719] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3920] - new: [..1720] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13722] - new: [..1721] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1074] - new: [..1722] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..777] - new: [..1723] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8083] - new: [..1724] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2068] - new: [..1725] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1094] - new: [..1726] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4045] - new: [..1727] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9099] - new: [..1728] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56738] - new: [..1729] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32777] - new: [..1730] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..787] - new: [..1731] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9111] - new: [..1732] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..544] - new: [..1733] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8383] - new: [..1734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50000] - new: [..1735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6129] - new: [..1736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3351] - new: [..1737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52822] - new: [..1738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16018] - new: [..1739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49167] - new: [..1740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6789] - new: [..1741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6004] - new: [..1742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1057] - new: [..1743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3914] - new: [..1744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65389] - new: [..1745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6502] - new: [..1746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16993] - new: [..1747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1149] - new: [..1748] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1089] - new: [..1749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30951] - new: [..1750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2010] - new: [..1751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7103] - new: [..1752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6667] - new: [..1753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20221] - new: [..1754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3211] - new: [..1755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..444] - new: [..1756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5357] - new: [..1757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2910] - new: [..1758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4321] - new: [..1759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7402] - new: [..1760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5633] - new: [..1761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3005] - new: [..1762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6006] - new: [..1763] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1080] - new: [..1764] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2006] - new: [..1765] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3998] - new: [..1766] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9998] - new: [..1767] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50002] - new: [..1768] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3011] - new: [..1769] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3003] - new: [..1770] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6969] - new: [..1771] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25735] - new: [..1772] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6901] - new: [..1773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1494] - new: [..1774] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5911] - new: [..1775] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32770] - new: [..1776] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][63331] - new: [..1777] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1434] - new: [..1778] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5061] - new: [..1779] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2045] - new: [..1780] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..911] - new: [..1781] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6059] - new: [..1782] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1198] - new: [..1783] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9011] - new: [..1784] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1580] - new: [..1785] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2040] - new: [..1786] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6123] - new: [..1787] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3828] - new: [..1788] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8333] - new: [..1789] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8022] - new: [..1790] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5555] - new: [..1791] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55056] - new: [..1792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2160] - new: [..1793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8654] - new: [..1794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50006] - new: [..1795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2366] - new: [..1796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][23502] - new: [..1797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1063] - new: [..1798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5003] - new: [..1799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50636] - new: [..1800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1152] - new: [..1801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27353] - new: [..1802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7007] - new: [..1803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5915] - new: [..1804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1234] - new: [..1805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5925] - new: [..1806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50389] - new: [..1807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1149] - new: [..1808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16993] - new: [..1809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6502] - new: [..1810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65389] - new: [..1811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3914] - new: [..1812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1057] - new: [..1813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6004] - new: [..1814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6789] - new: [..1815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49167] - new: [..1816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16018] - new: [..1817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52822] - new: [..1818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3351] - new: [..1819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6129] - new: [..1820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50000] - new: [..1821] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1038] - new: [..1822] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2008] - new: [..1823] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1236] - new: [..1824] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...85] - new: [..1825] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2049] - new: [..1826] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6646] - new: [..1827] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1007] - new: [..1828] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1108] - new: [..1829] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][42510] - new: [..1830] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..465] - new: [..1831] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3128] - new: [..1832] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..625] - new: [..1833] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2065] - new: [..1834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32770] - new: [..1835] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5911] - new: [..1836] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1494] - new: [..1837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2920] - new: [..1838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3689] - new: [..1839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5678] - new: [..1840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2607] - new: [..1841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1801] - new: [..1842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4001] - new: [..1843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32775] - new: [..1844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..389] - new: [..1845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3372] - new: [..1846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..687] - new: [..1847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7920] - new: [..1848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49160] - new: [..1849] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3013] - new: [..1850] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5225] - new: [..1851] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2251] - new: [..1852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5925] - new: [..1853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1234] - new: [..1854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5915] - new: [..1855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7007] - new: [..1856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27353] - new: [..1857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1152] - new: [..1858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50636] - new: [..1859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5003] - new: [..1860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1063] - new: [..1861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][23502] - new: [..1862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2366] - new: [..1863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50006] - new: [..1864] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8654] - new: [..1865] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2160] - new: [..1866] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55056] - new: [..1867] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5555] - new: [..1868] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8022] - new: [..1869] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8333] - new: [..1870] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3828] - new: [..1871] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6123] - new: [..1872] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2040] - new: [..1873] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1580] - new: [..1874] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9011] - new: [..1875] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1198] - new: [..1876] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6059] - new: [..1877] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..911] - new: [..1878] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2045] - new: [..1879] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5061] - new: [..1880] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1434] - new: [..1881] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][63331] - new: [..1882] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50389] - new: [..1883] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1236] - new: [..1884] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2008] - new: [..1885] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1038] - new: [..1886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..259] - new: [..1887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10243] - new: [..1888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2033] - new: [..1889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5862] - new: [..1890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8093] - new: [..1891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..179] - new: [..1892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1984] - new: [..1893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9877] - new: [..1894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..563] - new: [..1895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...90] - new: [..1896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8084] - new: [..1897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2725] - new: [..1898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..311] - new: [..1899] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6666] - new: [..1900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3128] - new: [..1901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..465] - new: [..1902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][42510] - new: [..1903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1108] - new: [..1904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1007] - new: [..1905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6646] - new: [..1906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2049] - new: [..1907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...85] - new: [..1908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2065] - new: [..1909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..625] - new: [..1910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2251] - new: [..1911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5225] - new: [..1912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3013] - new: [..1913] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49160] - new: [..1914] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7920] - new: [..1915] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..687] - new: [..1916] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3372] - new: [..1917] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..389] - new: [..1918] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32775] - new: [..1919] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4001] - new: [..1920] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1801] - new: [..1921] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2607] - new: [..1922] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5678] - new: [..1923] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3689] - new: [..1924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2920] - new: [..1925] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10012] - new: [..1926] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1021] - new: [..1927] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60020] - new: [..1928] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4998] - new: [..1929] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5002] - new: [..1930] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1092] - new: [..1931] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2103] - new: [..1932] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1049] - new: [..1933] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8800] - new: [..1934] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9290] - new: [..1935] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49152] - new: [..1936] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1863] - new: [..1937] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2401] - new: [..1938] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3031] - new: [..1939] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..306] - new: [..1940] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1812] - new: [..1941] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1104] - new: [..1942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2718] - new: [..1943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1110] - new: [..1944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6005] - new: [..1945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2034] - new: [..1946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5269] - new: [..1947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5962] - new: [..1948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3268] - new: [..1949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1044] - new: [..1950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..512] - new: [..1951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49157] - new: [..1952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3261] - new: [..1953] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6666] - new: [..1954] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..311] - new: [..1955] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2725] - new: [..1956] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8084] - new: [..1957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...90] - new: [..1958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..563] - new: [..1959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9877] - new: [..1960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1984] - new: [..1961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..179] - new: [..1962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8093] - new: [..1963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5862] - new: [..1964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2033] - new: [..1965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10243] - new: [..1966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..259] - new: [..1967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60020] - new: [..1968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1021] - new: [..1969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10012] - new: [..1970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3261] - new: [..1971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49157] - new: [..1972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..512] - new: [..1973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1044] - new: [..1974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3268] - new: [..1975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5962] - new: [..1976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5269] - new: [..1977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2034] - new: [..1978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6005] - new: [..1979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1110] - new: [..1980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2718] - new: [..1981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1104] - new: [..1982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1812] - new: [..1983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..306] - new: [..1984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3031] - new: [..1985] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2401] - new: [..1986] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1863] - new: [..1987] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49152] - new: [..1988] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9290] - new: [..1989] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8800] - new: [..1990] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1049] - new: [..1991] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2103] - new: [..1992] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1092] - new: [..1993] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5002] - new: [..1994] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4998] + new: [.....1] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..443] + new: [.....2] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..143] + new: [.....3] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3306] + new: [.....4] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..199] + new: [.....5] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..111] + new: [.....6] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1025] + new: [.....7] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..995] + new: [.....8] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..587] + new: [.....9] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...53] + new: [....10] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5900] + new: [....11] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...21] + new: [....12] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..113] + new: [....13] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...80] + new: [....14] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..139] + new: [....15] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3389] + new: [....16] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...23] + new: [....17] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...23] + new: [....18] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3389] + new: [....19] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..139] + new: [....20] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...21] + new: [....21] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5900] + new: [....22] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..587] + new: [....23] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..995] + new: [....24] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1025] + new: [....25] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..111] + new: [....26] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..199] + new: [....27] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3306] + new: [....28] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..143] + new: [....29] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..443] + new: [....30] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1723] + new: [....31] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..993] + new: [....32] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..110] + new: [....33] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8080] + new: [....34] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1720] + new: [....35] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...25] + new: [....36] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..445] + new: [....37] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..256] + new: [....38] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..554] + new: [....39] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..135] + new: [....40] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...22] + new: [....41] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8888] + new: [....42] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..548] + new: [....43] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1056] + new: [....44] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10629] + new: [....45] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2605] + new: [....46] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10621] + new: [....47] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..990] + new: [....48] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5414] + new: [....49] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2222] + new: [....50] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6000] + new: [....51] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1687] + new: [....52] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1233] + new: [....53] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2030] + new: [....54] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....6] + new: [....55] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1417] + new: [....56] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8222] + new: [....57] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..683] + new: [....58] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3050] + new: [....59] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..548] + new: [....60] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8888] + new: [....61] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..135] + new: [....62] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..554] + new: [....63] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..256] + new: [....64] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..445] + new: [....65] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1720] + new: [....66] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8080] + new: [....67] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..110] + new: [....68] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..993] + new: [....69] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1723] + new: [....70] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3050] + new: [....71] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..683] + new: [....72] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8222] + new: [....73] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1417] + new: [....74] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....6] + new: [....75] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2030] + new: [....76] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1233] + new: [....77] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1687] + new: [....78] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6000] + new: [....79] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2222] + new: [....80] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5414] + new: [....81] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..990] + new: [....82] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10621] + new: [....83] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2605] + new: [....84] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10629] + new: [....85] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1056] + new: [....86] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2038] + new: [....87] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14238] + new: [....88] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..514] + new: [....89] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3880] + new: [....90] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17877] + new: [....91] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7777] + new: [....92] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4848] + new: [....93] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32778] + new: [....94] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16080] + new: [....95] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1594] + new: [....96] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65000] + new: [....97] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1075] + new: [....98] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1300] + new: [....99] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2701] + new: [...100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..843] + new: [...101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2005] + new: [...102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9200] + new: [...103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5903] + new: [...104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1067] + new: [...105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4003] + new: [...106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33899] + new: [...107] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7676] + new: [...108] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14442] + new: [...109] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31337] + new: [...110] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1247] + new: [...111] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1311] + new: [...112] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9917] + new: [...113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65000] + new: [...114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1594] + new: [...115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16080] + new: [...116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32778] + new: [...117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4848] + new: [...118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7777] + new: [...119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17877] + new: [...120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3880] + new: [...121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..514] + new: [...122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14238] + new: [...123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2038] + new: [...124] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8291] + new: [...125] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3826] + new: [...126] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3077] + new: [...127] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1187] + new: [...128] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7200] + new: [...129] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5822] + new: [...130] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1024] + new: [...131] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10626] + new: [...132] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...32] + new: [...133] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15004] + new: [...134] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52848] + new: [...135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...24] + new: [...136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5101] + new: [...137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1296] + new: [...138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9102] + new: [...139] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9917] + new: [...140] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1311] + new: [...141] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1247] + new: [...142] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14442] + new: [...143] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7676] + new: [...144] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33899] + new: [...145] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4003] + new: [...146] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1067] + new: [...147] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5903] + new: [...148] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9200] + new: [...149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2005] + new: [...150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..843] + new: [...151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2701] + new: [...152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1300] + new: [...153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1075] + new: [...154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9102] + new: [...155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1296] + new: [...156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5101] + new: [...157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...24] + new: [...158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52848] + new: [...159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15004] + new: [...160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...32] + new: [...161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10626] + new: [...162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1024] + new: [...163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5822] + new: [...164] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7200] + new: [...165] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1187] + new: [...166] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3077] + new: [...167] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3826] + new: [...168] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8291] + new: [...169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5959] + new: [...170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..425] + new: [...171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9500] + new: [...172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14000] + new: [...173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15660] + new: [...174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13456] + new: [...175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1073] + new: [...176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2106] + new: [...177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61532] + new: [...178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..497] + new: [...179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2869] + new: [...180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6669] + new: [...181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1433] + new: [...182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4000] + new: [...183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1043] + new: [...184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9575] + new: [...185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32768] + new: [...186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1641] + new: [...187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5825] + new: [...188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9898] + new: [...189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27355] + new: [...190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1583] + new: [...191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6580] + new: [...192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3001] + new: [...193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2190] + new: [...194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49155] + new: [...195] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2869] + new: [...196] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..497] + new: [...197] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61532] + new: [...198] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2106] + new: [...199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1073] + new: [...200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13456] + new: [...201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15660] + new: [...202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14000] + new: [...203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9500] + new: [...204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..425] + new: [...205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5959] + new: [...206] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7496] + new: [...207] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1071] + new: [...208] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30718] + new: [...209] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..808] + new: [...210] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6543] + new: [...211] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3071] + new: [...212] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5033] + new: [...213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1095] + new: [...214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1064] + new: [...215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1111] + new: [...216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8649] + new: [...217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2099] + new: [...218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..765] + new: [...219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9010] + new: [...220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9071] + new: [...221] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49155] + new: [...222] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2190] + new: [...223] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3001] + new: [...224] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6580] + new: [...225] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1583] + new: [...226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27355] + new: [...227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9898] + new: [...228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5825] + new: [...229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1641] + new: [...230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32768] + new: [...231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9575] + new: [...232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1043] + new: [...233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4000] + new: [...234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1433] + new: [...235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6669] + new: [...236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9071] + new: [...237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9010] + new: [...238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..765] + new: [...239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2099] + new: [...240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8649] + new: [...241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1111] + new: [...242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1064] + new: [...243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1095] + new: [...244] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5033] + new: [...245] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3071] + new: [...246] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6543] + new: [...247] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..808] + new: [...248] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30718] + new: [...249] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1071] + new: [...250] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7496] + new: [...251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44176] + new: [...252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1183] + new: [...253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49999] + new: [...254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8300] + new: [...255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11967] + new: [...256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3945] + new: [...257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5431] + new: [...258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8045] + new: [...259] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6788] + new: [...260] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5190] + new: [...261] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1084] + new: [...262] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6839] + new: [...263] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40911] + new: [...264] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9666] + new: [...265] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1123] + new: [...266] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6389] + new: [...267] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2525] + new: [...268] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7000] + new: [...269] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1840] + new: [...270] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..280] + new: [...271] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1131] + new: [...272] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10002] + new: [...273] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3017] + new: [...274] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..700] + new: [...275] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5500] + new: [...276] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32781] + new: [...277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1084] + new: [...278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5190] + new: [...279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6788] + new: [...280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8045] + new: [...281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5431] + new: [...282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3945] + new: [...283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11967] + new: [...284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8300] + new: [...285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49999] + new: [...286] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1183] + new: [...287] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44176] + new: [...288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5214] + new: [...289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...17] + new: [...290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6699] + new: [...291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3814] + new: [...292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24444] + new: [...293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...26] + new: [...294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3369] + new: [...295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2382] + new: [...296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..666] + new: [...297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1244] + new: [...298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3052] + new: [...299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][62078] + new: [...300] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3918] + new: [...301] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..801] + new: [...302] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19101] + new: [...303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32781] + new: [...304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5500] + new: [...305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..700] + new: [...306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3017] + new: [...307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10002] + new: [...308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1131] + new: [...309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..280] + new: [...310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1840] + new: [...311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7000] + new: [...312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2525] + new: [...313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6389] + new: [...314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1123] + new: [...315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9666] + new: [...316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40911] + new: [...317] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6839] + new: [...318] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19101] + new: [...319] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..801] + new: [...320] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3918] + new: [...321] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][62078] + new: [...322] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3052] + new: [...323] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1244] + new: [...324] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..666] + new: [...325] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2382] + new: [...326] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3369] + new: [...327] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...26] + new: [...328] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24444] + new: [...329] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3814] + new: [...330] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6699] + new: [...331] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...17] + new: [...332] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5214] + new: [...333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4899] + new: [...334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52869] + new: [...335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4006] + new: [...336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3493] + new: [...337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3737] + new: [...338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5221] + new: [...339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5080] + new: [...340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2020] + new: [...341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][48080] + new: [...342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20222] + new: [...343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5963] + new: [...344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1524] + new: [...345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1154] + new: [...346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8086] + new: [...347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1047] + new: [...348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1060] + new: [...349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2522] + new: [...350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2046] + new: [...351] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3476] + new: [...352] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2811] + new: [...353] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4129] + new: [...354] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16001] + new: [...355] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2001] + new: [...356] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5631] + new: [...357] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3827] + new: [...358] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3809] + new: [...359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5963] + new: [...360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20222] + new: [...361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][48080] + new: [...362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2020] + new: [...363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5080] + new: [...364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5221] + new: [...365] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3737] + new: [...366] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3493] + new: [...367] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4006] + new: [...368] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52869] + new: [...369] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4899] + new: [...370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44501] + new: [...371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....9] + new: [...372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1328] + new: [...373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1166] + new: [...374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4005] + new: [...375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5800] + new: [...376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1040] + new: [...377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...99] + new: [...378] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5440] + new: [...379] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27356] + new: [...380] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4111] + new: [...381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19780] + new: [...382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7800] + new: [...383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1087] + new: [...384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1666] + new: [...385] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3809] + new: [...386] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3827] + new: [...387] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5631] + new: [...388] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2001] + new: [...389] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16001] + new: [...390] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4129] + new: [...391] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2811] + new: [...392] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3476] + new: [...393] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2046] + new: [...394] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2522] + new: [...395] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1060] + new: [...396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1047] + new: [...397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8086] + new: [...398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1154] + new: [...399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1524] + new: [...400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1666] + new: [...401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1087] + new: [...402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7800] + new: [...403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19780] + new: [...404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4111] + new: [...405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27356] + new: [...406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5440] + new: [...407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...99] + new: [...408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1040] + new: [...409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5800] + new: [...410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4005] + new: [...411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1166] + new: [...412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1328] + new: [...413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....9] + new: [...414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44501] + new: [...415] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2968] + new: [...416] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2909] + new: [...417] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2393] + new: [...418] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1070] + new: [...419] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..254] + new: [...420] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3784] + new: [...421] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10009] + new: [...422] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1097] + new: [...423] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9593] + new: [...424] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1151] + new: [...425] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4224] + new: [...426] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49176] + new: [...427] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8000] + new: [...428] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1027] + new: [...429] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...30] + new: [...430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5811] + new: [...431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2260] + new: [...432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1461] + new: [...433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3000] + new: [...434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60443] + new: [...435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8400] + new: [...436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32785] + new: [...437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9110] + new: [...438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5200] + new: [...439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1048] + new: [...440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1688] + new: [...441] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4224] + new: [...442] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1151] + new: [...443] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9593] + new: [...444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1097] + new: [...445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10009] + new: [...446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3784] + new: [...447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..254] + new: [...448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1070] + new: [...449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2393] + new: [...450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2909] + new: [...451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2968] + new: [...452] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8651] + new: [...453] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1805] + new: [...454] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25734] + new: [...455] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15742] + new: [...456] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..912] + new: [...457] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..726] + new: [...458] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7741] + new: [...459] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4662] + new: [...460] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2800] + new: [...461] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6346] + new: [...462] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57797] + new: [...463] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4126] + new: [...464] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9415] + new: [...465] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2161] + new: [...466] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...82] + new: [...467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1688] + new: [...468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1048] + new: [...469] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5200] + new: [...470] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9110] + new: [...471] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32785] + new: [...472] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8400] + new: [...473] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60443] + new: [...474] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3000] + new: [...475] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1461] + new: [...476] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2260] + new: [...477] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5811] + new: [...478] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...30] + new: [...479] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1027] + new: [...480] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8000] + new: [...481] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49176] + new: [...482] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...82] + new: [...483] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2161] + new: [...484] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9415] + new: [...485] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4126] + new: [...486] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57797] + new: [...487] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6346] + new: [...488] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2800] + new: [...489] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4662] + new: [...490] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7741] + new: [...491] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..726] + new: [...492] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..912] + new: [...493] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15742] + new: [...494] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25734] + new: [...495] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1805] + new: [...496] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8651] + new: [...497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..646] + new: [...498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11111] + new: [...499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9944] + new: [...500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1862] + new: [...501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8100] + new: [...502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7911] + new: [...503] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32780] + new: [...504] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..163] + new: [...505] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3301] + new: [...506] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2200] + new: [...507] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7070] + new: [...508] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1065] + new: [...509] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32776] + new: [...510] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1259] + new: [...511] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9595] + new: [...512] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][35500] + new: [...513] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10082] + new: [...514] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....7] + new: [...515] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2013] + new: [...516] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..464] + new: [...517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6025] + new: [...518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5730] + new: [...519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8021] + new: [...520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3517] + new: [...521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1088] + new: [...522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..999] + new: [...523] [ip4][..tcp] [.....172.16.0.8][36061] -> [...64.13.134.52][..113] + new: [...524] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7070] + new: [...525] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2200] + new: [...526] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3301] + new: [...527] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..163] + new: [...528] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32780] + new: [...529] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7911] + new: [...530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8100] + new: [...531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1862] + new: [...532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9944] + new: [...533] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11111] + new: [...534] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..646] + new: [...535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5906] + new: [...536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2288] + new: [...537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1719] + new: [...538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9418] + new: [...539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10000] + new: [...540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20031] + new: [...541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4567] + new: [...542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8193] + new: [...543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1322] + new: [...544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....3] + new: [...545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1761] + new: [...546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10566] + new: [...547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1169] + new: [...548] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9220] + new: [...549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..999] + new: [...550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1088] + new: [...551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3517] + new: [...552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8021] + new: [...553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5730] + new: [...554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6025] + new: [...555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..464] + new: [...556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2013] + new: [...557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....7] + new: [...558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10082] + new: [...559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][35500] + new: [...560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9595] + new: [...561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1259] + new: [...562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32776] + new: [...563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1065] + new: [...564] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..212] + new: [...565] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65129] + new: [...566] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1185] + new: [...567] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9009] + new: [...568] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1248] + new: [...569] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1058] + new: [...570] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5988] + new: [...571] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1277] + new: [...572] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2126] + new: [...573] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1216] + new: [...574] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9091] + new: [...575] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1455] + new: [...576] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1009] + new: [...577] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10001] + new: [...578] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8292] + new: [...579] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55600] + new: [...580] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20005] + new: [...581] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1036] + new: [...582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6106] + new: [...583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7201] + new: [...584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1053] + new: [...585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32774] + new: [...586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2998] + new: [...587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2047] + new: [...588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8200] + new: [...589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..888] + new: [...590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34572] + new: [...591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1201] + new: [...592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9003] + new: [...593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3367] + new: [...594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2196] + new: [...595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2121] + new: [...596] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5850] + new: [...597] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7512] + new: [...598] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1096] + new: [...599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9220] + new: [...600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1169] + new: [...601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10566] + new: [...602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1761] + new: [...603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....3] + new: [...604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1322] + new: [...605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8193] + new: [...606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4567] + new: [...607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20031] + new: [...608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10000] + new: [...609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9418] + new: [...610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1719] + new: [...611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2288] + new: [...612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5906] + new: [...613] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7100] + new: [...614] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3851] + new: [...615] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10180] + new: [...616] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7001] + new: [...617] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4449] + new: [...618] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54328] + new: [...619] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...83] + new: [...620] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1309] + new: [...621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8009] + new: [...622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4343] + new: [...623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9050] + new: [...624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3905] + new: [...625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7625] + new: [...626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10004] + new: [...627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6779] + new: [...628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5999] + new: [...629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5810] + new: [...630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9101] + new: [...631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..749] + new: [...632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1301] + new: [...633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8002] + new: [...634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8099] + new: [...635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3030] + new: [...636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1031] + new: [...637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2048] + new: [...638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6547] + new: [...639] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1036] + new: [...640] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20005] + new: [...641] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55600] + new: [...642] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8292] + new: [...643] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10001] + new: [...644] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1009] + new: [...645] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1455] + new: [...646] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9091] + new: [...647] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1216] + new: [...648] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2126] + new: [...649] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1277] + new: [...650] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5988] + new: [...651] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1058] + new: [...652] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1248] + new: [...653] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9009] + new: [...654] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1185] + new: [...655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65129] + new: [...656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..212] + new: [...657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1096] + new: [...658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7512] + new: [...659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5850] + new: [...660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2121] + new: [...661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2196] + new: [...662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3367] + new: [...663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9003] + new: [...664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1201] + new: [...665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34572] + new: [...666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..888] + new: [...667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8200] + new: [...668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2047] + new: [...669] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2998] + new: [...670] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32774] + new: [...671] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1053] + new: [...672] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7201] + new: [...673] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6106] + new: [...674] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9050] + new: [...675] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4343] + new: [...676] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8009] + new: [...677] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1309] + new: [...678] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...83] + new: [...679] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54328] + new: [...680] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4449] + new: [...681] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7001] + new: [...682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10180] + new: [...683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3851] + new: [...684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7100] + new: [...685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1218] + new: [...686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19315] + new: [...687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19842] + new: [...688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3546] + new: [...689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1086] + new: [...690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1052] + new: [...691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3995] + new: [...692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4900] + new: [...693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30000] + new: [...694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...42] + new: [...695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51493] + new: [...696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8192] + new: [...697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1271] + new: [...698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16016] + new: [...699] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6547] + new: [...700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2048] + new: [...701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1031] + new: [...702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3030] + new: [...703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8099] + new: [...704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8002] + new: [...705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1301] + new: [...706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..749] + new: [...707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9101] + new: [...708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5810] + new: [...709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5999] + new: [...710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6779] + new: [...711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10004] + new: [...712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7625] + new: [...713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3905] + new: [...714] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1083] + new: [...715] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8701] + new: [...716] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3390] + new: [...717] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1875] + new: [...718] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1199] + new: [...719] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1721] + new: [...720] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10778] + new: [...721] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1718] + new: [...722] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16000] + new: [...723] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..125] + new: [...724] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1658] + new: [...725] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1148] + new: [...726] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..366] + new: [...727] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49165] + new: [...728] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1839] + new: [...729] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9943] + new: [...730] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2107] + new: [...731] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10617] + new: [...732] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2717] + new: [...733] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10003] + new: [...734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1041] + new: [...735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1042] + new: [...736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8082] + new: [...737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1165] + new: [...738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5405] + new: [...739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5051] + new: [...740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2383] + new: [...741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2022] + new: [...742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6510] + new: [...743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9876] + new: [...744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1072] + new: [...745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5001] + new: [...746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8181] + new: [...747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..301] + new: [...748] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1078] + new: [...749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16016] + new: [...750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1271] + new: [...751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8192] + new: [...752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51493] + new: [...753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...42] + new: [...754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30000] + new: [...755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4900] + new: [...756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3995] + new: [...757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1052] + new: [...758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1086] + new: [...759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3546] + new: [...760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19842] + new: [...761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19315] + new: [...762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1218] + new: [...763] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..109] + new: [...764] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1999] + new: [...765] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4125] + new: [...766] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12265] + new: [...767] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49163] + new: [...768] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1085] + new: [...769] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5922] + new: [...770] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32782] + new: [...771] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1079] + new: [...772] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1141] + new: [...773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..617] + new: [...774] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10617] + new: [...775] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2107] + new: [...776] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9943] + new: [...777] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1839] + new: [...778] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49165] + new: [...779] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..366] + new: [...780] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1148] + new: [...781] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1658] + new: [...782] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..125] + new: [...783] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16000] + new: [...784] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1718] + new: [...785] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10778] + new: [...786] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1721] + new: [...787] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1199] + new: [...788] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1875] + new: [...789] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3390] + new: [...790] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8701] + new: [...791] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1083] + new: [...792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32779] + new: [...793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49156] + new: [...794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5510] + new: [...795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5566] + new: [...796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9999] + new: [...797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9485] + new: [...798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3878] + new: [...799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...84] + new: [...800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3801] + new: [...801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17988] + new: [...802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49154] + new: [...803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10010] + new: [...804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5718] + new: [...805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3168] + new: [...806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3006] + new: [...807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1078] + new: [...808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..301] + new: [...809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8181] + new: [...810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5001] + new: [...811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1072] + new: [...812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9876] + new: [...813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6510] + new: [...814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2022] + new: [...815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2383] + new: [...816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5051] + new: [...817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5405] + new: [...818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1165] + new: [...819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8082] + new: [...820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1042] + new: [...821] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1041] + new: [...822] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10003] + new: [...823] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2717] + new: [...824] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..617] + new: [...825] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1141] + new: [...826] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1079] + new: [...827] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32782] + new: [...828] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5922] + new: [...829] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1085] + new: [...830] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49163] + new: [...831] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12265] + new: [...832] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4125] + new: [...833] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1999] + new: [...834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..109] + new: [...835] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5280] + new: [...836] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1066] + new: [...837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..481] + new: [...838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5901] + new: [...839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8042] + new: [...840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2967] + new: [...841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....4] + new: [...842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1082] + new: [...843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1521] + new: [...844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2100] + new: [...845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1001] + new: [...846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8090] + new: [...847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1914] + new: [...848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7937] + new: [...849] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3006] + new: [...850] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3168] + new: [...851] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5718] + new: [...852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10010] + new: [...853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49154] + new: [...854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17988] + new: [...855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3801] + new: [...856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...84] + new: [...857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3878] + new: [...858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9485] + new: [...859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9999] + new: [...860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5566] + new: [...861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5510] + new: [...862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49156] + new: [...863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32779] + new: [...864] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1029] + new: [...865] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1864] + new: [...866] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..901] + new: [...867] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..981] + new: [...868] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5560] + new: [...869] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3007] + new: [...870] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1119] + new: [...871] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55555] + new: [...872] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3766] + new: [...873] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1600] + new: [...874] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1192] + new: [...875] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12174] + new: [...876] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11110] + new: [...877] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15002] + new: [...878] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12345] + new: [...879] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9968] + new: [...880] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1974] + new: [...881] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9900] + new: [...882] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1164] + new: [...883] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..898] + new: [...884] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6881] + new: [...885] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34571] + new: [...886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..500] + new: [...887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5120] + new: [...888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18040] + new: [...889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5060] + new: [...890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3659] + new: [...891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1051] + new: [...892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..545] + new: [...893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2004] + new: [...894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1002] + new: [...895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2601] + new: [...896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1093] + new: [...897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5989] + new: [...898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4550] + new: [...899] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7937] + new: [...900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1914] + new: [...901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8090] + new: [...902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1001] + new: [...903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2100] + new: [...904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1521] + new: [...905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1082] + new: [...906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....4] + new: [...907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2967] + new: [...908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8042] + new: [...909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5901] + new: [...910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..481] + new: [...911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1066] + new: [...912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5280] + new: [...913] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7778] + new: [...914] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..987] + new: [...915] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5679] + new: [...916] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8180] + new: [...917] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4279] + new: [...918] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14441] + new: [...919] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44443] + new: [...920] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9618] + new: [...921] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2301] + new: [...922] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50800] + new: [...923] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8010] + new: [...924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9900] + new: [...925] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1974] + new: [...926] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9968] + new: [...927] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12345] + new: [...928] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15002] + new: [...929] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11110] + new: [...930] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12174] + new: [...931] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1192] + new: [...932] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1600] + new: [...933] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3766] + new: [...934] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55555] + new: [...935] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1119] + new: [...936] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3007] + new: [...937] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5560] + new: [...938] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..981] + new: [...939] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..901] + new: [...940] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1864] + new: [...941] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1029] + new: [...942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5987] + new: [...943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9502] + new: [...944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....1] + new: [...945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1046] + new: [...946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27715] + new: [...947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7002] + new: [...948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][28201] + new: [...949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1186] + new: [...950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..705] + new: [...951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2009] + new: [...952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64680] + new: [...953] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18101] + new: [...954] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49158] + new: [...955] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3971] + new: [...956] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6689] + new: [...957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4550] + new: [...958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5989] + new: [...959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1093] + new: [...960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2601] + new: [...961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1002] + new: [...962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2004] + new: [...963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..545] + new: [...964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1051] + new: [...965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3659] + new: [...966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5060] + new: [...967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18040] + new: [...968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5120] + new: [...969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..500] + new: [...970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34571] + new: [...971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6881] + new: [...972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..898] + new: [...973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1164] + new: [...974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8010] + new: [...975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50800] + new: [...976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2301] + new: [...977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9618] + new: [...978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44443] + new: [...979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14441] + new: [...980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4279] + new: [...981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8180] + new: [...982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5679] + new: [...983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..987] + new: [...984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7778] + new: [...985] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31038] + new: [...986] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12000] + new: [...987] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10616] + new: [...988] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1059] + new: [...989] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2604] + new: [...990] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50500] + new: [...991] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4443] + new: [...992] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1900] + new: [...993] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1137] + new: [...994] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9081] + new: [...995] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5802] + new: [...996] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19801] + new: [...997] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1443] + new: [...998] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32783] + new: [...999] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6689] + new: [..1000] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3971] + new: [..1001] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49158] + new: [..1002] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18101] + new: [..1003] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64680] + new: [..1004] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2009] + new: [..1005] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..705] + new: [..1006] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1186] + new: [..1007] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][28201] + new: [..1008] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7002] + new: [..1009] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27715] + new: [..1010] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1046] + new: [..1011] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....1] + new: [..1012] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9502] + new: [..1013] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5987] + new: [..1014] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1783] + new: [..1015] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4445] + new: [..1016] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2381] + new: [..1017] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][45100] + new: [..1018] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7019] + new: [..1019] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16992] + new: [..1020] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1174] + new: [..1021] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13782] + new: [..1022] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5902] + new: [..1023] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9878] + new: [..1024] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..667] + new: [..1025] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9080] + new: [..1026] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5102] + new: [..1027] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5877] + new: [..1028] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1037] + new: [..1029] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5907] + new: [..1030] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..211] + new: [..1031] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2035] + new: [..1032] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..144] + new: [..1033] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1112] + new: [..1034] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2170] + new: [..1035] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6101] + new: [..1036] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..800] + new: [..1037] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8994] + new: [..1038] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2399] + new: [..1039] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3580] + new: [..1040] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...89] + new: [..1041] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8873] + new: [..1042] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7106] + new: [..1043] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8087] + new: [..1044] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9594] + new: [..1045] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1099] + new: [..1046] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34573] + new: [..1047] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5030] + new: [..1048] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2702] + new: [..1049] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32783] + new: [..1050] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1443] + new: [..1051] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19801] + new: [..1052] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5802] + new: [..1053] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9081] + new: [..1054] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1137] + new: [..1055] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1900] + new: [..1056] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4443] + new: [..1057] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50500] + new: [..1058] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2604] + new: [..1059] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1059] + new: [..1060] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10616] + new: [..1061] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12000] + new: [..1062] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][31038] + new: [..1063] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9002] + new: [..1064] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5998] + new: [..1065] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9503] + new: [..1066] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1062] + new: [..1067] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1217] + new: [..1068] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50001] + new: [..1069] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3325] + new: [..1070] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1011] + new: [..1071] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1117] + new: [..1072] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1533] + new: [..1073] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3404] + new: [..1074] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2035] + new: [..1075] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..211] + new: [..1076] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5907] + new: [..1077] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1037] + new: [..1078] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5877] + new: [..1079] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5102] + new: [..1080] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9080] + new: [..1081] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..667] + new: [..1082] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9878] + new: [..1083] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5902] + new: [..1084] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13782] + new: [..1085] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1174] + new: [..1086] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16992] + new: [..1087] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7019] + new: [..1088] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][45100] + new: [..1089] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2381] + new: [..1090] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4445] + new: [..1091] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1783] + new: [..1092] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..902] + new: [..1093] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3690] + new: [..1094] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8089] + new: [..1095] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1010] + new: [..1096] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8402] + new: [..1097] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9090] + new: [..1098] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3527] + new: [..1099] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..992] + new: [..1100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8652] + new: [..1101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..255] + new: [..1102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33354] + new: [..1103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1050] + new: [..1104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1782] + new: [..1105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..406] + new: [..1106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][22939] + new: [..1107] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2702] + new: [..1108] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5030] + new: [..1109] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34573] + new: [..1110] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1099] + new: [..1111] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9594] + new: [..1112] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8087] + new: [..1113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7106] + new: [..1114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8873] + new: [..1115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...89] + new: [..1116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3580] + new: [..1117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2399] + new: [..1118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8994] + new: [..1119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..800] + new: [..1120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6101] + new: [..1121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2170] + new: [..1122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1112] + new: [..1123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..144] + new: [..1124] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3404] + new: [..1125] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1533] + new: [..1126] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1117] + new: [..1127] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1011] + new: [..1128] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3325] + new: [..1129] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50001] + new: [..1130] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1217] + new: [..1131] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1062] + new: [..1132] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9503] + new: [..1133] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5998] + new: [..1134] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9002] + new: [..1135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..524] + new: [..1136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5100] + new: [..1137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1091] + new: [..1138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15000] + new: [..1139] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...19] + new: [..1140] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2042] + new: [..1141] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1138] + new: [..1142] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5960] + new: [..1143] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2144] + new: [..1144] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1106] + new: [..1145] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4446] + new: [..1146] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5432] + new: [..1147] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8085] + new: [..1148] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2119] + new: [..1149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][22939] + new: [..1150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..406] + new: [..1151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1782] + new: [..1152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1050] + new: [..1153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33354] + new: [..1154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..255] + new: [..1155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8652] + new: [..1156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..992] + new: [..1157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3527] + new: [..1158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9090] + new: [..1159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8402] + new: [..1160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1010] + new: [..1161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8089] + new: [..1162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3690] + new: [..1163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..902] + new: [..1164] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1971] + new: [..1165] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5222] + new: [..1166] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1100] + new: [..1167] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6668] + new: [..1168] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8600] + new: [..1169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5000] + new: [..1170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..714] + new: [..1171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7921] + new: [..1172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6112] + new: [..1173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50300] + new: [..1174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6156] + new: [..1175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13783] + new: [..1176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8007] + new: [..1177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32773] + new: [..1178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1105] + new: [..1179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5050] + new: [..1180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1175] + new: [..1181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3260] + new: [..1182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9001] + new: [..1183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15003] + new: [..1184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...70] + new: [..1185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2003] + new: [..1186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1030] + new: [..1187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..543] + new: [..1188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1132] + new: [..1189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64623] + new: [..1190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6007] + new: [..1191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3300] + new: [..1192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..222] + new: [..1193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8194] + new: [..1194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10628] + new: [..1195] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4444] + new: [..1196] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...79] + new: [..1197] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7938] + new: [..1198] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1032] + new: [..1199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2119] + new: [..1200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8085] + new: [..1201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5432] + new: [..1202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4446] + new: [..1203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1106] + new: [..1204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2144] + new: [..1205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5960] + new: [..1206] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1138] + new: [..1207] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2042] + new: [..1208] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...19] + new: [..1209] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15000] + new: [..1210] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1091] + new: [..1211] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5100] + new: [..1212] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..524] + new: [..1213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1272] + new: [..1214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8899] + new: [..1215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1121] + new: [..1216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10024] + new: [..1217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6003] + new: [..1218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8088] + new: [..1219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][41511] + new: [..1220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5298] + new: [..1221] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1717] + new: [..1222] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...43] + new: [..1223] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1122] + new: [..1224] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..711] + new: [..1225] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32769] + new: [..1226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3260] + new: [..1227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1175] + new: [..1228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5050] + new: [..1229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1105] + new: [..1230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32773] + new: [..1231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8007] + new: [..1232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13783] + new: [..1233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6156] + new: [..1234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50300] + new: [..1235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6112] + new: [..1236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7921] + new: [..1237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..714] + new: [..1238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5000] + new: [..1239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8600] + new: [..1240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6668] + new: [..1241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1100] + new: [..1242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5222] + new: [..1243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1971] + new: [..1244] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1501] + new: [..1245] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2602] + new: [..1246] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1163] + new: [..1247] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1045] + new: [..1248] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..106] + new: [..1249] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1061] + new: [..1250] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1972] + new: [..1251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3800] + new: [..1252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1124] + new: [..1253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27000] + new: [..1254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5544] + new: [..1255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7025] + new: [..1256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3551] + new: [..1257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1098] + new: [..1258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2041] + new: [..1259] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7938] + new: [..1260] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...79] + new: [..1261] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4444] + new: [..1262] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10628] + new: [..1263] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8194] + new: [..1264] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..222] + new: [..1265] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3300] + new: [..1266] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6007] + new: [..1267] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64623] + new: [..1268] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1132] + new: [..1269] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..543] + new: [..1270] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1030] + new: [..1271] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2003] + new: [..1272] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15003] + new: [..1273] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9001] + new: [..1274] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1032] + new: [..1275] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1122] + new: [..1276] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...43] + new: [..1277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1717] + new: [..1278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5298] + new: [..1279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][41511] + new: [..1280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8088] + new: [..1281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6003] + new: [..1282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10024] + new: [..1283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1121] + new: [..1284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8899] + new: [..1285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1272] + new: [..1286] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2179] + new: [..1287] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5087] + new: [..1288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44442] + new: [..1289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..427] + new: [..1290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4004] + new: [..1291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2394] + new: [..1292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5952] + new: [..1293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2608] + new: [..1294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..458] + new: [..1295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1068] + new: [..1296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1700] + new: [..1297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..691] + new: [..1298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5910] + new: [..1299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9103] + new: [..1300] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32769] + new: [..1301] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..711] + new: [..1302] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2041] + new: [..1303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1098] + new: [..1304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3551] + new: [..1305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7025] + new: [..1306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5544] + new: [..1307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27000] + new: [..1308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1124] + new: [..1309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3800] + new: [..1310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1972] + new: [..1311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1061] + new: [..1312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..106] + new: [..1313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1045] + new: [..1314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1163] + new: [..1315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2602] + new: [..1316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1501] + new: [..1317] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][38292] + new: [..1318] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..416] + new: [..1319] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1998] + new: [..1320] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...20] + new: [..1321] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1287] + new: [..1322] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57294] + new: [..1323] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..541] + new: [..1324] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1352] + new: [..1325] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3283] + new: [..1326] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1145] + new: [..1327] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2191] + new: [..1328] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20000] + new: [..1329] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1035] + new: [..1330] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...88] + new: [..1331] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1055] + new: [..1332] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32772] + new: [..1333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1077] + new: [..1334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6566] + new: [..1335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56737] + new: [..1336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5961] + new: [..1337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][58080] + new: [..1338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9207] + new: [..1339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1126] + new: [..1340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19283] + new: [..1341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..513] + new: [..1342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..722] + new: [..1343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49153] + new: [..1344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8001] + new: [..1345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3370] + new: [..1346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4242] + new: [..1347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6009] + new: [..1348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3869] + new: [..1349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1069] + new: [..1350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16113] + new: [..1351] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9103] + new: [..1352] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5910] + new: [..1353] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..691] + new: [..1354] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1700] + new: [..1355] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1068] + new: [..1356] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..458] + new: [..1357] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2608] + new: [..1358] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5952] + new: [..1359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2394] + new: [..1360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4004] + new: [..1361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..427] + new: [..1362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44442] + new: [..1363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5087] + new: [..1364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2179] + new: [..1365] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...81] + new: [..1366] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3221] + new: [..1367] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2557] + new: [..1368] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...37] + new: [..1369] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2135] + new: [..1370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2809] + new: [..1371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51103] + new: [..1372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3871] + new: [..1373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...13] + new: [..1374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5801] + new: [..1375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3322] + new: [..1376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2021] + new: [..1377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3333] + new: [..1378] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1998] + new: [..1379] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..416] + new: [..1380] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][38292] + new: [..1381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6100] + new: [..1382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..720] + new: [..1383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8031] + new: [..1384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..146] + new: [..1385] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..407] + new: [..1386] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3323] + new: [..1387] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24800] + new: [..1388] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7999] + new: [..1389] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19350] + new: [..1390] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61900] + new: [..1391] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..593] + new: [..1392] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6002] + new: [..1393] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1310] + new: [..1394] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8008] + new: [..1395] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1114] + new: [..1396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1069] + new: [..1397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3869] + new: [..1398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6009] + new: [..1399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4242] + new: [..1400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3370] + new: [..1401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8001] + new: [..1402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49153] + new: [..1403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..722] + new: [..1404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..513] + new: [..1405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19283] + new: [..1406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1126] + new: [..1407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9207] + new: [..1408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][58080] + new: [..1409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5961] + new: [..1410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56737] + new: [..1411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6566] + new: [..1412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1077] + new: [..1413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32772] + new: [..1414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1055] + new: [..1415] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...88] + new: [..1416] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1035] + new: [..1417] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20000] + new: [..1418] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2191] + new: [..1419] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1145] + new: [..1420] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3283] + new: [..1421] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1352] + new: [..1422] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..541] + new: [..1423] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57294] + new: [..1424] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1287] + new: [..1425] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...20] + new: [..1426] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16113] + new: [..1427] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2557] + new: [..1428] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3221] + new: [..1429] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...81] + new: [..1430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3889] + new: [..1431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6565] + new: [..1432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2007] + new: [..1433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3269] + new: [..1434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1000] + new: [..1435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2492] + new: [..1436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2710] + new: [..1437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5004] + new: [..1438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7443] + new: [..1439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27352] + new: [..1440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7004] + new: [..1441] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52673] + new: [..1442] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8081] + new: [..1443] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49175] + new: [..1444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3322] + new: [..1445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5801] + new: [..1446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...13] + new: [..1447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3871] + new: [..1448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51103] + new: [..1449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2809] + new: [..1450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2135] + new: [..1451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...37] + new: [..1452] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3333] + new: [..1453] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2021] + new: [..1454] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1114] + new: [..1455] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8008] + new: [..1456] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1310] + new: [..1457] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6002] + new: [..1458] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..593] + new: [..1459] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61900] + new: [..1460] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19350] + new: [..1461] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7999] + new: [..1462] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24800] + new: [..1463] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3323] + new: [..1464] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..407] + new: [..1465] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..146] + new: [..1466] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8031] + new: [..1467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..720] + new: [..1468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6100] + new: [..1469] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5815] + new: [..1470] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8500] + new: [..1471] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1026] + new: [..1472] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16012] + new: [..1473] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40193] + new: [..1474] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1947] + new: [..1475] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5666] + new: [..1476] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5226] + new: [..1477] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9040] + new: [..1478] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8011] + new: [..1479] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..417] + new: [..1480] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32771] + new: [..1481] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6001] + new: [..1482] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1503] + new: [..1483] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1076] + new: [..1484] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4002] + new: [..1485] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...49] + new: [..1486] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2111] + new: [..1487] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..264] + new: [..1488] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1500] + new: [..1489] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49161] + new: [..1490] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1081] + new: [..1491] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2500] + new: [..1492] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6567] + new: [..1493] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1033] + new: [..1494] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..631] + new: [..1495] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..648] + new: [..1496] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2002] + new: [..1497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..340] + new: [..1498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7435] + new: [..1499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6792] + new: [..1500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..783] + new: [..1501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1147] + new: [..1502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54045] + new: [..1503] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49175] + new: [..1504] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8081] + new: [..1505] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52673] + new: [..1506] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7004] + new: [..1507] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27352] + new: [..1508] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7443] + new: [..1509] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5004] + new: [..1510] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2710] + new: [..1511] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2492] + new: [..1512] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1000] + new: [..1513] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3269] + new: [..1514] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2007] + new: [..1515] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6565] + new: [..1516] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3889] + new: [..1517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1113] + new: [..1518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3986] + new: [..1519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8443] + new: [..1520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1054] + new: [..1521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][21571] + new: [..1522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5950] + new: [..1523] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9100] + new: [..1524] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49400] + new: [..1525] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1130] + new: [..1526] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2875] + new: [..1527] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32784] + new: [..1528] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1556] + new: [..1529] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1022] + new: [..1530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1026] + new: [..1531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8500] + new: [..1532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5815] + new: [..1533] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1102] + new: [..1534] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55055] + new: [..1535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3371] + new: [..1536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10025] + new: [..1537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..616] + new: [..1538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1039] + new: [..1539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7627] + new: [..1540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10215] + new: [..1541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6692] + new: [..1542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5009] + new: [..1543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2323] + new: [..1544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8290] + new: [..1545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2043] + new: [..1546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1034] + new: [..1547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1935] + new: [..1548] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1147] + new: [..1549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..783] + new: [..1550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6792] + new: [..1551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7435] + new: [..1552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..340] + new: [..1553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2002] + new: [..1554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..648] + new: [..1555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..631] + new: [..1556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1033] + new: [..1557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6567] + new: [..1558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2500] + new: [..1559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1081] + new: [..1560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49161] + new: [..1561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1500] + new: [..1562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..264] + new: [..1563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2111] + new: [..1564] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...49] + new: [..1565] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4002] + new: [..1566] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1076] + new: [..1567] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1503] + new: [..1568] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6001] + new: [..1569] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32771] + new: [..1570] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..417] + new: [..1571] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8011] + new: [..1572] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9040] + new: [..1573] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5226] + new: [..1574] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5666] + new: [..1575] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1947] + new: [..1576] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40193] + new: [..1577] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16012] + new: [..1578] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54045] + new: [..1579] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8443] + new: [..1580] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3986] + new: [..1581] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1113] + new: [..1582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1107] + new: [..1583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..636] + new: [..1584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5054] + new: [..1585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1334] + new: [..1586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1023] + new: [..1587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..903] + new: [..1588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..100] + new: [..1589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3703] + new: [..1590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1028] + new: [..1591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..900] + new: [..1592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..873] + new: [..1593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..119] + new: [..1594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][26214] + new: [..1595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20828] + new: [..1596] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32784] + new: [..1597] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2875] + new: [..1598] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1130] + new: [..1599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49400] + new: [..1600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9100] + new: [..1601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5950] + new: [..1602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][21571] + new: [..1603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1054] + new: [..1604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1022] + new: [..1605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1556] + new: [..1606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1935] + new: [..1607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1034] + new: [..1608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2043] + new: [..1609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8290] + new: [..1610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2323] + new: [..1611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5009] + new: [..1612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6692] + new: [..1613] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10215] + new: [..1614] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7627] + new: [..1615] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1039] + new: [..1616] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..616] + new: [..1617] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10025] + new: [..1618] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3371] + new: [..1619] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55055] + new: [..1620] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1102] + new: [..1621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5550] + new: [..1622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2638] + new: [..1623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..515] + new: [..1624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..555] + new: [..1625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..880] + new: [..1626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1755] + new: [..1627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49159] + new: [..1628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8254] + new: [..1629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1090] + new: [..1630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3324] + new: [..1631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2000] + new: [..1632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50003] + new: [..1633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9535] + new: [..1634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..161] + new: [..1635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9000] + new: [..1636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2105] + new: [..1637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1213] + new: [..1638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18988] + new: [..1639] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..668] + new: [..1640] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...33] + new: [..1641] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5859] + new: [..1642] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32777] + new: [..1643] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56738] + new: [..1644] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9099] + new: [..1645] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4045] + new: [..1646] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1094] + new: [..1647] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2068] + new: [..1648] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8083] + new: [..1649] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..777] + new: [..1650] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1074] + new: [..1651] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13722] + new: [..1652] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3920] + new: [..1653] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5904] + new: [..1654] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..787] + new: [..1655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20828] + new: [..1656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][26214] + new: [..1657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..119] + new: [..1658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..873] + new: [..1659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..900] + new: [..1660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1028] + new: [..1661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3703] + new: [..1662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..100] + new: [..1663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..903] + new: [..1664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1023] + new: [..1665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1334] + new: [..1666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5054] + new: [..1667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..636] + new: [..1668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1107] + new: [..1669] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8383] + new: [..1670] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..544] + new: [..1671] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9111] + new: [..1672] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..444] + new: [..1673] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3211] + new: [..1674] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20221] + new: [..1675] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6667] + new: [..1676] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7103] + new: [..1677] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2010] + new: [..1678] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30951] + new: [..1679] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1089] + new: [..1680] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2910] + new: [..1681] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5357] + new: [..1682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..515] + new: [..1683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2638] + new: [..1684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5550] + new: [..1685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6901] + new: [..1686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25735] + new: [..1687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6969] + new: [..1688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3003] + new: [..1689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3011] + new: [..1690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50002] + new: [..1691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9998] + new: [..1692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3998] + new: [..1693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2006] + new: [..1694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1080] + new: [..1695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6006] + new: [..1696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3005] + new: [..1697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5633] + new: [..1698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7402] + new: [..1699] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4321] + new: [..1700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5859] + new: [..1701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...33] + new: [..1702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..668] + new: [..1703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18988] + new: [..1704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1213] + new: [..1705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2105] + new: [..1706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9000] + new: [..1707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..161] + new: [..1708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9535] + new: [..1709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50003] + new: [..1710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2000] + new: [..1711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3324] + new: [..1712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1090] + new: [..1713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8254] + new: [..1714] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49159] + new: [..1715] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1755] + new: [..1716] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..880] + new: [..1717] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..555] + new: [..1718] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5904] + new: [..1719] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3920] + new: [..1720] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13722] + new: [..1721] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1074] + new: [..1722] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..777] + new: [..1723] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8083] + new: [..1724] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2068] + new: [..1725] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1094] + new: [..1726] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4045] + new: [..1727] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9099] + new: [..1728] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56738] + new: [..1729] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32777] + new: [..1730] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..787] + new: [..1731] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9111] + new: [..1732] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..544] + new: [..1733] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8383] + new: [..1734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50000] + new: [..1735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6129] + new: [..1736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3351] + new: [..1737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52822] + new: [..1738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16018] + new: [..1739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49167] + new: [..1740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6789] + new: [..1741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6004] + new: [..1742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1057] + new: [..1743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3914] + new: [..1744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65389] + new: [..1745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6502] + new: [..1746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16993] + new: [..1747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1149] + new: [..1748] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1089] + new: [..1749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30951] + new: [..1750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2010] + new: [..1751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7103] + new: [..1752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6667] + new: [..1753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20221] + new: [..1754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3211] + new: [..1755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..444] + new: [..1756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5357] + new: [..1757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2910] + new: [..1758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4321] + new: [..1759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7402] + new: [..1760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5633] + new: [..1761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3005] + new: [..1762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6006] + new: [..1763] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1080] + new: [..1764] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2006] + new: [..1765] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3998] + new: [..1766] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9998] + new: [..1767] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50002] + new: [..1768] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3011] + new: [..1769] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3003] + new: [..1770] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6969] + new: [..1771] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25735] + new: [..1772] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6901] + new: [..1773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1494] + new: [..1774] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5911] + new: [..1775] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32770] + new: [..1776] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][63331] + new: [..1777] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1434] + new: [..1778] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5061] + new: [..1779] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2045] + new: [..1780] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..911] + new: [..1781] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6059] + new: [..1782] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1198] + new: [..1783] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9011] + new: [..1784] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1580] + new: [..1785] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2040] + new: [..1786] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6123] + new: [..1787] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3828] + new: [..1788] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8333] + new: [..1789] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8022] + new: [..1790] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5555] + new: [..1791] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55056] + new: [..1792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2160] + new: [..1793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8654] + new: [..1794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50006] + new: [..1795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2366] + new: [..1796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][23502] + new: [..1797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1063] + new: [..1798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5003] + new: [..1799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50636] + new: [..1800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1152] + new: [..1801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27353] + new: [..1802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7007] + new: [..1803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5915] + new: [..1804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1234] + new: [..1805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5925] + new: [..1806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50389] + new: [..1807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1149] + new: [..1808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16993] + new: [..1809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6502] + new: [..1810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65389] + new: [..1811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3914] + new: [..1812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1057] + new: [..1813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6004] + new: [..1814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6789] + new: [..1815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49167] + new: [..1816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16018] + new: [..1817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52822] + new: [..1818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3351] + new: [..1819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6129] + new: [..1820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50000] + new: [..1821] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1038] + new: [..1822] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2008] + new: [..1823] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1236] + new: [..1824] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...85] + new: [..1825] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2049] + new: [..1826] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6646] + new: [..1827] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1007] + new: [..1828] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1108] + new: [..1829] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][42510] + new: [..1830] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..465] + new: [..1831] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3128] + new: [..1832] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..625] + new: [..1833] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2065] + new: [..1834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32770] + new: [..1835] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5911] + new: [..1836] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1494] + new: [..1837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2920] + new: [..1838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3689] + new: [..1839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5678] + new: [..1840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2607] + new: [..1841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1801] + new: [..1842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4001] + new: [..1843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32775] + new: [..1844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..389] + new: [..1845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3372] + new: [..1846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..687] + new: [..1847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7920] + new: [..1848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49160] + new: [..1849] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3013] + new: [..1850] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5225] + new: [..1851] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2251] + new: [..1852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5925] + new: [..1853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1234] + new: [..1854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5915] + new: [..1855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7007] + new: [..1856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27353] + new: [..1857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1152] + new: [..1858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50636] + new: [..1859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5003] + new: [..1860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1063] + new: [..1861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][23502] + new: [..1862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2366] + new: [..1863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50006] + new: [..1864] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8654] + new: [..1865] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2160] + new: [..1866] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55056] + new: [..1867] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5555] + new: [..1868] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8022] + new: [..1869] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8333] + new: [..1870] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3828] + new: [..1871] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6123] + new: [..1872] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2040] + new: [..1873] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1580] + new: [..1874] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9011] + new: [..1875] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1198] + new: [..1876] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6059] + new: [..1877] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..911] + new: [..1878] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2045] + new: [..1879] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5061] + new: [..1880] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1434] + new: [..1881] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][63331] + new: [..1882] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50389] + new: [..1883] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1236] + new: [..1884] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2008] + new: [..1885] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1038] + new: [..1886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..259] + new: [..1887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10243] + new: [..1888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2033] + new: [..1889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5862] + new: [..1890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8093] + new: [..1891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..179] + new: [..1892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1984] + new: [..1893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9877] + new: [..1894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..563] + new: [..1895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...90] + new: [..1896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8084] + new: [..1897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2725] + new: [..1898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..311] + new: [..1899] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6666] + new: [..1900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3128] + new: [..1901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..465] + new: [..1902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][42510] + new: [..1903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1108] + new: [..1904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1007] + new: [..1905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6646] + new: [..1906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2049] + new: [..1907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...85] + new: [..1908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2065] + new: [..1909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..625] + new: [..1910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2251] + new: [..1911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5225] + new: [..1912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3013] + new: [..1913] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49160] + new: [..1914] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7920] + new: [..1915] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..687] + new: [..1916] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3372] + new: [..1917] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..389] + new: [..1918] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32775] + new: [..1919] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4001] + new: [..1920] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1801] + new: [..1921] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2607] + new: [..1922] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5678] + new: [..1923] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3689] + new: [..1924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2920] + new: [..1925] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10012] + new: [..1926] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1021] + new: [..1927] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60020] + new: [..1928] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4998] + new: [..1929] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5002] + new: [..1930] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1092] + new: [..1931] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2103] + new: [..1932] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1049] + new: [..1933] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8800] + new: [..1934] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9290] + new: [..1935] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49152] + new: [..1936] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1863] + new: [..1937] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2401] + new: [..1938] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3031] + new: [..1939] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..306] + new: [..1940] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1812] + new: [..1941] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1104] + new: [..1942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2718] + new: [..1943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1110] + new: [..1944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6005] + new: [..1945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2034] + new: [..1946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5269] + new: [..1947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5962] + new: [..1948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3268] + new: [..1949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1044] + new: [..1950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..512] + new: [..1951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49157] + new: [..1952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3261] + new: [..1953] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6666] + new: [..1954] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..311] + new: [..1955] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2725] + new: [..1956] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8084] + new: [..1957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...90] + new: [..1958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..563] + new: [..1959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9877] + new: [..1960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1984] + new: [..1961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..179] + new: [..1962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8093] + new: [..1963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5862] + new: [..1964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2033] + new: [..1965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10243] + new: [..1966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..259] + new: [..1967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60020] + new: [..1968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1021] + new: [..1969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10012] + new: [..1970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3261] + new: [..1971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49157] + new: [..1972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..512] + new: [..1973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1044] + new: [..1974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3268] + new: [..1975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5962] + new: [..1976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5269] + new: [..1977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2034] + new: [..1978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6005] + new: [..1979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1110] + new: [..1980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2718] + new: [..1981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1104] + new: [..1982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1812] + new: [..1983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..306] + new: [..1984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3031] + new: [..1985] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2401] + new: [..1986] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1863] + new: [..1987] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49152] + new: [..1988] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9290] + new: [..1989] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8800] + new: [..1990] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1049] + new: [..1991] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2103] + new: [..1992] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1092] + new: [..1993] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5002] + new: [..1994] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4998] guessed: [....15] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing, Unidirectional Traffic - idle: [....15] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3389] + idle: [....15] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3389] not-detected: [...716] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3390] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...716] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3390] + idle: [...716] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3390] guessed: [....18] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing, Unidirectional Traffic - idle: [....18] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3389] + idle: [....18] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3389] not-detected: [..1633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9535] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9535] + idle: [..1633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9535] not-detected: [...789] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3390] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...789] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3390] + idle: [...789] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3390] not-detected: [..1708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9535] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9535] + idle: [..1708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9535] not-detected: [...378] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5440] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...378] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5440] + idle: [...378] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5440] not-detected: [...406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5440] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5440] + idle: [...406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5440] not-detected: [...990] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...990] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50500] + idle: [...990] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50500] not-detected: [...381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19780] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19780] + idle: [...381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19780] not-detected: [..1057] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1057] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50500] + idle: [..1057] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50500] not-detected: [...403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19780] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19780] + idle: [...403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19780] guessed: [..1324] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1352] [LotusNotes][Unknown][Collaborative][Acceptable] RISK: Unidirectional Traffic - idle: [..1324] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1352] + idle: [..1324] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1352] not-detected: [...206] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7496] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...206] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7496] + idle: [...206] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7496] guessed: [..1421] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1352] [LotusNotes][Unknown][Collaborative][Acceptable] RISK: Unidirectional Traffic - idle: [..1421] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1352] + idle: [..1421] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1352] not-detected: [...250] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7496] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...250] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7496] + idle: [...250] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7496] not-detected: [..1073] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3404] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1073] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3404] + idle: [..1073] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3404] not-detected: [..1124] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3404] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1124] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3404] + idle: [..1124] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3404] not-detected: [...597] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7512] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...597] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7512] + idle: [...597] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7512] not-detected: [...996] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...996] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19801] + idle: [...996] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19801] not-detected: [...658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7512] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7512] + idle: [...658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7512] not-detected: [..1051] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1051] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19801] + idle: [..1051] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19801] not-detected: [...184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9575] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9575] + idle: [...184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9575] not-detected: [...231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9575] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9575] + idle: [...231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9575] not-detected: [...423] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9593] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...423] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9593] + idle: [...423] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9593] not-detected: [..1044] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9594] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1044] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9594] + idle: [..1044] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9594] not-detected: [...443] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9593] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...443] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9593] + idle: [...443] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9593] not-detected: [..1111] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9594] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1111] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9594] + idle: [..1111] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9594] not-detected: [...511] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9595] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...511] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9595] + idle: [...511] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9595] not-detected: [...560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9595] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9595] + idle: [...560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9595] not-detected: [...275] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...275] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5500] + idle: [...275] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5500] not-detected: [...304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5500] + idle: [...304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5500] not-detected: [...455] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15742] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...455] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15742] + idle: [...455] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15742] not-detected: [...493] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15742] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...493] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15742] + idle: [...493] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15742] not-detected: [...687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19842] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19842] + idle: [...687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19842] not-detected: [...760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19842] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19842] + idle: [...760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19842] not-detected: [...794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5510] + idle: [...794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5510] not-detected: [...861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5510] + idle: [...861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5510] not-detected: [....55] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1417] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....55] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1417] + idle: [....55] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1417] not-detected: [....73] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1417] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....73] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1417] + idle: [....73] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1417] not-detected: [...920] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9618] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...920] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9618] + idle: [...920] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9618] not-detected: [...977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9618] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9618] + idle: [...977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9618] not-detected: [..1317] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][38292] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1317] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][38292] + idle: [..1317] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][38292] not-detected: [...351] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3476] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...351] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3476] + idle: [...351] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3476] not-detected: [..1380] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][38292] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1380] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][38292] + idle: [..1380] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][38292] not-detected: [...392] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3476] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...392] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3476] + idle: [...392] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3476] guessed: [...181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [...181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1433] + idle: [...181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1433] not-detected: [..1651] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13722] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1651] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13722] + idle: [..1651] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13722] not-detected: [..1288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44442] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44442] + idle: [..1288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44442] guessed: [..1777] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1434] [MsSQL-TDS][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [..1777] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1434] + idle: [..1777] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1434] guessed: [...234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1433] [MsSQL-TDS][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [...234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1433] + idle: [...234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1433] not-detected: [..1362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44442] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44442] + idle: [..1362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44442] guessed: [..1880] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1434] [MsSQL-TDS][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [..1880] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1434] + idle: [..1880] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1434] not-detected: [..1720] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13722] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1720] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13722] + idle: [..1720] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13722] not-detected: [...919] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...919] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44443] + idle: [...919] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44443] not-detected: [...978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44443] + idle: [...978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44443] not-detected: [..1335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56737] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56737] + idle: [..1335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56737] not-detected: [..1643] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56738] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1643] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56738] + idle: [..1643] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][56738] not-detected: [..1410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56737] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56737] + idle: [..1410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56737] not-detected: [..1728] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56738] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1728] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56738] + idle: [..1728] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][56738] not-detected: [...997] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...997] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1443] + idle: [...997] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1443] not-detected: [..1050] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1050] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1443] + idle: [..1050] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1443] not-detected: [...336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3493] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3493] + idle: [...336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3493] not-detected: [...366] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3493] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...366] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3493] + idle: [...366] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3493] not-detected: [..1254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5544] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5544] + idle: [..1254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5544] not-detected: [..1306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5544] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5544] + idle: [..1306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5544] not-detected: [..1621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5550] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5550] + idle: [..1621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5550] not-detected: [..1684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5550] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5550] + idle: [..1684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5550] not-detected: [...575] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1455] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...575] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1455] + idle: [...575] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1455] not-detected: [...645] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1455] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...645] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1455] + idle: [...645] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1455] not-detected: [..1790] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1790] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5555] + idle: [..1790] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5555] not-detected: [..1867] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1867] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5555] + idle: [..1867] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5555] not-detected: [...432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1461] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1461] + idle: [...432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1461] not-detected: [...475] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1461] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...475] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1461] + idle: [...475] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1461] not-detected: [...868] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5560] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...868] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5560] + idle: [...868] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5560] not-detected: [...937] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5560] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...937] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5560] + idle: [...937] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5560] not-detected: [...520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3517] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3517] + idle: [...520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3517] not-detected: [...795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5566] + idle: [...795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5566] not-detected: [...551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3517] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3517] + idle: [...551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3517] not-detected: [...860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5566] + idle: [...860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5566] not-detected: [..1441] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52673] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1441] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52673] + idle: [..1441] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52673] not-detected: [..1505] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52673] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1505] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52673] + idle: [..1505] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52673] not-detected: [...264] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...264] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9666] + idle: [...264] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9666] not-detected: [...315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9666] + idle: [...315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9666] not-detected: [..1098] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3527] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1098] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3527] + idle: [..1098] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3527] not-detected: [..1157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3527] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3527] + idle: [..1157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3527] not-detected: [...625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7625] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7625] + idle: [...625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7625] not-detected: [...712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7625] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7625] + idle: [...712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7625] not-detected: [..1539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7627] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7627] + idle: [..1539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7627] not-detected: [..1799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50636] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50636] + idle: [..1799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50636] not-detected: [..1614] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7627] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1614] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7627] + idle: [..1614] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7627] not-detected: [..1858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50636] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50636] + idle: [..1858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50636] not-detected: [...370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44501] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44501] + idle: [...370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44501] not-detected: [....90] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....90] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17877] + idle: [....90] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17877] not-detected: [...414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44501] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44501] + idle: [...414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44501] guessed: [..1773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1494] [Citrix][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1494] + idle: [..1773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1494] not-detected: [..1021] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1021] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13782] + idle: [..1021] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13782] not-detected: [...119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17877] + idle: [...119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17877] guessed: [..1836] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1494] [Citrix][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1836] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1494] + idle: [..1836] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1494] not-detected: [..1175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13783] + idle: [..1175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13783] not-detected: [..1084] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1084] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13782] + idle: [..1084] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13782] not-detected: [..1232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13783] + idle: [..1232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13783] not-detected: [...688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3546] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3546] + idle: [...688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3546] not-detected: [...759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3546] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3546] + idle: [...759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3546] not-detected: [..1488] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1488] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1500] + idle: [..1488] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1500] not-detected: [..1561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1500] + idle: [..1561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1500] not-detected: [..1244] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1501] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1244] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1501] + idle: [..1244] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1501] not-detected: [..1316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1501] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1501] + idle: [..1316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1501] not-detected: [..1482] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1503] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1482] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1503] + idle: [..1482] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1503] not-detected: [..1256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3551] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3551] + idle: [..1256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3551] not-detected: [..1567] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1503] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1567] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1503] + idle: [..1567] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1503] not-detected: [..1304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3551] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3551] + idle: [..1304] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3551] not-detected: [....96] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....96] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65000] + idle: [....96] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65000] not-detected: [...113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65000] + idle: [...113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65000] guessed: [...843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1521] [Oracle][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [...843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1521] + idle: [...843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1521] guessed: [...904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1521] [Oracle][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [...904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1521] + idle: [...904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1521] not-detected: [...344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1524] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1524] + idle: [...344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1524] not-detected: [...399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1524] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1524] + idle: [...399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1524] not-detected: [..1039] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1039] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3580] + idle: [..1039] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3580] not-detected: [...107] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7676] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...107] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7676] + idle: [...107] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7676] not-detected: [..1116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3580] + idle: [..1116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3580] not-detected: [..1072] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1533] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1072] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1533] + idle: [..1072] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1533] not-detected: [...143] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7676] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...143] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7676] + idle: [...143] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7676] not-detected: [..1125] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1533] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1125] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1533] + idle: [..1125] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1533] not-detected: [...356] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5631] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...356] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5631] + idle: [...356] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5631] not-detected: [...387] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5631] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...387] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5631] + idle: [...387] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5631] not-detected: [..1697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5633] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5633] + idle: [..1697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5633] not-detected: [..1760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5633] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5633] + idle: [..1760] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5633] not-detected: [..1829] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][42510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1829] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][42510] + idle: [..1829] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][42510] not-detected: [..1902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][42510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][42510] + idle: [..1902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][42510] not-detected: [..1528] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1556] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1528] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1556] + idle: [..1528] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1556] not-detected: [..1605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1556] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1556] + idle: [..1605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1556] guessed: [..1328] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20000] [DNP3][Unknown][IoT-Scada][Acceptable] RISK: Unidirectional Traffic - idle: [..1328] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20000] + idle: [..1328] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20000] guessed: [..1417] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20000] [DNP3][Unknown][IoT-Scada][Acceptable] RISK: Unidirectional Traffic - idle: [..1417] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20000] + idle: [..1417] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20000] not-detected: [..1475] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1475] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5666] + idle: [..1475] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5666] not-detected: [..1574] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1574] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5666] + idle: [..1574] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5666] not-detected: [...580] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...580] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20005] + idle: [...580] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20005] not-detected: [...640] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...640] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20005] + idle: [...640] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20005] not-detected: [...948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][28201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][28201] + idle: [...948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][28201] not-detected: [..1007] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][28201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1007] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][28201] + idle: [..1007] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][28201] not-detected: [..1784] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1784] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1580] + idle: [..1784] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1580] not-detected: [..1873] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1873] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1580] + idle: [..1873] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1580] not-detected: [..1839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5678] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5678] + idle: [..1839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5678] not-detected: [..1922] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5678] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1922] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5678] + idle: [..1922] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5678] not-detected: [...915] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5679] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...915] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5679] + idle: [...915] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5679] not-detected: [...190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1583] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1583] + idle: [...190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1583] not-detected: [...982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5679] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5679] + idle: [...982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5679] not-detected: [...225] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1583] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...225] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1583] + idle: [...225] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1583] not-detected: [....95] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1594] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....95] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1594] + idle: [....95] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1594] not-detected: [...114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1594] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1594] + idle: [...114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1594] not-detected: [...458] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7741] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...458] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7741] + idle: [...458] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7741] not-detected: [...490] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7741] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...490] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7741] + idle: [...490] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7741] not-detected: [...540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20031] + idle: [...540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20031] not-detected: [...873] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...873] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1600] + idle: [...873] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1600] not-detected: [...607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20031] + idle: [...607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20031] not-detected: [...932] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...932] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1600] + idle: [...932] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1600] not-detected: [...801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17988] + idle: [...801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][17988] not-detected: [...854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17988] + idle: [...854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][17988] not-detected: [...890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3659] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3659] + idle: [...890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3659] not-detected: [...965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3659] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3659] + idle: [...965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3659] not-detected: [..1737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52822] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52822] + idle: [..1737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52822] not-detected: [...804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5718] + idle: [...804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5718] not-detected: [..1817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52822] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52822] + idle: [..1817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52822] not-detected: [...851] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...851] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5718] + idle: [...851] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5718] not-detected: [....91] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....91] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7777] + idle: [....91] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7777] not-detected: [...913] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...913] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7778] + idle: [...913] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7778] not-detected: [...518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5730] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5730] + idle: [...518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5730] not-detected: [...118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7777] + idle: [...118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7777] not-detected: [...984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7778] + idle: [...984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7778] not-detected: [...553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5730] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5730] + idle: [...553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5730] not-detected: [..1594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][26214] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][26214] + idle: [..1594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][26214] not-detected: [..1656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][26214] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][26214] + idle: [..1656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][26214] not-detected: [..1838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3689] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3689] + idle: [..1838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3689] not-detected: [...565] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...565] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65129] + idle: [...565] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65129] not-detected: [...186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1641] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1641] + idle: [...186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1641] not-detected: [..1923] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3689] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1923] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3689] + idle: [..1923] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3689] not-detected: [..1093] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1093] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3690] + idle: [..1093] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3690] not-detected: [...655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65129] + idle: [...655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65129] not-detected: [...229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1641] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1641] + idle: [...229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1641] not-detected: [..1162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3690] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3690] + idle: [..1162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3690] not-detected: [...922] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...922] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50800] + idle: [...922] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50800] not-detected: [...134] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52848] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...134] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52848] + idle: [...134] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52848] not-detected: [...975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50800] + idle: [...975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50800] not-detected: [...158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52848] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52848] + idle: [...158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52848] not-detected: [..1589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3703] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3703] + idle: [..1589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3703] not-detected: [...888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18040] + idle: [...888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18040] not-detected: [..1661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3703] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3703] + idle: [..1661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3703] not-detected: [...382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7800] + idle: [...382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7800] not-detected: [...967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18040] + idle: [...967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18040] not-detected: [...402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7800] + idle: [...402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7800] not-detected: [...724] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1658] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...724] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1658] + idle: [...724] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1658] not-detected: [...781] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1658] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...781] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1658] + idle: [...781] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1658] not-detected: [...722] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...722] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16000] + idle: [...722] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16000] not-detected: [...783] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...783] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16000] + idle: [...783] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16000] not-detected: [...354] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...354] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16001] + idle: [...354] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16001] not-detected: [...389] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...389] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16001] + idle: [...389] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16001] not-detected: [...384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1666] + idle: [...384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1666] not-detected: [...400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1666] + idle: [...400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1666] not-detected: [...334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52869] + idle: [...334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][52869] not-detected: [...368] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...368] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52869] + idle: [...368] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][52869] not-detected: [..1472] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16012] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1472] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16012] + idle: [..1472] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16012] not-detected: [..1577] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16012] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1577] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16012] + idle: [..1577] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16012] not-detected: [...698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16016] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16016] + idle: [...698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16016] not-detected: [...749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16016] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16016] + idle: [...749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16016] not-detected: [..1738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16018] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16018] + idle: [..1738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16018] not-detected: [..1816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16018] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16018] + idle: [..1816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16018] not-detected: [...743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9876] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9876] + idle: [...743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9876] not-detected: [..1893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9877] + idle: [..1893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9877] not-detected: [...812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9876] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9876] + idle: [...812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9876] not-detected: [..1959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9877] + idle: [..1959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9877] not-detected: [..1023] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9878] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1023] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9878] + idle: [..1023] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9878] not-detected: [..1082] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9878] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1082] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9878] + idle: [..1082] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9878] not-detected: [....51] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1687] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....51] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1687] + idle: [....51] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1687] not-detected: [...440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1688] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1688] + idle: [...440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1688] not-detected: [....77] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1687] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....77] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1687] + idle: [....77] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1687] not-detected: [...467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1688] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1688] + idle: [...467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1688] not-detected: [...337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3737] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3737] + idle: [...337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3737] not-detected: [...365] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3737] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...365] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3737] + idle: [...365] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3737] not-detected: [..1296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1700] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1700] + idle: [..1296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1700] not-detected: [..1354] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1700] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1354] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1700] + idle: [..1354] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1700] guessed: [...375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5800] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [...375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5800] + idle: [...375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5800] not-detected: [..1374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5801] + idle: [..1374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5801] guessed: [...409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5800] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [...409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5800] + idle: [...409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5800] not-detected: [..1445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5801] + idle: [..1445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5801] not-detected: [...995] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5802] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...995] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5802] + idle: [...995] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5802] not-detected: [...188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9898] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9898] + idle: [...188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9898] not-detected: [..1052] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5802] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1052] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5802] + idle: [..1052] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5802] not-detected: [...227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9898] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9898] + idle: [...227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9898] not-detected: [...881] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...881] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9900] + idle: [...881] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9900] not-detected: [...924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9900] + idle: [...924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9900] not-detected: [...172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14000] + idle: [...172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14000] not-detected: [...202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14000] + idle: [...202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14000] not-detected: [...629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5810] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5810] + idle: [...629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5810] not-detected: [...708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5810] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5810] + idle: [...708] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5810] not-detected: [...430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5811] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5811] + idle: [...430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5811] not-detected: [...477] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5811] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...477] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5811] + idle: [...477] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5811] not-detected: [..1221] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1717] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1221] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1717] + idle: [..1221] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1717] not-detected: [...953] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...953] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18101] + idle: [...953] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18101] not-detected: [..1002] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1002] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18101] + idle: [..1002] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18101] not-detected: [..1277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1717] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1717] + idle: [..1277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1717] not-detected: [...872] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3766] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...872] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3766] + idle: [...872] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3766] not-detected: [...721] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...721] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1718] + idle: [...721] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1718] not-detected: [..1469] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5815] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1469] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5815] + idle: [..1469] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5815] not-detected: [...933] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3766] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...933] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3766] + idle: [...933] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3766] not-detected: [...784] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...784] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1718] + idle: [...784] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1718] guessed: [...537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1719] [H323][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1719] + idle: [...537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1719] not-detected: [..1532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5815] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5815] + idle: [..1532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5815] guessed: [...610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1719] [H323][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1719] + idle: [...610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1719] guessed: [....34] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1720] [H323][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [....34] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1720] + idle: [....34] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1720] not-detected: [...719] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1721] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...719] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1721] + idle: [...719] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1721] guessed: [....65] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1720] [H323][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [....65] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1720] + idle: [....65] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1720] not-detected: [...786] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1721] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...786] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1721] + idle: [...786] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1721] not-detected: [....30] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1723] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....30] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1723] + idle: [....30] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1723] not-detected: [....69] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1723] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....69] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1723] + idle: [....69] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1723] not-detected: [...112] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9917] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...112] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9917] + idle: [...112] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9917] not-detected: [...139] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9917] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...139] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9917] + idle: [...139] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9917] not-detected: [...129] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5822] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...129] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5822] + idle: [...129] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5822] not-detected: [...255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11967] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11967] + idle: [...255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11967] not-detected: [...163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5822] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5822] + idle: [...163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5822] not-detected: [...283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11967] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11967] + idle: [...283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11967] not-detected: [...187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5825] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5825] + idle: [...187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5825] not-detected: [...228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5825] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5825] + idle: [...228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5825] not-detected: [...420] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3784] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...420] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3784] + idle: [...420] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3784] not-detected: [...446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3784] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3784] + idle: [...446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3784] not-detected: [....94] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....94] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16080] + idle: [....94] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16080] not-detected: [...115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16080] + idle: [...115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16080] not-detected: [...729] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9943] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...729] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9943] + idle: [...729] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9943] not-detected: [...776] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9943] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...776] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9943] + idle: [...776] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9943] not-detected: [..1251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3800] + idle: [..1251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3800] not-detected: [...499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9944] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9944] + idle: [...499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9944] not-detected: [..1309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3800] + idle: [..1309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3800] not-detected: [...800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3801] + idle: [...800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3801] not-detected: [...532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9944] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9944] + idle: [...532] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9944] not-detected: [...855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3801] + idle: [...855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3801] not-detected: [...596] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5850] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...596] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5850] + idle: [...596] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5850] not-detected: [..1626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1755] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1755] + idle: [..1626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1755] not-detected: [...659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5850] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5850] + idle: [...659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5850] not-detected: [..1715] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1755] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1715] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1755] + idle: [..1715] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1755] not-detected: [...986] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...986] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12000] + idle: [...986] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12000] not-detected: [..1061] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1061] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12000] + idle: [..1061] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12000] not-detected: [...545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1761] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1761] + idle: [...545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1761] not-detected: [...358] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3809] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...358] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3809] + idle: [...358] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3809] not-detected: [...602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1761] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1761] + idle: [...602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1761] not-detected: [...385] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3809] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...385] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3809] + idle: [...385] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3809] not-detected: [..1641] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5859] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1641] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5859] + idle: [..1641] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5859] not-detected: [..1700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5859] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5859] + idle: [..1700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5859] not-detected: [..1889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5862] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5862] + idle: [..1889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5862] not-detected: [...291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3814] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3814] + idle: [...291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3814] not-detected: [..1963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5862] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5862] + idle: [..1963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5862] not-detected: [...502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7911] + idle: [...502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7911] not-detected: [...329] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3814] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...329] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3814] + idle: [...329] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3814] not-detected: [...529] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...529] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7911] + idle: [...529] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7911] not-detected: [..1847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7920] + idle: [..1847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7920] not-detected: [...879] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9968] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...879] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9968] + idle: [...879] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9968] not-detected: [..1350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16113] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16113] + idle: [..1350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16113] not-detected: [..1914] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1914] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7920] + idle: [..1914] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7920] not-detected: [..1171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7921] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7921] + idle: [..1171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7921] not-detected: [...926] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9968] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...926] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9968] + idle: [...926] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9968] not-detected: [..1426] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16113] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1426] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16113] + idle: [..1426] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16113] not-detected: [..1236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7921] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7921] + idle: [..1236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7921] not-detected: [...125] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3826] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...125] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3826] + idle: [...125] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3826] not-detected: [...357] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3827] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...357] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3827] + idle: [...357] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3827] not-detected: [...167] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3826] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...167] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3826] + idle: [...167] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3826] not-detected: [..1787] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3828] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1787] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3828] + idle: [..1787] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3828] not-detected: [...386] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3827] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...386] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3827] + idle: [...386] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3827] not-detected: [..1870] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3828] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1870] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3828] + idle: [..1870] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3828] not-detected: [..1027] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1027] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5877] + idle: [..1027] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5877] not-detected: [..1104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1782] + idle: [..1104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1782] not-detected: [..1078] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5877] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1078] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5877] + idle: [..1078] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5877] not-detected: [..1151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1782] + idle: [..1151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1782] not-detected: [..1014] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1014] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1783] + idle: [..1014] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1783] not-detected: [..1091] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1091] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1783] + idle: [..1091] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1783] not-detected: [..1674] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1674] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20221] + idle: [..1674] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20221] not-detected: [..1753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20221] + idle: [..1753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20221] not-detected: [...342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20222] + idle: [...342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20222] not-detected: [...360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20222] + idle: [...360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20222] not-detected: [...848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7937] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7937] + idle: [...848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7937] not-detected: [..1197] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7938] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1197] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7938] + idle: [..1197] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7938] not-detected: [...899] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7937] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...899] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7937] + idle: [...899] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7937] not-detected: [..1259] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7938] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1259] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7938] + idle: [..1259] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7938] not-detected: [..1841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1801] + idle: [..1841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1801] not-detected: [..1920] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1920] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1801] + idle: [..1920] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1801] not-detected: [...885] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34571] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...885] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34571] + idle: [...885] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34571] not-detected: [...614] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3851] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...614] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3851] + idle: [...614] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3851] not-detected: [...970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34571] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34571] + idle: [...970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34571] not-detected: [...590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34572] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34572] + idle: [...590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34572] not-detected: [...683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3851] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3851] + idle: [...683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3851] guessed: [....10] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5900] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [....10] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5900] + idle: [....10] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5900] not-detected: [..1046] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34573] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1046] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34573] + idle: [..1046] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][34573] not-detected: [...665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34572] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34572] + idle: [...665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34572] guessed: [...838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5901] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [...838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5901] + idle: [...838] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5901] not-detected: [...453] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1805] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...453] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1805] + idle: [...453] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1805] guessed: [....21] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5900] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [....21] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5900] + idle: [....21] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5900] not-detected: [..1691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9998] + idle: [..1691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9998] not-detected: [..1109] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34573] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1109] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34573] + idle: [..1109] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][34573] not-detected: [..1022] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5902] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1022] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5902] + idle: [..1022] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5902] guessed: [...909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5901] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [...909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5901] + idle: [...909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5901] not-detected: [...495] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1805] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...495] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1805] + idle: [...495] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1805] not-detected: [..1766] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1766] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9998] + idle: [..1766] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9998] not-detected: [..1534] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55055] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1534] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55055] + idle: [..1534] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55055] not-detected: [..1083] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5902] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1083] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5902] + idle: [..1083] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5902] guessed: [...796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] RISK: Unidirectional Traffic - idle: [...796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9999] + idle: [...796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9999] not-detected: [...103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5903] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5903] + idle: [...103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5903] not-detected: [..1791] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55056] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1791] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55056] + idle: [..1791] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55056] not-detected: [..1619] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55055] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1619] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55055] + idle: [..1619] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55055] guessed: [...859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] RISK: Unidirectional Traffic - idle: [...859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9999] + idle: [...859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9999] guessed: [...539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10000] [CiscoVPN][Unknown][VPN][Acceptable] RISK: Unidirectional Traffic - idle: [...539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10000] + idle: [...539] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10000] not-detected: [..1653] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5904] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1653] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5904] + idle: [..1653] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5904] not-detected: [...147] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5903] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...147] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5903] + idle: [...147] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5903] not-detected: [..1866] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55056] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1866] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55056] + idle: [..1866] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55056] guessed: [...608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10000] [CiscoVPN][Unknown][VPN][Acceptable] RISK: Unidirectional Traffic - idle: [...608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10000] + idle: [...608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10000] not-detected: [..1718] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5904] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1718] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5904] + idle: [..1718] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5904] not-detected: [...577] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...577] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10001] + idle: [...577] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10001] not-detected: [...643] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...643] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10001] + idle: [...643] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10001] not-detected: [...535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5906] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5906] + idle: [...535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5906] not-detected: [...272] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...272] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10002] + idle: [...272] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10002] not-detected: [...733] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...733] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10003] + idle: [...733] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10003] not-detected: [..1029] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5907] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1029] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5907] + idle: [..1029] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5907] not-detected: [...612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5906] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5906] + idle: [...612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5906] not-detected: [...307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10002] + idle: [...307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10002] not-detected: [...822] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...822] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10003] + idle: [...822] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10003] guessed: [..1940] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1812] [Radius][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1940] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1812] + idle: [..1940] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1812] not-detected: [..1076] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5907] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1076] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5907] + idle: [..1076] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5907] not-detected: [...626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10004] + idle: [...626] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10004] guessed: [..1982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1812] [Radius][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1812] + idle: [..1982] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1812] not-detected: [...711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10004] + idle: [...711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10004] not-detected: [..1298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5910] + idle: [..1298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5910] not-detected: [..1774] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1774] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5911] + idle: [..1774] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5911] not-detected: [..1352] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1352] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5910] + idle: [..1352] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5910] not-detected: [..1835] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1835] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5911] + idle: [..1835] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5911] not-detected: [...421] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...421] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10009] + idle: [...421] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10009] not-detected: [...803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10010] + idle: [...803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10010] not-detected: [...445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10009] + idle: [...445] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10009] not-detected: [..1803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5915] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5915] + idle: [..1803] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5915] not-detected: [...852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10010] + idle: [...852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10010] not-detected: [..1925] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10012] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1925] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10012] + idle: [..1925] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10012] not-detected: [..1854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5915] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5915] + idle: [..1854] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5915] not-detected: [..1969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10012] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10012] + idle: [..1969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10012] not-detected: [..1348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3869] + idle: [..1348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3869] not-detected: [..1397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3869] + idle: [..1397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3869] not-detected: [..1372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3871] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3871] + idle: [..1372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3871] not-detected: [..1447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3871] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3871] + idle: [..1447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3871] not-detected: [...769] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5922] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...769] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5922] + idle: [...769] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5922] not-detected: [...828] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5922] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...828] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5922] + idle: [...828] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5922] not-detected: [..1805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5925] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5925] + idle: [..1805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5925] not-detected: [..1852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5925] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5925] + idle: [..1852] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5925] not-detected: [...798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3878] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3878] + idle: [...798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3878] not-detected: [...857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3878] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3878] + idle: [...857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3878] not-detected: [..1216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10024] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10024] + idle: [..1216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10024] not-detected: [....89] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3880] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....89] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3880] + idle: [....89] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3880] not-detected: [..1536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10025] + idle: [..1536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10025] not-detected: [..1282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10024] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10024] + idle: [..1282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10024] not-detected: [...120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3880] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3880] + idle: [...120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3880] not-detected: [..1617] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1617] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10025] + idle: [..1617] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10025] not-detected: [...728] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1839] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...728] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1839] + idle: [...728] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1839] not-detected: [...777] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1839] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...777] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1839] + idle: [...777] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1839] not-detected: [...269] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1840] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...269] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1840] + idle: [...269] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1840] not-detected: [..1430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3889] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3889] + idle: [..1430] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3889] not-detected: [...310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1840] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1840] + idle: [...310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1840] not-detected: [..1516] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3889] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1516] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3889] + idle: [..1516] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3889] not-detected: [..1522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5950] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5950] + idle: [..1522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5950] not-detected: [..1601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5950] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5950] + idle: [..1601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5950] not-detected: [..1388] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1388] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7999] + idle: [..1388] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7999] not-detected: [..1461] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1461] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7999] + idle: [..1461] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7999] not-detected: [..1292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5952] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5952] + idle: [..1292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5952] not-detected: [...427] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...427] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8000] + idle: [...427] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8000] not-detected: [..1358] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5952] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1358] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5952] + idle: [..1358] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5952] not-detected: [..1344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8001] + idle: [..1344] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8001] not-detected: [...624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3905] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3905] + idle: [...624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3905] not-detected: [...480] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...480] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8000] + idle: [...480] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8000] not-detected: [..1401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8001] + idle: [..1401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8001] not-detected: [...713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3905] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3905] + idle: [...713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3905] not-detected: [...633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8002] + idle: [...633] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8002] not-detected: [...704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8002] + idle: [...704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8002] not-detected: [...500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1862] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1862] + idle: [...500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1862] not-detected: [..1176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8007] + idle: [..1176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8007] not-detected: [..1936] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1863] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1936] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1863] + idle: [..1936] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1863] not-detected: [...531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1862] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1862] + idle: [...531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1862] not-detected: [...169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5959] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5959] + idle: [...169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5959] guessed: [..1394] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8008] [CiscoVPN][Unknown][VPN][Acceptable] RISK: Unidirectional Traffic - idle: [..1394] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8008] + idle: [..1394] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8008] not-detected: [..1231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8007] + idle: [..1231] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8007] not-detected: [..1986] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1863] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1986] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1863] + idle: [..1986] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1863] not-detected: [..1142] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5960] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1142] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5960] + idle: [..1142] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5960] not-detected: [...865] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1864] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...865] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1864] + idle: [...865] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1864] not-detected: [...205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5959] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5959] + idle: [...205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5959] guessed: [..1455] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8008] [CiscoVPN][Unknown][VPN][Acceptable] RISK: Unidirectional Traffic - idle: [..1455] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8008] + idle: [..1455] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8008] not-detected: [..1336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5961] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5961] + idle: [..1336] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5961] not-detected: [..1205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5960] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5960] + idle: [..1205] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5960] not-detected: [...940] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1864] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...940] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1864] + idle: [...940] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1864] guessed: [...621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8009] [AJP][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [...621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8009] + idle: [...621] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8009] not-detected: [..1947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5962] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5962] + idle: [..1947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5962] not-detected: [..1743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3914] + idle: [..1743] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3914] not-detected: [..1409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5961] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5961] + idle: [..1409] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5961] guessed: [...923] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8010] [AJP][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [...923] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8010] + idle: [...923] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8010] guessed: [...676] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8009] [AJP][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [...676] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8009] + idle: [...676] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8009] not-detected: [..1975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5962] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5962] + idle: [..1975] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5962] not-detected: [..1478] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1478] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8011] + idle: [..1478] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8011] guessed: [...974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8010] [AJP][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [...974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8010] + idle: [...974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8010] not-detected: [..1811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3914] + idle: [..1811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3914] not-detected: [...343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5963] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5963] + idle: [...343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5963] not-detected: [..1571] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1571] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8011] + idle: [..1571] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8011] not-detected: [...359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5963] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5963] + idle: [...359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5963] not-detected: [...300] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3918] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...300] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3918] + idle: [...300] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3918] not-detected: [...320] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3918] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...320] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3918] + idle: [...320] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3918] not-detected: [..1652] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1652] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3920] + idle: [..1652] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3920] not-detected: [..1719] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1719] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3920] + idle: [..1719] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3920] not-detected: [...717] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1875] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...717] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1875] + idle: [...717] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1875] not-detected: [...788] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1875] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...788] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1875] + idle: [...788] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1875] not-detected: [...519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8021] + idle: [...519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8021] not-detected: [..1789] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1789] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8022] + idle: [..1789] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8022] not-detected: [...552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8021] + idle: [...552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8021] not-detected: [..1868] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1868] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8022] + idle: [..1868] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8022] not-detected: [..1383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8031] + idle: [..1383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8031] not-detected: [..1466] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1466] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8031] + idle: [..1466] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8031] not-detected: [...513] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...513] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10082] + idle: [...513] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10082] not-detected: [..1776] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][63331] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1776] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][63331] + idle: [..1776] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][63331] not-detected: [...942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5987] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5987] + idle: [...942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5987] not-detected: [...558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10082] + idle: [...558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10082] not-detected: [..1881] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][63331] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1881] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][63331] + idle: [..1881] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][63331] not-detected: [..1013] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5987] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1013] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5987] + idle: [..1013] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5987] not-detected: [...570] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...570] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5988] + idle: [...570] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5988] not-detected: [...897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5989] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5989] + idle: [...897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5989] not-detected: [...650] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...650] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5988] + idle: [...650] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5988] not-detected: [...958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5989] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5989] + idle: [...958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5989] not-detected: [...256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3945] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3945] + idle: [...256] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3945] not-detected: [...839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8042] + idle: [...839] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8042] not-detected: [...282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3945] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3945] + idle: [...282] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3945] not-detected: [...908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8042] + idle: [...908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8042] not-detected: [...992] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...992] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1900] + idle: [...992] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1900] not-detected: [..1744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65389] + idle: [..1744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][65389] not-detected: [..1055] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1055] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1900] + idle: [..1055] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1900] not-detected: [...258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8045] + idle: [...258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8045] not-detected: [..1810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65389] + idle: [..1810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][65389] not-detected: [..1064] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1064] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5998] + idle: [..1064] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5998] not-detected: [...280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8045] + idle: [...280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8045] not-detected: [..1133] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1133] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5998] + idle: [..1133] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5998] not-detected: [...628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5999] + idle: [...628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5999] not-detected: [...709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5999] + idle: [...709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5999] not-detected: [....50] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....50] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6000] + idle: [....50] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6000] not-detected: [..1481] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1481] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6001] + idle: [..1481] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6001] not-detected: [....78] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....78] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6000] + idle: [....78] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6000] not-detected: [..1568] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1568] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6001] + idle: [..1568] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6001] not-detected: [..1392] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1392] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6002] + idle: [..1392] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6002] not-detected: [..1457] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1457] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6002] + idle: [..1457] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6002] not-detected: [..1217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6003] + idle: [..1217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6003] not-detected: [..1741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6004] + idle: [..1741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6004] not-detected: [..1281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6003] + idle: [..1281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6003] not-detected: [..1944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6005] + idle: [..1944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6005] not-detected: [..1813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6004] + idle: [..1813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6004] not-detected: [..1978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6005] + idle: [..1978] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6005] not-detected: [..1695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6006] + idle: [..1695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6006] not-detected: [..1762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6006] + idle: [..1762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6006] not-detected: [..1190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6007] + idle: [..1190] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6007] not-detected: [..1266] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1266] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6007] + idle: [..1266] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6007] not-detected: [..1347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6009] + idle: [..1347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6009] not-detected: [..1398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6009] + idle: [..1398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6009] not-detected: [...847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1914] + idle: [...847] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1914] not-detected: [...900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1914] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1914] + idle: [...900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1914] not-detected: [...292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24444] + idle: [...292] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24444] not-detected: [...328] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...328] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24444] + idle: [...328] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24444] not-detected: [...955] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3971] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...955] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3971] + idle: [...955] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3971] not-detected: [..1000] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3971] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1000] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3971] + idle: [..1000] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3971] not-detected: [...517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6025] + idle: [...517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6025] not-detected: [...554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6025] + idle: [...554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6025] not-detected: [...875] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12174] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...875] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12174] + idle: [...875] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12174] guessed: [..1547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1935] [RTMP][Unknown][Media][Acceptable] RISK: Unidirectional Traffic - idle: [..1547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1935] + idle: [..1547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1935] not-detected: [...930] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12174] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...930] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12174] + idle: [...930] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12174] guessed: [..1606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1935] [RTMP][Unknown][Media][Acceptable] RISK: Unidirectional Traffic - idle: [..1606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1935] + idle: [..1606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1935] guessed: [....33] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....33] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8080] + idle: [....33] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8080] not-detected: [..1442] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1442] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8081] + idle: [..1442] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8081] guessed: [....66] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8080] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....66] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8080] + idle: [....66] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8080] not-detected: [..1504] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1504] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8081] + idle: [..1504] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8081] not-detected: [..1518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3986] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3986] + idle: [..1518] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3986] not-detected: [...736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8082] + idle: [...736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8082] not-detected: [..1648] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8083] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1648] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8083] + idle: [..1648] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8083] not-detected: [..1580] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3986] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1580] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3986] + idle: [..1580] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3986] not-detected: [...819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8082] + idle: [...819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8082] not-detected: [..1896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8084] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8084] + idle: [..1896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8084] not-detected: [..1723] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8083] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1723] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8083] + idle: [..1723] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8083] not-detected: [..1956] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8084] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1956] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8084] + idle: [..1956] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8084] not-detected: [..1147] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8085] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1147] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8085] + idle: [..1147] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8085] not-detected: [..1200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8085] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8085] + idle: [..1200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8085] not-detected: [...346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8086] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8086] + idle: [...346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8086] not-detected: [..1043] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1043] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8087] + idle: [..1043] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8087] not-detected: [...397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8086] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8086] + idle: [...397] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8086] not-detected: [..1218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8088] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8088] + idle: [..1218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8088] not-detected: [..1112] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1112] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8087] + idle: [..1112] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8087] not-detected: [..1280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8088] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8088] + idle: [..1280] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8088] not-detected: [..1094] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8089] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1094] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8089] + idle: [..1094] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8089] not-detected: [..1161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8089] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8089] + idle: [..1161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8089] not-detected: [...846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8090] + idle: [...846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8090] not-detected: [...901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8090] + idle: [...901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8090] not-detected: [..1474] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1947] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1474] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1947] + idle: [..1474] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1947] not-detected: [...691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3995] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3995] + idle: [...691] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3995] not-detected: [..1575] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1947] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1575] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1947] + idle: [..1575] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1947] not-detected: [...756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3995] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3995] + idle: [...756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3995] not-detected: [..1890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8093] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8093] + idle: [..1890] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8093] not-detected: [..1962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8093] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8093] + idle: [..1962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8093] not-detected: [..1692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3998] + idle: [..1692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3998] not-detected: [....87] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14238] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....87] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14238] + idle: [....87] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14238] not-detected: [..1371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51103] + idle: [..1371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51103] not-detected: [..1765] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1765] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3998] + idle: [..1765] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3998] not-detected: [...122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14238] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14238] + idle: [...122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14238] not-detected: [..1448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51103] + idle: [..1448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51103] not-detected: [...182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4000] + idle: [...182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4000] not-detected: [..1842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4001] + idle: [..1842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4001] not-detected: [...233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4000] + idle: [...233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4000] not-detected: [..1919] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1919] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4001] + idle: [..1919] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4001] not-detected: [..1484] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1484] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4002] + idle: [..1484] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4002] not-detected: [..1565] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1565] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4002] + idle: [..1565] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4002] not-detected: [...634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8099] + idle: [...634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8099] not-detected: [...105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4003] + idle: [...105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4003] not-detected: [...703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8099] + idle: [...703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8099] not-detected: [...501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8100] + idle: [...501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8100] not-detected: [..1290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4004] + idle: [..1290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4004] not-detected: [...145] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...145] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4003] + idle: [...145] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4003] not-detected: [..1360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4004] + idle: [..1360] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4004] not-detected: [...530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8100] + idle: [...530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8100] not-detected: [...374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4005] + idle: [...374] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4005] not-detected: [...410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4005] + idle: [...410] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4005] not-detected: [...335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4006] + idle: [...335] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4006] not-detected: [...367] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...367] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4006] + idle: [...367] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4006] not-detected: [..1781] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6059] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1781] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6059] + idle: [..1781] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6059] not-detected: [..1876] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6059] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1876] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6059] + idle: [..1876] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6059] not-detected: [..1164] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1971] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1164] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1971] + idle: [..1164] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1971] not-detected: [..1250] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1972] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1250] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1972] + idle: [..1250] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1972] not-detected: [..1243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1971] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1971] + idle: [..1243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1971] not-detected: [..1310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1972] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1972] + idle: [..1310] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1972] not-detected: [...880] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1974] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...880] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1974] + idle: [...880] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1974] not-detected: [...925] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1974] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...925] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1974] + idle: [...925] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1974] not-detected: [..1892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1984] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1984] + idle: [..1892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1984] not-detected: [..1960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1984] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1984] + idle: [..1960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1984] not-detected: [...615] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10180] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...615] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10180] + idle: [...615] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10180] not-detected: [...682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10180] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10180] + idle: [...682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10180] not-detected: [..1645] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1645] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4045] + idle: [..1645] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4045] not-detected: [..1726] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1726] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4045] + idle: [..1726] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4045] not-detected: [..1322] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57294] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1322] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57294] + idle: [..1322] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57294] not-detected: [..1319] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1319] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1998] + idle: [..1319] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1998] not-detected: [..1423] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57294] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1423] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57294] + idle: [..1423] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57294] not-detected: [..1378] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1378] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1998] + idle: [..1378] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1998] not-detected: [...764] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...764] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1999] + idle: [...764] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1999] not-detected: [...263] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...263] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40911] + idle: [...263] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40911] guessed: [..1631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [..1631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2000] + idle: [..1631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2000] not-detected: [...833] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...833] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1999] + idle: [...833] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1999] not-detected: [...316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40911] + idle: [...316] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40911] guessed: [..1710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2000] [CiscoSkinny][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [..1710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2000] + idle: [..1710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2000] not-detected: [...355] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...355] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2001] + idle: [...355] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2001] not-detected: [..1496] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1496] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2002] + idle: [..1496] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2002] not-detected: [...388] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...388] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2001] + idle: [...388] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2001] not-detected: [..1553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2002] + idle: [..1553] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2002] not-detected: [..1185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2003] + idle: [..1185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2003] not-detected: [..1381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6100] + idle: [..1381] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6100] not-detected: [..1271] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1271] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2003] + idle: [..1271] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2003] not-detected: [...893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2004] + idle: [...893] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2004] not-detected: [..1468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6100] + idle: [..1468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6100] not-detected: [..1035] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1035] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6101] + idle: [..1035] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6101] not-detected: [...962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2004] + idle: [...962] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2004] not-detected: [...101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2005] + idle: [...101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2005] not-detected: [..1120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6101] + idle: [..1120] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6101] not-detected: [..1693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2006] + idle: [..1693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2006] not-detected: [...149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2005] + idle: [...149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2005] not-detected: [..1764] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1764] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2006] + idle: [..1764] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2006] not-detected: [..1432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2007] + idle: [..1432] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2007] not-detected: [..1822] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2008] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1822] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2008] + idle: [..1822] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2008] not-detected: [..1514] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1514] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2007] + idle: [..1514] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2007] not-detected: [..1884] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2008] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1884] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2008] + idle: [..1884] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2008] not-detected: [...951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2009] + idle: [...951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2009] not-detected: [..1677] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1677] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2010] + idle: [..1677] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2010] not-detected: [..1004] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1004] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2009] + idle: [..1004] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2009] not-detected: [...582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6106] + idle: [...582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6106] not-detected: [..1750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2010] + idle: [..1750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2010] not-detected: [...673] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...673] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6106] + idle: [...673] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6106] not-detected: [...515] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2013] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...515] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2013] + idle: [...515] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2013] not-detected: [...556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2013] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2013] + idle: [...556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2013] not-detected: [..1172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6112] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6112] + idle: [..1172] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6112] not-detected: [..1235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6112] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6112] + idle: [..1235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6112] not-detected: [...340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2020] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2020] + idle: [...340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2020] not-detected: [..1376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2021] + idle: [..1376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2021] not-detected: [...362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2020] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2020] + idle: [...362] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2020] not-detected: [..1453] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1453] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2021] + idle: [..1453] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2021] not-detected: [...741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2022] + idle: [...741] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2022] not-detected: [..1540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10215] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10215] + idle: [..1540] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10215] not-detected: [...814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2022] + idle: [...814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2022] not-detected: [..1613] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10215] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1613] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10215] + idle: [..1613] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10215] not-detected: [...766] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12265] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...766] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12265] + idle: [...766] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12265] not-detected: [...831] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12265] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...831] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12265] + idle: [...831] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12265] not-detected: [..1786] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6123] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1786] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6123] + idle: [..1786] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6123] not-detected: [..1871] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6123] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1871] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6123] + idle: [..1871] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6123] not-detected: [....53] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....53] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2030] + idle: [....53] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2030] not-detected: [....75] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....75] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2030] + idle: [....75] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2030] not-detected: [..1888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2033] + idle: [..1888] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2033] not-detected: [..1735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6129] + idle: [..1735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6129] not-detected: [..1964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2033] + idle: [..1964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2033] not-detected: [..1945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2034] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2034] + idle: [..1945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2034] not-detected: [..1819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6129] + idle: [..1819] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6129] not-detected: [..1977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2034] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2034] + idle: [..1977] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2034] not-detected: [..1031] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2035] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1031] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2035] + idle: [..1031] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2035] not-detected: [..1074] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2035] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1074] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2035] + idle: [..1074] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2035] not-detected: [...916] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8180] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...916] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8180] + idle: [...916] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8180] not-detected: [...981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8180] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8180] + idle: [...981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8180] not-detected: [...746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8181] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8181] + idle: [...746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8181] not-detected: [...809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8181] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8181] + idle: [...809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8181] not-detected: [....86] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....86] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2038] + idle: [....86] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2038] not-detected: [...123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2038] + idle: [...123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2038] not-detected: [..1785] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1785] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2040] + idle: [..1785] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2040] not-detected: [..1872] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1872] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2040] + idle: [..1872] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2040] not-detected: [..1258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2041] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2041] + idle: [..1258] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2041] not-detected: [..1302] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2041] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1302] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2041] + idle: [..1302] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2041] not-detected: [..1140] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1140] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2042] + idle: [..1140] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2042] not-detected: [..1545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2043] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2043] + idle: [..1545] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2043] not-detected: [..1207] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1207] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2042] + idle: [..1207] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2042] not-detected: [..1608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2043] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2043] + idle: [..1608] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2043] not-detected: [..1779] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1779] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2045] + idle: [..1779] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2045] not-detected: [..1878] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1878] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2045] + idle: [..1878] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2045] not-detected: [...350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2046] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2046] + idle: [...350] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2046] not-detected: [...208] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...208] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30718] + idle: [...208] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30718] not-detected: [...587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2047] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2047] + idle: [...587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2047] not-detected: [...393] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2046] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...393] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2046] + idle: [...393] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2046] not-detected: [...248] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...248] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30718] + idle: [...248] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30718] not-detected: [..1935] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49152] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1935] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49152] + idle: [..1935] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49152] not-detected: [...696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8192] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8192] + idle: [...696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8192] not-detected: [...668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2047] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2047] + idle: [...668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2047] not-detected: [...637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2048] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2048] + idle: [...637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2048] not-detected: [...185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32768] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32768] + idle: [...185] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32768] not-detected: [..1987] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49152] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1987] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49152] + idle: [..1987] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49152] not-detected: [..1343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49153] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49153] + idle: [..1343] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49153] not-detected: [..1225] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32769] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1225] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32769] + idle: [..1225] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32769] not-detected: [...751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8192] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8192] + idle: [...751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8192] guessed: [..1825] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2049] [NFS][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [..1825] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2049] + idle: [..1825] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2049] not-detected: [...944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....1] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....1] + idle: [...944] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....1] not-detected: [...700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2048] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2048] + idle: [...700] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2048] not-detected: [...542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8193] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8193] + idle: [...542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8193] not-detected: [...230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32768] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32768] + idle: [...230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32768] not-detected: [..1402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49153] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49153] + idle: [..1402] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49153] not-detected: [..1775] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32770] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1775] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32770] + idle: [..1775] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32770] not-detected: [..1300] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32769] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1300] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32769] + idle: [..1300] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32769] not-detected: [...802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49154] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49154] + idle: [...802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49154] guessed: [..1906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2049] [NFS][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [..1906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2049] + idle: [..1906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2049] not-detected: [..1193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8194] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8194] + idle: [..1193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8194] not-detected: [..1011] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....1] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1011] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....1] + idle: [..1011] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....1] not-detected: [...605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8193] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8193] + idle: [...605] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8193] not-detected: [...853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49154] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49154] + idle: [...853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49154] not-detected: [..1834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32770] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32770] + idle: [..1834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32770] not-detected: [..1887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10243] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10243] + idle: [..1887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10243] not-detected: [..1480] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32771] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1480] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32771] + idle: [..1480] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32771] not-detected: [..1263] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8194] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1263] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8194] + idle: [..1263] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8194] not-detected: [...544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....3] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....3] + idle: [...544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....3] not-detected: [...194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49155] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49155] + idle: [...194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49155] not-detected: [..1569] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32771] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1569] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32771] + idle: [..1569] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32771] not-detected: [..1965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10243] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10243] + idle: [..1965] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10243] not-detected: [..1332] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32772] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1332] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32772] + idle: [..1332] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32772] not-detected: [...793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49156] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49156] + idle: [...793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49156] not-detected: [...841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....4] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....4] + idle: [...841] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....4] not-detected: [...603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....3] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....3] + idle: [...603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....3] not-detected: [...221] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49155] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...221] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49155] + idle: [...221] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49155] not-detected: [..1951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49157] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49157] + idle: [..1951] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49157] not-detected: [..1413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32772] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32772] + idle: [..1413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32772] not-detected: [..1177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32773] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32773] + idle: [..1177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32773] not-detected: [...906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....4] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....4] + idle: [...906] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....4] not-detected: [...862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49156] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49156] + idle: [...862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49156] not-detected: [..1971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49157] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49157] + idle: [..1971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49157] not-detected: [..1230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32773] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32773] + idle: [..1230] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32773] not-detected: [...954] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49158] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...954] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49158] + idle: [...954] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49158] not-detected: [...585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32774] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32774] + idle: [...585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32774] not-detected: [....54] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....6] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....54] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....6] + idle: [....54] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....6] not-detected: [..1627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49159] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49159] + idle: [..1627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49159] not-detected: [..1001] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49158] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1001] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49158] + idle: [..1001] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49158] not-detected: [..1843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32775] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32775] + idle: [..1843] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32775] not-detected: [...670] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32774] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...670] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32774] + idle: [...670] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32774] not-detected: [...514] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....7] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...514] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....7] + idle: [...514] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....7] not-detected: [....74] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....6] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....74] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....6] + idle: [....74] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....6] not-detected: [..1918] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32775] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1918] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32775] + idle: [..1918] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32775] not-detected: [..1848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49160] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49160] + idle: [..1848] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49160] not-detected: [..1714] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49159] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1714] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49159] + idle: [..1714] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49159] not-detected: [...588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8200] + idle: [...588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8200] not-detected: [...557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....7] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....7] + idle: [...557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....7] not-detected: [...509] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32776] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...509] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32776] + idle: [...509] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32776] not-detected: [..1913] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49160] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1913] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49160] + idle: [..1913] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49160] not-detected: [..1489] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1489] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49161] + idle: [..1489] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49161] not-detected: [..1642] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1642] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32777] + idle: [..1642] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32777] not-detected: [...667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8200] + idle: [...667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8200] not-detected: [...562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32776] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32776] + idle: [...562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32776] not-detected: [...371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....9] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....9] + idle: [...371] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][....9] not-detected: [..1729] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1729] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32777] + idle: [..1729] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32777] not-detected: [..1560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49161] + idle: [..1560] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49161] not-detected: [...413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....9] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....9] + idle: [...413] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][....9] not-detected: [....93] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....93] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32778] + idle: [....93] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32778] not-detected: [...767] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...767] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49163] + idle: [...767] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49163] not-detected: [...792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32779] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32779] + idle: [...792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32779] not-detected: [...116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32778] + idle: [...116] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32778] not-detected: [...863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32779] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32779] + idle: [...863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32779] not-detected: [...830] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...830] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49163] + idle: [...830] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49163] not-detected: [..1174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6156] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6156] + idle: [..1174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6156] not-detected: [...503] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32780] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...503] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32780] + idle: [...503] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32780] not-detected: [...727] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49165] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...727] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49165] + idle: [...727] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49165] not-detected: [...528] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32780] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...528] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32780] + idle: [...528] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32780] not-detected: [..1373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...13] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...13] + idle: [..1373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...13] not-detected: [..1233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6156] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6156] + idle: [..1233] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6156] not-detected: [...276] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32781] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...276] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32781] + idle: [...276] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32781] not-detected: [...778] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49165] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...778] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49165] + idle: [...778] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49165] not-detected: [..1446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...13] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...13] + idle: [..1446] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...13] not-detected: [...770] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...770] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32782] + idle: [...770] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32782] not-detected: [...303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32781] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32781] + idle: [...303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32781] not-detected: [..1739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49167] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49167] + idle: [..1739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49167] not-detected: [...998] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...998] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32783] + idle: [...998] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32783] not-detected: [...827] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32782] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...827] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32782] + idle: [...827] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32782] not-detected: [...380] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...380] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4111] + idle: [...380] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4111] not-detected: [..1815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49167] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49167] + idle: [..1815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49167] not-detected: [..1527] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32784] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1527] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32784] + idle: [..1527] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32784] not-detected: [..1049] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1049] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32783] + idle: [..1049] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32783] not-detected: [...404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4111] + idle: [...404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4111] not-detected: [..1596] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32784] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1596] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32784] + idle: [..1596] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32784] not-detected: [..1833] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2065] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1833] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2065] + idle: [..1833] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2065] not-detected: [...436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32785] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32785] + idle: [...436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][32785] not-detected: [...289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...17] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...17] + idle: [...289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...17] not-detected: [..1908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2065] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2065] + idle: [..1908] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2065] not-detected: [...471] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32785] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...471] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32785] + idle: [...471] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][32785] not-detected: [...331] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...17] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...331] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...17] + idle: [...331] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...17] not-detected: [..1139] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...19] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1139] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...19] + idle: [..1139] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...19] not-detected: [..1647] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2068] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1647] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2068] + idle: [..1647] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2068] guessed: [..1320] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...20] [FTP_DATA][Unknown][Download][Acceptable] RISK: Unidirectional Traffic - idle: [..1320] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...20] + idle: [..1320] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...20] not-detected: [..1208] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...19] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1208] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...19] + idle: [..1208] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...19] not-detected: [..1724] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2068] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1724] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2068] + idle: [..1724] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2068] guessed: [..1425] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...20] [FTP_DATA][Unknown][Download][Acceptable] RISK: Unidirectional Traffic - idle: [..1425] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...20] + idle: [..1425] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...20] guessed: [....11] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....11] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...21] + idle: [....11] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...21] guessed: [....40] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...22] [SSH][Unknown][RemoteAccess][Acceptable] - idle: [....40] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...22] + idle: [....40] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...22] guessed: [....20] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...21] [FTP_CONTROL][Unknown][Download][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....20] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...21] + idle: [....20] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...21] not-detected: [..1443] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49175] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1443] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49175] + idle: [..1443] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49175] guessed: [....16] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...23] [Telnet][Unknown][RemoteAccess][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....16] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...23] + idle: [....16] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...23] not-detected: [..1503] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49175] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1503] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49175] + idle: [..1503] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49175] not-detected: [...426] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49176] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...426] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49176] + idle: [...426] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49176] not-detected: [...135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...24] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...24] + idle: [...135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...24] guessed: [....17] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...23] [Telnet][Unknown][RemoteAccess][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....17] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...23] + idle: [....17] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...23] not-detected: [...481] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49176] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...481] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49176] + idle: [...481] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49176] not-detected: [...157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...24] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...24] + idle: [...157] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...24] guessed: [....35] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...25] [SMTP][Unknown][Email][Acceptable][] RISK: TCP Connection Issues - end: [....35] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...25] + end: [....35] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...25] not-detected: [...293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...26] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...26] + idle: [...293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...26] not-detected: [...327] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...26] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...327] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...26] + idle: [...327] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...26] not-detected: [...765] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4125] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...765] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4125] + idle: [...765] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4125] not-detected: [...832] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4125] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...832] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4125] + idle: [...832] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4125] not-detected: [...463] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...463] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4126] + idle: [...463] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4126] not-detected: [...429] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...30] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...429] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...30] + idle: [...429] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...30] not-detected: [....56] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....56] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8222] + idle: [....56] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8222] not-detected: [...485] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...485] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4126] + idle: [...485] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4126] not-detected: [...478] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...30] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...478] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...30] + idle: [...478] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...30] not-detected: [....72] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....72] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8222] + idle: [....72] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8222] not-detected: [...132] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...32] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...132] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...32] + idle: [...132] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...32] not-detected: [...353] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...353] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4129] + idle: [...353] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4129] not-detected: [..1640] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...33] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1640] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...33] + idle: [..1640] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...33] not-detected: [...160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...32] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...32] + idle: [...160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...32] not-detected: [..1701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...33] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...33] + idle: [..1701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...33] not-detected: [...390] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4129] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...390] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4129] + idle: [...390] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4129] not-detected: [..1368] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...37] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1368] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...37] + idle: [..1368] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...37] not-detected: [..1451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...37] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...37] + idle: [..1451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...37] not-detected: [...694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...42] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...42] + idle: [...694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...42] guessed: [..1222] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...43] [Whois-DAS][Unknown][Network][Acceptable][] RISK: Unidirectional Traffic - idle: [..1222] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...43] + idle: [..1222] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...43] not-detected: [...753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...42] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...42] + idle: [...753] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...42] guessed: [..1276] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...43] [Whois-DAS][Unknown][Network][Acceptable][] RISK: Unidirectional Traffic - idle: [..1276] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...43] + idle: [..1276] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...43] not-detected: [..1017] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][45100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1017] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][45100] + idle: [..1017] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][45100] not-detected: [..1088] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][45100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1088] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][45100] + idle: [..1088] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][45100] not-detected: [..1485] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...49] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1485] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...49] + idle: [..1485] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...49] not-detected: [..1564] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...49] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1564] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...49] + idle: [..1564] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...49] not-detected: [...217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2099] + idle: [...217] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2099] not-detected: [...844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2100] + idle: [...844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2100] not-detected: [...239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2099] + idle: [...239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2099] not-detected: [...903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2100] + idle: [...903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2100] guessed: [.....9] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...53] [DNS][Unknown][Network][Acceptable][] - idle: [.....9] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...53] + idle: [.....9] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...53] not-detected: [..1931] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1931] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2103] + idle: [..1931] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2103] not-detected: [..1991] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1991] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2103] + idle: [..1991] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2103] not-detected: [..1636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2105] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2105] + idle: [..1636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2105] not-detected: [...878] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12345] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...878] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12345] + idle: [...878] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][12345] not-detected: [..1705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2105] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2105] + idle: [..1705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2105] not-detected: [...927] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12345] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...927] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12345] + idle: [...927] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][12345] not-detected: [...176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2106] + idle: [...176] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2106] not-detected: [...730] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2107] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...730] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2107] + idle: [...730] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2107] not-detected: [...198] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...198] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2106] + idle: [...198] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2106] not-detected: [...775] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2107] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...775] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2107] + idle: [...775] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2107] not-detected: [..1628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8254] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8254] + idle: [..1628] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8254] not-detected: [..1713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8254] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8254] + idle: [..1713] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8254] not-detected: [..1486] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1486] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2111] + idle: [..1486] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2111] not-detected: [..1563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2111] + idle: [..1563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2111] not-detected: [..1184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...70] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [..1184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...70] + end: [..1184] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...70] not-detected: [..1148] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2119] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1148] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2119] + idle: [..1148] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2119] not-detected: [..1199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2119] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2119] + idle: [..1199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2119] not-detected: [...595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2121] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2121] + idle: [...595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2121] not-detected: [...660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2121] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2121] + idle: [...660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2121] not-detected: [...572] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...572] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2126] + idle: [...572] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2126] not-detected: [..1196] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...79] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1196] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...79] + idle: [..1196] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...79] not-detected: [...648] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...648] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2126] + idle: [...648] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2126] not-detected: [..1260] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...79] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1260] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...79] + idle: [..1260] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...79] guessed: [....13] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [....13] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...80] + idle: [....13] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...80] not-detected: [..1365] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...81] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1365] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...81] + idle: [..1365] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...81] not-detected: [..1429] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...81] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1429] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...81] + idle: [..1429] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...81] not-detected: [...466] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...82] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...466] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...82] + idle: [...466] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...82] not-detected: [...619] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...83] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...619] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...83] + idle: [...619] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...83] not-detected: [...482] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...82] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...482] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...82] + idle: [...482] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...82] not-detected: [...799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...84] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...84] + idle: [...799] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...84] not-detected: [...678] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...83] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...678] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...83] + idle: [...678] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...83] not-detected: [..1824] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...85] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1824] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...85] + idle: [..1824] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...85] not-detected: [...856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...84] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...84] + idle: [...856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...84] not-detected: [..1907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...85] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...85] + idle: [..1907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...85] not-detected: [..1369] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2135] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1369] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2135] + idle: [..1369] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2135] not-detected: [..1450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2135] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2135] + idle: [..1450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2135] guessed: [..1330] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1330] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...88] + idle: [..1330] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...88] guessed: [..1415] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1415] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...88] + idle: [..1415] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...88] not-detected: [..1040] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...89] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1040] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...89] + idle: [..1040] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...89] not-detected: [..1895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...90] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...90] + idle: [..1895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...90] not-detected: [..1115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...89] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...89] + idle: [..1115] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...89] not-detected: [..1957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...90] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...90] + idle: [..1957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...90] not-detected: [...177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61532] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61532] + idle: [...177] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61532] not-detected: [...197] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61532] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...197] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61532] + idle: [...197] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61532] not-detected: [..1143] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1143] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2144] + idle: [..1143] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2144] not-detected: [..1204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2144] + idle: [..1204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2144] not-detected: [..1544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8290] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8290] + idle: [..1544] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8290] not-detected: [..1609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8290] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8290] + idle: [..1609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8290] not-detected: [...377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...99] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...99] + idle: [...377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][...99] not-detected: [...124] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8291] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...124] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8291] + idle: [...124] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8291] not-detected: [...578] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8292] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...578] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8292] + idle: [...578] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8292] not-detected: [..1588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..100] + idle: [..1588] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..100] not-detected: [...407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...99] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...99] + idle: [...407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][...99] not-detected: [...168] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8291] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...168] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8291] + idle: [...168] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8291] not-detected: [..1662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..100] + idle: [..1662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..100] not-detected: [...642] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8292] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...642] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8292] + idle: [...642] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8292] not-detected: [...918] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14441] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...918] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14441] + idle: [...918] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14441] not-detected: [...979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14441] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14441] + idle: [...979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14441] not-detected: [..1248] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1248] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..106] + idle: [..1248] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..106] not-detected: [...108] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14442] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...108] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14442] + idle: [...108] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][14442] not-detected: [..1312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..106] + idle: [..1312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..106] not-detected: [...142] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14442] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...142] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14442] + idle: [...142] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][14442] not-detected: [...254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8300] + idle: [...254] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8300] not-detected: [...763] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..109] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...763] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..109] + idle: [...763] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..109] not-detected: [...284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8300] + idle: [...284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8300] not-detected: [...834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..109] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..109] + idle: [...834] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..109] guessed: [....32] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....32] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..110] + idle: [....32] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..110] guessed: [....67] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..110] [POP3][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....67] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..110] + idle: [....67] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..110] not-detected: [.....5] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....5] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..111] + idle: [.....5] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..111] not-detected: [..1792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2160] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2160] + idle: [..1792] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2160] not-detected: [....25] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....25] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..111] + idle: [....25] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..111] not-detected: [..1865] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2160] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1865] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2160] + idle: [..1865] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2160] not-detected: [...465] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...465] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2161] + idle: [...465] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2161] not-detected: [....12] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..113] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [....12] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..113] + end: [....12] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..113] not-detected: [...483] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...483] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2161] + idle: [...483] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2161] not-detected: [..1593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..119] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..119] + idle: [..1593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..119] not-detected: [..1657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..119] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..119] + idle: [..1657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..119] not-detected: [..1034] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2170] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1034] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2170] + idle: [..1034] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2170] not-detected: [..1121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2170] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2170] + idle: [..1121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2170] not-detected: [...523] [ip4][..tcp] [.....172.16.0.8][36061] -> [...64.13.134.52][..113] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...523] [ip4][..tcp] [.....172.16.0.8][36061] -> [...64.13.134.52][..113] + end: [...523] [ip4][..tcp] [.....172.16.0.8][36061] -> [...64.13.134.52][..113] not-detected: [...723] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..125] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...723] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..125] + idle: [...723] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..125] not-detected: [...782] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..125] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...782] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..125] + idle: [...782] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..125] not-detected: [...425] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4224] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...425] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4224] + idle: [...425] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4224] not-detected: [...441] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4224] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...441] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4224] + idle: [...441] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4224] not-detected: [..1286] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2179] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1286] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2179] + idle: [..1286] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2179] not-detected: [..1364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2179] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2179] + idle: [..1364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2179] guessed: [....39] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..135] [RPC][Unknown][RPC][Acceptable] RISK: Unidirectional Traffic - idle: [....39] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..135] + idle: [....39] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..135] guessed: [....61] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..135] [RPC][Unknown][RPC][Acceptable] RISK: Unidirectional Traffic - idle: [....61] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..135] + idle: [....61] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..135] guessed: [....14] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..139] [NetBIOS][Unknown][System][Acceptable][] RISK: Unidirectional Traffic - idle: [....14] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..139] + idle: [....14] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..139] guessed: [....19] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..139] [NetBIOS][Unknown][System][Acceptable][] RISK: Unidirectional Traffic - idle: [....19] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..139] + idle: [....19] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..139] guessed: [..1788] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] RISK: Unidirectional Traffic - idle: [..1788] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8333] + idle: [..1788] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8333] guessed: [..1869] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8333] [BITCOIN][Unknown][Crypto_Currency][Acceptable] RISK: Unidirectional Traffic - idle: [..1869] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8333] + idle: [..1869] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8333] guessed: [...193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2190] [TiVoConnect][Unknown][Network][Fun] RISK: Unidirectional Traffic - idle: [...193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2190] + idle: [...193] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2190] not-detected: [..1327] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2191] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1327] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2191] + idle: [..1327] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2191] guessed: [...222] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2190] [TiVoConnect][Unknown][Network][Fun] RISK: Unidirectional Traffic - idle: [...222] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2190] + idle: [...222] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2190] guessed: [.....2] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..143] [IMAP][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [.....2] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..143] + idle: [.....2] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..143] not-detected: [..1418] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2191] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1418] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2191] + idle: [..1418] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2191] not-detected: [..1032] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1032] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..144] + idle: [..1032] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..144] guessed: [....28] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..143] [IMAP][Unknown][Email][Unsafe] RISK: Unsafe Protocol, Unidirectional Traffic - idle: [....28] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..143] + idle: [....28] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..143] not-detected: [..1123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..144] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..144] + idle: [..1123] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..144] not-detected: [..1384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..146] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..146] + idle: [..1384] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..146] not-detected: [..1346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4242] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4242] + idle: [..1346] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4242] not-detected: [..1465] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..146] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1465] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..146] + idle: [..1465] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..146] not-detected: [..1399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4242] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4242] + idle: [..1399] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4242] not-detected: [...594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2196] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2196] + idle: [...594] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2196] not-detected: [...661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2196] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2196] + idle: [...661] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2196] not-detected: [...506] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...506] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2200] + idle: [...506] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2200] not-detected: [...525] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...525] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2200] + idle: [...525] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2200] not-detected: [..1634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..161] + idle: [..1634] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..161] not-detected: [..1707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..161] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..161] + idle: [..1707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..161] not-detected: [...504] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...504] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..163] + idle: [...504] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..163] not-detected: [...527] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...527] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..163] + idle: [...527] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..163] not-detected: [....49] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....49] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2222] + idle: [....49] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2222] not-detected: [....79] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....79] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2222] + idle: [....79] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2222] guessed: [..1891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..179] [BGP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..179] + idle: [..1891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..179] guessed: [..1961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..179] [BGP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..179] + idle: [..1961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..179] not-detected: [...917] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4279] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...917] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4279] + idle: [...917] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4279] not-detected: [...980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4279] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4279] + idle: [...980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4279] not-detected: [..1669] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8383] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1669] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8383] + idle: [..1669] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8383] not-detected: [..1733] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8383] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1733] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8383] + idle: [..1733] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8383] not-detected: [.....4] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..199] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....4] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..199] + idle: [.....4] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..199] not-detected: [....26] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..199] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....26] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..199] + idle: [....26] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..199] not-detected: [...461] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...461] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6346] + idle: [...461] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6346] not-detected: [..1851] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2251] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1851] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2251] + idle: [..1851] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2251] not-detected: [...487] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6346] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...487] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6346] + idle: [...487] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6346] not-detected: [..1910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2251] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2251] + idle: [..1910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2251] not-detected: [...435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8400] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8400] + idle: [...435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8400] not-detected: [...472] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8400] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...472] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8400] + idle: [...472] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8400] not-detected: [..1096] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8402] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1096] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8402] + idle: [..1096] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8402] not-detected: [..1159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8402] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8402] + idle: [..1159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8402] not-detected: [..1030] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..211] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1030] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..211] + idle: [..1030] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..211] not-detected: [..1075] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..211] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1075] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..211] + idle: [..1075] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..211] not-detected: [...564] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..212] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...564] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..212] + idle: [...564] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..212] not-detected: [...431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2260] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2260] + idle: [...431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2260] not-detected: [...656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..212] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..212] + idle: [...656] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..212] not-detected: [...476] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2260] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...476] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2260] + idle: [...476] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2260] not-detected: [..1192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..222] + idle: [..1192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..222] not-detected: [..1264] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1264] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..222] + idle: [..1264] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..222] not-detected: [..1387] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1387] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24800] + idle: [..1387] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][24800] not-detected: [..1699] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4321] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1699] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4321] + idle: [..1699] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4321] not-detected: [..1462] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1462] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24800] + idle: [..1462] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][24800] not-detected: [..1758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4321] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4321] + idle: [..1758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4321] not-detected: [..1678] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30951] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1678] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30951] + idle: [..1678] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30951] not-detected: [..1749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30951] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30951] + idle: [..1749] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30951] not-detected: [...536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2288] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2288] + idle: [...536] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2288] not-detected: [...611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2288] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2288] + idle: [...611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2288] not-detected: [...266] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...266] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6389] + idle: [...266] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6389] not-detected: [...313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6389] + idle: [...313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6389] guessed: [...622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4343] [Whois-DAS][Unknown][Network][Acceptable][] RISK: Unidirectional Traffic - idle: [...622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4343] + idle: [...622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4343] not-detected: [..1524] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49400] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1524] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49400] + idle: [..1524] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49400] guessed: [...675] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4343] [Whois-DAS][Unknown][Network][Acceptable][] RISK: Unidirectional Traffic - idle: [...675] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4343] + idle: [...675] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4343] not-detected: [..1599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49400] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49400] + idle: [..1599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49400] not-detected: [..1519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8443] + idle: [..1519] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8443] not-detected: [..1579] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1579] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8443] + idle: [..1579] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8443] not-detected: [...921] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...921] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2301] + idle: [...921] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2301] not-detected: [...976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2301] + idle: [...976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2301] not-detected: [...419] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..254] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...419] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..254] + idle: [...419] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..254] not-detected: [..1101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..255] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..255] + idle: [..1101] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..255] not-detected: [...447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..254] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..254] + idle: [...447] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..254] not-detected: [..1154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..255] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..255] + idle: [..1154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..255] not-detected: [....37] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..256] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....37] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..256] + idle: [....37] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..256] not-detected: [....63] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..256] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....63] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..256] + idle: [....63] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..256] not-detected: [..1886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..259] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..259] + idle: [..1886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..259] not-detected: [...871] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...871] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55555] + idle: [...871] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55555] not-detected: [..1966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..259] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..259] + idle: [..1966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..259] not-detected: [...934] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...934] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55555] + idle: [...934] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55555] not-detected: [..1487] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..264] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1487] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..264] + idle: [..1487] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..264] not-detected: [..1562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..264] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..264] + idle: [..1562] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..264] not-detected: [..1543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2323] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2323] + idle: [..1543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2323] not-detected: [..1610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2323] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2323] + idle: [..1610] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2323] not-detected: [...270] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..280] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...270] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..280] + idle: [...270] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..280] not-detected: [...309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..280] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..280] + idle: [...309] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..280] not-detected: [...695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51493] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51493] + idle: [...695] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][51493] not-detected: [...752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51493] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51493] + idle: [...752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][51493] not-detected: [...747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..301] + idle: [...747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..301] not-detected: [...808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..301] + idle: [...808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..301] not-detected: [...579] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...579] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55600] + idle: [...579] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][55600] not-detected: [...641] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...641] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55600] + idle: [...641] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][55600] not-detected: [..1939] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..306] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1939] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..306] + idle: [..1939] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..306] not-detected: [..1983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..306] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..306] + idle: [..1983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..306] not-detected: [..1470] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1470] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8500] + idle: [..1470] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8500] not-detected: [..1531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8500] + idle: [..1531] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8500] not-detected: [..1898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..311] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..311] + idle: [..1898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..311] not-detected: [..1954] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..311] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1954] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..311] + idle: [..1954] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..311] not-detected: [..1795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2366] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2366] + idle: [..1795] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2366] not-detected: [...985] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...985] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31038] + idle: [...985] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31038] not-detected: [..1862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2366] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2366] + idle: [..1862] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2366] not-detected: [..1062] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][31038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1062] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][31038] + idle: [..1062] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][31038] not-detected: [...546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10566] + idle: [...546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10566] not-detected: [...601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10566] + idle: [...601] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10566] not-detected: [..1016] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2381] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1016] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2381] + idle: [..1016] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2381] not-detected: [..1089] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2381] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1089] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2381] + idle: [..1089] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2381] not-detected: [...295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2382] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2382] + idle: [...295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2382] not-detected: [...740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2383] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2383] + idle: [...740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2383] not-detected: [...325] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2382] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...325] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2382] + idle: [...325] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2382] not-detected: [...815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2383] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2383] + idle: [...815] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2383] not-detected: [..1497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..340] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..340] + idle: [..1497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..340] not-detected: [..1552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..340] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..340] + idle: [..1552] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..340] not-detected: [...417] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2393] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...417] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2393] + idle: [...417] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2393] not-detected: [..1291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2394] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2394] + idle: [..1291] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2394] not-detected: [...449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2393] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2393] + idle: [...449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2393] not-detected: [..1359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2394] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2394] + idle: [..1359] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2394] not-detected: [...991] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...991] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4443] + idle: [...991] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4443] not-detected: [..1595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20828] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20828] + idle: [..1595] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][20828] not-detected: [..1195] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1195] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4444] + idle: [..1195] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4444] not-detected: [..1056] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1056] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4443] + idle: [..1056] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4443] not-detected: [..1655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20828] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20828] + idle: [..1655] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][20828] not-detected: [..1261] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1261] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4444] + idle: [..1261] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4444] not-detected: [..1015] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4445] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1015] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4445] + idle: [..1015] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4445] not-detected: [..1145] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4446] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1145] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4446] + idle: [..1145] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4446] not-detected: [..1090] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4445] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1090] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4445] + idle: [..1090] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4445] not-detected: [..1202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4446] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4446] + idle: [..1202] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4446] not-detected: [..1038] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2399] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1038] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2399] + idle: [..1038] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2399] not-detected: [..1117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2399] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2399] + idle: [..1117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2399] not-detected: [..1937] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2401] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1937] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2401] + idle: [..1937] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2401] not-detected: [...617] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4449] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...617] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4449] + idle: [...617] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4449] not-detected: [..1985] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2401] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1985] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2401] + idle: [..1985] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2401] not-detected: [...680] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4449] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...680] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4449] + idle: [...680] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4449] not-detected: [..1745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6502] + idle: [..1745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6502] not-detected: [..1809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6502] + idle: [..1809] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6502] not-detected: [...742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6510] + idle: [...742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6510] not-detected: [...726] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..366] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...726] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..366] + idle: [...726] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..366] not-detected: [...813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6510] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6510] + idle: [...813] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6510] not-detected: [...779] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..366] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...779] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..366] + idle: [...779] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..366] not-detected: [..1253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27000] + idle: [..1253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27000] not-detected: [...987] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...987] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10616] + idle: [...987] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10616] not-detected: [..1307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27000] + idle: [..1307] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27000] not-detected: [..1060] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1060] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10616] + idle: [..1060] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10616] not-detected: [...731] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10617] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...731] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10617] + idle: [...731] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10617] not-detected: [...774] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10617] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...774] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10617] + idle: [...774] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10617] not-detected: [....46] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10621] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....46] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10621] + idle: [....46] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10621] not-detected: [....82] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10621] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....82] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10621] + idle: [....82] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10621] not-detected: [...131] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10626] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...131] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10626] + idle: [...131] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10626] not-detected: [...161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10626] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10626] + idle: [...161] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10626] not-detected: [..1194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10628] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10628] + idle: [..1194] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10628] not-detected: [..1262] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10628] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1262] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10628] + idle: [..1262] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10628] guessed: [..1844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..389] [LDAP][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [..1844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..389] + idle: [..1844] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..389] not-detected: [....44] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10629] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....44] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10629] + idle: [....44] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10629] guessed: [..1917] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..389] [LDAP][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [..1917] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..389] + idle: [..1917] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..389] not-detected: [....84] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10629] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....84] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10629] + idle: [....84] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10629] not-detected: [...210] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6543] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...210] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6543] + idle: [...210] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6543] not-detected: [...246] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6543] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...246] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6543] + idle: [...246] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6543] not-detected: [...638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6547] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6547] + idle: [...638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6547] not-detected: [...699] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6547] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...699] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6547] + idle: [...699] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6547] not-detected: [..1105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..406] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..406] + idle: [..1105] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..406] not-detected: [..1385] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..407] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1385] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..407] + idle: [..1385] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..407] not-detected: [..1150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..406] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..406] + idle: [..1150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..406] not-detected: [..1464] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..407] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1464] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..407] + idle: [..1464] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..407] not-detected: [..1168] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1168] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8600] + idle: [..1168] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8600] not-detected: [..1239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8600] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8600] + idle: [..1239] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8600] not-detected: [..1106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][22939] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][22939] + idle: [..1106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][22939] not-detected: [..1149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][22939] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][22939] + idle: [..1149] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][22939] not-detected: [..1318] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..416] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1318] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..416] + idle: [..1318] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..416] not-detected: [..1479] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..417] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1479] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..417] + idle: [..1479] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..417] not-detected: [..1379] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..416] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1379] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..416] + idle: [..1379] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..416] not-detected: [..1570] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..417] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1570] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..417] + idle: [..1570] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..417] not-detected: [..1431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6565] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6565] + idle: [..1431] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6565] not-detected: [..1515] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6565] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1515] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6565] + idle: [..1515] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6565] not-detected: [..1334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6566] + idle: [..1334] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6566] not-detected: [..1492] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6567] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1492] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6567] + idle: [..1492] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6567] not-detected: [..1411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6566] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6566] + idle: [..1411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6566] not-detected: [..1557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6567] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6567] + idle: [..1557] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6567] not-detected: [...170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..425] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..425] + idle: [...170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..425] not-detected: [...204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..425] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..425] + idle: [...204] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..425] guessed: [..1289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] RISK: Unidirectional Traffic - idle: [..1289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..427] + idle: [..1289] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..427] guessed: [..1361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..427] [Service_Location_Protocol][Unknown][RPC][Acceptable] RISK: Unidirectional Traffic - idle: [..1361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..427] + idle: [..1361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..427] not-detected: [...191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6580] + idle: [...191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6580] not-detected: [...224] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6580] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...224] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6580] + idle: [...224] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6580] guessed: [.....1] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..443] + idle: [.....1] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..443] not-detected: [..1435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2492] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2492] + idle: [..1435] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2492] not-detected: [..1672] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1672] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..444] + idle: [..1672] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..444] guessed: [....29] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - idle: [....29] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..443] + idle: [....29] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..443] not-detected: [..1755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..444] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..444] + idle: [..1755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..444] not-detected: [..1511] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2492] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1511] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2492] + idle: [..1511] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2492] guessed: [....36] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..445] [SMBv23][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [....36] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..445] + idle: [....36] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..445] guessed: [....64] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..445] [SMBv23][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [....64] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..445] + idle: [....64] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..445] not-detected: [..1491] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1491] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2500] + idle: [..1491] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2500] not-detected: [..1558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2500] + idle: [..1558] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2500] not-detected: [...462] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57797] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...462] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57797] + idle: [...462] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][57797] not-detected: [...898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4550] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4550] + idle: [...898] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4550] not-detected: [...486] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57797] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...486] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57797] + idle: [...486] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][57797] not-detected: [...957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4550] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4550] + idle: [...957] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4550] not-detected: [...216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8649] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8649] + idle: [...216] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8649] not-detected: [..1294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..458] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..458] + idle: [..1294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..458] not-detected: [...240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8649] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8649] + idle: [...240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8649] not-detected: [..1356] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..458] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1356] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..458] + idle: [..1356] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..458] not-detected: [...452] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8651] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...452] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8651] + idle: [...452] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8651] not-detected: [..1390] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1390] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61900] + idle: [..1390] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][61900] not-detected: [..1100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8652] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8652] + idle: [..1100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8652] not-detected: [...496] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8651] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...496] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8651] + idle: [...496] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8651] not-detected: [..1459] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1459] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61900] + idle: [..1459] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][61900] not-detected: [..1155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8652] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8652] + idle: [..1155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8652] not-detected: [..1793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8654] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8654] + idle: [..1793] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8654] not-detected: [..1864] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8654] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1864] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8654] + idle: [..1864] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8654] not-detected: [...516] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..464] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...516] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..464] + idle: [...516] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..464] guessed: [..1830] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..465] [SMTPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [..1830] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..465] + idle: [..1830] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..465] not-detected: [...555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..464] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..464] + idle: [...555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..464] guessed: [..1901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..465] [SMTPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [..1901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..465] + idle: [..1901] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..465] not-detected: [...541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4567] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4567] + idle: [...541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4567] not-detected: [...606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4567] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4567] + idle: [...606] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4567] not-detected: [...349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2522] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2522] + idle: [...349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2522] not-detected: [...394] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2522] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...394] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2522] + idle: [...394] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2522] not-detected: [...267] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2525] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...267] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2525] + idle: [...267] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2525] not-detected: [...312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2525] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2525] + idle: [...312] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2525] not-detected: [...837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..481] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..481] + idle: [...837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..481] not-detected: [...910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..481] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..481] + idle: [...910] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..481] not-detected: [...178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..497] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..497] + idle: [...178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..497] not-detected: [...196] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..497] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...196] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..497] + idle: [...196] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..497] guessed: [...886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic - idle: [...886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..500] + idle: [...886] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..500] guessed: [...969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..500] [IPSec][Unknown][VPN][Safe] RISK: Unidirectional Traffic - idle: [...969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..500] + idle: [...969] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..500] not-detected: [..1826] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6646] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1826] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6646] + idle: [..1826] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6646] not-detected: [..1905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6646] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6646] + idle: [..1905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6646] not-detected: [..1367] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2557] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1367] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2557] + idle: [..1367] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2557] not-detected: [...715] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8701] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...715] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8701] + idle: [...715] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8701] not-detected: [..1427] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2557] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1427] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2557] + idle: [..1427] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2557] not-detected: [...790] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8701] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...790] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8701] + idle: [...790] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8701] not-detected: [..1950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..512] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..512] + idle: [..1950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..512] not-detected: [..1972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..512] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..512] + idle: [..1972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..512] not-detected: [..1341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..513] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..513] + idle: [..1341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..513] not-detected: [..1404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..513] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..513] + idle: [..1404] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..513] guessed: [....88] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..514] [Syslog][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [....88] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..514] + idle: [....88] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..514] not-detected: [..1623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..515] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..515] + idle: [..1623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..515] guessed: [...121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..514] [Syslog][Unknown][System][Acceptable] RISK: Unidirectional Traffic - idle: [...121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..514] + idle: [...121] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..514] not-detected: [..1682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..515] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..515] + idle: [..1682] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..515] not-detected: [..1899] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1899] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6666] + idle: [..1899] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6666] not-detected: [..1953] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1953] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6666] + idle: [..1953] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6666] not-detected: [..1675] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6667] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1675] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6667] + idle: [..1675] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6667] not-detected: [..1752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6667] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6667] + idle: [..1752] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6667] not-detected: [..1167] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6668] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1167] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6668] + idle: [..1167] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6668] not-detected: [..1135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..524] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..524] + idle: [..1135] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..524] not-detected: [..1240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6668] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6668] + idle: [..1240] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6668] not-detected: [..1212] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..524] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1212] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..524] + idle: [..1212] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..524] not-detected: [...180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6669] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6669] + idle: [...180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6669] not-detected: [...235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6669] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6669] + idle: [...235] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6669] not-detected: [...720] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...720] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10778] + idle: [...720] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][10778] not-detected: [...785] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10778] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...785] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10778] + idle: [...785] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][10778] not-detected: [..1323] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..541] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1323] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..541] + idle: [..1323] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..541] not-detected: [..1422] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..541] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1422] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..541] + idle: [..1422] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..541] not-detected: [..1187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..543] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..543] + idle: [..1187] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..543] not-detected: [..1670] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..544] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1670] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..544] + idle: [..1670] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..544] not-detected: [..1269] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..543] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1269] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..543] + idle: [..1269] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..543] not-detected: [..1732] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..544] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1732] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..544] + idle: [..1732] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..544] not-detected: [...956] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6689] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...956] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6689] + idle: [...956] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6689] not-detected: [...892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..545] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..545] + idle: [...892] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..545] not-detected: [...999] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6689] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...999] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6689] + idle: [...999] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6689] not-detected: [...963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..545] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..545] + idle: [...963] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..545] not-detected: [..1541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6692] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6692] + idle: [..1541] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6692] guessed: [....42] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..548] [AFP][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [....42] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..548] + idle: [....42] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..548] not-detected: [..1612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6692] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6692] + idle: [..1612] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6692] guessed: [....59] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..548] [AFP][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [....59] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..548] + idle: [....59] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..548] not-detected: [..1219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][41511] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][41511] + idle: [..1219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][41511] not-detected: [..1279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][41511] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][41511] + idle: [..1279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][41511] not-detected: [...895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2601] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2601] + idle: [...895] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2601] not-detected: [..1245] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2602] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1245] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2602] + idle: [..1245] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2602] not-detected: [...960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2601] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2601] + idle: [...960] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2601] guessed: [....38] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..554] [RTSP][Unknown][Media][Fun] RISK: Unidirectional Traffic - idle: [....38] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..554] + idle: [....38] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..554] not-detected: [..1315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2602] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2602] + idle: [..1315] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2602] not-detected: [...290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6699] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6699] + idle: [...290] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6699] not-detected: [..1624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..555] + idle: [..1624] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..555] guessed: [....62] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..554] [RTSP][Unknown][Media][Fun] RISK: Unidirectional Traffic - idle: [....62] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..554] + idle: [....62] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..554] not-detected: [..1638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18988] + idle: [..1638] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][18988] not-detected: [..1717] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..555] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1717] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..555] + idle: [..1717] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..555] guessed: [...989] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2604] [OSPF][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [...989] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2604] + idle: [...989] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2604] not-detected: [...330] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6699] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...330] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6699] + idle: [...330] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6699] not-detected: [..1703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18988] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18988] + idle: [..1703] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][18988] guessed: [..1058] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2604] [OSPF][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [..1058] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2604] + idle: [..1058] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2604] guessed: [....45] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2605] [BGP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [....45] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2605] + idle: [....45] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2605] guessed: [....83] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2605] [BGP][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [....83] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2605] + idle: [....83] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2605] not-detected: [..1840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2607] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2607] + idle: [..1840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2607] not-detected: [..1921] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2607] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1921] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2607] + idle: [..1921] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2607] not-detected: [..1293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2608] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2608] + idle: [..1293] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2608] not-detected: [..1357] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2608] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1357] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2608] + idle: [..1357] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2608] not-detected: [..1894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..563] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..563] + idle: [..1894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..563] not-detected: [..1958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..563] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..563] + idle: [..1958] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..563] not-detected: [...459] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4662] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...459] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4662] + idle: [...459] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4662] not-detected: [...489] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4662] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...489] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4662] + idle: [...489] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4662] not-detected: [..1102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33354] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33354] + idle: [..1102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33354] not-detected: [..1153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33354] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33354] + idle: [..1153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33354] guessed: [.....8] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..587] [SMTP][Unknown][Email][Acceptable][] RISK: Unidirectional Traffic - idle: [.....8] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..587] + idle: [.....8] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..587] guessed: [....22] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..587] [SMTP][Unknown][Email][Acceptable][] RISK: Unidirectional Traffic - idle: [....22] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..587] + idle: [....22] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..587] not-detected: [..1622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2638] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2638] + idle: [..1622] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2638] not-detected: [..1683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2638] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2638] + idle: [..1683] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2638] not-detected: [..1391] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..593] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1391] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..593] + idle: [..1391] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..593] not-detected: [..1458] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..593] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1458] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..593] + idle: [..1458] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..593] not-detected: [..1933] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1933] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8800] + idle: [..1933] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8800] not-detected: [..1019] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16992] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1019] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16992] + idle: [..1019] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16992] not-detected: [..1989] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1989] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8800] + idle: [..1989] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8800] not-detected: [..1746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16993] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16993] + idle: [..1746] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][16993] not-detected: [..1086] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16992] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1086] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16992] + idle: [..1086] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16992] not-detected: [..1808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16993] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16993] + idle: [..1808] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][16993] not-detected: [..1537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..616] + idle: [..1537] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..616] not-detected: [..1616] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..616] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1616] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..616] + idle: [..1616] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..616] not-detected: [...773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..617] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..617] + idle: [...773] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..617] not-detected: [...109] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31337] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [...109] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31337] + end: [...109] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][31337] not-detected: [...824] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..617] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...824] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..617] + idle: [...824] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..617] not-detected: [..1832] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..625] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1832] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..625] + idle: [..1832] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..625] not-detected: [..1909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..625] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..625] + idle: [..1909] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..625] not-detected: [..1927] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60020] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1927] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60020] + idle: [..1927] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60020] not-detected: [..1967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60020] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60020] + idle: [..1967] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60020] not-detected: [..1494] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..631] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1494] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..631] + idle: [..1494] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..631] not-detected: [..1555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..631] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..631] + idle: [..1555] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..631] not-detected: [...627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6779] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6779] + idle: [...627] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6779] not-detected: [..1583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..636] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..636] + idle: [..1583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..636] not-detected: [...710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6779] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6779] + idle: [...710] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6779] not-detected: [..1667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..636] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..636] + idle: [..1667] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..636] not-detected: [...299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][62078] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][62078] + idle: [...299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][62078] not-detected: [...321] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][62078] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...321] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][62078] + idle: [...321] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][62078] not-detected: [...259] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6788] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...259] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6788] + idle: [...259] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6788] not-detected: [..1740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6789] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6789] + idle: [..1740] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6789] not-detected: [...279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6788] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6788] + idle: [...279] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6788] not-detected: [..1814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6789] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6789] + idle: [..1814] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6789] not-detected: [...497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..646] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..646] + idle: [...497] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..646] not-detected: [...534] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..646] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...534] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..646] + idle: [...534] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..646] not-detected: [..1499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6792] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6792] + idle: [..1499] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6792] not-detected: [..1495] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..648] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1495] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..648] + idle: [..1495] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..648] not-detected: [..1554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..648] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..648] + idle: [..1554] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..648] not-detected: [..1550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6792] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6792] + idle: [..1550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6792] not-detected: [....99] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2701] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....99] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2701] + idle: [....99] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2701] not-detected: [..1048] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2702] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1048] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2702] + idle: [..1048] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2702] not-detected: [...151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2701] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2701] + idle: [...151] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2701] not-detected: [..1107] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2702] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1107] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2702] + idle: [..1107] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2702] not-detected: [..1436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2710] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2710] + idle: [..1436] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2710] not-detected: [..1510] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2710] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1510] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2710] + idle: [..1510] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2710] not-detected: [..1138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15000] + idle: [..1138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15000] not-detected: [..1209] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1209] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15000] + idle: [..1209] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15000] not-detected: [...877] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...877] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15002] + idle: [...877] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15002] not-detected: [...296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..666] + idle: [...296] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..666] not-detected: [..1183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15003] + idle: [..1183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15003] not-detected: [...928] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...928] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15002] + idle: [...928] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15002] not-detected: [..1024] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..667] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1024] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..667] + idle: [..1024] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..667] not-detected: [...324] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..666] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...324] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..666] + idle: [...324] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..666] not-detected: [..1272] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1272] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15003] + idle: [..1272] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15003] not-detected: [..1639] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..668] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1639] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..668] + idle: [..1639] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..668] not-detected: [..1081] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..667] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1081] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..667] + idle: [..1081] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..667] not-detected: [...133] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...133] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15004] + idle: [...133] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15004] not-detected: [...302] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...302] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19101] + idle: [...302] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19101] not-detected: [..1702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..668] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..668] + idle: [..1702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..668] not-detected: [...732] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2717] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...732] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2717] + idle: [...732] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2717] not-detected: [...159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15004] + idle: [...159] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15004] not-detected: [..1942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2718] + idle: [..1942] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2718] not-detected: [...823] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2717] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...823] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2717] + idle: [...823] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2717] not-detected: [...318] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...318] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19101] + idle: [...318] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19101] not-detected: [..1980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2718] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2718] + idle: [..1980] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2718] not-detected: [..1897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2725] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2725] + idle: [..1897] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2725] not-detected: [..1955] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2725] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1955] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2725] + idle: [..1955] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2725] not-detected: [..1041] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8873] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1041] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8873] + idle: [..1041] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8873] not-detected: [..1114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8873] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8873] + idle: [..1114] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8873] not-detected: [....57] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..683] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....57] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..683] + idle: [....57] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..683] not-detected: [...512] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][35500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...512] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][35500] + idle: [...512] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][35500] not-detected: [....71] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..683] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....71] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..683] + idle: [....71] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..683] not-detected: [...559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][35500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][35500] + idle: [...559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][35500] not-detected: [..1846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..687] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..687] + idle: [..1846] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..687] not-detected: [..1915] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..687] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1915] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..687] + idle: [..1915] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..687] not-detected: [..1297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..691] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..691] + idle: [..1297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..691] not-detected: [..1353] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..691] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1353] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..691] + idle: [..1353] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..691] not-detected: [...262] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6839] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...262] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6839] + idle: [...262] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6839] not-detected: [...317] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6839] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...317] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6839] + idle: [...317] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6839] not-detected: [....41] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8888] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....41] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8888] + idle: [....41] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8888] not-detected: [....60] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8888] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....60] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8888] + idle: [....60] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8888] not-detected: [...274] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..700] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...274] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..700] + idle: [...274] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..700] not-detected: [...305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..700] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..700] + idle: [...305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..700] not-detected: [...950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..705] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..705] + idle: [...950] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..705] not-detected: [..1005] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..705] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1005] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..705] + idle: [..1005] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..705] not-detected: [..1214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8899] + idle: [..1214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8899] not-detected: [..1284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8899] + idle: [..1284] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8899] not-detected: [..1224] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..711] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1224] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..711] + idle: [..1224] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..711] not-detected: [..1301] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..711] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1301] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..711] + idle: [..1301] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..711] not-detected: [..1170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..714] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..714] + idle: [..1170] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..714] not-detected: [..1237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..714] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..714] + idle: [..1237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..714] not-detected: [..1382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..720] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..720] + idle: [..1382] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..720] not-detected: [..1467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..720] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..720] + idle: [..1467] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..720] not-detected: [..1342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..722] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..722] + idle: [..1342] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..722] not-detected: [..1403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..722] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..722] + idle: [..1403] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..722] not-detected: [...457] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..726] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...457] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..726] + idle: [...457] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..726] not-detected: [...491] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..726] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...491] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..726] + idle: [...491] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..726] not-detected: [..1439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27352] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27352] + idle: [..1439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27352] not-detected: [..1801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27353] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27353] + idle: [..1801] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27353] not-detected: [..1507] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27352] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1507] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27352] + idle: [..1507] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27352] not-detected: [..1856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27353] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27353] + idle: [..1856] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27353] not-detected: [...189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27355] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27355] + idle: [...189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27355] not-detected: [...379] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27356] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...379] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27356] + idle: [...379] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27356] not-detected: [...226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27355] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27355] + idle: [...226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27355] not-detected: [...405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27356] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27356] + idle: [...405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27356] not-detected: [..1337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][58080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][58080] + idle: [..1337] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][58080] not-detected: [..1408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][58080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][58080] + idle: [..1408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][58080] not-detected: [...884] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6881] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...884] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6881] + idle: [...884] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6881] not-detected: [...971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6881] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6881] + idle: [...971] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6881] not-detected: [...631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..749] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..749] + idle: [...631] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..749] not-detected: [...706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..749] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..749] + idle: [...706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..749] not-detected: [...460] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...460] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2800] + idle: [...460] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2800] not-detected: [....92] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4848] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....92] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4848] + idle: [....92] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4848] not-detected: [...488] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...488] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2800] + idle: [...488] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2800] not-detected: [...117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4848] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4848] + idle: [...117] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4848] not-detected: [..1685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6901] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6901] + idle: [..1685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6901] not-detected: [..1772] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6901] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1772] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6901] + idle: [..1772] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6901] not-detected: [..1370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2809] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2809] + idle: [..1370] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2809] not-detected: [..1449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2809] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2809] + idle: [..1449] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2809] not-detected: [...352] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2811] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...352] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2811] + idle: [...352] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2811] not-detected: [...391] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2811] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...391] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2811] + idle: [...391] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2811] not-detected: [...218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..765] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..765] + idle: [...218] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..765] not-detected: [...238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..765] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..765] + idle: [...238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..765] not-detected: [..1649] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1649] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..777] + idle: [..1649] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..777] not-detected: [..1722] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..777] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1722] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..777] + idle: [..1722] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..777] not-detected: [..1500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..783] + idle: [..1500] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..783] not-detected: [..1549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..783] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..783] + idle: [..1549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..783] not-detected: [..1654] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..787] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1654] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..787] + idle: [..1654] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..787] not-detected: [..1730] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..787] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1730] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..787] + idle: [..1730] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..787] not-detected: [..1502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54045] + idle: [..1502] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54045] not-detected: [..1578] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1578] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54045] + idle: [..1578] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54045] not-detected: [..1036] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1036] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..800] + idle: [..1036] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..800] not-detected: [..1119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..800] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..800] + idle: [..1119] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..800] not-detected: [...301] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...301] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..801] + idle: [...301] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..801] not-detected: [..1037] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8994] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1037] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8994] + idle: [..1037] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.8994] not-detected: [...319] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..801] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...319] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..801] + idle: [...319] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..801] not-detected: [..1118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8994] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8994] + idle: [..1118] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.8994] not-detected: [...333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4899] + idle: [...333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4899] not-detected: [...692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4900] + idle: [...692] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4900] not-detected: [...369] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...369] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4899] + idle: [...369] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4899] not-detected: [...755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4900] + idle: [...755] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4900] not-detected: [..1635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9000] + idle: [..1635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9000] not-detected: [...209] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..808] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...209] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..808] + idle: [...209] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..808] not-detected: [..1706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9000] + idle: [..1706] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9000] not-detected: [..1182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9001] + idle: [..1182] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9001] not-detected: [...247] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..808] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...247] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..808] + idle: [...247] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..808] not-detected: [..1273] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1273] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9001] + idle: [..1273] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9001] not-detected: [..1063] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1063] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9002] + idle: [..1063] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9002] not-detected: [..1134] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1134] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9002] + idle: [..1134] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9002] not-detected: [...592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9003] + idle: [...592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9003] not-detected: [...663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9003] + idle: [...663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9003] not-detected: [...567] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...567] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9009] + idle: [...567] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9009] not-detected: [...653] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...653] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9009] + idle: [...653] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9009] not-detected: [...219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9010] + idle: [...219] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9010] not-detected: [..1783] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1783] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9011] + idle: [..1783] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9011] not-detected: [...237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9010] + idle: [...237] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9010] not-detected: [..1874] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1874] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9011] + idle: [..1874] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9011] not-detected: [...179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2869] + idle: [...179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2869] not-detected: [...195] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2869] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...195] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2869] + idle: [...195] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2869] not-detected: [..1687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6969] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6969] + idle: [..1687] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.6969] not-detected: [..1770] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6969] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1770] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6969] + idle: [..1770] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.6969] not-detected: [..1526] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2875] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1526] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2875] + idle: [..1526] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2875] not-detected: [..1597] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2875] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1597] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2875] + idle: [..1597] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2875] not-detected: [...100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..843] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..843] + idle: [...100] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..843] not-detected: [...150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..843] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..843] + idle: [...150] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..843] not-detected: [...253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49999] + idle: [...253] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][49999] not-detected: [..1734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50000] + idle: [..1734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50000] not-detected: [..1477] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1477] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9040] + idle: [..1477] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9040] not-detected: [...285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49999] + idle: [...285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][49999] not-detected: [..1820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50000] + idle: [..1820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50000] not-detected: [..1572] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1572] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9040] + idle: [..1572] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9040] not-detected: [..1068] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1068] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50001] + idle: [..1068] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50001] not-detected: [..1690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50002] + idle: [..1690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50002] not-detected: [..1129] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1129] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50001] + idle: [..1129] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50001] not-detected: [..1767] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1767] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50002] + idle: [..1767] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50002] not-detected: [..1632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50003] + idle: [..1632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50003] not-detected: [..1340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19283] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19283] + idle: [..1340] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19283] not-detected: [..1709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50003] + idle: [..1709] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50003] not-detected: [..1405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19283] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19283] + idle: [..1405] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19283] not-detected: [..1794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50006] + idle: [..1794] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50006] not-detected: [..1863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50006] + idle: [..1863] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50006] not-detected: [...268] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...268] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7000] + idle: [...268] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7000] not-detected: [...616] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...616] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7001] + idle: [...616] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7001] not-detected: [...311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7000] + idle: [...311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7000] not-detected: [...947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7002] + idle: [...947] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7002] not-detected: [...681] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...681] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7001] + idle: [...681] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7001] not-detected: [...623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9050] + idle: [...623] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9050] not-detected: [..1008] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1008] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7002] + idle: [..1008] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7002] not-detected: [...674] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...674] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9050] + idle: [...674] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9050] not-detected: [..1440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7004] + idle: [..1440] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7004] not-detected: [..1506] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1506] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7004] + idle: [..1506] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7004] not-detected: [...416] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2909] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...416] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2909] + idle: [...416] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2909] not-detected: [..1680] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1680] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2910] + idle: [..1680] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2910] not-detected: [...450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2909] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2909] + idle: [...450] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2909] not-detected: [..1802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7007] + idle: [..1802] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7007] not-detected: [..1757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2910] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2910] + idle: [..1757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2910] not-detected: [..1855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7007] + idle: [..1855] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7007] not-detected: [...876] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...876] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11110] + idle: [...876] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11110] not-detected: [...929] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...929] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11110] + idle: [...929] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11110] not-detected: [...498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11111] + idle: [...498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][11111] not-detected: [..1837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2920] + idle: [..1837] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2920] not-detected: [...533] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...533] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11111] + idle: [...533] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][11111] not-detected: [..1924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2920] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2920] + idle: [..1924] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2920] guessed: [..1592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..873] [RSYNC][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [..1592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..873] + idle: [..1592] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..873] guessed: [..1658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..873] [RSYNC][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [..1658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..873] + idle: [..1658] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..873] not-detected: [..1018] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7019] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1018] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7019] + idle: [..1018] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7019] not-detected: [..1087] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7019] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1087] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7019] + idle: [..1087] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7019] not-detected: [...220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9071] + idle: [...220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9071] not-detected: [..1625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..880] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..880] + idle: [..1625] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..880] not-detected: [...236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9071] + idle: [...236] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9071] not-detected: [..1716] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..880] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1716] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..880] + idle: [..1716] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..880] not-detected: [..1255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7025] + idle: [..1255] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7025] not-detected: [..1305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7025] + idle: [..1305] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7025] not-detected: [...686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19315] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19315] + idle: [...686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19315] not-detected: [...761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19315] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19315] + idle: [...761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19315] not-detected: [..1025] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1025] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9080] + idle: [..1025] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9080] not-detected: [...589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..888] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..888] + idle: [...589] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..888] not-detected: [..1080] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1080] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9080] + idle: [..1080] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9080] not-detected: [...994] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...994] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9081] + idle: [...994] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9081] not-detected: [...666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..888] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..888] + idle: [...666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..888] not-detected: [..1053] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1053] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9081] + idle: [..1053] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9081] not-detected: [..1097] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1097] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9090] + idle: [..1097] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9090] not-detected: [...883] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..898] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...883] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..898] + idle: [...883] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..898] not-detected: [..1158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9090] + idle: [..1158] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9090] not-detected: [...972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..898] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..898] + idle: [...972] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..898] not-detected: [...574] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9091] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...574] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9091] + idle: [...574] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9091] not-detected: [..1591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..900] + idle: [..1591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..900] not-detected: [...646] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9091] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...646] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9091] + idle: [...646] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9091] not-detected: [..1659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..900] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..900] + idle: [..1659] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..900] not-detected: [...866] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..901] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...866] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..901] + idle: [...866] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..901] not-detected: [..1928] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1928] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4998] + idle: [..1928] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.4998] not-detected: [..1092] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..902] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1092] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..902] + idle: [..1092] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..902] not-detected: [...939] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..901] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...939] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..901] + idle: [...939] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..901] not-detected: [..1994] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1994] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4998] + idle: [..1994] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.4998] guessed: [..1587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..903] [VMware][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [..1587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..903] + idle: [..1587] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..903] not-detected: [..1163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..902] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..902] + idle: [..1163] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..902] guessed: [..1663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..903] [VMware][Unknown][RemoteAccess][Acceptable] RISK: Unidirectional Traffic - idle: [..1663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..903] + idle: [..1663] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..903] not-detected: [..1169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5000] + idle: [..1169] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5000] not-detected: [..1238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5000] + idle: [..1238] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5000] guessed: [...745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5001] [TargusDataspeed][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [...745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5001] + idle: [...745] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5001] not-detected: [..1929] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1929] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5002] + idle: [..1929] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5002] guessed: [...810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5001] [TargusDataspeed][Unknown][Network][Acceptable] RISK: Unidirectional Traffic - idle: [...810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5001] + idle: [...810] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5001] not-detected: [..1993] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1993] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5002] + idle: [..1993] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5002] not-detected: [..1798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5003] + idle: [..1798] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5003] not-detected: [..1644] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1644] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9099] + idle: [..1644] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9099] not-detected: [..1727] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1727] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9099] + idle: [..1727] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9099] not-detected: [..1859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5003] + idle: [..1859] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5003] not-detected: [..1523] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1523] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9100] + idle: [..1523] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9100] not-detected: [..1437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5004] + idle: [..1437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5004] not-detected: [..1600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9100] + idle: [..1600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9100] not-detected: [..1509] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5004] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1509] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5004] + idle: [..1509] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5004] not-detected: [...630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9101] + idle: [...630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9101] not-detected: [...707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9101] + idle: [...707] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9101] not-detected: [...138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9102] + idle: [...138] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9102] not-detected: [..1780] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1780] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..911] + idle: [..1780] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..911] not-detected: [..1299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9103] + idle: [..1299] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9103] not-detected: [...154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9102] + idle: [...154] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9102] not-detected: [..1877] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..911] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1877] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..911] + idle: [..1877] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..911] not-detected: [..1351] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1351] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9103] + idle: [..1351] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9103] not-detected: [...456] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..912] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...456] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..912] + idle: [...456] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..912] not-detected: [..1542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5009] + idle: [..1542] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5009] not-detected: [...492] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..912] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...492] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..912] + idle: [...492] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..912] not-detected: [..1611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5009] + idle: [..1611] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5009] not-detected: [..1389] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19350] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1389] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19350] + idle: [..1389] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][19350] not-detected: [...437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9110] + idle: [...437] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9110] not-detected: [..1460] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19350] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1460] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19350] + idle: [..1460] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][19350] not-detected: [..1671] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1671] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9111] + idle: [..1671] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9111] not-detected: [...840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2967] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2967] + idle: [...840] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2967] not-detected: [...470] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...470] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9110] + idle: [...470] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9110] not-detected: [..1731] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1731] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9111] + idle: [..1731] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9111] not-detected: [...907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2967] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2967] + idle: [...907] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2967] not-detected: [...415] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2968] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...415] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2968] + idle: [...415] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2968] not-detected: [...451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2968] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2968] + idle: [...451] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2968] not-detected: [...507] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...507] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7070] + idle: [...507] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7070] not-detected: [...524] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...524] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7070] + idle: [...524] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7070] not-detected: [..1047] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1047] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5030] + idle: [..1047] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5030] not-detected: [..1108] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1108] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5030] + idle: [..1108] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5030] not-detected: [...212] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...212] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5033] + idle: [...212] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5033] not-detected: [...244] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...244] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5033] + idle: [...244] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5033] not-detected: [...586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2998] + idle: [...586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.2998] not-detected: [...669] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2998] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...669] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2998] + idle: [...669] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.2998] not-detected: [...433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3000] + idle: [...433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3000] not-detected: [...474] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...474] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3000] + idle: [...474] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3000] not-detected: [...192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3001] + idle: [...192] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3001] not-detected: [..1179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5050] + idle: [..1179] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5050] not-detected: [...223] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...223] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3001] + idle: [...223] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3001] not-detected: [..1228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5050] + idle: [..1228] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5050] not-detected: [..1688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3003] + idle: [..1688] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3003] not-detected: [...739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5051] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5051] + idle: [...739] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5051] not-detected: [..1769] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3003] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1769] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3003] + idle: [..1769] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3003] not-detected: [...816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5051] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5051] + idle: [...816] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5051] not-detected: [...613] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...613] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7100] + idle: [...613] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7100] not-detected: [..1696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3005] + idle: [..1696] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3005] not-detected: [...684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7100] + idle: [...684] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7100] not-detected: [..1761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3005] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3005] + idle: [..1761] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3005] not-detected: [..1584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5054] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5054] + idle: [..1584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5054] not-detected: [...806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3006] + idle: [...806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3006] not-detected: [..1676] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1676] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7103] + idle: [..1676] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7103] not-detected: [..1666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5054] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5054] + idle: [..1666] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5054] not-detected: [...869] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...869] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3007] + idle: [...869] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3007] not-detected: [...849] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3006] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...849] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3006] + idle: [...849] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3006] not-detected: [..1751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7103] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7103] + idle: [..1751] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7103] not-detected: [...936] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...936] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3007] + idle: [...936] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3007] not-detected: [..1042] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1042] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7106] + idle: [..1042] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7106] not-detected: [..1689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3011] + idle: [..1689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3011] not-detected: [..1113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7106] + idle: [..1113] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7106] not-detected: [..1768] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1768] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3011] + idle: [..1768] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3011] guessed: [...889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5060] + idle: [...889] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5060] not-detected: [..1849] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3013] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1849] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3013] + idle: [..1849] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3013] guessed: [..1778] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5061] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [..1778] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5061] + idle: [..1778] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5061] guessed: [...966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5060] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [...966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5060] + idle: [...966] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5060] not-detected: [..1912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3013] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3013] + idle: [..1912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3013] guessed: [..1879] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5061] [SIP][Unknown][VoIP][Acceptable] RISK: Unidirectional Traffic - idle: [..1879] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5061] + idle: [..1879] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5061] not-detected: [...273] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3017] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...273] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3017] + idle: [...273] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3017] not-detected: [...306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3017] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3017] + idle: [...306] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3017] not-detected: [..1796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][23502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][23502] + idle: [..1796] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][23502] not-detected: [..1861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][23502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][23502] + idle: [..1861] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][23502] not-detected: [...341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][48080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][48080] + idle: [...341] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][48080] not-detected: [...361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][48080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][48080] + idle: [...361] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][48080] not-detected: [...867] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..981] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...867] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..981] + idle: [...867] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..981] not-detected: [...938] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..981] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...938] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..981] + idle: [...938] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..981] not-detected: [...635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3030] + idle: [...635] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3030] not-detected: [..1938] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1938] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3031] + idle: [..1938] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3031] not-detected: [...702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3030] + idle: [...702] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3030] not-detected: [..1984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3031] + idle: [..1984] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3031] not-detected: [...339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5080] + idle: [...339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5080] not-detected: [...363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5080] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5080] + idle: [...363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5080] not-detected: [...914] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..987] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...914] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..987] + idle: [...914] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..987] not-detected: [...983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..987] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..987] + idle: [...983] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..987] not-detected: [....47] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..990] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....47] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..990] + idle: [....47] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..990] not-detected: [..1287] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1287] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5087] + idle: [..1287] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5087] not-detected: [....81] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..990] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....81] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..990] + idle: [....81] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..990] not-detected: [..1363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5087] + idle: [..1363] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5087] not-detected: [..1099] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..992] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1099] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..992] + idle: [..1099] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..992] not-detected: [..1156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..992] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..992] + idle: [..1156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..992] guessed: [....31] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..993] [IMAPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [....31] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..993] + idle: [....31] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..993] guessed: [....68] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..993] [IMAPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [....68] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..993] + idle: [....68] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..993] guessed: [.....7] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..995] [POPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [.....7] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..995] + idle: [.....7] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..995] guessed: [....23] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..995] [POPS][Unknown][Email][Safe] RISK: Unidirectional Traffic - idle: [....23] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..995] + idle: [....23] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..995] not-detected: [...522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..999] + idle: [...522] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][..999] not-detected: [..1434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1000] + idle: [..1434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1000] not-detected: [...549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..999] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..999] + idle: [...549] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][..999] not-detected: [..1512] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1512] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1000] + idle: [..1512] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1000] not-detected: [...845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1001] + idle: [...845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1001] not-detected: [...902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1001] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1001] + idle: [...902] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1001] not-detected: [...894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1002] + idle: [...894] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1002] not-detected: [....58] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....58] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3050] + idle: [....58] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3050] not-detected: [...961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1002] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1002] + idle: [...961] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1002] not-detected: [....70] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....70] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3050] + idle: [....70] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3050] not-detected: [..1136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5100] + idle: [..1136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5100] not-detected: [...298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3052] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3052] + idle: [...298] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3052] not-detected: [..1211] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1211] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5100] + idle: [..1211] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5100] not-detected: [...322] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3052] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...322] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3052] + idle: [...322] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3052] not-detected: [...136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5101] + idle: [...136] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5101] not-detected: [..1026] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1026] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5102] + idle: [..1026] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5102] not-detected: [...156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5101] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5101] + idle: [...156] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5101] not-detected: [..1827] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1827] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1007] + idle: [..1827] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1007] not-detected: [..1079] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1079] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5102] + idle: [..1079] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5102] not-detected: [..1904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1007] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1007] + idle: [..1904] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1007] not-detected: [...102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9200] + idle: [...102] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9200] not-detected: [...576] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...576] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1009] + idle: [...576] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1009] not-detected: [...148] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...148] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9200] + idle: [...148] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9200] not-detected: [..1095] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1095] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1010] + idle: [..1095] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1010] not-detected: [...644] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1009] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...644] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1009] + idle: [...644] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1009] not-detected: [..1160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1010] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1010] + idle: [..1160] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1010] not-detected: [..1070] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1070] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1011] + idle: [..1070] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1011] not-detected: [..1127] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1011] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1127] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1011] + idle: [..1127] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1011] not-detected: [..1338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9207] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9207] + idle: [..1338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9207] not-detected: [..1407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9207] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9207] + idle: [..1407] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9207] not-detected: [..1926] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1926] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1021] + idle: [..1926] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1021] not-detected: [..1968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1021] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1021] + idle: [..1968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1021] not-detected: [..1529] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1529] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1022] + idle: [..1529] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1022] not-detected: [..1604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1022] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1022] + idle: [..1604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1022] not-detected: [..1586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1023] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1023] + idle: [..1586] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1023] not-detected: [...211] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...211] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3071] + idle: [...211] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3071] not-detected: [...887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5120] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5120] + idle: [...887] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5120] not-detected: [..1664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1023] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1023] + idle: [..1664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1023] not-detected: [...245] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...245] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3071] + idle: [...245] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3071] not-detected: [...130] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1024] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...130] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1024] + idle: [...130] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1024] not-detected: [...968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5120] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5120] + idle: [...968] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5120] not-detected: [...162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1024] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1024] + idle: [...162] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1024] not-detected: [.....6] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1025] + idle: [.....6] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1025] not-detected: [..1471] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1026] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1471] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1026] + idle: [..1471] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1026] not-detected: [....24] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1025] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....24] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1025] + idle: [....24] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1025] not-detected: [..1530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1026] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1026] + idle: [..1530] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1026] not-detected: [...428] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1027] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...428] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1027] + idle: [...428] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1027] not-detected: [...548] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9220] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...548] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9220] + idle: [...548] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9220] not-detected: [..1590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1028] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1028] + idle: [..1590] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1028] not-detected: [...479] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1027] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...479] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1027] + idle: [...479] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1027] not-detected: [...599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9220] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9220] + idle: [...599] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9220] not-detected: [..1660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1028] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1028] + idle: [..1660] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1028] not-detected: [...864] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1029] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...864] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1029] + idle: [...864] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1029] not-detected: [...126] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3077] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...126] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3077] + idle: [...126] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3077] not-detected: [..1186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1030] + idle: [..1186] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1030] not-detected: [...941] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1029] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...941] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1029] + idle: [...941] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1029] not-detected: [...166] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3077] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...166] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3077] + idle: [...166] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3077] not-detected: [..1270] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1030] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1270] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1030] + idle: [..1270] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1030] not-detected: [...636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1031] + idle: [...636] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1031] not-detected: [..1198] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1032] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1198] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1032] + idle: [..1198] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1032] not-detected: [...701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1031] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1031] + idle: [...701] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1031] not-detected: [..1493] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1493] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1033] + idle: [..1493] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1033] not-detected: [..1274] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1032] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1274] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1032] + idle: [..1274] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1032] not-detected: [..1556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1033] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1033] + idle: [..1556] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1033] not-detected: [..1546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1034] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1034] + idle: [..1546] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1034] not-detected: [..1607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1034] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1034] + idle: [..1607] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1034] not-detected: [..1329] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1035] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1329] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1035] + idle: [..1329] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1035] not-detected: [..1416] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1035] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1416] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1035] + idle: [..1416] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1035] not-detected: [...581] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1036] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...581] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1036] + idle: [...581] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1036] not-detected: [..1028] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1037] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1028] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1037] + idle: [..1028] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1037] not-detected: [...639] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1036] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...639] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1036] + idle: [...639] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1036] not-detected: [..1821] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1821] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1038] + idle: [..1821] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1038] not-detected: [..1077] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1037] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1077] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1037] + idle: [..1077] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1037] not-detected: [..1885] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1038] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1885] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1038] + idle: [..1885] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1038] not-detected: [..1538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1039] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1039] + idle: [..1538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1039] not-detected: [..1615] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1039] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1615] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1039] + idle: [..1615] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1039] not-detected: [...376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1040] + idle: [...376] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1040] not-detected: [...734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1041] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1041] + idle: [...734] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1041] not-detected: [...408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1040] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1040] + idle: [...408] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1040] not-detected: [...821] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1041] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...821] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1041] + idle: [...821] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1041] not-detected: [...735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1042] + idle: [...735] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1042] not-detected: [...820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1042] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1042] + idle: [...820] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1042] not-detected: [...183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1043] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1043] + idle: [...183] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1043] not-detected: [..1949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1044] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1044] + idle: [..1949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1044] not-detected: [...232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1043] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1043] + idle: [...232] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1043] not-detected: [..1973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1044] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1044] + idle: [..1973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1044] not-detected: [..1247] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1247] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1045] + idle: [..1247] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1045] not-detected: [..1313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1045] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1045] + idle: [..1313] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1045] not-detected: [...945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1046] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1046] + idle: [...945] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1046] not-detected: [..1010] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1046] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1010] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1046] + idle: [..1010] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1046] not-detected: [...347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1047] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1047] + idle: [...347] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1047] not-detected: [...439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1048] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1048] + idle: [...439] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1048] not-detected: [...396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1047] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1047] + idle: [...396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1047] not-detected: [..1932] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1049] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1932] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1049] + idle: [..1932] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1049] not-detected: [...468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1048] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1048] + idle: [...468] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1048] not-detected: [..1990] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1049] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1990] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1049] + idle: [..1990] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1049] not-detected: [..1103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1050] + idle: [..1103] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1050] not-detected: [..1152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1050] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1050] + idle: [..1152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1050] not-detected: [...891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1051] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1051] + idle: [...891] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1051] not-detected: [...434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60443] + idle: [...434] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][60443] not-detected: [...964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1051] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1051] + idle: [...964] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1051] not-detected: [...690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1052] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1052] + idle: [...690] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1052] not-detected: [...473] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...473] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60443] + idle: [...473] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][60443] not-detected: [...757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1052] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1052] + idle: [...757] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1052] not-detected: [...584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1053] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1053] + idle: [...584] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1053] not-detected: [..1520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1054] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1054] + idle: [..1520] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1054] not-detected: [...671] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1053] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...671] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1053] + idle: [...671] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1053] not-detected: [..1603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1054] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1054] + idle: [..1603] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1054] not-detected: [..1331] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1055] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1331] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1055] + idle: [..1331] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1055] not-detected: [..1414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1055] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1055] + idle: [..1414] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1055] not-detected: [...128] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...128] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7200] + idle: [...128] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7200] not-detected: [....43] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1056] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....43] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1056] + idle: [....43] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1056] not-detected: [...583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7201] + idle: [...583] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7201] not-detected: [...164] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...164] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7200] + idle: [...164] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7200] not-detected: [..1742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1057] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1057] + idle: [..1742] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1057] not-detected: [....85] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1056] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....85] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1056] + idle: [....85] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1056] not-detected: [..1812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1057] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1057] + idle: [..1812] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1057] not-detected: [...672] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...672] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7201] + idle: [...672] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7201] not-detected: [...569] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1058] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...569] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1058] + idle: [...569] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1058] not-detected: [...988] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1059] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...988] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1059] + idle: [...988] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1059] not-detected: [...651] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1058] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...651] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1058] + idle: [...651] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1058] not-detected: [..1059] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1059] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1059] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1059] + idle: [..1059] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1059] not-detected: [...348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1060] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1060] + idle: [...348] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1060] not-detected: [..1249] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1061] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1249] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1061] + idle: [..1249] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1061] not-detected: [...395] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1060] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...395] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1060] + idle: [...395] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1060] not-detected: [..1311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1061] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1061] + idle: [..1311] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1061] not-detected: [..1066] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1062] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1066] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1062] + idle: [..1066] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1062] not-detected: [..1797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1063] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1063] + idle: [..1797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1063] not-detected: [..1131] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1062] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1131] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1062] + idle: [..1131] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1062] not-detected: [..1860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1063] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1063] + idle: [..1860] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1063] not-detected: [...214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1064] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1064] + idle: [...214] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1064] not-detected: [...508] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1065] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...508] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1065] + idle: [...508] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1065] not-detected: [...242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1064] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1064] + idle: [...242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1064] not-detected: [...836] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1066] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...836] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1066] + idle: [...836] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1066] not-detected: [...563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1065] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1065] + idle: [...563] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1065] not-detected: [...911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1066] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1066] + idle: [...911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1066] not-detected: [...104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1067] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1067] + idle: [...104] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1067] not-detected: [..1295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1068] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1068] + idle: [..1295] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1068] not-detected: [...146] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1067] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...146] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1067] + idle: [...146] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1067] not-detected: [..1355] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1068] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1355] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1068] + idle: [..1355] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1068] not-detected: [..1349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1069] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1069] + idle: [..1349] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1069] not-detected: [..1396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1069] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1069] + idle: [..1396] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1069] not-detected: [...418] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...418] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1070] + idle: [...418] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1070] not-detected: [...448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1070] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1070] + idle: [...448] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1070] not-detected: [...207] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...207] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1071] + idle: [...207] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1071] not-detected: [...744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1072] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1072] + idle: [...744] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1072] not-detected: [...249] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1071] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...249] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1071] + idle: [...249] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1071] not-detected: [...811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1072] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1072] + idle: [...811] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1072] not-detected: [...175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1073] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1073] + idle: [...175] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1073] not-detected: [..1650] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1074] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1650] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1074] + idle: [..1650] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1074] not-detected: [...199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1073] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1073] + idle: [...199] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1073] not-detected: [..1721] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1074] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1721] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1074] + idle: [..1721] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1074] not-detected: [....97] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1075] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....97] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1075] + idle: [....97] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1075] not-detected: [..1483] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1076] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1483] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1076] + idle: [..1483] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1076] not-detected: [...153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1075] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1075] + idle: [...153] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1075] not-detected: [..1566] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1076] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1566] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1076] + idle: [..1566] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1076] not-detected: [..1333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1077] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1077] + idle: [..1333] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1077] not-detected: [..1412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1077] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1077] + idle: [..1412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1077] not-detected: [...748] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1078] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...748] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1078] + idle: [...748] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1078] not-detected: [...807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1078] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1078] + idle: [...807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1078] not-detected: [...771] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1079] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...771] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1079] + idle: [...771] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1079] guessed: [..1831] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3128] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [..1831] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3128] + idle: [..1831] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3128] guessed: [..1694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1080] [SOCKS][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [..1694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1080] + idle: [..1694] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1080] not-detected: [...826] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1079] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...826] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1079] + idle: [...826] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1079] not-detected: [...618] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54328] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...618] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54328] + idle: [...618] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][54328] guessed: [..1900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3128] [HTTP_Proxy][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [..1900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3128] + idle: [..1900] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3128] guessed: [..1763] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1080] [SOCKS][Unknown][Web][Acceptable] RISK: Unidirectional Traffic - idle: [..1763] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1080] + idle: [..1763] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1080] not-detected: [..1490] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1490] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1081] + idle: [..1490] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1081] not-detected: [...679] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54328] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...679] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54328] + idle: [...679] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][54328] not-detected: [..1559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1081] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1081] + idle: [..1559] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1081] not-detected: [...842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1082] + idle: [...842] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1082] not-detected: [...905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1082] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1082] + idle: [...905] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1082] not-detected: [...714] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1083] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...714] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1083] + idle: [...714] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1083] not-detected: [...791] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1083] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...791] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1083] + idle: [...791] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1083] not-detected: [...261] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1084] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...261] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1084] + idle: [...261] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1084] not-detected: [...768] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1085] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...768] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1085] + idle: [...768] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1085] not-detected: [...277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1084] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1084] + idle: [...277] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1084] not-detected: [...829] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1085] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...829] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1085] + idle: [...829] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1085] not-detected: [...689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1086] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1086] + idle: [...689] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1086] not-detected: [...758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1086] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1086] + idle: [...758] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1086] not-detected: [...383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1087] + idle: [...383] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1087] not-detected: [...521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1088] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1088] + idle: [...521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1088] not-detected: [...401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1087] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1087] + idle: [...401] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1087] not-detected: [..1679] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1089] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1679] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1089] + idle: [..1679] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1089] not-detected: [...550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1088] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1088] + idle: [...550] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1088] not-detected: [..1748] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1089] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1748] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1089] + idle: [..1748] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1089] not-detected: [..1629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1090] + idle: [..1629] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1090] not-detected: [..1712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1090] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1090] + idle: [..1712] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1090] not-detected: [..1521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][21571] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][21571] + idle: [..1521] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][21571] not-detected: [..1137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1091] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1091] + idle: [..1137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1091] not-detected: [...946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27715] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27715] + idle: [...946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][27715] not-detected: [..1602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][21571] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][21571] + idle: [..1602] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][21571] not-detected: [..1930] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1092] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1930] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1092] + idle: [..1930] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1092] not-detected: [..1210] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1091] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1210] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1091] + idle: [..1210] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1091] not-detected: [..1009] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27715] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1009] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27715] + idle: [..1009] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][27715] not-detected: [..1992] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1092] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1992] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1092] + idle: [..1992] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1092] not-detected: [...896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1093] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1093] + idle: [...896] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1093] not-detected: [..1646] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1094] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1646] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1094] + idle: [..1646] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1094] not-detected: [...959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1093] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1093] + idle: [...959] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1093] not-detected: [...260] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5190] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...260] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5190] + idle: [...260] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5190] not-detected: [..1725] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1094] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1725] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1094] + idle: [..1725] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1094] not-detected: [...278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5190] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5190] + idle: [...278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5190] not-detected: [...213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1095] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1095] + idle: [...213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1095] not-detected: [...598] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1096] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...598] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1096] + idle: [...598] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1096] not-detected: [...243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1095] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1095] + idle: [...243] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1095] not-detected: [...657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1096] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1096] + idle: [...657] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1096] not-detected: [...422] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1097] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...422] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1097] + idle: [...422] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1097] not-detected: [..1934] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9290] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1934] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9290] + idle: [..1934] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9290] not-detected: [..1257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1098] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1098] + idle: [..1257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1098] not-detected: [...444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1097] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1097] + idle: [...444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1097] not-detected: [..1988] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9290] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1988] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9290] + idle: [..1988] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9290] not-detected: [..1303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1098] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1098] + idle: [..1303] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1098] not-detected: [..1045] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1045] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1099] + idle: [..1045] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1099] not-detected: [..1166] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1166] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1100] + idle: [..1166] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1100] not-detected: [..1110] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1099] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1110] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1099] + idle: [..1110] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1099] not-detected: [..1241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1100] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1100] + idle: [..1241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1100] not-detected: [..1533] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1533] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1102] + idle: [..1533] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1102] not-detected: [..1620] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1102] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1620] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1102] + idle: [..1620] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1102] not-detected: [..1941] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1104] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1941] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1104] + idle: [..1941] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1104] not-detected: [...438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5200] + idle: [...438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5200] not-detected: [..1981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1104] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1104] + idle: [..1981] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1104] not-detected: [..1178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1105] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1105] + idle: [..1178] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1105] not-detected: [...469] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5200] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...469] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5200] + idle: [...469] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5200] not-detected: [..1229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1105] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1105] + idle: [..1229] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1105] not-detected: [..1144] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1144] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1106] + idle: [..1144] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1106] not-detected: [..1582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1107] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1107] + idle: [..1582] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1107] not-detected: [..1203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1106] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1106] + idle: [..1203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1106] not-detected: [..1828] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1108] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1828] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1108] + idle: [..1828] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1108] not-detected: [..1668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1107] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1107] + idle: [..1668] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1107] not-detected: [..1903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1108] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1108] + idle: [..1903] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1108] not-detected: [..1943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1110] + idle: [..1943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1110] not-detected: [..1979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1110] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1110] + idle: [..1979] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1110] not-detected: [...215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1111] + idle: [...215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1111] not-detected: [..1033] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1112] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1033] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1112] + idle: [..1033] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1112] not-detected: [...241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1111] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1111] + idle: [...241] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1111] not-detected: [..1517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1113] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1113] + idle: [..1517] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1113] not-detected: [..1122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1112] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1112] + idle: [..1122] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1112] not-detected: [..1581] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1113] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1581] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1113] + idle: [..1581] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1113] not-detected: [..1395] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1114] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1395] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1114] + idle: [..1395] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1114] not-detected: [..1454] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1114] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1454] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1114] + idle: [..1454] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1114] not-detected: [..1071] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1117] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1071] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1117] + idle: [..1071] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1117] not-detected: [..1126] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1117] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1126] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1117] + idle: [..1126] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1117] not-detected: [...288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5214] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5214] + idle: [...288] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5214] guessed: [...870] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1119] [Starcraft][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [...870] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1119] + idle: [...870] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1119] not-detected: [...332] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5214] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...332] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5214] + idle: [...332] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5214] guessed: [...935] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1119] [Starcraft][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [...935] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1119] + idle: [...935] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1119] not-detected: [...805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3168] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3168] + idle: [...805] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3168] not-detected: [..1215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1121] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1121] + idle: [..1215] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1121] not-detected: [...850] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3168] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...850] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3168] + idle: [...850] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3168] not-detected: [..1283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1121] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1121] + idle: [..1283] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1121] not-detected: [..1223] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1122] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1223] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1122] + idle: [..1223] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1122] not-detected: [..1275] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1122] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1275] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1122] + idle: [..1275] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1122] not-detected: [...265] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1123] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...265] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1123] + idle: [...265] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1123] not-detected: [..1252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1124] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1124] + idle: [..1252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1124] not-detected: [...314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1123] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1123] + idle: [...314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1123] not-detected: [..1308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1124] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1124] + idle: [..1308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1124] not-detected: [...338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5221] + idle: [...338] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5221] not-detected: [..1339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1126] + idle: [..1339] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1126] not-detected: [..1165] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1165] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5222] + idle: [..1165] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5222] not-detected: [...364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5221] + idle: [...364] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5221] not-detected: [..1406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1126] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1126] + idle: [..1406] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1126] not-detected: [..1242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5222] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5222] + idle: [..1242] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5222] not-detected: [..1850] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5225] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1850] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5225] + idle: [..1850] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5225] not-detected: [..1911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5225] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5225] + idle: [..1911] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5225] not-detected: [..1525] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1130] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1525] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1130] + idle: [..1525] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1130] not-detected: [..1476] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5226] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1476] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5226] + idle: [..1476] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5226] not-detected: [..1598] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1130] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1598] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1130] + idle: [..1598] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1130] not-detected: [..1573] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5226] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1573] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5226] + idle: [..1573] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5226] not-detected: [...271] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1131] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...271] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1131] + idle: [...271] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1131] not-detected: [...106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33899] + idle: [...106] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][33899] not-detected: [..1188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1132] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1132] + idle: [..1188] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1132] not-detected: [...308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1131] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1131] + idle: [...308] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1131] not-detected: [...144] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33899] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...144] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33899] + idle: [...144] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][33899] not-detected: [..1268] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1132] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1268] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1132] + idle: [..1268] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1132] not-detected: [..1189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64623] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64623] + idle: [..1189] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64623] not-detected: [..1267] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64623] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1267] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64623] + idle: [..1267] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64623] not-detected: [...993] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1137] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...993] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1137] + idle: [...993] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1137] not-detected: [..1141] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1138] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1141] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1138] + idle: [..1141] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1138] not-detected: [..1054] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1137] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1054] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1137] + idle: [..1054] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1137] not-detected: [..1206] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1138] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1206] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1138] + idle: [..1206] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1138] not-detected: [...772] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1141] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...772] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1141] + idle: [...772] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1141] not-detected: [...825] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1141] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...825] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1141] + idle: [...825] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1141] not-detected: [..1326] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1145] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1326] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1145] + idle: [..1326] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1145] not-detected: [..1419] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1145] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1419] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1145] + idle: [..1419] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1145] not-detected: [..1501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1147] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1147] + idle: [..1501] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1147] not-detected: [..1548] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1147] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1548] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1147] + idle: [..1548] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1147] not-detected: [..1173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50300] + idle: [..1173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50300] not-detected: [...725] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1148] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...725] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1148] + idle: [...725] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1148] not-detected: [..1234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50300] + idle: [..1234] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50300] not-detected: [..1747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1149] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1149] + idle: [..1747] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1149] not-detected: [...780] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1148] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...780] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1148] + idle: [...780] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1148] not-detected: [..1807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1149] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1149] + idle: [..1807] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1149] not-detected: [...424] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1151] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...424] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1151] + idle: [...424] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1151] not-detected: [..1800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1152] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1152] + idle: [..1800] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1152] not-detected: [...442] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1151] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...442] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1151] + idle: [...442] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1151] not-detected: [..1857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1152] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1152] + idle: [..1857] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1152] not-detected: [...345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1154] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1154] + idle: [...345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1154] not-detected: [...398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1154] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1154] + idle: [...398] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1154] not-detected: [...454] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25734] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...454] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25734] + idle: [...454] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25734] not-detected: [..1686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25735] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25735] + idle: [..1686] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][25735] not-detected: [...494] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25734] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...494] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25734] + idle: [...494] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25734] not-detected: [..1771] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25735] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1771] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25735] + idle: [..1771] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][25735] not-detected: [..1673] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3211] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1673] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3211] + idle: [..1673] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3211] not-detected: [..1246] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1246] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1163] + idle: [..1246] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1163] not-detected: [..1754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3211] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3211] + idle: [..1754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3211] not-detected: [..1314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1163] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1163] + idle: [..1314] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1163] not-detected: [...882] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1164] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...882] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1164] + idle: [...882] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1164] not-detected: [...973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1164] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1164] + idle: [...973] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1164] not-detected: [...737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1165] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1165] + idle: [...737] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1165] not-detected: [...818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1165] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1165] + idle: [...818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1165] not-detected: [...373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1166] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1166] + idle: [...373] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1166] not-detected: [...411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1166] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1166] + idle: [...411] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1166] not-detected: [...251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44176] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44176] + idle: [...251] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][44176] not-detected: [...174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13456] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13456] + idle: [...174] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][13456] not-detected: [...287] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44176] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...287] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44176] + idle: [...287] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][44176] not-detected: [...547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1169] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1169] + idle: [...547] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1169] not-detected: [...200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13456] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13456] + idle: [...200] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][13456] not-detected: [...600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1169] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1169] + idle: [...600] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1169] not-detected: [..1946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5269] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5269] + idle: [..1946] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5269] not-detected: [..1366] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1366] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3221] + idle: [..1366] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3221] not-detected: [..1976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5269] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5269] + idle: [..1976] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5269] not-detected: [..1428] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3221] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1428] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3221] + idle: [..1428] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3221] not-detected: [..1020] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1174] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1020] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1174] + idle: [..1020] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1174] not-detected: [..1180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1175] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1175] + idle: [..1180] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1175] not-detected: [..1085] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1174] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1085] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1174] + idle: [..1085] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1174] not-detected: [..1227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1175] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1175] + idle: [..1227] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1175] not-detected: [...252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1183] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1183] + idle: [...252] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1183] not-detected: [...835] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5280] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...835] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5280] + idle: [...835] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5280] not-detected: [...286] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1183] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...286] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1183] + idle: [...286] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1183] not-detected: [...912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5280] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5280] + idle: [...912] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5280] not-detected: [...566] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1185] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...566] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1185] + idle: [...566] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1185] not-detected: [...949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1186] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1186] + idle: [...949] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1186] not-detected: [...654] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1185] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...654] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1185] + idle: [...654] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1185] not-detected: [..1006] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1186] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1006] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1186] + idle: [..1006] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1186] not-detected: [...127] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1187] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...127] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1187] + idle: [...127] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1187] not-detected: [...165] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1187] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...165] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1187] + idle: [...165] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1187] not-detected: [...952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64680] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64680] + idle: [...952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][64680] not-detected: [...874] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1192] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...874] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1192] + idle: [...874] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1192] not-detected: [..1003] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64680] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1003] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64680] + idle: [..1003] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][64680] not-detected: [...931] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1192] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...931] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1192] + idle: [...931] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1192] not-detected: [..1782] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1198] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1782] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1198] + idle: [..1782] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1198] not-detected: [..1875] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1198] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1875] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1198] + idle: [..1875] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1198] not-detected: [...718] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1199] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...718] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1199] + idle: [...718] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1199] not-detected: [...787] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1199] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...787] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1199] + idle: [...787] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1199] not-detected: [...591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1201] + idle: [...591] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1201] not-detected: [..1220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5298] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5298] + idle: [..1220] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5298] not-detected: [...664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1201] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1201] + idle: [...664] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1201] not-detected: [..1278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5298] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5298] + idle: [..1278] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5298] not-detected: [..1181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3260] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3260] + idle: [..1181] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3260] not-detected: [..1952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3261] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3261] + idle: [..1952] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3261] not-detected: [..1637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1213] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1213] + idle: [..1637] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1213] not-detected: [..1226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3260] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3260] + idle: [..1226] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3260] not-detected: [..1970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3261] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3261] + idle: [..1970] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3261] not-detected: [..1704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1213] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1213] + idle: [..1704] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1213] not-detected: [...573] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1216] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...573] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1216] + idle: [...573] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1216] not-detected: [..1067] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1217] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1067] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1217] + idle: [..1067] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1217] not-detected: [...647] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1216] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...647] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1216] + idle: [...647] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1216] not-detected: [..1130] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1217] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1130] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1217] + idle: [..1130] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1217] not-detected: [...685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1218] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1218] + idle: [...685] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1218] not-detected: [...762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1218] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1218] + idle: [...762] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1218] not-detected: [..1948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3268] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3268] + idle: [..1948] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3268] not-detected: [..1974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3268] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3268] + idle: [..1974] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3268] not-detected: [..1433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3269] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3269] + idle: [..1433] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3269] not-detected: [..1513] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3269] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1513] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3269] + idle: [..1513] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3269] not-detected: [...464] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9415] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...464] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9415] + idle: [...464] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9415] not-detected: [...484] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9415] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...484] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9415] + idle: [...484] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9415] guessed: [...538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9418] [Git][Unknown][Collaborative][Safe] RISK: Unidirectional Traffic - idle: [...538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9418] + idle: [...538] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9418] guessed: [...609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9418] [Git][Unknown][Collaborative][Safe] RISK: Unidirectional Traffic - idle: [...609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9418] + idle: [...609] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9418] not-detected: [....52] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1233] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....52] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1233] + idle: [....52] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1233] not-detected: [..1804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1234] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1234] + idle: [..1804] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1234] not-detected: [....76] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1233] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....76] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1233] + idle: [....76] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1233] not-detected: [..1853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1234] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1234] + idle: [..1853] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1234] not-detected: [..1325] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3283] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1325] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3283] + idle: [..1325] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3283] not-detected: [..1823] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1236] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1823] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1236] + idle: [..1823] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1236] not-detected: [..1420] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3283] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1420] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3283] + idle: [..1420] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3283] not-detected: [..1883] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1236] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1883] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1236] + idle: [..1883] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1236] not-detected: [..1806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50389] + idle: [..1806] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][50389] not-detected: [..1882] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50389] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1882] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50389] + idle: [..1882] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][50389] not-detected: [...297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1244] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1244] + idle: [...297] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1244] not-detected: [...323] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1244] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...323] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1244] + idle: [...323] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1244] not-detected: [...110] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1247] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...110] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1247] + idle: [...110] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1247] not-detected: [...568] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1248] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...568] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1248] + idle: [...568] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1248] not-detected: [...141] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1247] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...141] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1247] + idle: [...141] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1247] not-detected: [...652] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1248] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...652] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1248] + idle: [...652] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1248] not-detected: [..1191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3300] + idle: [..1191] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3300] not-detected: [..1265] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1265] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3300] + idle: [..1265] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3300] not-detected: [...505] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...505] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3301] + idle: [...505] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3301] not-detected: [...526] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...526] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3301] + idle: [...526] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3301] not-detected: [..1698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7402] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7402] + idle: [..1698] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7402] guessed: [.....3] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3306] [MySQL][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [.....3] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3306] + idle: [.....3] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3306] not-detected: [..1759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7402] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7402] + idle: [..1759] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7402] not-detected: [...510] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1259] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...510] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1259] + idle: [...510] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1259] guessed: [....27] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3306] [MySQL][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [....27] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3306] + idle: [....27] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3306] not-detected: [...561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1259] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1259] + idle: [...561] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1259] not-detected: [..1681] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5357] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1681] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5357] + idle: [..1681] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5357] not-detected: [..1756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5357] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5357] + idle: [..1756] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5357] not-detected: [...697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1271] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1271] + idle: [...697] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1271] not-detected: [..1213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1272] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1272] + idle: [..1213] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1272] not-detected: [...750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1271] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1271] + idle: [...750] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1271] not-detected: [..1285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1272] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1272] + idle: [..1285] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1272] not-detected: [..1375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3322] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3322] + idle: [..1375] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3322] not-detected: [..1444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3322] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3322] + idle: [..1444] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3322] not-detected: [..1386] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3323] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1386] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3323] + idle: [..1386] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3323] not-detected: [..1630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3324] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3324] + idle: [..1630] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3324] not-detected: [..1463] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3323] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1463] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3323] + idle: [..1463] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3323] not-detected: [..1711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3324] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3324] + idle: [..1711] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3324] not-detected: [..1069] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3325] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1069] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3325] + idle: [..1069] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3325] not-detected: [...571] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1277] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...571] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1277] + idle: [...571] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1277] not-detected: [..1128] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3325] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1128] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3325] + idle: [..1128] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3325] not-detected: [...649] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1277] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...649] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1277] + idle: [...649] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1277] not-detected: [..1473] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40193] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1473] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40193] + idle: [..1473] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][40193] not-detected: [..1576] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40193] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1576] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40193] + idle: [..1576] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][40193] not-detected: [..1377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3333] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3333] + idle: [..1377] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3333] not-detected: [..1452] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3333] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1452] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3333] + idle: [..1452] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3333] not-detected: [..1321] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1287] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1321] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1287] + idle: [..1321] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1287] not-detected: [..1424] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1287] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1424] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1287] + idle: [..1424] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1287] not-detected: [..1498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7435] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7435] + idle: [..1498] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7435] not-detected: [..1551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7435] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7435] + idle: [..1551] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7435] not-detected: [...797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9485] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9485] + idle: [...797] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9485] not-detected: [...858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9485] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9485] + idle: [...858] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9485] not-detected: [...137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1296] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1296] + idle: [...137] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1296] not-detected: [...155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1296] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1296] + idle: [...155] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1296] not-detected: [..1438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7443] + idle: [..1438] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.7443] not-detected: [..1508] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7443] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1508] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7443] + idle: [..1508] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.7443] not-detected: [....98] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....98] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1300] + idle: [....98] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1300] not-detected: [...632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1301] + idle: [...632] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1301] not-detected: [...152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1300] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1300] + idle: [...152] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1300] not-detected: [...705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1301] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1301] + idle: [...705] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1301] not-detected: [..1736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3351] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3351] + idle: [..1736] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3351] not-detected: [..1818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3351] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3351] + idle: [..1818] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3351] not-detected: [...171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9500] + idle: [...171] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9500] not-detected: [...738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5405] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5405] + idle: [...738] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5405] not-detected: [...620] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1309] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...620] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1309] + idle: [...620] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1309] not-detected: [...203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9500] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9500] + idle: [...203] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9500] not-detected: [...943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9502] + idle: [...943] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9502] not-detected: [...817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5405] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5405] + idle: [...817] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5405] not-detected: [..1393] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1310] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1393] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1310] + idle: [..1393] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1310] not-detected: [...677] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1309] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...677] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1309] + idle: [...677] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1309] not-detected: [..1456] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1310] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1456] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1310] + idle: [..1456] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1310] not-detected: [..1065] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9503] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1065] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9503] + idle: [..1065] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.9503] not-detected: [..1012] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9502] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1012] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9502] + idle: [..1012] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9502] not-detected: [...111] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1311] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...111] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1311] + idle: [...111] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1311] not-detected: [..1132] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9503] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1132] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9503] + idle: [..1132] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.9503] not-detected: [...140] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1311] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...140] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1311] + idle: [...140] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1311] not-detected: [....48] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5414] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....48] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5414] + idle: [....48] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5414] not-detected: [...593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3367] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3367] + idle: [...593] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3367] not-detected: [....80] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5414] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....80] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5414] + idle: [....80] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5414] not-detected: [...662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3367] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3367] + idle: [...662] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3367] not-detected: [...294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3369] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3369] + idle: [...294] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3369] not-detected: [..1345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3370] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3370] + idle: [..1345] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3370] not-detected: [...543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1322] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1322] + idle: [...543] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1322] not-detected: [...326] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3369] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...326] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3369] + idle: [...326] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3369] not-detected: [..1535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3371] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3371] + idle: [..1535] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3371] not-detected: [..1400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3370] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3370] + idle: [..1400] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3370] not-detected: [...604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1322] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1322] + idle: [...604] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1322] not-detected: [..1845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3372] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3372] + idle: [..1845] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.3372] not-detected: [..1618] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3371] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1618] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3371] + idle: [..1618] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3371] not-detected: [...173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15660] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15660] + idle: [...173] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][15660] not-detected: [..1916] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3372] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1916] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3372] + idle: [..1916] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.3372] not-detected: [...201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15660] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15660] + idle: [...201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][15660] not-detected: [...693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30000] + idle: [...693] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][30000] not-detected: [...372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1328] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1328] + idle: [...372] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1328] not-detected: [...754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30000] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30000] + idle: [...754] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][30000] not-detected: [...412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1328] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1328] + idle: [...412] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1328] not-detected: [..1585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1334] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1334] + idle: [..1585] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.1334] not-detected: [..1665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1334] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [..1665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1334] + idle: [..1665] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.1334] not-detected: [...257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5431] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5431] + idle: [...257] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5431] guessed: [..1146] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5432] [PostgreSQL][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [..1146] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5432] + idle: [..1146] [ip4][..tcp] [.....172.16.0.8][36050] -> [...64.13.134.52][.5432] not-detected: [...281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5431] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [...281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5431] + idle: [...281] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5431] guessed: [..1201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5432] [PostgreSQL][Unknown][Database][Acceptable] RISK: Unidirectional Traffic - idle: [..1201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5432] + idle: [..1201] [ip4][..tcp] [.....172.16.0.8][36051] -> [...64.13.134.52][.5432] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/syslog.pcap.out b/test/results/flow-info/default/syslog.pcap.out index c61911b3f..84acf374d 100644 --- a/test/results/flow-info/default/syslog.pcap.out +++ b/test/results/flow-info/default/syslog.pcap.out @@ -3,80 +3,80 @@ ERROR-EVENT: Unknown packet type [2/16] DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...172.20.51.54][..514] -> [..172.31.110.40][..514] + new: [.....1] [ip4][..udp] [...172.20.51.54][..514] -> [..172.31.110.40][..514] detected: [.....1] [ip4][..udp] [...172.20.51.54][..514] -> [..172.31.110.40][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..10.251.23.139][59194] -> [....62.39.3.142][..514] + new: [.....2] [ip4][..udp] [..10.251.23.139][59194] -> [....62.39.3.142][..514] detected: [.....2] [ip4][..udp] [..10.251.23.139][59194] -> [....62.39.3.142][..514] [Syslog][Unknown][System][Acceptable] idle: [.....1] [ip4][..udp] [...172.20.51.54][..514] -> [..172.31.110.40][..514] [Syslog][Unknown][System][Acceptable] update: [.....2] [ip4][..udp] [..10.251.23.139][59194] -> [....62.39.3.142][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 17 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] + new: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] detected: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] idle: [.....2] [ip4][..udp] [..10.251.23.139][59194] -> [....62.39.3.142][..514] [Syslog][Unknown][System][Acceptable] update: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] - new: [.....4] [ip4][..udp] [..192.168.121.2][50352] -> [.192.168.120.10][..514] + new: [.....4] [ip4][..udp] [..192.168.121.2][50352] -> [.192.168.120.10][..514] detected: [.....4] [ip4][..udp] [..192.168.121.2][50352] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] update: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 23 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....5] [ip4][...41] [..193.24.227.10] -> [..216.66.86.114] - new: [.....6] [ip4][...41] [...216.66.80.30] -> [..193.24.227.12] + new: [.....5] [ip4][...41] [..193.24.227.10] -> [..216.66.86.114] + new: [.....6] [ip4][...41] [...216.66.80.30] -> [..193.24.227.12] idle: [.....4] [ip4][..udp] [..192.168.121.2][50352] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] idle: [.....3] [ip4][..udp] [.192.168.121.10][50080] -> [.192.168.120.10][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 29 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [.....7] [ip4][..udp] [..172.21.251.36][62679] -> [..172.19.196.11][..514] + new: [.....7] [ip4][..udp] [..172.21.251.36][62679] -> [..172.19.196.11][..514] detected: [.....7] [ip4][..udp] [..172.21.251.36][62679] -> [..172.19.196.11][..514] [Syslog][Unknown][System][Acceptable] not-detected: [.....6] [ip4][...41] [...216.66.80.30] -> [..193.24.227.12] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....6] [ip4][...41] [...216.66.80.30] -> [..193.24.227.12] + idle: [.....6] [ip4][...41] [...216.66.80.30] -> [..193.24.227.12] not-detected: [.....5] [ip4][...41] [..193.24.227.10] -> [..216.66.86.114] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [.....5] [ip4][...41] [..193.24.227.10] -> [..216.66.86.114] - new: [.....8] [ip4][..udp] [.192.168.72.140][62679] -> [192.168.178.148][..514] + idle: [.....5] [ip4][...41] [..193.24.227.10] -> [..216.66.86.114] + new: [.....8] [ip4][..udp] [.192.168.72.140][62679] -> [192.168.178.148][..514] detected: [.....8] [ip4][..udp] [.192.168.72.140][62679] -> [192.168.178.148][..514] [Syslog][Unknown][System][Acceptable] update: [.....7] [ip4][..udp] [..172.21.251.36][62679] -> [..172.19.196.11][..514] [Syslog][Unknown][System][Acceptable] - new: [.....9] [ip4][..udp] [.192.168.67.241][62679] -> [....10.193.53.6][..514] + new: [.....9] [ip4][..udp] [.192.168.67.241][62679] -> [....10.193.53.6][..514] detected: [.....9] [ip4][..udp] [.192.168.67.241][62679] -> [....10.193.53.6][..514] [Syslog][Unknown][System][Acceptable] idle: [.....7] [ip4][..udp] [..172.21.251.36][62679] -> [..172.19.196.11][..514] [Syslog][Unknown][System][Acceptable] update: [.....8] [ip4][..udp] [.192.168.72.140][62679] -> [192.168.178.148][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 35 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 9|skipped: 0|!detected: 2|guessed: 0|detection-updates: 0|updates: 5] - new: [....10] [ip4][..udp] [192.168.126.102][57166] -> [.172.19.177.230][..514] + new: [....10] [ip4][..udp] [192.168.126.102][57166] -> [.172.19.177.230][..514] detected: [....10] [ip4][..udp] [192.168.126.102][57166] -> [.172.19.177.230][..514] [Syslog][Unknown][System][Acceptable] idle: [.....8] [ip4][..udp] [.192.168.72.140][62679] -> [192.168.178.148][..514] [Syslog][Unknown][System][Acceptable] idle: [.....9] [ip4][..udp] [.192.168.67.241][62679] -> [....10.193.53.6][..514] [Syslog][Unknown][System][Acceptable] - new: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] + new: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] detected: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] [Syslog][Unknown][System][Acceptable] update: [....10] [ip4][..udp] [192.168.126.102][57166] -> [.172.19.177.230][..514] [Syslog][Unknown][System][Acceptable] - new: [....12] [ip4][..udp] [.192.168.45.162][57166] -> [..10.208.120.95][..514] + new: [....12] [ip4][..udp] [.192.168.45.162][57166] -> [..10.208.120.95][..514] detected: [....12] [ip4][..udp] [.192.168.45.162][57166] -> [..10.208.120.95][..514] [Syslog][Unknown][System][Acceptable] update: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] [Syslog][Unknown][System][Acceptable] - new: [....13] [ip4][..udp] [..10.224.43.149][57166] -> [..172.23.243.89][..514] + new: [....13] [ip4][..udp] [..10.224.43.149][57166] -> [..172.23.243.89][..514] detected: [....13] [ip4][..udp] [..10.224.43.149][57166] -> [..172.23.243.89][..514] [Syslog][Unknown][System][Acceptable] idle: [....10] [ip4][..udp] [192.168.126.102][57166] -> [.172.19.177.230][..514] [Syslog][Unknown][System][Acceptable] update: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] [Syslog][Unknown][System][Acceptable] update: [....12] [ip4][..udp] [.192.168.45.162][57166] -> [..10.208.120.95][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 49 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 13|skipped: 0|!detected: 2|guessed: 0|detection-updates: 0|updates: 9] - new: [....14] [ip4][..udp] [.172.26.229.190][..514] -> [..172.23.80.196][..514] + new: [....14] [ip4][..udp] [.172.26.229.190][..514] -> [..172.23.80.196][..514] detected: [....14] [ip4][..udp] [.172.26.229.190][..514] -> [..172.23.80.196][..514] [Syslog][Unknown][System][Acceptable] idle: [....13] [ip4][..udp] [..10.224.43.149][57166] -> [..172.23.243.89][..514] [Syslog][Unknown][System][Acceptable] idle: [....11] [ip4][..udp] [..10.22.179.215][57166] -> [...172.26.54.76][..514] [Syslog][Unknown][System][Acceptable] idle: [....12] [ip4][..udp] [.192.168.45.162][57166] -> [..10.208.120.95][..514] [Syslog][Unknown][System][Acceptable] - new: [....15] [ip4][..tcp] [.10.186.117.194][49948] -> [..169.46.82.162][52173] + new: [....15] [ip4][..tcp] [.10.186.117.194][49948] -> [..169.46.82.162][52173] update: [....14] [ip4][..udp] [.172.26.229.190][..514] -> [..172.23.80.196][..514] [Syslog][Unknown][System][Acceptable] detected: [....15] [ip4][..tcp] [.10.186.117.194][49948] -> [..169.46.82.162][52173] [Syslog][Unknown][System][Acceptable] RISK: Known Proto on Non Std Port idle: [....14] [ip4][..udp] [.172.26.229.190][..514] -> [..172.23.80.196][..514] [Syslog][Unknown][System][Acceptable] - new: [....16] [ip4][..udp] [192.168.254.157][49611] -> [.196.240.66.148][..514] + new: [....16] [ip4][..udp] [192.168.254.157][49611] -> [.196.240.66.148][..514] detected: [....16] [ip4][..udp] [192.168.254.157][49611] -> [.196.240.66.148][..514] [Syslog][Unknown][System][Acceptable] DAEMON-EVENT: [Processed: 81 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 16|skipped: 0|!detected: 2|guessed: 0|detection-updates: 0|updates: 10] - new: [....17] [ip4][..udp] [..10.11.105.154][20627] -> [.....10.6.15.11][..514] + new: [....17] [ip4][..udp] [..10.11.105.154][20627] -> [.....10.6.15.11][..514] detected: [....17] [ip4][..udp] [..10.11.105.154][20627] -> [.....10.6.15.11][..514] [Syslog][Unknown][System][Acceptable] idle: [....16] [ip4][..udp] [192.168.254.157][49611] -> [.196.240.66.148][..514] [Syslog][Unknown][System][Acceptable] end: [....15] [ip4][..tcp] [.10.186.117.194][49948] -> [..169.46.82.162][52173] [Syslog][Unknown][System][Acceptable] @@ -89,9 +89,9 @@ ERROR-EVENT: Unknown packet type [4/16] DAEMON-EVENT: [Processed: 82 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 17|skipped: 0|!detected: 2|guessed: 0|detection-updates: 0|updates: 10] - new: [....18] [ip4][..udp] [...10.94.232.21][57374] -> [...10.94.150.21][..514] + new: [....18] [ip4][..udp] [...10.94.232.21][57374] -> [...10.94.150.21][..514] detected: [....18] [ip4][..udp] [...10.94.232.21][57374] -> [...10.94.150.21][..514] [Syslog][Unknown][System][Acceptable] - new: [....19] [ip4][..udp] [....10.94.80.60][39438] -> [...10.94.150.22][..514] + new: [....19] [ip4][..udp] [....10.94.80.60][39438] -> [...10.94.150.22][..514] detected: [....19] [ip4][..udp] [....10.94.80.60][39438] -> [...10.94.150.22][..514] [Syslog][Unknown][System][Acceptable] idle: [....19] [ip4][..udp] [....10.94.80.60][39438] -> [...10.94.150.22][..514] [Syslog][Unknown][System][Acceptable] idle: [....17] [ip4][..udp] [..10.11.105.154][20627] -> [.....10.6.15.11][..514] [Syslog][Unknown][System][Acceptable] diff --git a/test/results/flow-info/default/tailscale.pcap.out b/test/results/flow-info/default/tailscale.pcap.out index 8f9c03c87..a225f0241 100644 --- a/test/results/flow-info/default/tailscale.pcap.out +++ b/test/results/flow-info/default/tailscale.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.88.3][41641] -> [..18.196.71.179][41641] + new: [.....1] [ip4][..udp] [...192.168.88.3][41641] -> [..18.196.71.179][41641] detected: [.....1] [ip4][..udp] [...192.168.88.3][41641] -> [..18.196.71.179][41641] [Tailscale][AmazonAWS][VPN][Acceptable] analyse: [.....1] [ip4][..udp] [...192.168.88.3][41641] -> [..18.196.71.179][41641] [Tailscale][AmazonAWS][VPN][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/targusdataspeed_false_positives.pcap.out b/test/results/flow-info/default/targusdataspeed_false_positives.pcap.out index fcce46984..012ecbc41 100644 --- a/test/results/flow-info/default/targusdataspeed_false_positives.pcap.out +++ b/test/results/flow-info/default/targusdataspeed_false_positives.pcap.out @@ -1,8 +1,8 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..udp] [......10.0.2.15][23994] -> [..79.164.55.123][.5001] + new: [.....1] [ip4][..udp] [......10.0.2.15][23994] -> [..79.164.55.123][.5001] detected: [.....1] [ip4][..udp] [......10.0.2.15][23994] -> [..79.164.55.123][.5001] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....2] [ip4][..udp] [......10.0.2.15][23994] -> [...89.64.45.227][.5201] + new: [.....2] [ip4][..udp] [......10.0.2.15][23994] -> [...89.64.45.227][.5201] detected: [.....2] [ip4][..udp] [......10.0.2.15][23994] -> [...89.64.45.227][.5201] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port idle: [.....2] [ip4][..udp] [......10.0.2.15][23994] -> [...89.64.45.227][.5201] [BitTorrent][Unknown][Download][Acceptable] diff --git a/test/results/flow-info/default/tcp_scan.pcapng.out b/test/results/flow-info/default/tcp_scan.pcapng.out index 9751e38c4..d80764238 100644 --- a/test/results/flow-info/default/tcp_scan.pcapng.out +++ b/test/results/flow-info/default/tcp_scan.pcapng.out @@ -1,32 +1,32 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][56272] -> [....192.168.1.2][...80] - new: [.....2] [ip4][..tcp] [..192.168.1.178][56273] -> [....192.168.1.2][..443] - new: [.....3] [ip4][..tcp] [..192.168.1.178][56274] -> [....192.168.1.2][..445] - new: [.....4] [ip4][..tcp] [..192.168.1.178][43067] -> [....192.168.1.2][.3389] - new: [.....5] [ip4][..tcp] [..192.168.1.178][62971] -> [....192.168.1.2][.3390] [MIDSTREAM] - new: [.....6] [ip4][..tcp] [..192.168.1.178][57916] -> [....192.168.1.2][.3391] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [..192.168.1.178][63243] -> [....192.168.1.2][.3392] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.178][56272] -> [....192.168.1.2][...80] + new: [.....2] [ip4][..tcp] [..192.168.1.178][56273] -> [....192.168.1.2][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.178][56274] -> [....192.168.1.2][..445] + new: [.....4] [ip4][..tcp] [..192.168.1.178][43067] -> [....192.168.1.2][.3389] + new: [.....5] [ip4][..tcp] [..192.168.1.178][62971] -> [....192.168.1.2][.3390] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.178][57916] -> [....192.168.1.2][.3391] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..192.168.1.178][63243] -> [....192.168.1.2][.3392] [MIDSTREAM] not-detected: [.....6] [ip4][..tcp] [..192.168.1.178][57916] -> [....192.168.1.2][.3391] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [.....6] [ip4][..tcp] [..192.168.1.178][57916] -> [....192.168.1.2][.3391] + end: [.....6] [ip4][..tcp] [..192.168.1.178][57916] -> [....192.168.1.2][.3391] not-detected: [.....5] [ip4][..tcp] [..192.168.1.178][62971] -> [....192.168.1.2][.3390] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [.....5] [ip4][..tcp] [..192.168.1.178][62971] -> [....192.168.1.2][.3390] + end: [.....5] [ip4][..tcp] [..192.168.1.178][62971] -> [....192.168.1.2][.3390] guessed: [.....1] [ip4][..tcp] [..192.168.1.178][56272] -> [....192.168.1.2][...80] [HTTP][Unknown][Web][Acceptable][] RISK: TCP Connection Issues - end: [.....1] [ip4][..tcp] [..192.168.1.178][56272] -> [....192.168.1.2][...80] + end: [.....1] [ip4][..tcp] [..192.168.1.178][56272] -> [....192.168.1.2][...80] not-detected: [.....7] [ip4][..tcp] [..192.168.1.178][63243] -> [....192.168.1.2][.3392] [Unknown][Unknown][Unrated] RISK: TCP Connection Issues - end: [.....7] [ip4][..tcp] [..192.168.1.178][63243] -> [....192.168.1.2][.3392] + end: [.....7] [ip4][..tcp] [..192.168.1.178][63243] -> [....192.168.1.2][.3392] guessed: [.....4] [ip4][..tcp] [..192.168.1.178][43067] -> [....192.168.1.2][.3389] [RDP][Unknown][RemoteAccess][Acceptable] RISK: Desktop/File Sharing, TCP Connection Issues - end: [.....4] [ip4][..tcp] [..192.168.1.178][43067] -> [....192.168.1.2][.3389] + end: [.....4] [ip4][..tcp] [..192.168.1.178][43067] -> [....192.168.1.2][.3389] guessed: [.....2] [ip4][..tcp] [..192.168.1.178][56273] -> [....192.168.1.2][..443] [TLS][Unknown][Web][Safe] RISK: TCP Connection Issues - end: [.....2] [ip4][..tcp] [..192.168.1.178][56273] -> [....192.168.1.2][..443] + end: [.....2] [ip4][..tcp] [..192.168.1.178][56273] -> [....192.168.1.2][..443] guessed: [.....3] [ip4][..tcp] [..192.168.1.178][56274] -> [....192.168.1.2][..445] [SMBv23][Unknown][System][Acceptable] RISK: TCP Connection Issues - end: [.....3] [ip4][..tcp] [..192.168.1.178][56274] -> [....192.168.1.2][..445] + end: [.....3] [ip4][..tcp] [..192.168.1.178][56274] -> [....192.168.1.2][..445] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/teams.pcap.out b/test/results/flow-info/default/teams.pcap.out index 407badd2d..5fbd73a71 100644 --- a/test/results/flow-info/default/teams.pcap.out +++ b/test/results/flow-info/default/teams.pcap.out @@ -1,20 +1,20 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] + new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] detected: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][tl-sg116e] ERROR-EVENT: Unknown packet type [1/16] - new: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [MIDSTREAM] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] ERROR-EVENT: Unknown packet type [4/16] ERROR-EVENT: Unknown packet type [5/16] ERROR-EVENT: Unknown packet type [6/16] - new: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] detection-update: [.....3] [ip4][..udp] [....192.168.1.6][60813] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] - new: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] - new: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] + new: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] + new: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] detected: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detection-update: [.....5] [ip4][..tcp] [....192.168.1.6][60533] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detected: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -33,7 +33,7 @@ detection-update: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [7/16] - new: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] + new: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] detected: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] detection-update: [.....6] [ip4][..tcp] [....192.168.1.6][60534] -> [.....40.126.9.5][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] analyse: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] @@ -48,10 +48,10 @@ [ENTROPIES...: 4.4,5.2,4.9,5.6,7.3,7.3,4.9,7.7,4.9,5.9,5.5,4.9,7.9,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.1,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.1,7.9,7.9,7.9] detection-update: [.....4] [ip4][..tcp] [....192.168.1.6][60532] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] + new: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] detected: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] + new: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] detected: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] detection-update: [.....8] [ip4][..tcp] [....192.168.1.6][60536] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] analyse: [.....7] [ip4][..tcp] [....192.168.1.6][60535] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] @@ -66,17 +66,17 @@ [ENTROPIES...: 4.3,5.2,5.0,6.0,7.3,7.7,5.1,7.3,5.0,6.0,5.7,5.1,7.8,7.9,7.9,5.2,7.9,7.9,7.9,7.9,5.2,7.9,7.9,5.2,7.9,7.8,5.1,5.2,5.2,7.5,5.0,5.3] ERROR-EVENT: Unknown packet type [8/16] ERROR-EVENT: Unknown packet type [9/16] - new: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] + new: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] detected: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....9] [ip4][..tcp] [....192.168.1.6][60537] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [10/16] - new: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] + new: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] detected: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] - new: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] + new: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] detected: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] + new: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] detected: [....12] [ip4][..udp] [....192.168.1.6][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] ERROR-EVENT: Unknown packet type [11/16] ERROR-EVENT: Unknown packet type [12/16] @@ -84,45 +84,45 @@ RISK: Unidirectional Traffic detection-update: [....10] [ip4][..udp] [....192.168.1.6][64046] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] RISK: Error Code - new: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....13] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][] - new: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [MIDSTREAM] + new: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [MIDSTREAM] detected: [....14] [ip4][..tcp] [..93.62.150.157][..443] -> [....192.168.1.6][60512] [TLS][Unknown][Web][Safe] ERROR-EVENT: Unknown packet type [13/16] - new: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] + new: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] detected: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com.edgekey.net] detection-update: [....15] [ip4][..udp] [....192.168.1.6][56634] -> [....192.168.1.1][...53] [DNS.Apple][Unknown][Network][Safe][captive.apple.com.edgekey.net] ERROR-EVENT: Unknown packet type [14/16] ERROR-EVENT: Unknown packet type [15/16] - new: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] + new: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] detected: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][eu-api.asm.skype.com] - new: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] + new: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] detected: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....17] [ip4][..udp] [....192.168.1.6][63106] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][eu-prod.asyncgw.teams.microsoft.com] - new: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] + new: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] detection-update: [....16] [ip4][..udp] [....192.168.1.6][51033] -> [....192.168.1.1][...53] [DNS.Skype_Teams][Unknown][Network][Acceptable][eu-api.asm.skype.com] - new: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] + new: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] detected: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detected: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] detection-update: [....18] [ip4][..tcp] [....192.168.1.6][60538] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....19] [ip4][..tcp] [....192.168.1.6][60539] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] - new: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] - new: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] + new: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] + new: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] detected: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detected: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] - new: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] + new: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] detected: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][config.teams.microsoft.com] detection-update: [....20] [ip4][..tcp] [....192.168.1.6][60540] -> [...52.114.75.70][..443] [TLS.Teams][Azure][Collaborative][Safe][eu-prod.asyncgw.teams.microsoft.com] detection-update: [....21] [ip4][..tcp] [....192.168.1.6][60541] -> [...52.114.75.69][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][eu-api.asm.skype.com] detection-update: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][config.teams.microsoft.com] - new: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] + new: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] detected: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] detection-update: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] - new: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] + new: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] detected: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][northeuropecns.trafficmanager.net] - new: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] + new: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] detection-update: [....24] [ip4][..udp] [....192.168.1.6][65387] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][northeuropecns.trafficmanager.net] - new: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] + new: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] detected: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....26] [ip4][..tcp] [....192.168.1.6][60544] -> [...52.114.76.48][..443] [TLS.Teams][Azure][Collaborative][Safe][northeurope.notifications.teams.microsoft.com] @@ -130,11 +130,11 @@ detection-update: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [16/16] - new: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] + new: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] detected: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][presence.services.sfb.trafficmanager.net] detection-update: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][presence.services.sfb.trafficmanager.net] - new: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] - new: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [MIDSTREAM] + new: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] + new: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [MIDSTREAM] detected: [....29] [ip4][..tcp] [.162.125.19.131][..443] -> [....192.168.1.6][60344] [TLS][Dropbox][Web][Safe] detected: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com] detection-update: [....28] [ip4][..tcp] [....192.168.1.6][60545] -> [...52.114.77.58][..443] [TLS.Teams][Azure][Collaborative][Safe][presence.teams.microsoft.com] @@ -150,7 +150,7 @@ [ENTROPIES...: 4.4,5.3,5.0,5.9,5.1,7.3,7.3,5.0,7.7,5.0,5.9,5.2,5.6,5.0,7.9,7.8,7.9,5.2,7.9,7.9,7.9,7.9,5.2,7.9,7.9,5.2,7.9,7.9,7.8,7.9,5.2,7.9] detection-update: [....25] [ip4][..tcp] [....192.168.1.6][60543] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] + new: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] detected: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port detection-update: [....30] [ip4][..tcp] [....192.168.1.6][60546] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] @@ -165,12 +165,12 @@ [IATS(ms)....: 45.7,45.8,0.2,47.9,0.0,47.7,0.0,0.1,0.2,0.1,0.2,9.9,9.9,3.5,10.4,0.4,51.4,37.1,0.2,0.2,0.2,7.1,7.0,1.3,1.2,79.2,201.4,0.0,0.0,167.5,0.2] [PKTLENS.....: 64,52,40,259,1492,1492,52,40,40,1492,1492,40,453,40,198,133,503,91,40,109,40,78,78,40,479,40,46,1480,150,206,46,82] [ENTROPIES...: 4.4,5.0,4.6,5.4,7.1,7.4,4.7,4.7,4.5,7.6,7.6,4.7,7.5,4.7,6.6,6.1,7.6,5.4,4.6,6.0,4.5,5.2,5.4,4.7,7.5,4.7,4.5,7.9,6.6,6.7,4.5,5.4] - new: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] + new: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] detected: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][chatsvcagg.svcs.teams.office.com] detection-update: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][chatsvcagg.svcs.teams.office.com] - new: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] + new: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] detected: [....32] [ip4][..tcp] [....192.168.1.6][60547] -> [...52.114.88.59][..443] [TLS.Teams][Azure][Collaborative][Safe][chatsvcagg.teams.microsoft.com] - new: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] + new: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] detected: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....33] [ip4][..tcp] [....192.168.1.6][60548] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -185,10 +185,10 @@ [IATS(ms)....: 34.2,34.3,0.3,36.9,0.0,36.6,0.0,0.2,0.2,0.1,0.0,0.1,1.0,12.0,0.3,36.0,22.7,0.2,0.2,0.1,10.4,10.3,0.6,0.6,77.1,91.7,0.0,49.1,80.4,115.1,0.2] [PKTLENS.....: 64,60,52,273,1492,1492,64,52,1492,52,1492,302,52,178,145,533,103,52,121,52,90,90,52,414,52,52,1480,247,52,227,52,1139] [ENTROPIES...: 4.3,5.1,4.7,5.5,7.4,7.3,4.8,4.8,7.5,4.7,7.6,7.4,4.8,6.3,6.2,7.5,5.6,4.9,6.0,4.9,5.4,5.5,4.8,7.4,4.9,5.1,7.8,7.0,5.0,6.8,4.7,7.8] - new: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] + new: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] detected: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][substrate.office.com] detection-update: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][substrate.office.com] - new: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] + new: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] detected: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] detection-update: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] analyse: [....23] [ip4][..tcp] [....192.168.1.6][60542] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe] @@ -213,29 +213,29 @@ [PKTLENS.....: 64,52,40,251,46,1492,1492,40,1492,80,40,198,133,578,172,46,366,109,40,40,78,46,78,40,46,689,40,359,40,1480,694,248] [ENTROPIES...: 4.4,4.9,4.5,5.4,4.5,6.7,7.5,4.6,7.6,5.7,4.7,6.5,6.2,7.6,6.5,4.5,7.2,5.8,4.6,4.6,5.3,4.5,5.4,4.6,4.5,7.7,4.7,7.3,4.7,7.8,7.7,7.0] detection-update: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable][substrate.office.com] - new: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] + new: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] detected: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][euaz.tr.teams.microsoft.com] - new: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] + new: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] detected: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] + new: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] detected: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] + new: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] detected: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][api.flightproxy.teams.microsoft.com] detection-update: [....37] [ip4][..udp] [....192.168.1.6][53678] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] detection-update: [....38] [ip4][..udp] [....192.168.1.6][65230] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][trouter2-asse-a.trouter.teams.microsoft.com] - new: [....40] [ip4][..tcp] [....192.168.1.6][60551] -> [...52.114.15.45][..443] + new: [....40] [ip4][..tcp] [....192.168.1.6][60551] -> [...52.114.15.45][..443] detection-update: [....39] [ip4][..udp] [....192.168.1.6][50653] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][api.flightproxy.teams.microsoft.com] detection-update: [....36] [ip4][..udp] [....192.168.1.6][61245] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][euaz.tr.teams.microsoft.com] RISK: Minor Issues - new: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] + new: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] detected: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][outlook.office.com] detection-update: [....41] [ip4][..udp] [....192.168.1.6][58457] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable][outlook.office.com] - new: [....42] [ip4][..tcp] [....192.168.1.6][60552] -> [...52.114.77.33][..443] - new: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] - new: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] + new: [....42] [ip4][..tcp] [....192.168.1.6][60552] -> [...52.114.77.33][..443] + new: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] + new: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] detected: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] - new: [....45] [ip4][..tcp] [....192.168.1.6][60555] -> [...52.114.77.33][..443] - new: [....46] [ip4][..tcp] [....192.168.1.6][60556] -> [.....40.126.9.7][..443] + new: [....45] [ip4][..tcp] [....192.168.1.6][60555] -> [...52.114.77.33][..443] + new: [....46] [ip4][..tcp] [....192.168.1.6][60556] -> [.....40.126.9.7][..443] detected: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][skypedataprdcolneu04.cloudapp.net] @@ -267,12 +267,12 @@ [ENTROPIES...: 4.4,4.9,4.5,5.5,4.4,7.3,7.5,4.6,7.5,4.5,7.7,6.7,4.6,6.5,4.5,5.7,4.5,5.6,4.6,7.8,4.6,7.9,7.9,4.6,7.9,4.6,7.9,7.9,4.6,4.5,7.9,7.9] detection-update: [....43] [ip4][..tcp] [....192.168.1.6][60554] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][config.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] + new: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] detected: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....47] [ip4][..tcp] [....192.168.1.6][60557] -> [.52.113.194.132][..443] [TLS.Teams][Skype_Teams][Collaborative][Safe][teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] + new: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] detected: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....48] [ip4][..tcp] [....192.168.1.6][60559] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] @@ -287,18 +287,18 @@ [IATS(ms)....: 48.6,48.7,0.3,51.0,0.1,50.7,0.0,0.3,0.3,1.7,49.8,48.1,1.4,0.0,0.0,50.5,49.1,0.0,0.0,0.0,37.2,37.2,0.0,11.5,11.5,1.0,36.0,16.0,53.0,0.7,0.1] [PKTLENS.....: 64,60,52,258,1492,1492,64,52,1375,52,145,103,52,1480,1480,1480,52,1480,1480,1480,1480,52,1480,1480,52,985,52,52,497,52,83,52] [ENTROPIES...: 4.4,5.3,4.9,6.0,7.3,7.3,5.1,4.9,7.6,5.0,5.9,5.7,5.0,7.9,7.9,7.9,5.1,7.9,7.9,7.9,7.9,5.2,7.8,7.9,5.1,7.8,5.1,5.2,7.6,5.1,5.3,5.0] - new: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] + new: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] detected: [....49] [ip4][..udp] [..192.168.1.112][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] + new: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] detected: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] detection-update: [....50] [ip4][..tcp] [....192.168.1.6][60560] -> [....40.126.9.67][..443] [TLS.Microsoft365][Azure][Collaborative][Acceptable][login.microsoftonline.com] - new: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] + new: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] detected: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] + new: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] detected: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][api.microsoftstream.com] detection-update: [....52] [ip4][..udp] [....192.168.1.6][54069] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][api.microsoftstream.com] - new: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] + new: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] detected: [....53] [ip4][..tcp] [....192.168.1.6][60562] -> [.104.40.187.151][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][api.microsoftstream.com] detection-update: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS @@ -312,10 +312,10 @@ [IATS(ms)....: 29.5,29.6,0.2,45.7,0.2,45.7,0.1,0.1,0.1,0.1,0.0,0.1,0.6,23.2,0.2,30.2,0.0,6.1,0.0,0.2,22.9,22.6,1.5,1.4,2.9,0.0,32.7,0.2,30.1,125.5,125.6] [PKTLENS.....: 64,60,52,266,1492,1492,64,1492,52,52,1492,281,52,145,145,424,103,121,52,52,90,90,52,548,52,1365,135,52,94,52,510,52] [ENTROPIES...: 4.4,5.2,4.9,5.6,7.4,7.5,4.9,7.4,4.9,4.8,7.6,7.1,5.0,5.9,6.3,7.4,5.6,6.1,4.9,4.9,5.4,5.6,4.9,7.5,5.0,7.9,6.1,5.1,5.7,5.0,7.5,4.9] - new: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] + new: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] detected: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][euno-1.api.microsoftstream.com] detection-update: [....54] [ip4][..udp] [....192.168.1.6][62735] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][euno-1.api.microsoftstream.com] - new: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] + new: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] analyse: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.162| 0.032| 0.044| 1964.919| 3.600] @@ -329,16 +329,16 @@ detection-update: [....51] [ip4][..tcp] [....192.168.1.6][60561] -> [...52.114.77.33][..443] [TLS.Microsoft][Azure][Cloud][Safe][mobile.pipe.aria.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detected: [....55] [ip4][..tcp] [....192.168.1.6][60563] -> [.52.169.186.119][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][euno-1.api.microsoftstream.com] - new: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] + new: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] detected: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][dc.applicationinsights.microsoft.com] detection-update: [....56] [ip4][..udp] [....192.168.1.6][63930] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][dc.applicationinsights.microsoft.com] - new: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] + new: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] detected: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] detection-update: [....57] [ip4][..tcp] [....192.168.1.6][60564] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] - new: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] + new: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] detected: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][emea.ng.msg.teams-msgapi.trafficmanager.net] detection-update: [....58] [ip4][..udp] [....192.168.1.6][62863] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][emea.ng.msg.teams-msgapi.trafficmanager.net] - new: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] + new: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] detected: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com] detection-update: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe][emea.ng.msg.teams.microsoft.com] analyse: [....59] [ip4][..tcp] [....192.168.1.6][60565] -> [...52.114.108.8][..443] [TLS.Teams][Azure][Collaborative][Safe] @@ -361,40 +361,40 @@ [IATS(ms)....: 47.1,47.2,0.5,44.4,0.0,43.9,0.0,0.0,0.2,0.1,0.0,0.2,0.0,4.4,9.7,0.3,46.5,32.1,0.5,0.4,0.1,18.9,1.4,20.2,62.9,403.2,425.0,8978.2,0.0,0.0,0.0] [PKTLENS.....: 64,52,40,276,1492,1492,52,40,40,1492,1492,309,40,40,198,133,568,91,40,109,40,78,46,409,40,46,1100,46,411,415,86,78] [ENTROPIES...: 4.3,4.9,4.6,5.6,7.4,7.3,4.7,4.6,4.6,7.5,7.6,7.1,4.7,4.6,6.5,6.1,7.6,5.4,4.6,5.9,4.6,5.2,4.5,7.4,4.7,4.5,7.8,4.6,7.4,7.5,5.6,5.5] - new: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [MIDSTREAM] - new: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] + new: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [MIDSTREAM] + new: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] detected: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port detection-update: [....61] [ip4][..tcp] [....192.168.1.6][60566] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port - new: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] - new: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] + new: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] + new: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] detected: [....63] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.123][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] - new: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] + new: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] + new: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] detected: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] [DNS.Azure][Unknown][Network][Acceptable][b-tr-teams-euno-05.northeurope.cloudapp.azure.com] detection-update: [....65] [ip4][..udp] [....192.168.1.6][55765] -> [....192.168.1.1][...53] [DNS.Azure][Unknown][Network][Acceptable][b-tr-teams-euno-05.northeurope.cloudapp.azure.com] detected: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] + new: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] detected: [....66] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.123][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] - new: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] + new: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] + new: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] detected: [....68] [ip4][..udp] [....192.168.1.6][50016] -> [.52.114.250.141][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detection-update: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] + new: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] detected: [....69] [ip4][..udp] [....192.168.1.6][50017] -> [.52.114.250.141][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detected: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] + new: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] detected: [....70] [ip4][..udp] [....192.168.1.6][50036] -> [.52.114.250.137][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] - new: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] + new: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] detected: [....71] [ip4][..udp] [....192.168.1.6][50037] -> [.52.114.250.137][.3478] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] detection-update: [....67] [ip4][..tcp] [....192.168.1.6][50021] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe][euaz.tr.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] - new: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] + new: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] + new: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] detected: [....72] [ip4][..tcp] [....192.168.1.6][50014] -> [.52.114.250.152][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][52.114.250.152] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detected: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][52.114.250.153] @@ -403,30 +403,30 @@ RISK: TLS Cert Mismatch, TLS (probably) Not Carrying HTTPS detection-update: [....73] [ip4][..tcp] [....192.168.1.6][50036] -> [.52.114.250.153][..443] [TLS.Teams][Azure][Collaborative][Safe][52.114.250.153] RISK: TLS Cert Mismatch, TLS (probably) Not Carrying HTTPS - new: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] - new: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] + new: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] + new: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] detected: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][c-flightproxy-euno-01-teams.cloudapp.net] detection-update: [....75] [ip4][..udp] [....192.168.1.6][60837] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe][c-flightproxy-euno-01-teams.cloudapp.net] detected: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] [TLS.Teams][Azure][Collaborative][Safe][api.flightproxy.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....74] [ip4][..tcp] [....192.168.1.6][60567] -> [..52.114.77.136][..443] [TLS.Teams][Azure][Collaborative][Safe][api.flightproxy.teams.microsoft.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] + new: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] detected: [....76] [ip4][..udp] [....192.168.1.6][50016] -> [....192.168.0.4][50005] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] + new: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] detected: [....77] [ip4][..udp] [....192.168.1.6][50036] -> [....192.168.0.4][50020] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] + new: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] detected: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] + new: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] detected: [....79] [ip4][..udp] [..93.71.110.205][16333] -> [....192.168.1.6][50036] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] + new: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] detected: [....80] [ip4][..udp] [..52.114.252.21][.3480] -> [....192.168.1.6][50036] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] + new: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] detected: [....81] [ip4][..udp] [...52.114.252.8][.3479] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Azure][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....64] [ip4][..tcp] [....192.168.1.6][50018] -> [.52.114.250.123][..443] [TLS.Teams][Azure][Collaborative][Safe] @@ -439,10 +439,10 @@ [IATS(ms)....: 45.0,45.1,0.2,47.4,47.2,0.2,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.1,0.0,0.0,8.0,0.0,0.0,52.4,1.2,45.6,48.6,92.2,43.7,69.1,0.3,113.5,1566.9] [PKTLENS.....: 64,52,40,227,1492,52,1492,588,52,52,1492,588,52,40,588,166,40,40,40,147,46,85,46,91,40,141,224,40,71,40,46,46] [ENTROPIES...: 4.4,4.9,4.5,5.4,7.5,4.6,7.4,6.2,4.7,4.7,7.7,7.0,4.7,4.5,7.6,6.6,4.4,4.5,4.5,6.4,4.5,5.8,4.6,5.4,4.6,6.4,6.9,4.5,5.4,4.4,4.6,4.6] - new: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] + new: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] detected: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] detection-update: [....82] [ip4][..tcp] [....192.168.1.6][60568] -> [...40.79.138.41][..443] [TLS.Skype_Teams][Azure][VoIP][Acceptable][gate.hockeyapp.net] - new: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] + new: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] detected: [....83] [ip4][.icmp] [..93.71.110.205] -> [....192.168.1.6] [ICMP][Unknown][Network][Acceptable] analyse: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -516,7 +516,7 @@ idle: [....11] [ip4][..udp] [....192.168.1.6][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] guessed: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] [TLS][Telegram][Web][Safe] RISK: Unidirectional Traffic - end: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] + end: [.....2] [ip4][..tcp] [....192.168.1.6][58533] -> [.149.154.167.91][..443] idle: [....34] [ip4][..udp] [....192.168.1.6][59403] -> [....192.168.1.1][...53] [DNS.Microsoft365][Unknown][Network][Acceptable] idle: [....35] [ip4][..tcp] [....192.168.1.6][60549] -> [...13.107.18.11][..443] [TLS.Microsoft365][Outlook][Collaborative][Acceptable] idle: [....44] [ip4][..udp] [....192.168.1.6][51309] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -527,10 +527,10 @@ RISK: Known Proto on Non Std Port idle: [....31] [ip4][..udp] [....192.168.1.6][57504] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe] guessed: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] [Skype_Teams][Azure][VoIP][Acceptable] - idle: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] + idle: [....62] [ip4][..udp] [....192.168.1.6][51681] -> [..52.114.77.136][.3478] idle: [....27] [ip4][..udp] [....192.168.1.6][57530] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe] not-detected: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] [Unknown][Unknown][Unrated] - idle: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] + idle: [....60] [ip4][..tcp] [..151.11.50.139][.2222] -> [....192.168.1.6][54750] idle: [....22] [ip4][..udp] [....192.168.1.6][49514] -> [....192.168.1.1][...53] [DNS.Teams][Unknown][Network][Safe] idle: [....78] [ip4][..udp] [..93.71.110.205][16332] -> [....192.168.1.6][50016] [STUN.Skype_TeamsCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port diff --git a/test/results/flow-info/default/teamspeak3.pcap.out b/test/results/flow-info/default/teamspeak3.pcap.out index 6da1f15c2..28a1451f3 100644 --- a/test/results/flow-info/default/teamspeak3.pcap.out +++ b/test/results/flow-info/default/teamspeak3.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.0.0.1][53187] -> [.......10.0.0.2][.9987] + new: [.....1] [ip4][..udp] [.......10.0.0.1][53187] -> [.......10.0.0.2][.9987] detected: [.....1] [ip4][..udp] [.......10.0.0.1][53187] -> [.......10.0.0.2][.9987] [TeamSpeak][Unknown][VoIP][Fun] DAEMON-EVENT: [Processed: 13 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [...193.31.25.70][.2011] -> [...51.68.181.92][.2010] + new: [.....2] [ip4][..udp] [...193.31.25.70][.2011] -> [...51.68.181.92][.2010] detected: [.....2] [ip4][..udp] [...193.31.25.70][.2011] -> [...51.68.181.92][.2010] [TeamSpeak][Unknown][VoIP][Fun] idle: [.....1] [ip4][..udp] [.......10.0.0.1][53187] -> [.......10.0.0.2][.9987] [TeamSpeak][Unknown][VoIP][Fun] update: [.....2] [ip4][..udp] [...193.31.25.70][.2011] -> [...51.68.181.92][.2010] [TeamSpeak][Unknown][VoIP][Fun] diff --git a/test/results/flow-info/default/teamviewer.pcap.out b/test/results/flow-info/default/teamviewer.pcap.out index 09930c1c7..641510f2b 100644 --- a/test/results/flow-info/default/teamviewer.pcap.out +++ b/test/results/flow-info/default/teamviewer.pcap.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [......10.0.2.15][35732] -> [..162.250.2.170][.5938] + new: [.....1] [ip4][..tcp] [......10.0.2.15][35732] -> [..162.250.2.170][.5938] detected: [.....1] [ip4][..tcp] [......10.0.2.15][35732] -> [..162.250.2.170][.5938] [TeamViewer][Unknown][RemoteAccess][Acceptable] analyse: [.....1] [ip4][..tcp] [......10.0.2.15][35732] -> [..162.250.2.170][.5938] [TeamViewer][Unknown][RemoteAccess][Acceptable] min| max| avg| stddev| variance| entropy @@ -11,7 +11,7 @@ [IATS(ms)....: 136.3,137.2,0.6,1.8,12.1,11.9,35.7,0.1,35.8,0.0,88.3,88.6,11.6,11.6,151.9,0.1,152.0,35.7,35.9,255.8,274.4,18.6,256.5,257.6,1.1,0.3,0.3,28.9,0.0,29.1,0.0] [PKTLENS.....: 60,44,46,77,40,106,40,1500,418,40,40,88,46,187,46,1500,1276,46,1118,40,1129,1141,40,480,96,40,88,40,1500,415,40,40] [ENTROPIES...: 4.6,4.7,4.3,4.6,4.6,4.0,4.6,7.6,7.3,4.5,4.5,4.9,4.3,3.9,4.4,7.7,7.8,4.4,7.7,4.7,7.5,7.7,4.7,6.5,4.6,4.7,3.8,4.6,7.6,7.4,4.7,4.7] - new: [.....2] [ip4][..udp] [......10.0.2.15][34417] -> [..93.47.224.241][36037] + new: [.....2] [ip4][..udp] [......10.0.2.15][34417] -> [..93.47.224.241][36037] detected: [.....2] [ip4][..udp] [......10.0.2.15][34417] -> [..93.47.224.241][36037] [TeamViewer][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port, Desktop/File Sharing analyse: [.....2] [ip4][..udp] [......10.0.2.15][34417] -> [..93.47.224.241][36037] [TeamViewer][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/telegram.pcap.out b/test/results/flow-info/default/telegram.pcap.out index 7686e1b7e..38bf42fce 100644 --- a/test/results/flow-info/default/telegram.pcap.out +++ b/test/results/flow-info/default/telegram.pcap.out @@ -1,31 +1,31 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] + new: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] detected: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][tl-sg116e] - new: [.....2] [ip4][..udp] [...192.168.1.53][54306] -> [239.255.255.250][.1900] + new: [.....2] [ip4][..udp] [...192.168.1.53][54306] -> [239.255.255.250][.1900] detected: [.....2] [ip4][..udp] [...192.168.1.53][54306] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] + new: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] detected: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_spotify-connect._tcp.local] - new: [.....4] [ip4][..udp] [...192.168.1.69][.5353] -> [....224.0.0.251][.5353] + new: [.....4] [ip4][..udp] [...192.168.1.69][.5353] -> [....224.0.0.251][.5353] detected: [.....4] [ip4][..udp] [...192.168.1.69][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_spotify-connect._tcp.local] - new: [.....5] [ip4][..udp] [...192.168.1.75][.5353] -> [....224.0.0.251][.5353] + new: [.....5] [ip4][..udp] [...192.168.1.75][.5353] -> [....224.0.0.251][.5353] detected: [.....5] [ip4][..udp] [...192.168.1.75][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_dacp._tcp.local] - new: [.....6] [ip6][..udp] [................fe80::4ba:91a:7817:e318][.5353] -> [...............................ff02::fb][.5353] + new: [.....6] [ip6][..udp] [................fe80::4ba:91a:7817:e318][.5353] -> [...............................ff02::fb][.5353] detected: [.....6] [ip6][..udp] [................fe80::4ba:91a:7817:e318][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_dacp._tcp.local] - new: [.....7] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.75][.5353] + new: [.....7] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.75][.5353] detected: [.....7] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.75][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [.....8] [ip4][..udp] [...192.168.1.77][61631] -> [....192.168.1.1][...53] + new: [.....8] [ip4][..udp] [...192.168.1.77][61631] -> [....192.168.1.1][...53] detected: [.....8] [ip4][..udp] [...192.168.1.77][61631] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e7047.e12.akamaiedge.net] detection-update: [.....8] [ip4][..udp] [...192.168.1.77][61631] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e7047.e12.akamaiedge.net] - new: [.....9] [ip4][..udp] [...192.168.1.77][17500] -> [255.255.255.255][17500] + new: [.....9] [ip4][..udp] [...192.168.1.77][17500] -> [255.255.255.255][17500] detected: [.....9] [ip4][..udp] [...192.168.1.77][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....10] [ip4][..udp] [...192.168.1.77][17500] -> [..192.168.1.255][17500] + new: [....10] [ip4][..udp] [...192.168.1.77][17500] -> [..192.168.1.255][17500] detected: [....10] [ip4][..udp] [...192.168.1.77][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] detection-update: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....11] [ip6][..udp] [..............fe80::18a0:a412:8935:c01b][.5353] -> [...............................ff02::fb][.5353] + new: [....11] [ip6][..udp] [..............fe80::18a0:a412:8935:c01b][.5353] -> [...............................ff02::fb][.5353] detected: [....11] [ip6][..udp] [..............fe80::18a0:a412:8935:c01b][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....12] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.53][.5353] + new: [....12] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.53][.5353] detected: [....12] [ip4][..udp] [...192.168.1.77][.5353] -> [...192.168.1.53][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] analyse: [.....5] [ip4][..udp] [...192.168.1.75][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy @@ -49,34 +49,34 @@ [ENTROPIES...: 4.9,5.3,5.1,5.1,4.5,5.1,4.5,5.1,5.0,5.1,4.5,4.5,5.0,4.9,5.3,5.1,5.1,4.5,5.1,4.5,5.0,5.0,5.1,4.5,4.5,5.0,4.5,4.9,5.3,5.1,5.1,4.5] detection-update: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_sleep-proxy._udp.local] detection-update: [....11] [ip6][..udp] [..............fe80::18a0:a412:8935:c01b][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_sleep-proxy._udp.local] - new: [....13] [ip4][..udp] [...192.168.1.77][52118] -> [....192.168.1.1][...53] + new: [....13] [ip4][..udp] [...192.168.1.77][52118] -> [....192.168.1.1][...53] detected: [....13] [ip4][..udp] [...192.168.1.77][52118] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][in.appcenter.ms] detection-update: [....13] [ip4][..udp] [...192.168.1.77][52118] -> [....192.168.1.1][...53] [DNS.Microsoft][Unknown][Network][Safe][in.appcenter.ms] - new: [....14] [ip4][..udp] [...192.168.1.53][57621] -> [..192.168.1.255][57621] + new: [....14] [ip4][..udp] [...192.168.1.53][57621] -> [..192.168.1.255][57621] detected: [....14] [ip4][..udp] [...192.168.1.53][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [....15] [ip4][..udp] [...192.168.1.75][57916] -> [239.255.255.250][.1900] + new: [....15] [ip4][..udp] [...192.168.1.75][57916] -> [239.255.255.250][.1900] detected: [....15] [ip4][..udp] [...192.168.1.75][57916] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....16] [ip4][..udp] [...192.168.1.77][61120] -> [....192.168.1.1][...53] + new: [....16] [ip4][..udp] [...192.168.1.77][61120] -> [....192.168.1.1][...53] detected: [....16] [ip4][..udp] [...192.168.1.77][61120] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e4518.dscx.akamaiedge.net] detection-update: [....16] [ip4][..udp] [...192.168.1.77][61120] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e4518.dscx.akamaiedge.net] - new: [....17] [ip4][..udp] [...192.168.1.52][.5353] -> [....224.0.0.251][.5353] + new: [....17] [ip4][..udp] [...192.168.1.52][.5353] -> [....224.0.0.251][.5353] detected: [....17] [ip4][..udp] [...192.168.1.52][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....18] [ip6][..udp] [...............fe80::4dc:edec:5b0c:a661][.5353] -> [...............................ff02::fb][.5353] + new: [....18] [ip6][..udp] [...............fe80::4dc:edec:5b0c:a661][.5353] -> [...............................ff02::fb][.5353] detected: [....18] [ip6][..udp] [...............fe80::4dc:edec:5b0c:a661][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....19] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.7][..521] + new: [....19] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.7][..521] detected: [....19] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.7][..521] [Telegram][Telegram][Chat][Acceptable] - new: [....20] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.5][..523] + new: [....20] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.5][..523] detected: [....20] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.5][..523] [Telegram][Telegram][Chat][Acceptable] - new: [....21] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.1][..527] + new: [....21] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.1][..527] detected: [....21] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.1][..527] [Telegram][Telegram][Chat][Acceptable] - new: [....22] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.1][..536] + new: [....22] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.1][..536] detected: [....22] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.12.1][..536] [Telegram][Telegram][Chat][Acceptable] - new: [....23] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.8][..538] + new: [....23] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.8][..538] detected: [....23] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.8][..538] [Telegram][Telegram][Chat][Acceptable] - new: [....24] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.4][..538] + new: [....24] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.4][..538] detected: [....24] [ip4][..udp] [...192.168.1.77][23174] -> [....91.108.16.4][..538] [Telegram][Telegram][Chat][Acceptable] - new: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] - new: [....26] [ip4][..udp] [...192.168.1.77][23174] -> [..87.11.205.195][60723] + new: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] + new: [....26] [ip4][..udp] [...192.168.1.77][23174] -> [..87.11.205.195][60723] detected: [....26] [ip4][..udp] [...192.168.1.77][23174] -> [..87.11.205.195][60723] [OpenVPN][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port analyse: [....19] [ip4][..udp] [...192.168.1.77][23174] -> [.....91.108.8.7][..521] [Telegram][Telegram][Chat][Acceptable] @@ -89,11 +89,11 @@ [IATS(ms)....: 33.7,303.8,500.9,195.8,135.7,308.4,212.1,0.7,38.9,154.1,154.5,74.5,133.7,63.7,29.9,38.6,63.9,177.4,37.8,26.0,43.6,64.2,189.8,58.8,4.5,63.5,64.5,43.0,64.5,315.9,64.4] [PKTLENS.....: 68,92,124,68,92,124,124,60,124,76,68,92,220,124,220,124,220,204,124,124,204,220,204,68,92,204,204,188,204,204,124,220] [ENTROPIES...: 4.9,5.1,6.5,4.9,5.1,6.6,6.5,4.6,6.6,5.1,4.9,5.1,7.1,6.4,7.0,6.5,7.0,7.0,6.5,6.4,7.0,7.1,7.0,4.9,5.1,6.9,6.8,6.9,7.0,7.0,6.4,7.0] - new: [....27] [ip4][..udp] [...192.168.1.77][47127] -> [....192.168.1.1][...53] + new: [....27] [ip4][..udp] [...192.168.1.77][47127] -> [....192.168.1.1][...53] detected: [....27] [ip4][..udp] [...192.168.1.77][47127] -> [....192.168.1.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][www.googletagservices.com] detection-update: [....27] [ip4][..udp] [...192.168.1.77][47127] -> [....192.168.1.1][...53] [DNS.GoogleServices][Unknown][Network][Acceptable][www.googletagservices.com] RISK: Minor Issues - analyse: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] + analyse: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] min| max| avg| stddev| variance| entropy [IAT.........: 0.042| 1.999| 0.261| 0.473| 223426.380| 3.600] [PKTLEN......: 76.000| 268.000| 191.500| 54.500| 2971.800| 4.900] @@ -103,46 +103,46 @@ [IATS(ms)....: 176.6,505.7,492.8,1175.3,327.6,331.9,1681.3,64.2,63.5,64.3,42.3,63.9,1998.8,63.8,58.3,64.1,69.6,64.4,57.8,43.1,58.1,62.2,58.1,63.8,58.2,64.2,58.2,62.0,69.6,66.6,57.7] [PKTLENS.....: 108,108,108,76,92,76,92,220,252,268,252,252,236,204,220,220,220,204,188,220,204,204,204,220,204,204,204,204,220,204,220,220] [ENTROPIES...: 6.4,6.1,6.3,5.8,6.0,5.8,6.0,6.9,7.1,7.2,7.1,7.1,7.1,7.0,7.0,7.1,7.0,6.9,6.8,7.0,7.0,7.0,6.9,6.9,6.9,6.9,6.9,6.9,7.0,6.9,7.0,7.1] - new: [....28] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....28] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....28] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][] - new: [....29] [ip4][..udp] [...192.168.1.43][..138] -> [..192.168.1.255][..138] + new: [....29] [ip4][..udp] [...192.168.1.43][..138] -> [..192.168.1.255][..138] detected: [....29] [ip4][..udp] [...192.168.1.43][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][desktop-rb5t12g] RISK: Unsafe Protocol - new: [....30] [ip4][..udp] [...192.168.1.77][..137] -> [..192.168.1.255][..137] + new: [....30] [ip4][..udp] [...192.168.1.77][..137] -> [..192.168.1.255][..137] detected: [....30] [ip4][..udp] [...192.168.1.77][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] - new: [....31] [ip4][..udp] [...192.168.1.77][49764] -> [....192.168.1.1][...53] + new: [....31] [ip4][..udp] [...192.168.1.77][49764] -> [....192.168.1.1][...53] detected: [....31] [ip4][..udp] [...192.168.1.77][49764] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][dati.ntop.org] detection-update: [....31] [ip4][..udp] [...192.168.1.77][49764] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][dati.ntop.org] - new: [....32] [ip4][..udp] [...192.168.1.77][.5812] -> [....192.168.1.1][...53] + new: [....32] [ip4][..udp] [...192.168.1.77][.5812] -> [....192.168.1.1][...53] detected: [....32] [ip4][..udp] [...192.168.1.77][.5812] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][pixel.wp.com] detection-update: [....32] [ip4][..udp] [...192.168.1.77][.5812] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][pixel.wp.com] RISK: Minor Issues - new: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] + new: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] detected: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] detection-update: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....34] [ip4][..udp] [...192.168.1.77][61974] -> [..216.58.205.68][..443] + new: [....34] [ip4][..udp] [...192.168.1.77][61974] -> [..216.58.205.68][..443] detected: [....34] [ip4][..udp] [...192.168.1.77][61974] -> [..216.58.205.68][..443] [QUIC.Google][Google][Web][Acceptable][www.google.com] - new: [....35] [ip4][..udp] [...192.168.1.77][50822] -> [..216.58.205.68][..443] + new: [....35] [ip4][..udp] [...192.168.1.77][50822] -> [..216.58.205.68][..443] detected: [....35] [ip4][..udp] [...192.168.1.77][50822] -> [..216.58.205.68][..443] [QUIC.Google][Google][Web][Acceptable][www.google.com] - new: [....36] [ip4][..udp] [...192.168.1.77][57621] -> [..192.168.1.255][57621] + new: [....36] [ip4][..udp] [...192.168.1.77][57621] -> [..192.168.1.255][57621] detected: [....36] [ip4][..udp] [...192.168.1.77][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [....37] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.8][..529] + new: [....37] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.8][..529] detected: [....37] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.8][..529] [Telegram][Telegram][Chat][Acceptable] - new: [....38] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.1][..529] + new: [....38] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.1][..529] detected: [....38] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.1][..529] [Telegram][Telegram][Chat][Acceptable] - new: [....39] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.3][..530] + new: [....39] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.3][..530] detected: [....39] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.3][..530] [Telegram][Telegram][Chat][Acceptable] - new: [....40] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.1][..533] + new: [....40] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.1][..533] detected: [....40] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.1][..533] [Telegram][Telegram][Chat][Acceptable] - new: [....41] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.5][..537] + new: [....41] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.5][..537] detected: [....41] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.12.5][..537] [Telegram][Telegram][Chat][Acceptable] - new: [....42] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.3][..537] + new: [....42] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.3][..537] detected: [....42] [ip4][..udp] [...192.168.1.77][28150] -> [....91.108.16.3][..537] [Telegram][Telegram][Chat][Acceptable] detection-update: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] RISK: Unidirectional Traffic detection-update: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe][b._dns-sd._udp.ntop.org] RISK: Error Code - new: [....43] [ip4][..udp] [...192.168.1.77][52127] -> [239.255.255.250][.1900] + new: [....43] [ip4][..udp] [...192.168.1.77][52127] -> [239.255.255.250][.1900] detected: [....43] [ip4][..udp] [...192.168.1.77][52127] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] analyse: [....37] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.8][..529] [Telegram][Telegram][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -154,7 +154,7 @@ [IATS(ms)....: 38.7,504.7,472.2,31.4,48.8,83.1,90.1,75.5,57.5,58.0,58.1,58.1,52.0,386.6,9.5,8.5,27.3,36.0,21.7,40.2,58.1,58.0,58.2,57.9,70.0,57.9,58.0,8.2,436.3,11.3,25.6] [PKTLENS.....: 68,92,68,124,92,124,124,60,204,204,204,220,204,68,124,124,204,92,124,204,76,204,204,188,204,188,204,204,68,124,124,92] [ENTROPIES...: 4.8,5.0,4.8,6.4,4.9,6.5,6.5,4.5,7.0,6.9,6.9,7.0,6.9,4.9,6.5,6.5,7.0,5.0,6.4,6.9,5.1,6.9,6.9,6.8,7.0,6.8,6.8,7.0,4.9,6.4,6.5,5.0] - new: [....44] [ip4][..udp] [...192.168.1.77][28150] -> [..87.11.205.195][59772] + new: [....44] [ip4][..udp] [...192.168.1.77][28150] -> [..87.11.205.195][59772] analyse: [....40] [ip4][..udp] [...192.168.1.77][28150] -> [.....91.108.8.1][..533] [Telegram][Telegram][Chat][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.007| 0.505| 0.113| 0.151| 22855.887| 4.100] @@ -165,7 +165,7 @@ [IATS(ms)....: 34.1,504.9,476.9,26.3,48.6,90.1,359.3,474.9,22.9,54.0,44.1,48.8,32.7,70.5,63.7,63.7,64.6,42.0,447.9,51.4,12.5,7.1,54.2,56.0,36.2,28.9,63.9,41.9,63.9,64.6,64.6] [PKTLENS.....: 68,92,68,124,92,124,60,68,124,92,124,76,124,204,204,188,204,204,204,68,124,204,92,124,204,124,204,204,188,204,188,204] [ENTROPIES...: 5.0,5.1,4.9,6.5,5.0,6.5,4.6,4.9,6.5,5.1,6.3,5.1,6.5,6.9,7.0,6.9,7.0,6.9,7.0,4.9,6.5,7.0,5.0,6.3,6.9,6.4,6.9,6.9,6.9,7.0,6.9,7.0] - new: [....45] [ip4][..udp] [...192.168.1.53][50698] -> [239.255.255.250][.1900] + new: [....45] [ip4][..udp] [...192.168.1.53][50698] -> [239.255.255.250][.1900] detected: [....45] [ip4][..udp] [...192.168.1.53][50698] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] update: [.....1] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [...192.168.1.77][17500] -> [255.255.255.255][17500] [Dropbox][Unknown][Cloud][Acceptable] @@ -177,11 +177,11 @@ update: [.....5] [ip4][..udp] [...192.168.1.75][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [...192.168.1.53][54306] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [.....6] [ip6][..udp] [................fe80::4ba:91a:7817:e318][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....46] [ip4][..udp] [...192.168.1.53][56384] -> [239.255.255.250][.1900] + new: [....46] [ip4][..udp] [...192.168.1.53][56384] -> [239.255.255.250][.1900] detected: [....46] [ip4][..udp] [...192.168.1.53][56384] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....47] [ip4][..udp] [...192.168.1.77][58615] -> [....192.168.1.1][...53] + new: [....47] [ip4][..udp] [...192.168.1.77][58615] -> [....192.168.1.1][...53] detected: [....47] [ip4][..udp] [...192.168.1.77][58615] -> [....192.168.1.1][...53] [DNS.Dropbox][Unknown][Network][Acceptable][telemetry.dropbox.com] - new: [....48] [ip4][..udp] [...192.168.1.77][49533] -> [....192.168.1.1][...53] + new: [....48] [ip4][..udp] [...192.168.1.77][49533] -> [....192.168.1.1][...53] detected: [....48] [ip4][..udp] [...192.168.1.77][49533] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e4518.dscx.akamaiedge.net] detection-update: [....48] [ip4][..udp] [...192.168.1.77][49533] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][e4518.dscx.akamaiedge.net] detection-update: [....47] [ip4][..udp] [...192.168.1.77][58615] -> [....192.168.1.1][...53] [DNS.Dropbox][Unknown][Network][Acceptable][telemetry.dropbox.com] @@ -215,7 +215,7 @@ idle: [.....3] [ip4][..udp] [...192.168.1.53][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] not-detected: [....44] [ip4][..udp] [...192.168.1.77][28150] -> [..87.11.205.195][59772] [Unknown][Unknown][Unrated] RISK: Unidirectional Traffic - idle: [....44] [ip4][..udp] [...192.168.1.77][28150] -> [..87.11.205.195][59772] + idle: [....44] [ip4][..udp] [...192.168.1.77][28150] -> [..87.11.205.195][59772] idle: [....36] [ip4][..udp] [...192.168.1.77][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] idle: [....14] [ip4][..udp] [...192.168.1.53][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] idle: [....43] [ip4][..udp] [...192.168.1.77][52127] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -238,7 +238,7 @@ idle: [....33] [ip4][..udp] [...192.168.1.77][54595] -> [....192.168.1.1][...53] [DNS.ntop][Unknown][Network][Safe] RISK: Error Code not-detected: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] [Unknown][Unknown][Unrated] - idle: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] + idle: [....25] [ip4][..udp] [...192.168.1.77][23174] -> [...192.168.1.52][31480] idle: [....34] [ip4][..udp] [...192.168.1.77][61974] -> [..216.58.205.68][..443] [QUIC.Google][Google][Web][Acceptable] idle: [.....6] [ip6][..udp] [................fe80::4ba:91a:7817:e318][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/telegram_videocall.pcapng.out b/test/results/flow-info/default/telegram_videocall.pcapng.out index 9ca37fc75..228fa0b49 100644 --- a/test/results/flow-info/default/telegram_videocall.pcapng.out +++ b/test/results/flow-info/default/telegram_videocall.pcapng.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][icmp6] [..............fe80::98df:58ff:fefa:ebdc] -> [................................ff02::2] + new: [.....1] [ip6][icmp6] [..............fe80::98df:58ff:fefa:ebdc] -> [................................ff02::2] detected: [.....1] [ip6][icmp6] [..............fe80::98df:58ff:fefa:ebdc] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] + new: [.....2] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] detected: [.....2] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....3] [ip4][..tcp] [.192.168.12.169][37948] -> [.149.154.167.91][..443] - new: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] - new: [.....5] [ip4][..tcp] [.192.168.12.169][46862] -> [.149.154.167.51][..443] - new: [.....6] [ip4][..tcp] [.192.168.12.169][46866] -> [.149.154.167.51][..443] - analyse: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] + new: [.....3] [ip4][..tcp] [.192.168.12.169][37948] -> [.149.154.167.91][..443] + new: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] + new: [.....5] [ip4][..tcp] [.192.168.12.169][46862] -> [.149.154.167.51][..443] + new: [.....6] [ip4][..tcp] [.192.168.12.169][46866] -> [.149.154.167.51][..443] + analyse: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.127| 0.025| 0.031| 963.939| 3.900] [PKTLEN......: 52.000| 1280.000| 541.900| 516.100| 266324.800| 4.300] @@ -19,10 +19,10 @@ [IATS(ms)....: 30.7,31.9,0.3,33.0,35.6,10.2,44.5,8.2,4.4,4.1,48.7,1.4,3.1,6.4,36.5,17.8,50.9,88.4,126.9,78.7,32.9,0.1,0.0,0.0,65.5,0.3,2.2,0.0,0.0,0.0,0.0] [PKTLENS.....: 60,60,52,333,157,52,936,825,672,141,141,52,767,189,301,52,349,317,52,157,52,1280,1280,1280,1280,52,52,1280,1280,1280,1280,1280] [ENTROPIES...: 4.8,5.2,5.2,7.3,6.7,5.1,7.8,7.7,7.7,6.6,6.6,5.1,7.7,6.9,7.2,5.2,7.4,7.3,5.3,6.7,5.3,7.9,7.8,7.9,7.8,5.2,5.2,7.8,7.8,7.9,7.9,7.8] - new: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] - new: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] - new: [.....9] [ip4][..tcp] [.192.168.12.169][40834] -> [149.154.167.222][..443] - analyse: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] + new: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] + new: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] + new: [.....9] [ip4][..tcp] [.192.168.12.169][40834] -> [149.154.167.222][..443] + analyse: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.047| 0.009| 0.015| 220.392| 3.200] [PKTLEN......: 52.000| 1280.000| 644.300| 571.900| 327061.800| 4.300] @@ -32,43 +32,43 @@ [IATS(ms)....: 30.1,31.4,0.3,0.6,31.5,0.0,0.0,35.0,0.2,6.9,41.7,13.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,46.8,0.1,0.0,0.1,0.9,6.5,31.9,0.0,0.0,0.0,0.0] [PKTLENS.....: 60,60,52,630,221,52,157,262,52,52,333,221,1280,1280,1280,1280,1280,1280,1280,1280,1280,52,52,52,52,52,285,1280,1280,1280,1280,1280] [ENTROPIES...: 4.8,5.2,5.2,7.7,7.0,5.2,6.8,7.1,5.2,5.2,7.4,7.1,7.9,7.9,7.8,7.9,7.8,7.8,7.8,7.8,7.8,5.1,5.2,5.1,5.1,5.2,7.1,7.9,7.8,7.9,7.8,7.8] - new: [....10] [ip4][..tcp] [.192.168.12.169][37966] -> [.149.154.167.91][..443] - new: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] + new: [....10] [ip4][..tcp] [.192.168.12.169][37966] -> [.149.154.167.91][..443] + new: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] detected: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_ipps._tcp.local] - new: [....12] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.9.35][.1400] + new: [....12] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.9.35][.1400] detected: [....12] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.9.35][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....13] [ip4][..udp] [.192.168.12.169][40906] -> [...91.108.13.23][.1400] + new: [....13] [ip4][..udp] [.192.168.12.169][40906] -> [...91.108.13.23][.1400] detected: [....13] [ip4][..udp] [.192.168.12.169][40906] -> [...91.108.13.23][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....14] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.17.2][.1400] + new: [....14] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.17.2][.1400] detected: [....14] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.17.2][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....15] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.9.35][.1400] + new: [....15] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.9.35][.1400] detected: [....15] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.9.35][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....16] [ip4][..udp] [.192.168.12.169][42197] -> [...91.108.13.23][.1400] + new: [....16] [ip4][..udp] [.192.168.12.169][42197] -> [...91.108.13.23][.1400] detected: [....16] [ip4][..udp] [.192.168.12.169][42197] -> [...91.108.13.23][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....17] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.17.2][.1400] + new: [....17] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.17.2][.1400] detected: [....17] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.17.2][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....18] [ip4][..udp] [.192.168.12.169][40643] -> [....91.108.9.35][.1400] + new: [....18] [ip4][..udp] [.192.168.12.169][40643] -> [....91.108.9.35][.1400] detected: [....18] [ip4][..udp] [.192.168.12.169][40643] -> [....91.108.9.35][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....19] [ip4][..udp] [.192.168.12.169][49667] -> [...91.108.13.23][.1400] + new: [....19] [ip4][..udp] [.192.168.12.169][49667] -> [...91.108.13.23][.1400] detected: [....19] [ip4][..udp] [.192.168.12.169][49667] -> [...91.108.13.23][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....20] [ip4][..udp] [.192.168.12.169][49780] -> [....91.108.17.2][.1400] + new: [....20] [ip4][..udp] [.192.168.12.169][49780] -> [....91.108.17.2][.1400] detected: [....20] [ip4][..udp] [.192.168.12.169][49780] -> [....91.108.17.2][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....21] [ip4][..udp] [.192.168.12.169][37849] -> [....91.108.9.35][.1400] + new: [....21] [ip4][..udp] [.192.168.12.169][37849] -> [....91.108.9.35][.1400] detected: [....21] [ip4][..udp] [.192.168.12.169][37849] -> [....91.108.9.35][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....22] [ip4][..udp] [.192.168.12.169][37530] -> [...91.108.13.23][.1400] + new: [....22] [ip4][..udp] [.192.168.12.169][37530] -> [...91.108.13.23][.1400] detected: [....22] [ip4][..udp] [.192.168.12.169][37530] -> [...91.108.13.23][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port - new: [....23] [ip4][..udp] [.192.168.12.169][37444] -> [....91.108.17.2][.1400] + new: [....23] [ip4][..udp] [.192.168.12.169][37444] -> [....91.108.17.2][.1400] detected: [....23] [ip4][..udp] [.192.168.12.169][37444] -> [....91.108.17.2][.1400] [STUN][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [....21] [ip4][..udp] [.192.168.12.169][37849] -> [....91.108.9.35][.1400] [STUN.TelegramVoip][Telegram][VoIP][Acceptable][telegram.org] @@ -83,19 +83,19 @@ RISK: Known Proto on Non Std Port detection-update: [....23] [ip4][..udp] [.192.168.12.169][37444] -> [....91.108.17.2][.1400] [STUN.TelegramVoip][Telegram][VoIP][Acceptable][telegram.org] RISK: Known Proto on Non Std Port - new: [....24] [ip4][..udp] [.192.168.12.169][42405] -> [..10.46.103.200][42554] + new: [....24] [ip4][..udp] [.192.168.12.169][42405] -> [..10.46.103.200][42554] detected: [....24] [ip4][..udp] [.192.168.12.169][42405] -> [..10.46.103.200][42554] [STUN.TelegramVoip][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....25] [ip4][..udp] [.192.168.12.169][40906] -> [..10.46.103.200][42554] + new: [....25] [ip4][..udp] [.192.168.12.169][40906] -> [..10.46.103.200][42554] detected: [....25] [ip4][..udp] [.192.168.12.169][40906] -> [..10.46.103.200][42554] [STUN.TelegramVoip][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....26] [ip4][..udp] [.192.168.12.169][42405] -> [...93.36.13.115][35393] + new: [....26] [ip4][..udp] [.192.168.12.169][42405] -> [...93.36.13.115][35393] detected: [....26] [ip4][..udp] [.192.168.12.169][42405] -> [...93.36.13.115][35393] [STUN.TelegramVoip][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....27] [ip4][..udp] [.192.168.12.169][40906] -> [...93.36.13.115][35393] + new: [....27] [ip4][..udp] [.192.168.12.169][40906] -> [...93.36.13.115][35393] detected: [....27] [ip4][..udp] [.192.168.12.169][40906] -> [...93.36.13.115][35393] [STUN.TelegramVoip][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....28] [ip6][icmp6] [...............fe80::abe:acff:fe0b:176e] -> [................................ff02::2] + new: [....28] [ip6][icmp6] [...............fe80::abe:acff:fe0b:176e] -> [................................ff02::2] detected: [....28] [ip6][icmp6] [...............fe80::abe:acff:fe0b:176e] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] analyse: [....26] [ip4][..udp] [.192.168.12.169][42405] -> [...93.36.13.115][35393] [STUN.TelegramVoip][Unknown][VoIP][Acceptable] min| max| avg| stddev| variance| entropy @@ -107,9 +107,9 @@ [IATS(ms)....: 75.7,88.0,12.8,2.3,9.0,48.9,21.7,0.2,117.5,0.1,18.9,57.5,0.3,20.7,0.0,35.1,54.6,306.4,41.6,24.8,9.9,17.7,18.1,17.4,474.7,0.1,42.1,15.5,14.1,40.1,18.5] [PKTLENS.....: 128,92,51,124,92,128,128,65,71,92,92,124,54,92,64,49,124,92,265,119,119,119,119,119,265,53,64,59,119,119,79,119] [ENTROPIES...: 5.4,5.7,5.3,5.6,5.6,5.5,5.4,5.7,5.8,5.8,5.7,5.6,5.5,5.8,5.7,5.3,5.6,5.8,7.1,6.5,6.4,6.4,6.5,6.4,7.2,5.5,5.7,5.6,6.3,6.4,5.9,6.5] - new: [....29] [ip6][..udp] [...............fe80::abe:acff:fe0b:176e][.5353] -> [...............................ff02::fb][.5353] + new: [....29] [ip6][..udp] [...............fe80::abe:acff:fe0b:176e][.5353] -> [...............................ff02::fb][.5353] detected: [....29] [ip6][..udp] [...............fe80::abe:acff:fe0b:176e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_ipps._tcp.local] - new: [....30] [ip4][..tcp] [.192.168.12.169][40710] -> [....52.58.18.25][.5222] [MIDSTREAM] + new: [....30] [ip4][..tcp] [.192.168.12.169][40710] -> [....52.58.18.25][.5222] [MIDSTREAM] detection-update: [....12] [ip4][..udp] [.192.168.12.169][40906] -> [....91.108.9.35][.1400] [STUN.TelegramVoip][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port detection-update: [....15] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.9.35][.1400] [STUN.TelegramVoip][Telegram][Network][Acceptable][] @@ -123,7 +123,7 @@ detection-update: [....17] [ip4][..udp] [.192.168.12.169][42197] -> [....91.108.17.2][.1400] [STUN.TelegramVoip][Telegram][Network][Acceptable][] RISK: Known Proto on Non Std Port update: [.....1] [ip6][icmp6] [..............fe80::98df:58ff:fefa:ebdc] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - analyse: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] + analyse: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 25.078| 1.818| 6.147| 37780767.900| 1.500] [PKTLEN......: 52.000| 1280.000| 482.700| 530.000| 280877.200| 4.100] @@ -133,23 +133,23 @@ [IATS(ms)....: 29.1,30.6,0.5,31.6,35.4,6.5,41.7,9.9,0.0,0.0,0.0,46.9,0.0,41.7,2909.6,2997.7,0.0,0.0,0.0,2.4,0.1,0.1,44.3,0.0,0.0,0.1,0.1,0.1,0.1,25044.9,25078.5] [PKTLENS.....: 60,60,52,630,262,52,205,221,1280,1280,1280,700,52,52,52,381,1280,1280,1280,1280,1280,1280,680,52,52,52,52,52,52,52,52,52] [ENTROPIES...: 4.9,5.3,5.2,7.6,7.1,5.1,6.9,7.0,7.8,7.8,7.8,7.7,5.2,5.1,5.1,7.5,7.8,7.9,7.8,7.9,7.8,7.8,7.7,5.2,5.0,5.1,5.1,5.2,5.2,5.1,5.1,5.2] - new: [....31] [ip4][.icmp] [.192.168.12.169] -> [....91.108.9.35] + new: [....31] [ip4][.icmp] [.192.168.12.169] -> [....91.108.9.35] detected: [....31] [ip4][.icmp] [.192.168.12.169] -> [....91.108.9.35] [ICMP][Telegram][Network][Acceptable] - new: [....32] [ip4][.icmp] [.192.168.12.169] -> [...91.108.13.23] + new: [....32] [ip4][.icmp] [.192.168.12.169] -> [...91.108.13.23] detected: [....32] [ip4][.icmp] [.192.168.12.169] -> [...91.108.13.23] [ICMP][Telegram][Network][Acceptable] - new: [....33] [ip4][.icmp] [.192.168.12.169] -> [....91.108.17.2] + new: [....33] [ip4][.icmp] [.192.168.12.169] -> [....91.108.17.2] detected: [....33] [ip4][.icmp] [.192.168.12.169] -> [....91.108.17.2] [ICMP][Telegram][Network][Acceptable] - new: [....34] [ip4][..tcp] [..18.195.162.93][..443] -> [.192.168.12.169][38956] [MIDSTREAM] + new: [....34] [ip4][..tcp] [..18.195.162.93][..443] -> [.192.168.12.169][38956] [MIDSTREAM] detected: [....34] [ip4][..tcp] [..18.195.162.93][..443] -> [.192.168.12.169][38956] [TLS][AmazonAWS][Web][Safe] guessed: [.....3] [ip4][..tcp] [.192.168.12.169][37948] -> [.149.154.167.91][..443] [TLS][Telegram][Web][Safe] RISK: TCP Connection Issues - end: [.....3] [ip4][..tcp] [.192.168.12.169][37948] -> [.149.154.167.91][..443] + end: [.....3] [ip4][..tcp] [.192.168.12.169][37948] -> [.149.154.167.91][..443] guessed: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - idle: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] + idle: [.....4] [ip4][..tcp] [.192.168.12.169][37950] -> [.149.154.167.91][..443] guessed: [....10] [ip4][..tcp] [.192.168.12.169][37966] -> [.149.154.167.91][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - idle: [....10] [ip4][..tcp] [.192.168.12.169][37966] -> [.149.154.167.91][..443] + idle: [....10] [ip4][..tcp] [.192.168.12.169][37966] -> [.149.154.167.91][..443] idle: [....18] [ip4][..udp] [.192.168.12.169][40643] -> [....91.108.9.35][.1400] [STUN.TelegramVoip][Telegram][VoIP][Acceptable] RISK: Known Proto on Non Std Port idle: [....28] [ip6][icmp6] [...............fe80::abe:acff:fe0b:176e] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] @@ -167,19 +167,19 @@ idle: [....29] [ip6][..udp] [...............fe80::abe:acff:fe0b:176e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] guessed: [.....5] [ip4][..tcp] [.192.168.12.169][46862] -> [.149.154.167.51][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - end: [.....5] [ip4][..tcp] [.192.168.12.169][46862] -> [.149.154.167.51][..443] + end: [.....5] [ip4][..tcp] [.192.168.12.169][46862] -> [.149.154.167.51][..443] guessed: [.....6] [ip4][..tcp] [.192.168.12.169][46866] -> [.149.154.167.51][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - end: [.....6] [ip4][..tcp] [.192.168.12.169][46866] -> [.149.154.167.51][..443] + end: [.....6] [ip4][..tcp] [.192.168.12.169][46866] -> [.149.154.167.51][..443] guessed: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - end: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] + end: [.....7] [ip4][..tcp] [.192.168.12.169][40830] -> [149.154.167.222][..443] guessed: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - end: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] + end: [.....8] [ip4][..tcp] [.192.168.12.169][40832] -> [149.154.167.222][..443] guessed: [.....9] [ip4][..tcp] [.192.168.12.169][40834] -> [149.154.167.222][..443] [TLS][Telegram][Web][Safe] RISK: Fully encrypted flow - idle: [.....9] [ip4][..tcp] [.192.168.12.169][40834] -> [149.154.167.222][..443] + idle: [.....9] [ip4][..tcp] [.192.168.12.169][40834] -> [149.154.167.222][..443] idle: [....19] [ip4][..udp] [.192.168.12.169][49667] -> [...91.108.13.23][.1400] [STUN.TelegramVoip][Telegram][VoIP][Acceptable] RISK: Known Proto on Non Std Port idle: [....25] [ip4][..udp] [.192.168.12.169][40906] -> [..10.46.103.200][42554] [STUN.TelegramVoip][Unknown][VoIP][Acceptable] @@ -197,7 +197,7 @@ RISK: Known Proto on Non Std Port end: [....34] [ip4][..tcp] [..18.195.162.93][..443] -> [.192.168.12.169][38956] [TLS][AmazonAWS][Web][Safe] guessed: [....30] [ip4][..tcp] [.192.168.12.169][40710] -> [....52.58.18.25][.5222] [AmazonAWS][AmazonAWS][Cloud][Acceptable] - idle: [....30] [ip4][..tcp] [.192.168.12.169][40710] -> [....52.58.18.25][.5222] + idle: [....30] [ip4][..tcp] [.192.168.12.169][40710] -> [....52.58.18.25][.5222] idle: [....21] [ip4][..udp] [.192.168.12.169][37849] -> [....91.108.9.35][.1400] [STUN.TelegramVoip][Telegram][VoIP][Acceptable] RISK: Known Proto on Non Std Port idle: [....27] [ip4][..udp] [.192.168.12.169][40906] -> [...93.36.13.115][35393] [STUN.TelegramVoip][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/telnet.pcap.out b/test/results/flow-info/default/telnet.pcap.out index aa842932b..2ec9af369 100644 --- a/test/results/flow-info/default/telnet.pcap.out +++ b/test/results/flow-info/default/telnet.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.0.2][.1550] -> [....192.168.0.1][...23] + new: [.....1] [ip4][..tcp] [....192.168.0.2][.1550] -> [....192.168.0.1][...23] detected: [.....1] [ip4][..tcp] [....192.168.0.2][.1550] -> [....192.168.0.1][...23] [Telnet][Unknown][RemoteAccess][Unsafe] RISK: Unsafe Protocol detection-update: [.....1] [ip4][..tcp] [....192.168.0.2][.1550] -> [....192.168.0.1][...23] [Telnet][Unknown][RemoteAccess][Unsafe] diff --git a/test/results/flow-info/default/teredo.pcap.out b/test/results/flow-info/default/teredo.pcap.out index 3c97b0156..0875c5c76 100644 --- a/test/results/flow-info/default/teredo.pcap.out +++ b/test/results/flow-info/default/teredo.pcap.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..10.112.16.106][52513] -> [..194.136.28.76][.3544] + new: [.....1] [ip4][..udp] [..10.112.16.106][52513] -> [..194.136.28.76][.3544] detected: [.....1] [ip4][..udp] [..10.112.16.106][52513] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...10.112.16.89][60381] -> [..194.136.28.76][.3544] + new: [.....2] [ip4][..udp] [...10.112.16.89][60381] -> [..194.136.28.76][.3544] detected: [.....2] [ip4][..udp] [...10.112.16.89][60381] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [...10.112.16.92][63448] -> [..194.136.28.76][.3544] + new: [.....3] [ip4][..udp] [...10.112.16.92][63448] -> [..194.136.28.76][.3544] detected: [.....3] [ip4][..udp] [...10.112.16.92][63448] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [...10.112.16.64][56154] -> [..194.136.28.76][.3544] + new: [.....4] [ip4][..udp] [...10.112.16.64][56154] -> [..194.136.28.76][.3544] detected: [.....4] [ip4][..udp] [...10.112.16.64][56154] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [...10.112.16.67][51812] -> [..194.136.28.76][.3544] + new: [.....5] [ip4][..udp] [...10.112.16.67][51812] -> [..194.136.28.76][.3544] detected: [.....5] [ip4][..udp] [...10.112.16.67][51812] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] idle: [.....5] [ip4][..udp] [...10.112.16.67][51812] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] idle: [.....4] [ip4][..udp] [...10.112.16.64][56154] -> [..194.136.28.76][.3544] [Teredo][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/tftp.pcap.out b/test/results/flow-info/default/tftp.pcap.out index c37eeabc8..b5587917a 100644 --- a/test/results/flow-info/default/tftp.pcap.out +++ b/test/results/flow-info/default/tftp.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....172.28.4.53][54626] -> [...172.16.5.170][...69] - new: [.....2] [ip4][..udp] [....172.28.4.53][54632] -> [...172.16.5.170][...69] - new: [.....3] [ip4][..udp] [..192.168.0.253][50618] -> [...192.168.0.10][...69] + new: [.....1] [ip4][..udp] [....172.28.4.53][54626] -> [...172.16.5.170][...69] + new: [.....2] [ip4][..udp] [....172.28.4.53][54632] -> [...172.16.5.170][...69] + new: [.....3] [ip4][..udp] [..192.168.0.253][50618] -> [...192.168.0.10][...69] detected: [.....3] [ip4][..udp] [..192.168.0.253][50618] -> [...192.168.0.10][...69] [TFTP][Unknown][DataTransfer][Acceptable] - new: [.....4] [ip4][..udp] [...192.168.0.10][.3445] -> [..192.168.0.253][50618] + new: [.....4] [ip4][..udp] [...192.168.0.10][.3445] -> [..192.168.0.253][50618] detected: [.....4] [ip4][..udp] [...192.168.0.10][.3445] -> [..192.168.0.253][50618] [TFTP][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....4] [ip4][..udp] [...192.168.0.10][.3445] -> [..192.168.0.253][50618] [TFTP][Unknown][DataTransfer][Acceptable] @@ -20,22 +20,22 @@ [ENTROPIES...: 4.3,3.0,4.6,3.0,4.9,3.0,4.9,2.9,4.4,3.0,4.6,3.0,4.6,3.0,4.6,3.0,4.5,3.0,4.4,2.9,4.4,3.0,4.5,2.9,4.7,2.9,4.6,3.0,4.5,3.0,4.3,3.0] DAEMON-EVENT: [Processed: 101 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [....172.28.4.53][54627] -> [...172.16.5.170][...69] + new: [.....5] [ip4][..udp] [....172.28.4.53][54627] -> [...172.16.5.170][...69] detected: [.....5] [ip4][..udp] [....172.28.4.53][54627] -> [...172.16.5.170][...69] [TFTP][Unknown][DataTransfer][Acceptable] guessed: [.....1] [ip4][..udp] [....172.28.4.53][54626] -> [...172.16.5.170][...69] [TFTP][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [.....1] [ip4][..udp] [....172.28.4.53][54626] -> [...172.16.5.170][...69] + idle: [.....1] [ip4][..udp] [....172.28.4.53][54626] -> [...172.16.5.170][...69] guessed: [.....2] [ip4][..udp] [....172.28.4.53][54632] -> [...172.16.5.170][...69] [TFTP][Unknown][DataTransfer][Acceptable] RISK: Unidirectional Traffic - idle: [.....2] [ip4][..udp] [....172.28.4.53][54632] -> [...172.16.5.170][...69] + idle: [.....2] [ip4][..udp] [....172.28.4.53][54632] -> [...172.16.5.170][...69] idle: [.....4] [ip4][..udp] [...192.168.0.10][.3445] -> [..192.168.0.253][50618] [TFTP][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port idle: [.....3] [ip4][..udp] [..192.168.0.253][50618] -> [...192.168.0.10][...69] [TFTP][Unknown][DataTransfer][Acceptable] DAEMON-EVENT: [Processed: 102 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 2|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..udp] [....172.28.5.91][44618] -> [...172.28.5.170][...69] + new: [.....6] [ip4][..udp] [....172.28.5.91][44618] -> [...172.28.5.170][...69] detected: [.....6] [ip4][..udp] [....172.28.5.91][44618] -> [...172.28.5.170][...69] [TFTP][Unknown][DataTransfer][Acceptable] - new: [.....7] [ip4][..udp] [...172.28.5.170][62058] -> [....172.28.5.91][44618] + new: [.....7] [ip4][..udp] [...172.28.5.170][62058] -> [....172.28.5.91][44618] detected: [.....7] [ip4][..udp] [...172.28.5.170][62058] -> [....172.28.5.91][44618] [TFTP][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port idle: [.....7] [ip4][..udp] [...172.28.5.170][62058] -> [....172.28.5.91][44618] [TFTP][Unknown][DataTransfer][Acceptable] diff --git a/test/results/flow-info/default/threema.pcap.out b/test/results/flow-info/default/threema.pcap.out index fafc62bb7..e36a4c89a 100644 --- a/test/results/flow-info/default/threema.pcap.out +++ b/test/results/flow-info/default/threema.pcap.out @@ -1,30 +1,30 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][50298] -> [.185.88.236.110][.5222] + new: [.....1] [ip4][..tcp] [..192.168.2.100][50298] -> [.185.88.236.110][.5222] detected: [.....1] [ip4][..tcp] [..192.168.2.100][50298] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] - new: [.....2] [ip4][..tcp] [..192.168.2.100][50484] -> [.185.88.236.110][.5222] + new: [.....2] [ip4][..tcp] [..192.168.2.100][50484] -> [.185.88.236.110][.5222] detected: [.....2] [ip4][..tcp] [..192.168.2.100][50484] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] - new: [.....3] [ip4][..tcp] [..192.168.2.100][50500] -> [.185.88.236.110][.5222] + new: [.....3] [ip4][..tcp] [..192.168.2.100][50500] -> [.185.88.236.110][.5222] detected: [.....3] [ip4][..tcp] [..192.168.2.100][50500] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] DAEMON-EVENT: [Processed: 42 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.2.100][50618] -> [.185.88.236.110][.5222] + new: [.....4] [ip4][..tcp] [..192.168.2.100][50618] -> [.185.88.236.110][.5222] detected: [.....4] [ip4][..tcp] [..192.168.2.100][50618] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] end: [.....3] [ip4][..tcp] [..192.168.2.100][50500] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] DAEMON-EVENT: [Processed: 57 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][50718] -> [.185.88.236.110][.5222] + new: [.....5] [ip4][..tcp] [..192.168.2.100][50718] -> [.185.88.236.110][.5222] end: [.....4] [ip4][..tcp] [..192.168.2.100][50618] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][50860] -> [.185.88.236.110][.5222] + new: [.....6] [ip4][..tcp] [..192.168.2.100][50860] -> [.185.88.236.110][.5222] guessed: [.....5] [ip4][..tcp] [..192.168.2.100][50718] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] RISK: Fully encrypted flow - end: [.....5] [ip4][..tcp] [..192.168.2.100][50718] -> [.185.88.236.110][.5222] + end: [.....5] [ip4][..tcp] [..192.168.2.100][50718] -> [.185.88.236.110][.5222] idle: [.....1] [ip4][..tcp] [..192.168.2.100][50298] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] idle: [.....2] [ip4][..tcp] [..192.168.2.100][50484] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] guessed: [.....6] [ip4][..tcp] [..192.168.2.100][50860] -> [.185.88.236.110][.5222] [Threema][Threema][Chat][Fun] RISK: Fully encrypted flow - end: [.....6] [ip4][..tcp] [..192.168.2.100][50860] -> [.185.88.236.110][.5222] + end: [.....6] [ip4][..tcp] [..192.168.2.100][50860] -> [.185.88.236.110][.5222] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/thrift.pcap.out b/test/results/flow-info/default/thrift.pcap.out index dabdb8499..3100c6c17 100644 --- a/test/results/flow-info/default/thrift.pcap.out +++ b/test/results/flow-info/default/thrift.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.169.254.59.247][53387] -> [...169.254.46.4][11010] + new: [.....1] [ip4][..tcp] [.169.254.59.247][53387] -> [...169.254.46.4][11010] detected: [.....1] [ip4][..tcp] [.169.254.59.247][53387] -> [...169.254.46.4][11010] [Thrift][Unknown][RPC][Acceptable] analyse: [.....1] [ip4][..tcp] [.169.254.59.247][53387] -> [...169.254.46.4][11010] [Thrift][Unknown][RPC][Acceptable] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [ENTROPIES...: 4.4,4.9,4.6,4.6,4.6,5.1,4.6,4.5,4.8,5.0,4.5,4.9,4.0,4.5,5.1,4.8,4.6,4.8,4.6,4.8,5.0,6.1,6.1,4.6,6.1,6.1,4.6,6.1,6.1,4.6,6.1,6.1] DAEMON-EVENT: [Processed: 170 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [......127.0.0.1][49164] -> [......127.0.0.1][.6831] + new: [.....2] [ip4][..udp] [......127.0.0.1][49164] -> [......127.0.0.1][.6831] detected: [.....2] [ip4][..udp] [......127.0.0.1][49164] -> [......127.0.0.1][.6831] [Thrift][Unknown][RPC][Acceptable] end: [.....1] [ip4][..tcp] [.169.254.59.247][53387] -> [...169.254.46.4][11010] [Thrift][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..udp] [......127.0.0.1][49164] -> [......127.0.0.1][.6831] [Thrift][Unknown][RPC][Acceptable] diff --git a/test/results/flow-info/default/tinc.pcap.out b/test/results/flow-info/default/tinc.pcap.out index 604cb1e8a..41189fd24 100644 --- a/test/results/flow-info/default/tinc.pcap.out +++ b/test/results/flow-info/default/tinc.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.131.114.168.27][59244] -> [.185.83.218.112][55655] - new: [.....2] [ip4][..tcp] [.131.114.168.27][49290] -> [.185.83.218.112][55656] + new: [.....1] [ip4][..tcp] [.131.114.168.27][59244] -> [.185.83.218.112][55655] + new: [.....2] [ip4][..tcp] [.131.114.168.27][49290] -> [.185.83.218.112][55656] detected: [.....1] [ip4][..tcp] [.131.114.168.27][59244] -> [.185.83.218.112][55655] [TINC][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port detected: [.....2] [ip4][..tcp] [.131.114.168.27][49290] -> [.185.83.218.112][55656] [TINC][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port - new: [.....3] [ip4][..udp] [.131.114.168.27][55655] -> [.185.83.218.112][55655] + new: [.....3] [ip4][..udp] [.131.114.168.27][55655] -> [.185.83.218.112][55655] detected: [.....3] [ip4][..udp] [.131.114.168.27][55655] -> [.185.83.218.112][55655] [TINC][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port - new: [.....4] [ip4][..udp] [.185.83.218.112][55656] -> [.131.114.168.27][55656] + new: [.....4] [ip4][..udp] [.185.83.218.112][55656] -> [.131.114.168.27][55656] detected: [.....4] [ip4][..udp] [.185.83.218.112][55656] -> [.131.114.168.27][55656] [TINC][Unknown][VPN][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....3] [ip4][..udp] [.131.114.168.27][55655] -> [.185.83.218.112][55655] [TINC][Unknown][VPN][Acceptable] diff --git a/test/results/flow-info/default/tk.pcap.out b/test/results/flow-info/default/tk.pcap.out index 93e5913f3..8fe325a76 100644 --- a/test/results/flow-info/default/tk.pcap.out +++ b/test/results/flow-info/default/tk.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.178][51954] -> [....192.168.1.1][...53] + new: [.....1] [ip4][..udp] [..192.168.1.178][51954] -> [....192.168.1.1][...53] detected: [.....1] [ip4][..udp] [..192.168.1.178][51954] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] detection-update: [.....1] [ip4][..udp] [..192.168.1.178][51954] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] - new: [.....2] [ip4][..udp] [..192.168.1.178][55591] -> [....192.168.1.1][...53] + new: [.....2] [ip4][..udp] [..192.168.1.178][55591] -> [....192.168.1.1][...53] detected: [.....2] [ip4][..udp] [..192.168.1.178][55591] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] detection-update: [.....2] [ip4][..udp] [..192.168.1.178][55591] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] - new: [.....3] [ip4][..udp] [..192.168.1.178][53820] -> [....192.168.1.1][...53] + new: [.....3] [ip4][..udp] [..192.168.1.178][53820] -> [....192.168.1.1][...53] detected: [.....3] [ip4][..udp] [..192.168.1.178][53820] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] detection-update: [.....3] [ip4][..udp] [..192.168.1.178][53820] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][whois.dot.tk] idle: [.....2] [ip4][..udp] [..192.168.1.178][55591] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/tls-appdata.pcap.out b/test/results/flow-info/default/tls-appdata.pcap.out index d9f3adef0..f20d780e0 100644 --- a/test/results/flow-info/default/tls-appdata.pcap.out +++ b/test/results/flow-info/default/tls-appdata.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.179.60.195.173][..443] -> [..192.168.2.100][60636] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.179.60.195.173][..443] -> [..192.168.2.100][60636] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.179.60.195.173][..443] -> [..192.168.2.100][60636] [TLS][Facebook][Web][Safe] detection-update: [.....1] [ip4][..tcp] [.179.60.195.173][..443] -> [..192.168.2.100][60636] [TLS][Facebook][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....1] [ip4][..tcp] [.179.60.195.173][..443] -> [..192.168.2.100][60636] [TLS][Facebook][Web][Safe] DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][58976] -> [...52.223.198.7][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.2.100][58976] -> [...52.223.198.7][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.2.100][58976] -> [...52.223.198.7][..443] [TLS][Twitch][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....2] [ip4][..tcp] [..192.168.2.100][58976] -> [...52.223.198.7][..443] [TLS][Twitch][Web][Safe] diff --git a/test/results/flow-info/default/tls-esni-fuzzed.pcap.out b/test/results/flow-info/default/tls-esni-fuzzed.pcap.out index 0915a53a1..00b935077 100644 --- a/test/results/flow-info/default/tls-esni-fuzzed.pcap.out +++ b/test/results/flow-info/default/tls-esni-fuzzed.pcap.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [TLS][Cloudflare][Web][Safe][] - new: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [...192.168.1.12][49887] -> [.104.16.125.175][..443] [TLS][Cloudflare][Web][Safe][] - new: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [...192.168.1.12][49897] -> [..104.22.71.197][..443] [TLS][Cloudflare][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch idle: [.....1] [ip4][..tcp] [...192.168.1.12][49886] -> [..104.27.129.77][..443] [TLS][Cloudflare][Web][Safe] diff --git a/test/results/flow-info/default/tls-rdn-extract.pcap.out b/test/results/flow-info/default/tls-rdn-extract.pcap.out index 949b0b7ac..cd1bf5758 100644 --- a/test/results/flow-info/default/tls-rdn-extract.pcap.out +++ b/test/results/flow-info/default/tls-rdn-extract.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.0.0.1][31337] -> [213.199.149.251][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.......10.0.0.1][31337] -> [213.199.149.251][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.......10.0.0.1][31337] -> [213.199.149.251][..443] [TLS][Unknown][Web][Safe][ads1.msads.net] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....1] [ip4][..tcp] [.......10.0.0.1][31337] -> [213.199.149.251][..443] [TLS][Unknown][Web][Safe][ads1.msads.net] diff --git a/test/results/flow-info/default/tls_2_reasms.pcapng.out b/test/results/flow-info/default/tls_2_reasms.pcapng.out index eac5b4730..e362321f2 100644 --- a/test/results/flow-info/default/tls_2_reasms.pcapng.out +++ b/test/results/flow-info/default/tls_2_reasms.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.91.186.174][..443] -> [...25.137.80.32][38134] + new: [.....1] [ip4][..tcp] [.192.91.186.174][..443] -> [...25.137.80.32][38134] detected: [.....1] [ip4][..tcp] [.192.91.186.174][..443] -> [...25.137.80.32][38134] [TLS.Instagram][Unknown][SocialNetwork][Fun][i.instagram.com] detection-update: [.....1] [ip4][..tcp] [.192.91.186.174][..443] -> [...25.137.80.32][38134] [TLS.Instagram][Unknown][SocialNetwork][Fun][i.instagram.com] idle: [.....1] [ip4][..tcp] [.192.91.186.174][..443] -> [...25.137.80.32][38134] [TLS.Instagram][Unknown][SocialNetwork][Fun] diff --git a/test/results/flow-info/default/tls_2_reasms_b.pcapng.out b/test/results/flow-info/default/tls_2_reasms_b.pcapng.out index 52ee4ed98..9971451b4 100644 --- a/test/results/flow-info/default/tls_2_reasms_b.pcapng.out +++ b/test/results/flow-info/default/tls_2_reasms_b.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..88.14.137.195][..443] -> [196.234.165.216][37658] + new: [.....1] [ip4][..tcp] [..88.14.137.195][..443] -> [196.234.165.216][37658] detected: [.....1] [ip4][..tcp] [..88.14.137.195][..443] -> [196.234.165.216][37658] [TLS.FbookReelStory][Unknown][SocialNetwork][Fun][video.fmct2-3.fna.fbcdn.net] detection-update: [.....1] [ip4][..tcp] [..88.14.137.195][..443] -> [196.234.165.216][37658] [TLS.FbookReelStory][Unknown][SocialNetwork][Fun][video.fmct2-3.fna.fbcdn.net] idle: [.....1] [ip4][..tcp] [..88.14.137.195][..443] -> [196.234.165.216][37658] [TLS.FbookReelStory][Unknown][SocialNetwork][Fun] diff --git a/test/results/flow-info/default/tls_alert.pcap.out b/test/results/flow-info/default/tls_alert.pcap.out index 8c064b265..b7f2221f6 100644 --- a/test/results/flow-info/default/tls_alert.pcap.out +++ b/test/results/flow-info/default/tls_alert.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.192][63158] -> [...192.168.1.20][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.192][63158] -> [...192.168.1.20][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.192][63158] -> [...192.168.1.20][..443] [TLS.Google][Unknown][Advertisement][Acceptable][www.google-analytics.com] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....1] [ip4][..tcp] [..192.168.1.192][63158] -> [...192.168.1.20][..443] [TLS.Google][Unknown][Advertisement][Acceptable][www.google-analytics.com] RISK: Obsolete TLS (v1.1 or older), TLS Fatal Alert DAEMON-EVENT: [Processed: 11 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][37780] -> [.160.44.202.202][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.2.100][37780] -> [.160.44.202.202][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.2.100][37780] -> [.160.44.202.202][..443] [TLS][Unknown][Web][Safe] end: [.....1] [ip4][..tcp] [..192.168.1.192][63158] -> [...192.168.1.20][..443] [TLS.Google][Unknown][Advertisement][Acceptable] RISK: Obsolete TLS (v1.1 or older), TLS Fatal Alert diff --git a/test/results/flow-info/default/tls_certificate_too_long.pcap.out b/test/results/flow-info/default/tls_certificate_too_long.pcap.out index 6579949a1..77867b5b2 100644 --- a/test/results/flow-info/default/tls_certificate_too_long.pcap.out +++ b/test/results/flow-info/default/tls_certificate_too_long.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.121][52746] -> [...52.149.21.60][..443] [MIDSTREAM] - new: [.....2] [ip4][..tcp] [..192.168.1.121][52721] -> [..192.168.1.139][55367] [MIDSTREAM] - new: [.....3] [ip4][..udp] [..192.168.1.121][52251] -> [........8.8.8.8][...53] + new: [.....1] [ip4][..tcp] [..192.168.1.121][52746] -> [...52.149.21.60][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.1.121][52721] -> [..192.168.1.139][55367] [MIDSTREAM] + new: [.....3] [ip4][..udp] [..192.168.1.121][52251] -> [........8.8.8.8][...53] detected: [.....3] [ip4][..udp] [..192.168.1.121][52251] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][121.1.168.192.in-addr.arpa] detection-update: [.....3] [ip4][..udp] [..192.168.1.121][52251] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][60.21.149.52.in-addr.arpa] RISK: Unidirectional Traffic @@ -13,68 +13,68 @@ RISK: Error Code detection-update: [.....3] [ip4][..udp] [..192.168.1.121][52251] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][60.21.149.52.in-addr.arpa] RISK: Error Code - new: [.....4] [ip4][..udp] [..192.168.1.139][.5353] -> [....224.0.0.251][.5353] + new: [.....4] [ip4][..udp] [..192.168.1.139][.5353] -> [....224.0.0.251][.5353] detected: [.....4] [ip4][..udp] [..192.168.1.139][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [.....5] [ip6][..udp] [..............fe80::1059:a858:f9e7:cf94][.5353] -> [...............................ff02::fb][.5353] + new: [.....5] [ip6][..udp] [..............fe80::1059:a858:f9e7:cf94][.5353] -> [...............................ff02::fb][.5353] detected: [.....5] [ip6][..udp] [..............fe80::1059:a858:f9e7:cf94][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [.....6] [ip4][..udp] [..192.168.1.121][.5353] -> [..192.168.1.139][.5353] + new: [.....6] [ip4][..udp] [..192.168.1.121][.5353] -> [..192.168.1.139][.5353] detected: [.....6] [ip4][..udp] [..192.168.1.121][.5353] -> [..192.168.1.139][.5353] [MDNS][Unknown][Network][Acceptable][_companion-link._tcp.local] - new: [.....7] [ip4][....2] [..192.168.1.139] -> [......224.0.0.2] + new: [.....7] [ip4][....2] [..192.168.1.139] -> [......224.0.0.2] detected: [.....7] [ip4][....2] [..192.168.1.139] -> [......224.0.0.2] [IGMP][Unknown][Network][Acceptable] - new: [.....8] [ip4][....2] [..192.168.1.139] -> [....224.0.0.251] + new: [.....8] [ip4][....2] [..192.168.1.139] -> [....224.0.0.251] detected: [.....8] [ip4][....2] [..192.168.1.139] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [..192.168.1.121][55567] -> [........8.8.8.8][...53] + new: [.....9] [ip4][..udp] [..192.168.1.121][55567] -> [........8.8.8.8][...53] detected: [.....9] [ip4][..udp] [..192.168.1.121][55567] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][wdcp.microsoft.com] - new: [....10] [ip4][..udp] [..192.168.1.121][53884] -> [........8.8.8.8][...53] + new: [....10] [ip4][..udp] [..192.168.1.121][53884] -> [........8.8.8.8][...53] detected: [....10] [ip4][..udp] [..192.168.1.121][53884] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][wdcp.microsoft.com] detection-update: [....10] [ip4][..udp] [..192.168.1.121][53884] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][wdcp.microsoft.com] - new: [....11] [ip4][..udp] [..192.168.1.121][65492] -> [........8.8.8.8][...53] + new: [....11] [ip4][..udp] [..192.168.1.121][65492] -> [........8.8.8.8][...53] detected: [....11] [ip4][..udp] [..192.168.1.121][65492] -> [........8.8.8.8][...53] [DNS.Azure][Google][Network][Acceptable][wd-prod-cp-eu-north-2-fe.northeurope.cloudapp.azure.com] - new: [....12] [ip4][..tcp] [..192.168.1.121][53910] -> [...40.113.10.47][..443] + new: [....12] [ip4][..tcp] [..192.168.1.121][53910] -> [...40.113.10.47][..443] detection-update: [.....9] [ip4][..udp] [..192.168.1.121][55567] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][wdcp.microsoft.com] - new: [....13] [ip4][..tcp] [..192.168.1.121][53911] -> [...40.113.10.47][..443] + new: [....13] [ip4][..tcp] [..192.168.1.121][53911] -> [...40.113.10.47][..443] detection-update: [....11] [ip4][..udp] [..192.168.1.121][65492] -> [........8.8.8.8][...53] [DNS.Azure][Google][Network][Acceptable][wd-prod-cp-eu-north-2-fe.northeurope.cloudapp.azure.com] detected: [....12] [ip4][..tcp] [..192.168.1.121][53910] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detected: [....13] [ip4][..tcp] [..192.168.1.121][53911] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detection-update: [....12] [ip4][..tcp] [..192.168.1.121][53910] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long - new: [....14] [ip4][..udp] [..192.168.1.121][51364] -> [........8.8.8.8][...53] + new: [....14] [ip4][..udp] [..192.168.1.121][51364] -> [........8.8.8.8][...53] detected: [....14] [ip4][..udp] [..192.168.1.121][51364] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][www.microsoft.com] - new: [....15] [ip4][..udp] [..192.168.1.121][58161] -> [........8.8.8.8][...53] + new: [....15] [ip4][..udp] [..192.168.1.121][58161] -> [........8.8.8.8][...53] detected: [....15] [ip4][..udp] [..192.168.1.121][58161] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][www.microsoft.com] detection-update: [....14] [ip4][..udp] [..192.168.1.121][51364] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][www.microsoft.com] - new: [....16] [ip4][..udp] [..192.168.1.121][55578] -> [........8.8.8.8][...53] + new: [....16] [ip4][..udp] [..192.168.1.121][55578] -> [........8.8.8.8][...53] detected: [....16] [ip4][..udp] [..192.168.1.121][55578] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][e13678.dscb.akamaiedge.net] - new: [....17] [ip4][..udp] [..192.168.1.121][54561] -> [........8.8.8.8][...53] + new: [....17] [ip4][..udp] [..192.168.1.121][54561] -> [........8.8.8.8][...53] detected: [....17] [ip4][..udp] [..192.168.1.121][54561] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][e13678.dscb.akamaiedge.net] detection-update: [....13] [ip4][..tcp] [..192.168.1.121][53911] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long detection-update: [....16] [ip4][..udp] [..192.168.1.121][55578] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][e13678.dscb.akamaiedge.net] - new: [....18] [ip4][..tcp] [..192.168.1.121][53912] -> [....2.22.33.235][...80] + new: [....18] [ip4][..tcp] [..192.168.1.121][53912] -> [....2.22.33.235][...80] detection-update: [....15] [ip4][..udp] [..192.168.1.121][58161] -> [........8.8.8.8][...53] [DNS.Microsoft][Google][Network][Safe][www.microsoft.com] detected: [....18] [ip4][..tcp] [..192.168.1.121][53912] -> [....2.22.33.235][...80] [HTTP.Microsoft][Unknown][Cloud][Safe][www.microsoft.com] detection-update: [....17] [ip4][..udp] [..192.168.1.121][54561] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][e13678.dscb.akamaiedge.net] detection-update: [....18] [ip4][..tcp] [..192.168.1.121][53912] -> [....2.22.33.235][...80] [HTTP.Microsoft][Unknown][Download][Safe][www.microsoft.com] RISK: Binary App Transfer, HTTP Susp Header - new: [....19] [ip4][..tcp] [..192.168.1.121][53913] -> [....2.22.33.235][...80] + new: [....19] [ip4][..tcp] [..192.168.1.121][53913] -> [....2.22.33.235][...80] detected: [....19] [ip4][..tcp] [..192.168.1.121][53913] -> [....2.22.33.235][...80] [HTTP.Microsoft][Unknown][Cloud][Safe][www.microsoft.com] detection-update: [....19] [ip4][..tcp] [..192.168.1.121][53913] -> [....2.22.33.235][...80] [HTTP.Microsoft][Unknown][Download][Safe][www.microsoft.com] RISK: Binary App Transfer, HTTP Susp Header - new: [....20] [ip4][..tcp] [..192.168.1.121][53905] -> [..140.82.113.26][..443] [MIDSTREAM] - new: [....21] [ip4][..udp] [..192.168.1.121][65213] -> [........8.8.8.8][...53] + new: [....20] [ip4][..tcp] [..192.168.1.121][53905] -> [..140.82.113.26][..443] [MIDSTREAM] + new: [....21] [ip4][..udp] [..192.168.1.121][65213] -> [........8.8.8.8][...53] detected: [....21] [ip4][..udp] [..192.168.1.121][65213] -> [........8.8.8.8][...53] [DNS.Apple][Google][Network][Safe][time-macos.apple.com] detection-update: [....21] [ip4][..udp] [..192.168.1.121][65213] -> [........8.8.8.8][...53] [DNS.Apple][Google][Network][Safe][time-macos.apple.com] - new: [....22] [ip4][..udp] [..192.168.1.121][49216] -> [..17.253.54.251][..123] + new: [....22] [ip4][..udp] [..192.168.1.121][49216] -> [..17.253.54.251][..123] detected: [....22] [ip4][..udp] [..192.168.1.121][49216] -> [..17.253.54.251][..123] [NTP][Apple][System][Acceptable] detected: [....20] [ip4][..tcp] [..192.168.1.121][53905] -> [..140.82.113.26][..443] [TLS][Github][Web][Safe] - new: [....23] [ip4][..udp] [..192.168.1.121][51998] -> [........8.8.8.8][...53] + new: [....23] [ip4][..udp] [..192.168.1.121][51998] -> [........8.8.8.8][...53] detected: [....23] [ip4][..udp] [..192.168.1.121][51998] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][235.33.22.2.in-addr.arpa] detection-update: [....23] [ip4][..udp] [..192.168.1.121][51998] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][26.113.82.140.in-addr.arpa] RISK: Unidirectional Traffic - new: [....24] [ip4][..tcp] [..192.168.1.121][53429] -> [...52.98.163.18][..443] [MIDSTREAM] + new: [....24] [ip4][..tcp] [..192.168.1.121][53429] -> [...52.98.163.18][..443] [MIDSTREAM] detected: [....24] [ip4][..tcp] [..192.168.1.121][53429] -> [...52.98.163.18][..443] [TLS][Outlook][Web][Safe] RISK: Unidirectional Traffic - new: [....25] [ip4][..tcp] [..192.168.1.121][53428] -> [...52.98.163.18][..443] [MIDSTREAM] + new: [....25] [ip4][..tcp] [..192.168.1.121][53428] -> [...52.98.163.18][..443] [MIDSTREAM] detected: [....25] [ip4][..tcp] [..192.168.1.121][53428] -> [...52.98.163.18][..443] [TLS][Outlook][Web][Safe] RISK: Unidirectional Traffic detection-update: [....23] [ip4][..udp] [..192.168.1.121][51998] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][235.33.22.2.in-addr.arpa] @@ -100,37 +100,37 @@ [IATS(ms)....: 0.0,1.1,23.2,47.6,37.0,0.0,0.0,0.0,0.0,0.0,11.7,0.4,0.5,9.9,10.2,0.0,0.6,25.3,48.0,32.2,0.0,8.7,0.4,0.0,0.0,0.0,0.0,0.0,0.0,0.5,13.0] [PKTLENS.....: 1488,922,1278,40,1278,1352,175,259,438,82,85,40,74,40,52,1488,921,694,40,694,989,431,40,179,239,281,123,82,85,74,40,52] [ENTROPIES...: 7.9,7.8,7.9,4.9,7.9,7.8,6.6,7.1,7.5,5.7,5.6,4.7,5.4,4.7,4.9,7.9,7.8,7.6,4.9,7.6,7.8,7.5,4.6,6.6,7.0,7.2,6.2,5.6,5.8,5.5,4.7,5.0] - new: [....26] [ip4][..tcp] [..192.168.1.121][53914] -> [...40.113.10.47][..443] - new: [....27] [ip4][..tcp] [..192.168.1.121][53915] -> [...40.113.10.47][..443] + new: [....26] [ip4][..tcp] [..192.168.1.121][53914] -> [...40.113.10.47][..443] + new: [....27] [ip4][..tcp] [..192.168.1.121][53915] -> [...40.113.10.47][..443] detected: [....26] [ip4][..tcp] [..192.168.1.121][53914] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detected: [....27] [ip4][..tcp] [..192.168.1.121][53915] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detection-update: [....26] [ip4][..tcp] [..192.168.1.121][53914] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long detection-update: [....27] [ip4][..tcp] [..192.168.1.121][53915] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long - new: [....28] [ip4][..udp] [..192.168.1.121][50288] -> [..17.253.54.251][..123] + new: [....28] [ip4][..udp] [..192.168.1.121][50288] -> [..17.253.54.251][..123] detected: [....28] [ip4][..udp] [..192.168.1.121][50288] -> [..17.253.54.251][..123] [NTP][Apple][System][Acceptable] - new: [....29] [ip4][..tcp] [..192.168.1.121][53916] -> [...40.113.10.47][..443] - new: [....30] [ip4][..tcp] [..192.168.1.121][53917] -> [...40.113.10.47][..443] + new: [....29] [ip4][..tcp] [..192.168.1.121][53916] -> [...40.113.10.47][..443] + new: [....30] [ip4][..tcp] [..192.168.1.121][53917] -> [...40.113.10.47][..443] detected: [....29] [ip4][..tcp] [..192.168.1.121][53916] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detected: [....30] [ip4][..tcp] [..192.168.1.121][53917] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detection-update: [....29] [ip4][..tcp] [..192.168.1.121][53916] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long detection-update: [....30] [ip4][..tcp] [..192.168.1.121][53917] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long - new: [....31] [ip4][..udp] [..192.168.1.121][65099] -> [..17.253.54.251][..123] + new: [....31] [ip4][..udp] [..192.168.1.121][65099] -> [..17.253.54.251][..123] detected: [....31] [ip4][..udp] [..192.168.1.121][65099] -> [..17.253.54.251][..123] [NTP][Apple][System][Acceptable] - new: [....32] [ip4][..tcp] [..192.168.1.121][53918] -> [...40.113.10.47][..443] - new: [....33] [ip4][..tcp] [..192.168.1.121][53919] -> [...40.113.10.47][..443] + new: [....32] [ip4][..tcp] [..192.168.1.121][53918] -> [...40.113.10.47][..443] + new: [....33] [ip4][..tcp] [..192.168.1.121][53919] -> [...40.113.10.47][..443] detected: [....32] [ip4][..tcp] [..192.168.1.121][53918] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detected: [....33] [ip4][..tcp] [..192.168.1.121][53919] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] detection-update: [....32] [ip4][..tcp] [..192.168.1.121][53918] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long detection-update: [....33] [ip4][..tcp] [..192.168.1.121][53919] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe][wdcp.microsoft.com] RISK: TLS Cert Validity Too Long - new: [....34] [ip4][..udp] [..192.168.1.121][56865] -> [..17.253.54.251][..123] + new: [....34] [ip4][..udp] [..192.168.1.121][56865] -> [..17.253.54.251][..123] detected: [....34] [ip4][..udp] [..192.168.1.121][56865] -> [..17.253.54.251][..123] [NTP][Apple][System][Acceptable] - new: [....35] [ip4][..tcp] [.130.211.33.145][..443] -> [..192.168.1.121][53432] [MIDSTREAM] + new: [....35] [ip4][..tcp] [.130.211.33.145][..443] -> [..192.168.1.121][53432] [MIDSTREAM] detected: [....35] [ip4][..tcp] [.130.211.33.145][..443] -> [..192.168.1.121][53432] [TLS][GoogleCloud][Web][Safe] idle: [....11] [ip4][..udp] [..192.168.1.121][65492] -> [........8.8.8.8][...53] [DNS.Azure][Google][Network][Acceptable] idle: [.....8] [ip4][....2] [..192.168.1.139] -> [....224.0.0.251] [IGMP][Unknown][Network][Acceptable] @@ -155,7 +155,7 @@ idle: [....25] [ip4][..tcp] [..192.168.1.121][53428] -> [...52.98.163.18][..443] [TLS][Outlook][Web][Safe] idle: [....24] [ip4][..tcp] [..192.168.1.121][53429] -> [...52.98.163.18][..443] [TLS][Outlook][Web][Safe] guessed: [.....1] [ip4][..tcp] [..192.168.1.121][52746] -> [...52.149.21.60][..443] [TLS][Azure][Web][Safe] - idle: [.....1] [ip4][..tcp] [..192.168.1.121][52746] -> [...52.149.21.60][..443] + idle: [.....1] [ip4][..tcp] [..192.168.1.121][52746] -> [...52.149.21.60][..443] idle: [....17] [ip4][..udp] [..192.168.1.121][54561] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable] end: [....12] [ip4][..tcp] [..192.168.1.121][53910] -> [...40.113.10.47][..443] [TLS.Microsoft][Azure][Cloud][Safe] RISK: TLS Cert Validity Too Long @@ -178,6 +178,6 @@ idle: [.....5] [ip6][..udp] [..............fe80::1059:a858:f9e7:cf94][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] end: [....20] [ip4][..tcp] [..192.168.1.121][53905] -> [..140.82.113.26][..443] [TLS][Github][Web][Safe] not-detected: [.....2] [ip4][..tcp] [..192.168.1.121][52721] -> [..192.168.1.139][55367] [Unknown][Unknown][Unrated] - idle: [.....2] [ip4][..tcp] [..192.168.1.121][52721] -> [..192.168.1.139][55367] + idle: [.....2] [ip4][..tcp] [..192.168.1.121][52721] -> [..192.168.1.139][55367] idle: [....21] [ip4][..udp] [..192.168.1.121][65213] -> [........8.8.8.8][...53] [DNS.Apple][Google][Network][Safe] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tls_cipher_lens.pcap.out b/test/results/flow-info/default/tls_cipher_lens.pcap.out index cbb0eabc6..e0e269e84 100644 --- a/test/results/flow-info/default/tls_cipher_lens.pcap.out +++ b/test/results/flow-info/default/tls_cipher_lens.pcap.out @@ -1,19 +1,19 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.11.11][51587] -> [.173.194.35.191][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.11.11][51587] -> [.173.194.35.191][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.11.11][51587] -> [.173.194.35.191][..443] [TLS.Google][Google][Web][Acceptable][www.google.it] RISK: Obsolete TLS (v1.1 or older) - new: [.....2] [ip4][..tcp] [..192.168.11.11][51590] -> [.173.194.35.191][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.11.11][51590] -> [.173.194.35.191][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.11.11][51590] -> [.173.194.35.191][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [.....3] [ip4][..tcp] [..192.168.11.11][51589] -> [.173.194.35.191][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.11.11][51589] -> [.173.194.35.191][..443] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..192.168.11.11][51589] -> [.173.194.35.191][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [.....4] [ip4][..tcp] [..192.168.11.11][51588] -> [.173.194.35.191][..443] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.11.11][51588] -> [.173.194.35.191][..443] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.11.11][51588] -> [.173.194.35.191][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [.....5] [ip4][..tcp] [..192.168.11.11][51591] -> [.173.194.35.191][..443] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [..192.168.11.11][51591] -> [.173.194.35.191][..443] [MIDSTREAM] detected: [.....5] [ip4][..tcp] [..192.168.11.11][51591] -> [.173.194.35.191][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) idle: [.....1] [ip4][..tcp] [..192.168.11.11][51587] -> [.173.194.35.191][..443] [TLS.Google][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/tls_client_certificate_with_missing_server_one.pcapng.out b/test/results/flow-info/default/tls_client_certificate_with_missing_server_one.pcapng.out index 045be7a88..e36891ba5 100644 --- a/test/results/flow-info/default/tls_client_certificate_with_missing_server_one.pcapng.out +++ b/test/results/flow-info/default/tls_client_certificate_with_missing_server_one.pcapng.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [195.181.174.176][..443] -> [..192.168.1.128][48260] + new: [.....1] [ip4][..tcp] [195.181.174.176][..443] -> [..192.168.1.128][48260] detected: [.....1] [ip4][..tcp] [195.181.174.176][..443] -> [..192.168.1.128][48260] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] RISK: Missing SNI TLS Extn, Desktop/File Sharing, Uncommon TLS ALPN detection-update: [.....1] [ip4][..tcp] [195.181.174.176][..443] -> [..192.168.1.128][48260] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] RISK: Missing SNI TLS Extn, Desktop/File Sharing, Uncommon TLS ALPN - new: [.....2] [ip4][..tcp] [..192.168.1.128][59754] -> [..192.168.1.181][.7070] + new: [.....2] [ip4][..tcp] [..192.168.1.128][59754] -> [..192.168.1.181][.7070] detected: [.....2] [ip4][..tcp] [..192.168.1.128][59754] -> [..192.168.1.181][.7070] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn idle: [.....1] [ip4][..tcp] [195.181.174.176][..443] -> [..192.168.1.128][48260] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/tls_ech.pcapng.out b/test/results/flow-info/default/tls_ech.pcapng.out index bb565cb0c..4151d5f6e 100644 --- a/test/results/flow-info/default/tls_ech.pcapng.out +++ b/test/results/flow-info/default/tls_ech.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [..2001:b07:a3d:c112:ce16:b409:3d0a:9177][47460] -> [...................2606:4700::6812:1e4e][..443] + new: [.....1] [ip6][..tcp] [..2001:b07:a3d:c112:ce16:b409:3d0a:9177][47460] -> [...................2606:4700::6812:1e4e][..443] detected: [.....1] [ip6][..tcp] [..2001:b07:a3d:c112:ce16:b409:3d0a:9177][47460] -> [...................2606:4700::6812:1e4e][..443] [TLS.Cloudflare][Cloudflare][Web][Acceptable][performance.radar.cloudflare.com] detection-update: [.....1] [ip6][..tcp] [..2001:b07:a3d:c112:ce16:b409:3d0a:9177][47460] -> [...................2606:4700::6812:1e4e][..443] [TLS.Cloudflare][Cloudflare][Web][Acceptable][performance.radar.cloudflare.com] idle: [.....1] [ip6][..tcp] [..2001:b07:a3d:c112:ce16:b409:3d0a:9177][47460] -> [...................2606:4700::6812:1e4e][..443] [TLS.Cloudflare][Cloudflare][Web][Acceptable] diff --git a/test/results/flow-info/default/tls_esni_sni_both.pcap.out b/test/results/flow-info/default/tls_esni_sni_both.pcap.out index a08c7b272..1f339b35f 100644 --- a/test/results/flow-info/default/tls_esni_sni_both.pcap.out +++ b/test/results/flow-info/default/tls_esni_sni_both.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.1.21][55500] -> [..104.17.175.85][..443] + new: [.....1] [ip4][..tcp] [...192.168.1.21][55500] -> [..104.17.175.85][..443] detected: [.....1] [ip4][..tcp] [...192.168.1.21][55500] -> [..104.17.175.85][..443] [TLS][Cloudflare][Web][Safe][these-are-not-the-droids-youre-looking-for.com] RISK: TLS (probably) Not Carrying HTTPS, TLS Susp ESNI Usage detection-update: [.....1] [ip4][..tcp] [...192.168.1.21][55500] -> [..104.17.175.85][..443] [TLS][Cloudflare][Web][Safe][these-are-not-the-droids-youre-looking-for.com] RISK: TLS (probably) Not Carrying HTTPS, TLS Susp ESNI Usage - new: [.....2] [ip4][..tcp] [...192.168.1.21][55514] -> [..104.17.175.85][..443] + new: [.....2] [ip4][..tcp] [...192.168.1.21][55514] -> [..104.17.175.85][..443] detected: [.....2] [ip4][..tcp] [...192.168.1.21][55514] -> [..104.17.175.85][..443] [TLS][Cloudflare][Web][Safe][you-think-thats-normal-tls-traffic-youre-seeing.com] RISK: TLS (probably) Not Carrying HTTPS, TLS Susp ESNI Usage detection-update: [.....2] [ip4][..tcp] [...192.168.1.21][55514] -> [..104.17.175.85][..443] [TLS][Cloudflare][Web][Safe][you-think-thats-normal-tls-traffic-youre-seeing.com] diff --git a/test/results/flow-info/default/tls_false_positives.pcapng.out b/test/results/flow-info/default/tls_false_positives.pcapng.out index ca5e6bc9a..2af411665 100644 --- a/test/results/flow-info/default/tls_false_positives.pcapng.out +++ b/test/results/flow-info/default/tls_false_positives.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][.1445] -> [....192.168.0.1][20979] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][.1445] -> [....192.168.0.1][20979] not-detected: [.....1] [ip4][..tcp] [.....10.10.10.1][.1445] -> [....192.168.0.1][20979] [Unknown][Unknown][Unrated] - idle: [.....1] [ip4][..tcp] [.....10.10.10.1][.1445] -> [....192.168.0.1][20979] + idle: [.....1] [ip4][..tcp] [.....10.10.10.1][.1445] -> [....192.168.0.1][20979] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tls_invalid_reads.pcap.out b/test/results/flow-info/default/tls_invalid_reads.pcap.out index 98089627a..4658cd47a 100644 --- a/test/results/flow-info/default/tls_invalid_reads.pcap.out +++ b/test/results/flow-info/default/tls_invalid_reads.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.10.101][.3967] -> [..206.33.61.113][..443] + new: [.....1] [ip4][..tcp] [.192.168.10.101][.3967] -> [..206.33.61.113][..443] detected: [.....1] [ip4][..tcp] [.192.168.10.101][.3967] -> [..206.33.61.113][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....1] [ip4][..tcp] [.192.168.10.101][.3967] -> [..206.33.61.113][..443] [TLS][Unknown][Web][Safe][] @@ -10,7 +10,7 @@ RISK: Obsolete TLS (v1.1 or older) DAEMON-EVENT: [Processed: 8 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..tcp] [...74.80.160.99][.3258] -> [...67.217.77.28][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [...74.80.160.99][.3258] -> [...67.217.77.28][..443] [MIDSTREAM] idle: [.....1] [ip4][..tcp] [.192.168.10.101][.3967] -> [..206.33.61.113][..443] [TLS][Unknown][Web][Safe] RISK: Obsolete TLS (v1.1 or older) DAEMON-EVENT: [Processed: 9 pkts][ZLib][compressions: 0|diff: 0 / 0] @@ -20,5 +20,5 @@ ERROR-EVENT: Unknown packet type [3/16] guessed: [.....2] [ip4][..tcp] [...74.80.160.99][.3258] -> [...67.217.77.28][..443] [TLS][GoTo][Web][Safe] RISK: Unidirectional Traffic - idle: [.....2] [ip4][..tcp] [...74.80.160.99][.3258] -> [...67.217.77.28][..443] + idle: [.....2] [ip4][..tcp] [...74.80.160.99][.3258] -> [...67.217.77.28][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tls_long_cert.pcap.out b/test/results/flow-info/default/tls_long_cert.pcap.out index c7a1a3e07..a9b84f232 100644 --- a/test/results/flow-info/default/tls_long_cert.pcap.out +++ b/test/results/flow-info/default/tls_long_cert.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.126][60174] -> [.104.111.215.93][..443] + new: [.....1] [ip4][..tcp] [..192.168.2.126][60174] -> [.104.111.215.93][..443] detected: [.....1] [ip4][..tcp] [..192.168.2.126][60174] -> [.104.111.215.93][..443] [TLS][Unknown][Web][Safe][www.repubblica.it] detection-update: [.....1] [ip4][..tcp] [..192.168.2.126][60174] -> [.104.111.215.93][..443] [TLS][Unknown][Web][Safe][www.repubblica.it] detection-update: [.....1] [ip4][..tcp] [..192.168.2.126][60174] -> [.104.111.215.93][..443] [TLS][Unknown][Web][Safe][www.repubblica.it] diff --git a/test/results/flow-info/default/tls_missing_ch_frag.pcap.out b/test/results/flow-info/default/tls_missing_ch_frag.pcap.out index 078bf4928..dfb30fb92 100644 --- a/test/results/flow-info/default/tls_missing_ch_frag.pcap.out +++ b/test/results/flow-info/default/tls_missing_ch_frag.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][33063] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][33063] detected: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][33063] [TLS][Unknown][Web][Safe][] end: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][33063] [TLS][Unknown][Web][Safe] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tls_multiple_synack_different_seq.pcapng.out b/test/results/flow-info/default/tls_multiple_synack_different_seq.pcapng.out index 93fb60896..34da420c3 100644 --- a/test/results/flow-info/default/tls_multiple_synack_different_seq.pcapng.out +++ b/test/results/flow-info/default/tls_multiple_synack_different_seq.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][59927] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][59927] detected: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][59927] [TLS.AmazonAWS][Unknown][Cloud][Acceptable][bolt-prod-s3-eu-west-1.s3.eu-west-1.amazonaws.com] detection-update: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][59927] [TLS.AmazonAWS][Unknown][Cloud][Acceptable][bolt-prod-s3-eu-west-1.s3.eu-west-1.amazonaws.com] detection-update: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][59927] [TLS.AmazonAWS][Unknown][Cloud][Acceptable][bolt-prod-s3-eu-west-1.s3.eu-west-1.amazonaws.com] diff --git a/test/results/flow-info/default/tls_port_80.pcapng.out b/test/results/flow-info/default/tls_port_80.pcapng.out index 51b324381..28b318619 100644 --- a/test/results/flow-info/default/tls_port_80.pcapng.out +++ b/test/results/flow-info/default/tls_port_80.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..57.91.202.194][50541] -> [..132.49.141.56][...80] + new: [.....1] [ip4][..tcp] [..57.91.202.194][50541] -> [..132.49.141.56][...80] detected: [.....1] [ip4][..tcp] [..57.91.202.194][50541] -> [..132.49.141.56][...80] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS, Missing SNI TLS Extn detection-update: [.....1] [ip4][..tcp] [..57.91.202.194][50541] -> [..132.49.141.56][...80] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/default/tls_torrent.pcapng.out b/test/results/flow-info/default/tls_torrent.pcapng.out index 45838247c..ede0e5668 100644 --- a/test/results/flow-info/default/tls_torrent.pcapng.out +++ b/test/results/flow-info/default/tls_torrent.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][58842] + new: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][58842] detected: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][58842] [TLS][Unknown][Web][Safe][web.utorrent.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [.....10.10.10.1][..443] -> [....192.168.0.1][58842] [TLS][Unknown][Web][Safe][web.utorrent.com] diff --git a/test/results/flow-info/default/tls_unidirectional.pcap.out b/test/results/flow-info/default/tls_unidirectional.pcap.out index d59be472e..613d92820 100644 --- a/test/results/flow-info/default/tls_unidirectional.pcap.out +++ b/test/results/flow-info/default/tls_unidirectional.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.142.250.27.188][.5228] -> [...10.140.72.24][12654] + new: [.....1] [ip4][..tcp] [.142.250.27.188][.5228] -> [...10.140.72.24][12654] detected: [.....1] [ip4][..tcp] [.142.250.27.188][.5228] -> [...10.140.72.24][12654] [TLS][Google][Web][Safe][] RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [.....1] [ip4][..tcp] [.142.250.27.188][.5228] -> [...10.140.72.24][12654] [TLS.Google][Google][Web][Acceptable][] RISK: Known Proto on Non Std Port, Unidirectional Traffic DAEMON-EVENT: [Processed: 6 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.128][48260] -> [195.181.174.176][..443] [TLS.AnyDesk][Unknown][RemoteAccess][Acceptable][] RISK: Missing SNI TLS Extn, Desktop/File Sharing, Uncommon TLS ALPN, Unidirectional Traffic idle: [.....1] [ip4][..tcp] [.142.250.27.188][.5228] -> [...10.140.72.24][12654] [TLS.Google][Google][Web][Acceptable] diff --git a/test/results/flow-info/default/tls_verylong_certificate.pcap.out b/test/results/flow-info/default/tls_verylong_certificate.pcap.out index 6a0a933e6..86c3bcdae 100644 --- a/test/results/flow-info/default/tls_verylong_certificate.pcap.out +++ b/test/results/flow-info/default/tls_verylong_certificate.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.160][54804] -> [..151.101.66.49][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.160][54804] -> [..151.101.66.49][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.160][54804] -> [..151.101.66.49][..443] [TLS.Cybersec][Unknown][Cybersecurity][Safe][feodotracker.abuse.ch] detection-update: [.....1] [ip4][..tcp] [..192.168.1.160][54804] -> [..151.101.66.49][..443] [TLS.Cybersec][Unknown][Cybersecurity][Safe][feodotracker.abuse.ch] detection-update: [.....1] [ip4][..tcp] [..192.168.1.160][54804] -> [..151.101.66.49][..443] [TLS.Cybersec][Unknown][Cybersecurity][Safe][feodotracker.abuse.ch] diff --git a/test/results/flow-info/default/toca-boca.pcap.out b/test/results/flow-info/default/toca-boca.pcap.out index 22b6fda06..94a27efd1 100644 --- a/test/results/flow-info/default/toca-boca.pcap.out +++ b/test/results/flow-info/default/toca-boca.pcap.out @@ -1,96 +1,96 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.2.100][50173] -> [..91.199.81.225][.5055] + new: [.....1] [ip4][..udp] [..192.168.2.100][50173] -> [..91.199.81.225][.5055] detected: [.....1] [ip4][..udp] [..192.168.2.100][50173] -> [..91.199.81.225][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..udp] [..192.168.2.100][42022] -> [...92.38.154.49][.5055] + new: [.....2] [ip4][..udp] [..192.168.2.100][42022] -> [...92.38.154.49][.5055] detected: [.....2] [ip4][..udp] [..192.168.2.100][42022] -> [...92.38.154.49][.5055] [TocaBoca][Unknown][Game][Fun] idle: [.....1] [ip4][..udp] [..192.168.2.100][50173] -> [..91.199.81.225][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 16 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..udp] [..192.168.2.100][55544] -> [...92.38.154.49][.5055] + new: [.....3] [ip4][..udp] [..192.168.2.100][55544] -> [...92.38.154.49][.5055] detected: [.....3] [ip4][..udp] [..192.168.2.100][55544] -> [...92.38.154.49][.5055] [TocaBoca][Unknown][Game][Fun] idle: [.....2] [ip4][..udp] [..192.168.2.100][42022] -> [...92.38.154.49][.5055] [TocaBoca][Unknown][Game][Fun] - new: [.....4] [ip4][..udp] [...92.38.154.49][.5055] -> [..192.168.2.100][32867] + new: [.....4] [ip4][..udp] [...92.38.154.49][.5055] -> [..192.168.2.100][32867] detected: [.....4] [ip4][..udp] [...92.38.154.49][.5055] -> [..192.168.2.100][32867] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 32 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..udp] [..192.168.2.100][54983] -> [..91.199.81.123][.5055] + new: [.....5] [ip4][..udp] [..192.168.2.100][54983] -> [..91.199.81.123][.5055] detected: [.....5] [ip4][..udp] [..192.168.2.100][54983] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] - new: [.....6] [ip4][..udp] [..91.199.81.130][.5055] -> [..192.168.2.100][43064] + new: [.....6] [ip4][..udp] [..91.199.81.130][.5055] -> [..192.168.2.100][43064] detected: [.....6] [ip4][..udp] [..91.199.81.130][.5055] -> [..192.168.2.100][43064] [TocaBoca][Unknown][Game][Fun] idle: [.....4] [ip4][..udp] [...92.38.154.49][.5055] -> [..192.168.2.100][32867] [TocaBoca][Unknown][Game][Fun] idle: [.....3] [ip4][..udp] [..192.168.2.100][55544] -> [...92.38.154.49][.5055] [TocaBoca][Unknown][Game][Fun] - new: [.....7] [ip4][..udp] [..192.168.2.100][44818] -> [..91.199.81.123][.5055] + new: [.....7] [ip4][..udp] [..192.168.2.100][44818] -> [..91.199.81.123][.5055] detected: [.....7] [ip4][..udp] [..192.168.2.100][44818] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] update: [.....5] [ip4][..udp] [..192.168.2.100][54983] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] update: [.....6] [ip4][..udp] [..91.199.81.130][.5055] -> [..192.168.2.100][43064] [TocaBoca][Unknown][Game][Fun] - new: [.....8] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][60837] + new: [.....8] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][60837] detected: [.....8] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][60837] [TocaBoca][Unknown][Game][Fun] idle: [.....5] [ip4][..udp] [..192.168.2.100][54983] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] idle: [.....7] [ip4][..udp] [..192.168.2.100][44818] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] idle: [.....6] [ip4][..udp] [..91.199.81.130][.5055] -> [..192.168.2.100][43064] [TocaBoca][Unknown][Game][Fun] - new: [.....9] [ip4][..udp] [..192.168.2.100][37218] -> [..91.199.81.123][.5055] + new: [.....9] [ip4][..udp] [..192.168.2.100][37218] -> [..91.199.81.123][.5055] detected: [.....9] [ip4][..udp] [..192.168.2.100][37218] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] update: [.....8] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][60837] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 51 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [....10] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][33311] + new: [....10] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][33311] detected: [....10] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][33311] [TocaBoca][Unknown][Game][Fun] idle: [.....8] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][60837] [TocaBoca][Unknown][Game][Fun] idle: [.....9] [ip4][..udp] [..192.168.2.100][37218] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 52 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 10|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [....11] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][40290] + new: [....11] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][40290] detected: [....11] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][40290] [TocaBoca][Unknown][Game][Fun] idle: [....10] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][33311] [TocaBoca][Unknown][Game][Fun] - new: [....12] [ip4][..udp] [..192.168.2.100][33024] -> [..91.199.81.123][.5055] + new: [....12] [ip4][..udp] [..192.168.2.100][33024] -> [..91.199.81.123][.5055] detected: [....12] [ip4][..udp] [..192.168.2.100][33024] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] idle: [....11] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][40290] [TocaBoca][Unknown][Game][Fun] - new: [....13] [ip4][..udp] [..192.168.2.100][56864] -> [..91.199.81.123][.5055] + new: [....13] [ip4][..udp] [..192.168.2.100][56864] -> [..91.199.81.123][.5055] detected: [....13] [ip4][..udp] [..192.168.2.100][56864] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 55 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 13|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 3] - new: [....14] [ip4][..udp] [..192.168.2.100][50600] -> [..91.199.81.123][.5055] + new: [....14] [ip4][..udp] [..192.168.2.100][50600] -> [..91.199.81.123][.5055] detected: [....14] [ip4][..udp] [..192.168.2.100][50600] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] idle: [....13] [ip4][..udp] [..192.168.2.100][56864] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] idle: [....12] [ip4][..udp] [..192.168.2.100][33024] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] - new: [....15] [ip4][..udp] [..192.168.2.100][35671] -> [..91.199.81.123][.5055] + new: [....15] [ip4][..udp] [..192.168.2.100][35671] -> [..91.199.81.123][.5055] detected: [....15] [ip4][..udp] [..192.168.2.100][35671] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] update: [....14] [ip4][..udp] [..192.168.2.100][50600] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] - new: [....16] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][37167] + new: [....16] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][37167] idle: [....14] [ip4][..udp] [..192.168.2.100][50600] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] update: [....15] [ip4][..udp] [..192.168.2.100][35671] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 72 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 16|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 5] - new: [....17] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][34503] + new: [....17] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][34503] detected: [....17] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][34503] [TocaBoca][Unknown][Game][Fun] guessed: [....16] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][37167] [TocaBoca][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [....16] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][37167] + idle: [....16] [ip4][..udp] [..91.199.81.123][.5055] -> [..192.168.2.100][37167] idle: [....15] [ip4][..udp] [..192.168.2.100][35671] -> [..91.199.81.123][.5055] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 73 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 17|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 5] - new: [....18] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][50337] + new: [....18] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][50337] idle: [....17] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][34503] [TocaBoca][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 74 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 18|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 5] - new: [....19] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][56920] - new: [....20] [ip4][..udp] [..192.168.2.100][45096] -> [..91.199.81.208][.5055] + new: [....19] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][56920] + new: [....20] [ip4][..udp] [..192.168.2.100][45096] -> [..91.199.81.208][.5055] detected: [....20] [ip4][..udp] [..192.168.2.100][45096] -> [..91.199.81.208][.5055] [TocaBoca][Unknown][Game][Fun] guessed: [....18] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][50337] [TocaBoca][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [....18] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][50337] + idle: [....18] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][50337] DAEMON-EVENT: [Processed: 76 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 20|skipped: 0|!detected: 0|guessed: 2|detection-updates: 0|updates: 5] - new: [....21] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][43151] + new: [....21] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][43151] guessed: [....19] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][56920] [TocaBoca][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [....19] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][56920] + idle: [....19] [ip4][..udp] [..91.199.81.122][.5055] -> [..192.168.2.100][56920] idle: [....20] [ip4][..udp] [..192.168.2.100][45096] -> [..91.199.81.208][.5055] [TocaBoca][Unknown][Game][Fun] guessed: [....21] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][43151] [TocaBoca][Unknown][Game][Fun] RISK: Unidirectional Traffic - idle: [....21] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][43151] + idle: [....21] [ip4][..udp] [..91.199.81.225][.5055] -> [..192.168.2.100][43151] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tor.pcap.out b/test/results/flow-info/default/tor.pcap.out index e695c257a..38f3672cd 100644 --- a/test/results/flow-info/default/tor.pcap.out +++ b/test/results/flow-info/default/tor.pcap.out @@ -4,26 +4,26 @@ ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] - new: [.....1] [ip4][..tcp] [..192.168.1.252][51110] -> [..91.143.93.242][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.252][51110] -> [..91.143.93.242][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.252][51110] -> [..91.143.93.242][..443] [TLS][Unknown][Web][Safe][www.ct7ctrgb6cr7.com] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....1] [ip4][..tcp] [..192.168.1.252][51110] -> [..91.143.93.242][..443] [TLS][Unknown][Web][Safe][www.ct7ctrgb6cr7.com] RISK: Obsolete TLS (v1.1 or older), TLS Cert About To Expire ERROR-EVENT: Unknown packet type [4/16] - new: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.e6r5p57kbafwrxj3plz.com] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol detection-update: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.e6r5p57kbafwrxj3plz.com] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol ERROR-EVENT: Unknown packet type [5/16] - new: [.....3] [ip4][..tcp] [..192.168.1.252][51112] -> [...38.229.70.53][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.252][51112] -> [...38.229.70.53][..443] detected: [.....3] [ip4][..tcp] [..192.168.1.252][51112] -> [...38.229.70.53][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.q4cyamnc6mtokjurvdclt.com] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol detection-update: [.....3] [ip4][..tcp] [..192.168.1.252][51112] -> [...38.229.70.53][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.q4cyamnc6mtokjurvdclt.com] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol ERROR-EVENT: Unknown packet type [6/16] ERROR-EVENT: Unknown packet type [7/16] - new: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] + new: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] detected: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] ERROR-EVENT: Unknown packet type [8/16] ERROR-EVENT: Unknown packet type [9/16] @@ -34,7 +34,7 @@ ERROR-EVENT: Unknown packet type [14/16] ERROR-EVENT: Unknown packet type [15/16] ERROR-EVENT: Unknown packet type [16/16] - new: [.....5] [ip4][..udp] [..192.168.1.252][..138] -> [..192.168.1.255][..138] + new: [.....5] [ip4][..udp] [..192.168.1.252][..138] -> [..192.168.1.255][..138] detected: [.....5] [ip4][..udp] [..192.168.1.252][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][endian-pc] RISK: Unsafe Protocol analyse: [.....3] [ip4][..tcp] [..192.168.1.252][51112] -> [...38.229.70.53][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous] @@ -58,7 +58,7 @@ [PKTLENS.....: 52,52,46,255,40,788,174,99,114,1500,142,46,626,40,626,40,626,626,626,626,40,626,46,626,40,626,40,626,1500,46,1500,1500] [ENTROPIES...: 4.5,4.9,4.5,5.4,4.9,7.4,6.6,6.0,6.1,7.9,6.5,4.5,7.7,4.9,7.6,4.9,7.6,7.6,7.7,7.7,4.8,7.7,4.4,7.7,4.9,7.7,4.9,7.7,7.9,4.5,7.9,7.9] update: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....6] [ip4][..tcp] [..192.168.1.252][51104] -> [...157.56.30.46][..443] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.252][51104] -> [...157.56.30.46][..443] [MIDSTREAM] update: [.....5] [ip4][..udp] [..192.168.1.252][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol analyse: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous] @@ -74,8 +74,8 @@ ERROR-EVENT: Unknown packet type [1/16] ERROR-EVENT: Unknown packet type [2/16] ERROR-EVENT: Unknown packet type [3/16] - new: [.....7] [ip4][..tcp] [..192.168.1.252][51174] -> [.212.83.155.250][..443] - new: [.....8] [ip4][..tcp] [..192.168.1.252][51175] -> [..91.143.93.242][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.252][51174] -> [.212.83.155.250][..443] + new: [.....8] [ip4][..tcp] [..192.168.1.252][51175] -> [..91.143.93.242][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.252][51174] -> [.212.83.155.250][..443] [TLS][Unknown][Web][Safe][www.t3i3ru.com] RISK: Obsolete TLS (v1.1 or older) detected: [.....8] [ip4][..tcp] [..192.168.1.252][51175] -> [..91.143.93.242][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.gfu7hbxpfp.com] @@ -85,7 +85,7 @@ detection-update: [.....8] [ip4][..tcp] [..192.168.1.252][51175] -> [..91.143.93.242][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous][www.gfu7hbxpfp.com] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol, TLS Cert About To Expire ERROR-EVENT: Unknown packet type [4/16] - new: [.....9] [ip4][..tcp] [..192.168.1.252][51176] -> [...38.229.70.53][..443] + new: [.....9] [ip4][..tcp] [..192.168.1.252][51176] -> [...38.229.70.53][..443] detected: [.....9] [ip4][..tcp] [..192.168.1.252][51176] -> [...38.229.70.53][..443] [TLS][Unknown][Web][Safe][www.jmts2id.com] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....9] [ip4][..tcp] [..192.168.1.252][51176] -> [...38.229.70.53][..443] [TLS][Unknown][Web][Safe][www.jmts2id.com] @@ -107,7 +107,7 @@ RISK: Unsafe Protocol guessed: [.....6] [ip4][..tcp] [..192.168.1.252][51104] -> [...157.56.30.46][..443] [TLS][Azure][Web][Safe] RISK: Unidirectional Traffic - end: [.....6] [ip4][..tcp] [..192.168.1.252][51104] -> [...157.56.30.46][..443] + end: [.....6] [ip4][..tcp] [..192.168.1.252][51104] -> [...157.56.30.46][..443] end: [.....2] [ip4][..tcp] [..192.168.1.252][51111] -> [....46.59.52.31][..443] [TLS.Tor][Unknown][VPN][Potentially Dangerous] RISK: Obsolete TLS (v1.1 or older), Susp DGA Domain name, Unsafe Protocol update: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] @@ -123,12 +123,12 @@ ERROR-EVENT: Unknown packet type [15/16] ERROR-EVENT: Unknown packet type [16/16] update: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....10] [ip4][..tcp] [..192.168.1.252][51185] -> [.62.210.137.230][..443] + new: [....10] [ip4][..tcp] [..192.168.1.252][51185] -> [.62.210.137.230][..443] detected: [....10] [ip4][..tcp] [..192.168.1.252][51185] -> [.62.210.137.230][..443] [TLS][Unknown][Web][Safe][www.6gyip7tqim7sieb.com] RISK: Obsolete TLS (v1.1 or older) detection-update: [....10] [ip4][..tcp] [..192.168.1.252][51185] -> [.62.210.137.230][..443] [TLS][Unknown][Web][Safe][www.6gyip7tqim7sieb.com] RISK: Obsolete TLS (v1.1 or older) - new: [....11] [ip6][..udp] [..............fe80::c583:1972:5728:7323][..546] -> [..............................ff02::1:2][..547] + new: [....11] [ip6][..udp] [..............fe80::c583:1972:5728:7323][..546] -> [..............................ff02::1:2][..547] detected: [....11] [ip6][..udp] [..............fe80::c583:1972:5728:7323][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [....192.168.1.1][17500] -> [..192.168.1.255][17500] [Dropbox][Unknown][Cloud][Acceptable] DAEMON-EVENT: [Processed: 337 pkts][ZLib][compressions: 0|diff: 0 / 0] diff --git a/test/results/flow-info/default/tplink_shp.pcap.out b/test/results/flow-info/default/tplink_shp.pcap.out index e72308fa9..a2926f1b6 100644 --- a/test/results/flow-info/default/tplink_shp.pcap.out +++ b/test/results/flow-info/default/tplink_shp.pcap.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.192.168.242.41][.9999] -> [255.255.255.255][.9999] + new: [.....1] [ip4][..udp] [.192.168.242.41][.9999] -> [255.255.255.255][.9999] detected: [.....1] [ip4][..udp] [.192.168.242.41][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....2] [ip4][..udp] [.192.168.242.40][.9999] -> [255.255.255.255][.9999] + new: [.....2] [ip4][..udp] [.192.168.242.40][.9999] -> [255.255.255.255][.9999] detected: [.....2] [ip4][..udp] [.192.168.242.40][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....3] [ip4][..udp] [.192.168.242.99][.9999] -> [255.255.255.255][.9999] + new: [.....3] [ip4][..udp] [.192.168.242.99][.9999] -> [255.255.255.255][.9999] detected: [.....3] [ip4][..udp] [.192.168.242.99][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....4] [ip4][..udp] [.192.168.242.38][.9999] -> [255.255.255.255][.9999] + new: [.....4] [ip4][..udp] [.192.168.242.38][.9999] -> [255.255.255.255][.9999] detected: [.....4] [ip4][..udp] [.192.168.242.38][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....5] [ip4][..udp] [.192.168.242.98][.9999] -> [255.255.255.255][.9999] + new: [.....5] [ip4][..udp] [.192.168.242.98][.9999] -> [255.255.255.255][.9999] detected: [.....5] [ip4][..udp] [.192.168.242.98][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....6] [ip4][..udp] [192.168.242.122][.9999] -> [255.255.255.255][.9999] + new: [.....6] [ip4][..udp] [192.168.242.122][.9999] -> [255.255.255.255][.9999] detected: [.....6] [ip4][..udp] [192.168.242.122][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....7] [ip4][..udp] [.192.168.242.32][.9999] -> [255.255.255.255][.9999] + new: [.....7] [ip4][..udp] [.192.168.242.32][.9999] -> [255.255.255.255][.9999] detected: [.....7] [ip4][..udp] [.192.168.242.32][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] - new: [.....8] [ip4][..udp] [.192.168.242.33][.9999] -> [255.255.255.255][.9999] + new: [.....8] [ip4][..udp] [.192.168.242.33][.9999] -> [255.255.255.255][.9999] detected: [.....8] [ip4][..udp] [.192.168.242.33][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] update: [.....1] [ip4][..udp] [.192.168.242.41][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] update: [.....2] [ip4][..udp] [.192.168.242.40][.9999] -> [255.255.255.255][.9999] [TPLINK_SHP][Unknown][IoT-Scada][Acceptable] diff --git a/test/results/flow-info/default/trickbot.pcap.out b/test/results/flow-info/default/trickbot.pcap.out index 5d3d8b848..f40521b37 100644 --- a/test/results/flow-info/default/trickbot.pcap.out +++ b/test/results/flow-info/default/trickbot.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.12.29.101][61318] -> [.82.118.225.196][.7080] + new: [.....1] [ip4][..tcp] [...10.12.29.101][61318] -> [.82.118.225.196][.7080] detected: [.....1] [ip4][..tcp] [...10.12.29.101][61318] -> [.82.118.225.196][.7080] [HTTP][Unknown][Web][Acceptable][82.118.225.196] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....1] [ip4][..tcp] [...10.12.29.101][61318] -> [.82.118.225.196][.7080] [HTTP][Unknown][Web][Acceptable][82.118.225.196] diff --git a/test/results/flow-info/default/tumblr.pcap.out b/test/results/flow-info/default/tumblr.pcap.out index 7ec508140..3ebaed4e9 100644 --- a/test/results/flow-info/default/tumblr.pcap.out +++ b/test/results/flow-info/default/tumblr.pcap.out @@ -1,25 +1,25 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [MIDSTREAM] - new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [MIDSTREAM] + new: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [MIDSTREAM] + new: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [MIDSTREAM] detected: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [TLS][Unknown][Web][Safe] - new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [MIDSTREAM] + new: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [MIDSTREAM] detected: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [TLS][Unknown][Web][Safe] detection-update: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [MIDSTREAM] + new: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [MIDSTREAM] detected: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [TLS][Unknown][Web][Safe] detection-update: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [TLS][Unknown][Web][Safe] detection-update: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [TLS][Unknown][Web][Safe] detection-update: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [TLS][Unknown][Web][Safe] - new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [MIDSTREAM] + new: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [MIDSTREAM] analyse: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [TLS][Unknown][Web][Safe] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.701| 0.084| 0.189| 35694.846| 2.600] @@ -30,16 +30,16 @@ [IATS(ms)....: 0.9,91.7,194.1,0.0,0.0,2.8,104.4,700.9,700.8,1.3,5.8,45.0,0.4,357.1,395.3,1.5,0.0,0.0,0.0,0.0,0.0,0.0,0.0,1.5,0.0,0.0,0.0,0.0,0.0,0.0,0.0] [PKTLENS.....: 454,111,111,72,72,72,111,72,944,72,107,184,72,72,1460,72,84,1472,1472,1472,1472,835,1472,1472,72,72,72,72,72,72,72,72] [ENTROPIES...: 7.5,6.0,6.0,5.1,5.1,5.1,5.8,5.2,7.8,5.2,5.9,6.7,5.0,5.1,7.9,5.2,5.4,7.9,7.9,7.9,7.8,7.7,7.8,7.9,5.2,5.2,5.2,5.2,5.2,5.2,5.2,5.2] - new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [MIDSTREAM] + new: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [MIDSTREAM] detected: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] detection-update: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [MIDSTREAM] + new: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [MIDSTREAM] detected: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] detection-update: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] - new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58380] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] + new: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58380] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] detection-update: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] detected: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58380] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe][consent.cmp.oath.com] analyse: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] @@ -53,7 +53,7 @@ [PKTLENS.....: 184,111,183,172,72,72,72,72,1472,72,1472,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72,1472,1472,72,72] [ENTROPIES...: 6.6,5.9,6.6,6.5,5.0,5.0,4.9,5.0,7.9,5.1,7.9,5.1,7.9,7.8,5.1,5.1,7.9,7.8,5.1,5.1,7.9,7.9,5.1,5.1,7.9,7.8,5.1,5.1,7.9,7.9,5.1,5.1] detection-update: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] - new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58382] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] + new: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58382] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] detection-update: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58380] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe][consent.cmp.oath.com] detected: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58382] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe][consent.cmp.oath.com] detection-update: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58382] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe][consent.cmp.oath.com] @@ -67,12 +67,12 @@ [IATS(ms)....: 33.2,33.2,0.5,47.7,0.0,47.2,1.2,37.7,2.1,0.0,0.0,38.6,0.0,0.0,0.8,0.7,0.8,0.8,2.6,0.2,0.2,0.1,26.3,0.6,0.0,0.1,1.4,0.0,0.0,25.2,0.0] [PKTLENS.....: 80,80,72,589,72,171,72,595,72,1280,1280,1280,72,72,72,544,72,1055,72,146,164,329,128,72,72,72,72,327,327,168,72,72] [ENTROPIES...: 5.3,5.6,5.6,4.6,5.5,6.2,5.5,5.0,5.5,7.8,7.9,7.8,5.6,5.5,5.6,7.6,5.6,7.8,5.6,6.6,6.7,7.3,6.3,5.5,5.5,5.4,5.5,7.3,7.3,6.5,5.6,5.6] - new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] - new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47118] -> [.................2001:4998:14:800::1001][..443] + new: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] + new: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47118] -> [.................2001:4998:14:800::1001][..443] detected: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][sb.scorecardresearch.com] detected: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47118] -> [.................2001:4998:14:800::1001][..443] [TLS.Yahoo][Unknown][Web][Safe][cookiex.ngd.yahoo.com] detection-update: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][sb.scorecardresearch.com] - new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [MIDSTREAM] + new: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [MIDSTREAM] detected: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [TLS][Unknown][Web][Safe] detection-update: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic @@ -88,42 +88,42 @@ [PKTLENS.....: 192,111,201,202,143,108,72,72,72,72,72,1472,72,1472,72,1460,84,1472,72,72,1460,84,1327,103,72,72,111,1460,72,84,1460,72] [ENTROPIES...: 6.8,5.7,6.6,6.7,6.3,5.8,5.0,5.0,5.0,5.0,5.0,7.8,5.1,7.9,5.1,7.8,5.3,7.9,5.1,5.0,7.9,5.3,7.9,5.6,5.1,5.1,5.7,7.9,5.1,5.3,7.9,5.1] detection-update: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [TLS][Unknown][Web][Safe] - new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [MIDSTREAM] + new: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [MIDSTREAM] detected: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [TLS][Unknown][Web][Safe] detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detection-update: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [TLS][Unknown][Web][Safe] detection-update: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47118] -> [.................2001:4998:14:800::1001][..443] [TLS.Yahoo][Unknown][Web][Safe][cookiex.ngd.yahoo.com] - new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56842] -> [.....................64:ff9b::c000:4d03][..443] + new: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56842] -> [.....................64:ff9b::c000:4d03][..443] detected: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56842] -> [.....................64:ff9b::c000:4d03][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][64.media.tumblr.com] detection-update: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56842] -> [.....................64:ff9b::c000:4d03][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][64.media.tumblr.com] - new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] - new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] [MIDSTREAM] - new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49496] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] - new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43602] -> [......................64:ff9b::df9:21c6][..443] [MIDSTREAM] - new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][35892] -> [...............2a00:1450:4007:815::2002][..443] [MIDSTREAM] - new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45706] -> [...............2a00:1450:4007:80a::200e][..443] [MIDSTREAM] - new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49464] -> [...............2a00:1450:4007:809::200e][..443] [MIDSTREAM] - new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49462] -> [...............2a00:1450:4007:809::200e][..443] [MIDSTREAM] - new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57788] -> [...............2a00:1450:4007:80b::200e][..443] [MIDSTREAM] - new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49546] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] - new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44164] -> [...............2a00:1450:4007:805::2003][..443] [MIDSTREAM] - new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58618] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] - new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58616] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] - new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58614] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] - new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50906] -> [.....................64:ff9b::d83a:d582][..443] [MIDSTREAM] - new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48988] -> [...............2a00:1450:4007:811::2004][..443] [MIDSTREAM] - new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57770] -> [...............2a00:1450:4007:80b::200e][..443] [MIDSTREAM] - new: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58004] -> [...............2a00:1450:4007:808::200e][..443] [MIDSTREAM] - new: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55014] -> [...............2a00:1450:4007:806::200e][..443] [MIDSTREAM] - new: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49002] -> [...............2a00:1450:4007:811::2004][..443] [MIDSTREAM] - new: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] + new: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] [MIDSTREAM] + new: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] [MIDSTREAM] + new: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49496] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] + new: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43602] -> [......................64:ff9b::df9:21c6][..443] [MIDSTREAM] + new: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][35892] -> [...............2a00:1450:4007:815::2002][..443] [MIDSTREAM] + new: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45706] -> [...............2a00:1450:4007:80a::200e][..443] [MIDSTREAM] + new: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49464] -> [...............2a00:1450:4007:809::200e][..443] [MIDSTREAM] + new: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49462] -> [...............2a00:1450:4007:809::200e][..443] [MIDSTREAM] + new: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57788] -> [...............2a00:1450:4007:80b::200e][..443] [MIDSTREAM] + new: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49546] -> [...............2a00:1450:4007:815::2003][..443] [MIDSTREAM] + new: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44164] -> [...............2a00:1450:4007:805::2003][..443] [MIDSTREAM] + new: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58618] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] + new: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58616] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] + new: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58614] -> [...............2a00:1450:4007:805::200e][..443] [MIDSTREAM] + new: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50906] -> [.....................64:ff9b::d83a:d582][..443] [MIDSTREAM] + new: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48988] -> [...............2a00:1450:4007:811::2004][..443] [MIDSTREAM] + new: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57770] -> [...............2a00:1450:4007:80b::200e][..443] [MIDSTREAM] + new: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58004] -> [...............2a00:1450:4007:808::200e][..443] [MIDSTREAM] + new: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55014] -> [...............2a00:1450:4007:806::200e][..443] [MIDSTREAM] + new: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49002] -> [...............2a00:1450:4007:811::2004][..443] [MIDSTREAM] + new: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] detected: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][catasters.tumblr.com] - new: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55560] -> [...............2a00:1450:4007:817::200a][..443] [MIDSTREAM] + new: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55560] -> [...............2a00:1450:4007:817::200a][..443] [MIDSTREAM] detection-update: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][catasters.tumblr.com] detection-update: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][catasters.tumblr.com] analyse: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun] @@ -137,11 +137,11 @@ [PKTLENS.....: 80,80,72,589,72,1472,72,1472,1368,72,72,1073,72,157,163,523,72,72,72,338,142,72,72,102,72,1472,72,1472,72,1472,72,1472] [ENTROPIES...: 4.8,5.3,5.3,4.6,5.1,7.2,5.2,7.3,7.6,5.2,5.2,7.6,5.2,6.2,6.5,7.6,5.1,5.1,5.1,7.0,6.3,5.2,5.2,5.7,5.1,7.9,5.2,7.9,5.2,7.9,5.2,7.9] detection-update: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun][catasters.tumblr.com] - new: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49548] -> [...............2a00:1450:4007:809::200e][..443] + new: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49548] -> [...............2a00:1450:4007:809::200e][..443] detected: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic detected: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49548] -> [...............2a00:1450:4007:809::200e][..443] [TLS.Google][Google][Web][Acceptable][apis.google.com] - new: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38608] -> [...............2a00:1450:4007:80b::200a][..443] + new: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38608] -> [...............2a00:1450:4007:80b::200a][..443] detection-update: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS][Unknown][Web][Safe] analyse: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS][Unknown][Web][Safe] min| max| avg| stddev| variance| entropy @@ -179,9 +179,9 @@ [ENTROPIES...: 4.8,5.3,5.2,4.5,5.1,7.8,7.8,7.2,5.2,5.2,5.2,6.2,5.2,7.6,5.2,6.5,5.8,7.2,5.1,5.7,5.2,5.1,5.2,7.8,7.8,7.8,7.8,5.2,5.2,5.2,5.2,7.8] detected: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55560] -> [...............2a00:1450:4007:817::200a][..443] [TLS][Google][Web][Safe] detected: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [TLS][Unknown][Web][Safe] - new: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39164] -> [......................64:ff9b::6006:749][..443] + new: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39164] -> [......................64:ff9b::6006:749][..443] detected: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39164] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][sb.scorecardresearch.com] - new: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42674] -> [.....................64:ff9b::4a72:9a15][..443] [MIDSTREAM] + new: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42674] -> [.....................64:ff9b::4a72:9a15][..443] [MIDSTREAM] detection-update: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39164] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][sb.scorecardresearch.com] analyse: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] min| max| avg| stddev| variance| entropy @@ -193,80 +193,80 @@ [IATS(ms)....: 29.5,29.5,0.2,37.9,9.0,46.8,0.7,0.1,31.0,1.8,7.0,39.1,52.6,52.7,371.9,406.4,20.7,55.2,2.5,32.9,9.3,39.7,16556.7,16588.7,11.4,43.4,16.9,58.4,9.8,93.2,46.8] [PKTLENS.....: 80,80,72,692,72,342,72,152,489,72,72,359,72,1259,72,824,72,855,72,836,72,342,72,500,72,1351,72,644,72,672,72,656] [ENTROPIES...: 4.8,5.2,5.2,7.0,5.0,6.8,5.1,6.3,7.5,5.1,5.1,7.3,5.2,7.8,5.2,7.7,5.0,7.7,5.1,7.7,5.0,7.3,5.2,7.6,5.0,7.9,5.2,7.7,5.0,7.6,5.1,7.6] - new: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40190] -> [...............2a00:1450:4007:80a::200a][..443] [MIDSTREAM] + new: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40190] -> [...............2a00:1450:4007:80a::200a][..443] [MIDSTREAM] guessed: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48988] -> [...............2a00:1450:4007:811::2004][..443] [TLS][Google][Web][Safe] - idle: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48988] -> [...............2a00:1450:4007:811::2004][..443] + idle: [....36] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48988] -> [...............2a00:1450:4007:811::2004][..443] guessed: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49002] -> [...............2a00:1450:4007:811::2004][..443] [TLS][Google][Web][Safe] - idle: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49002] -> [...............2a00:1450:4007:811::2004][..443] + idle: [....40] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49002] -> [...............2a00:1450:4007:811::2004][..443] idle: [.....4] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][41266] -> [....2620:116:800d:21:8c6e:cf2c:8d6:9fb5][..443] [TLS][Unknown][Web][Safe] idle: [.....2] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][48240] -> [.....................64:ff9b::9765:789d][..443] [TLS][Unknown][Web][Safe] guessed: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] + idle: [....21] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56558] -> [.....................64:ff9b::9765:798c][..443] guessed: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] + idle: [....17] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56564] -> [.....................64:ff9b::9765:798c][..443] guessed: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] + idle: [....19] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56578] -> [.....................64:ff9b::9765:798c][..443] guessed: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] + idle: [....16] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56582] -> [.....................64:ff9b::9765:798c][..443] guessed: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] + idle: [.....1] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56592] -> [.....................64:ff9b::9765:798c][..443] guessed: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] + idle: [....18] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56594] -> [.....................64:ff9b::9765:798c][..443] idle: [....13] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][47118] -> [.................2001:4998:14:800::1001][..443] [TLS.Yahoo][Unknown][Web][Safe] idle: [....42] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55560] -> [...............2a00:1450:4007:817::200a][..443] [TLS][Google][Web][Safe] guessed: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] [TLS][Unknown][Web][Safe] - idle: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] + idle: [.....3] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56640] -> [.....................64:ff9b::9765:798c][..443] guessed: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49462] -> [...............2a00:1450:4007:809::200e][..443] [TLS][Google][Web][Safe] - idle: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49462] -> [...............2a00:1450:4007:809::200e][..443] + idle: [....28] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49462] -> [...............2a00:1450:4007:809::200e][..443] guessed: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49464] -> [...............2a00:1450:4007:809::200e][..443] [TLS][Google][Web][Safe] - idle: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49464] -> [...............2a00:1450:4007:809::200e][..443] + idle: [....27] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49464] -> [...............2a00:1450:4007:809::200e][..443] guessed: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49496] -> [...............2a00:1450:4007:815::2003][..443] [TLS][Google][Web][Safe] - idle: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49496] -> [...............2a00:1450:4007:815::2003][..443] + idle: [....23] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49496] -> [...............2a00:1450:4007:815::2003][..443] guessed: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49546] -> [...............2a00:1450:4007:815::2003][..443] [TLS][Google][Web][Safe] - idle: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49546] -> [...............2a00:1450:4007:815::2003][..443] + idle: [....30] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49546] -> [...............2a00:1450:4007:815::2003][..443] idle: [....43] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][49548] -> [...............2a00:1450:4007:809::200e][..443] [TLS.Google][Google][Web][Acceptable] idle: [.....7] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56782] -> [.....................64:ff9b::68f4:2ac8][..443] [TLS][Unknown][Web][Safe] guessed: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57770] -> [...............2a00:1450:4007:80b::200e][..443] [TLS][Google][Web][Safe] - idle: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57770] -> [...............2a00:1450:4007:80b::200e][..443] + idle: [....37] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57770] -> [...............2a00:1450:4007:80b::200e][..443] idle: [....14] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56794] -> [.....................64:ff9b::c000:4d03][..443] [TLS][Unknown][Web][Safe] guessed: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57788] -> [...............2a00:1450:4007:80b::200e][..443] [TLS][Google][Web][Safe] - idle: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57788] -> [...............2a00:1450:4007:80b::200e][..443] + idle: [....29] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57788] -> [...............2a00:1450:4007:80b::200e][..443] idle: [....20] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][56842] -> [.....................64:ff9b::c000:4d03][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun] guessed: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42674] -> [.....................64:ff9b::4a72:9a15][..443] [TLS][Unknown][Web][Safe] - idle: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42674] -> [.....................64:ff9b::4a72:9a15][..443] + idle: [....46] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42674] -> [.....................64:ff9b::4a72:9a15][..443] guessed: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45706] -> [...............2a00:1450:4007:80a::200e][..443] [TLS][Google][Web][Safe] - idle: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45706] -> [...............2a00:1450:4007:80a::200e][..443] + idle: [....26] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][45706] -> [...............2a00:1450:4007:80a::200e][..443] guessed: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58004] -> [...............2a00:1450:4007:808::200e][..443] [TLS][Google][Web][Safe] - idle: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58004] -> [...............2a00:1450:4007:808::200e][..443] + idle: [....38] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58004] -> [...............2a00:1450:4007:808::200e][..443] guessed: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50906] -> [.....................64:ff9b::d83a:d582][..443] [TLS][Unknown][Web][Safe] - idle: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50906] -> [.....................64:ff9b::d83a:d582][..443] + idle: [....35] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50906] -> [.....................64:ff9b::d83a:d582][..443] idle: [.....6] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][42908] -> [.....................64:ff9b::98c7:1593][..443] [TLS][Unknown][Web][Safe] idle: [.....5] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][57286] -> [.....................64:ff9b::8fcc:d927][..443] [TLS][Unknown][Web][Safe] idle: [....10] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58380] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe] end: [....11] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58382] -> [..2606:2800:135:155a:23ba:b2a:25ff:122d][..443] [TLS][Edgecast][Web][Safe] guessed: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][35892] -> [...............2a00:1450:4007:815::2002][..443] [TLS][Google][Web][Safe] - idle: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][35892] -> [...............2a00:1450:4007:815::2002][..443] + idle: [....25] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][35892] -> [...............2a00:1450:4007:815::2002][..443] guessed: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44164] -> [...............2a00:1450:4007:805::2003][..443] [TLS][Google][Web][Safe] - idle: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44164] -> [...............2a00:1450:4007:805::2003][..443] + idle: [....31] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][44164] -> [...............2a00:1450:4007:805::2003][..443] idle: [....12] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39152] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] idle: [....45] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][39164] -> [......................64:ff9b::6006:749][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] guessed: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58614] -> [...............2a00:1450:4007:805::200e][..443] [TLS][Google][Web][Safe] - idle: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58614] -> [...............2a00:1450:4007:805::200e][..443] + idle: [....34] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58614] -> [...............2a00:1450:4007:805::200e][..443] guessed: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58616] -> [...............2a00:1450:4007:805::200e][..443] [TLS][Google][Web][Safe] - idle: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58616] -> [...............2a00:1450:4007:805::200e][..443] + idle: [....33] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58616] -> [...............2a00:1450:4007:805::200e][..443] guessed: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58618] -> [...............2a00:1450:4007:805::200e][..443] [TLS][Google][Web][Safe] - idle: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58618] -> [...............2a00:1450:4007:805::200e][..443] + idle: [....32] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][58618] -> [...............2a00:1450:4007:805::200e][..443] guessed: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40190] -> [...............2a00:1450:4007:80a::200a][..443] [TLS][Google][Web][Safe] - idle: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40190] -> [...............2a00:1450:4007:80a::200a][..443] + idle: [....47] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][40190] -> [...............2a00:1450:4007:80a::200a][..443] idle: [....41] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43328] -> [.....................64:ff9b::4a72:9a16][..443] [TLS.Tumblr][Unknown][SocialNetwork][Fun] idle: [.....8] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43420] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] idle: [.....9] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43434] -> [.....................64:ff9b::c000:4d28][..443] [TLS][Unknown][Web][Safe] guessed: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43602] -> [......................64:ff9b::df9:21c6][..443] [TLS][Unknown][Web][Safe] - idle: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43602] -> [......................64:ff9b::df9:21c6][..443] + idle: [....24] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][43602] -> [......................64:ff9b::df9:21c6][..443] idle: [....15] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][51874] -> [.....................64:ff9b::c000:4c03][..443] [TLS][Unknown][Web][Safe] idle: [....44] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][38608] -> [...............2a00:1450:4007:80b::200a][..443] [TLS.GoogleServices][Google][Web][Acceptable] guessed: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55014] -> [...............2a00:1450:4007:806::200e][..443] [TLS][Google][Web][Safe] - idle: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55014] -> [...............2a00:1450:4007:806::200e][..443] + idle: [....39] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][55014] -> [...............2a00:1450:4007:806::200e][..443] guessed: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] [TLS][Google][Web][Safe] - idle: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] + idle: [....22] [ip6][..tcp] [2a01:cb01:2049:8b07:991d:ec85:28df:f629][50960] -> [...............2a00:1450:4007:805::2002][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/tunnelbear.pcap.out b/test/results/flow-info/default/tunnelbear.pcap.out index e2597db16..bcc494e60 100644 --- a/test/results/flow-info/default/tunnelbear.pcap.out +++ b/test/results/flow-info/default/tunnelbear.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.8.0.1][50178] -> [.104.17.154.236][..443] + new: [.....1] [ip4][..tcp] [.......10.8.0.1][50178] -> [.104.17.154.236][..443] detected: [.....1] [ip4][..tcp] [.......10.8.0.1][50178] -> [.104.17.154.236][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.tunnelbear.com] - new: [.....2] [ip4][..tcp] [.......10.8.0.1][45104] -> [..104.17.115.40][..443] - new: [.....3] [ip4][..tcp] [.......10.8.0.1][45106] -> [..104.17.115.40][..443] - new: [.....4] [ip4][..tcp] [.......10.8.0.1][45108] -> [..104.17.115.40][..443] + new: [.....2] [ip4][..tcp] [.......10.8.0.1][45104] -> [..104.17.115.40][..443] + new: [.....3] [ip4][..tcp] [.......10.8.0.1][45106] -> [..104.17.115.40][..443] + new: [.....4] [ip4][..tcp] [.......10.8.0.1][45108] -> [..104.17.115.40][..443] detected: [.....2] [ip4][..tcp] [.......10.8.0.1][45104] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] - new: [.....5] [ip4][..tcp] [.......10.8.0.1][45114] -> [..104.17.115.40][..443] + new: [.....5] [ip4][..tcp] [.......10.8.0.1][45114] -> [..104.17.115.40][..443] detected: [.....3] [ip4][..tcp] [.......10.8.0.1][45106] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detected: [.....4] [ip4][..tcp] [.......10.8.0.1][45108] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detected: [.....5] [ip4][..tcp] [.......10.8.0.1][45114] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] @@ -16,7 +16,7 @@ detection-update: [.....3] [ip4][..tcp] [.......10.8.0.1][45106] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detection-update: [.....4] [ip4][..tcp] [.......10.8.0.1][45108] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detection-update: [.....5] [ip4][..tcp] [.......10.8.0.1][45114] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] - new: [.....6] [ip4][..tcp] [.......10.8.0.1][47496] -> [162.247.243.188][..443] + new: [.....6] [ip4][..tcp] [.......10.8.0.1][47496] -> [162.247.243.188][..443] detected: [.....6] [ip4][..tcp] [.......10.8.0.1][47496] -> [162.247.243.188][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][mobile-collector.newrelic.com] detection-update: [.....6] [ip4][..tcp] [.......10.8.0.1][47496] -> [162.247.243.188][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][mobile-collector.newrelic.com] analyse: [.....2] [ip4][..tcp] [.......10.8.0.1][45104] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable] @@ -29,8 +29,8 @@ [IATS(ms)....: 4.8,10.8,0.0,6.0,71.1,71.7,62.5,63.1,0.2,0.1,0.1,0.1,2.3,2.2,58.3,58.8,0.5,0.2,0.2,0.1,0.2,0.1,0.6,0.8,214.5,265.9,52.4,51.4,53.8,54.6,51.8] [PKTLENS.....: 60,40,40,557,40,3697,40,133,40,576,40,576,40,305,40,376,361,40,576,40,150,40,40,78,40,1632,40,691,40,352,40,2871] [ENTROPIES...: 4.5,4.5,4.6,6.1,4.5,7.2,4.5,5.9,4.5,7.4,4.5,7.6,4.6,7.4,4.5,7.1,7.4,4.5,7.6,4.5,6.5,4.5,4.6,5.3,4.5,7.9,4.6,7.6,4.6,7.1,4.6,7.9] - new: [.....7] [ip4][..tcp] [.......10.8.0.1][45124] -> [..104.17.115.40][..443] - new: [.....8] [ip4][..tcp] [.......10.8.0.1][45126] -> [..104.17.115.40][..443] + new: [.....7] [ip4][..tcp] [.......10.8.0.1][45124] -> [..104.17.115.40][..443] + new: [.....8] [ip4][..tcp] [.......10.8.0.1][45126] -> [..104.17.115.40][..443] detected: [.....7] [ip4][..tcp] [.......10.8.0.1][45124] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detected: [.....8] [ip4][..tcp] [.......10.8.0.1][45126] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detection-update: [.....8] [ip4][..tcp] [.......10.8.0.1][45126] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] @@ -45,23 +45,23 @@ [IATS(ms)....: 3.4,3.9,2.0,2.9,57.3,108.0,0.8,51.4,0.3,0.1,0.1,0.1,0.1,0.1,50.9,51.9,1.0,50.4,50.8,196.8,233.7,37.7,51.5,50.9,51.1,0.1,51.0,0.5,0.2,0.4,1.0] [PKTLENS.....: 60,40,40,557,40,196,40,91,40,576,40,576,40,303,40,118,363,40,78,40,789,40,213,40,78,40,71,40,40,40,40,40] [ENTROPIES...: 4.5,4.6,4.6,6.1,4.5,6.1,4.7,5.4,4.5,7.4,4.6,7.6,4.5,7.2,4.5,5.9,7.4,4.6,5.3,4.6,7.7,4.7,6.8,4.7,5.3,4.6,5.1,4.5,4.5,4.4,4.5,4.5] - new: [.....9] [ip4][..tcp] [..10.158.132.91][38398] -> [..104.17.114.40][..443] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..10.158.132.91][38398] -> [..104.17.114.40][..443] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..10.158.132.91][38398] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] RISK: Unidirectional Traffic - new: [....10] [ip4][..tcp] [..10.158.132.91][51120] -> [........8.8.8.8][...53] [MIDSTREAM] - new: [....11] [ip4][..tcp] [.......10.8.0.1][60224] -> [...157.240.7.32][..443] + new: [....10] [ip4][..tcp] [..10.158.132.91][51120] -> [........8.8.8.8][...53] [MIDSTREAM] + new: [....11] [ip4][..tcp] [.......10.8.0.1][60224] -> [...157.240.7.32][..443] detected: [....11] [ip4][..tcp] [.......10.8.0.1][60224] -> [...157.240.7.32][..443] [TLS.Messenger][Facebook][Chat][Acceptable][mqtt-mini.facebook.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....11] [ip4][..tcp] [.......10.8.0.1][60224] -> [...157.240.7.32][..443] [TLS.Messenger][Facebook][Chat][Acceptable][mqtt-mini.facebook.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] + new: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] detected: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] [TLS][AmazonAWS][Web][Safe][capi.grammarly.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] [TLS][AmazonAWS][Web][Safe][capi.grammarly.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] [TLS][AmazonAWS][Web][Safe][capi.grammarly.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....13] [ip4][..tcp] [.......10.8.0.1][47046] -> [.74.125.200.188][.5228] + new: [....13] [ip4][..tcp] [.......10.8.0.1][47046] -> [.74.125.200.188][.5228] detected: [....13] [ip4][..tcp] [.......10.8.0.1][47046] -> [.74.125.200.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS end: [.....2] [ip4][..tcp] [.......10.8.0.1][45104] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable] @@ -72,20 +72,20 @@ end: [.....8] [ip4][..tcp] [.......10.8.0.1][45126] -> [..104.17.115.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable] detection-update: [....13] [ip4][..tcp] [.......10.8.0.1][47046] -> [.74.125.200.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable][mtalk.google.com] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS - new: [....14] [ip4][..tcp] [.......10.8.0.1][33830] -> [..104.17.114.40][..443] + new: [....14] [ip4][..tcp] [.......10.8.0.1][33830] -> [..104.17.114.40][..443] detected: [....14] [ip4][..tcp] [.......10.8.0.1][33830] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] - new: [....15] [ip4][..tcp] [.......10.8.0.1][50904] -> [.104.17.154.236][..443] - new: [....16] [ip4][..tcp] [.......10.8.0.1][33838] -> [..104.17.114.40][..443] + new: [....15] [ip4][..tcp] [.......10.8.0.1][50904] -> [.104.17.154.236][..443] + new: [....16] [ip4][..tcp] [.......10.8.0.1][33838] -> [..104.17.114.40][..443] detected: [....16] [ip4][..tcp] [.......10.8.0.1][33838] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] - new: [....17] [ip4][..tcp] [.......10.8.0.1][33842] -> [..104.17.114.40][..443] - new: [....18] [ip4][..tcp] [.......10.8.0.1][33846] -> [..104.17.114.40][..443] + new: [....17] [ip4][..tcp] [.......10.8.0.1][33842] -> [..104.17.114.40][..443] + new: [....18] [ip4][..tcp] [.......10.8.0.1][33846] -> [..104.17.114.40][..443] detected: [....15] [ip4][..tcp] [.......10.8.0.1][50904] -> [.104.17.154.236][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.tunnelbear.com] - new: [....19] [ip4][..tcp] [.......10.8.0.1][33848] -> [..104.17.114.40][..443] + new: [....19] [ip4][..tcp] [.......10.8.0.1][33848] -> [..104.17.114.40][..443] detected: [....17] [ip4][..tcp] [.......10.8.0.1][33842] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detected: [....18] [ip4][..tcp] [.......10.8.0.1][33846] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detected: [....19] [ip4][..tcp] [.......10.8.0.1][33848] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detection-update: [....14] [ip4][..tcp] [.......10.8.0.1][33830] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] - new: [....20] [ip4][..tcp] [.......10.8.0.1][48222] -> [162.247.243.188][..443] + new: [....20] [ip4][..tcp] [.......10.8.0.1][48222] -> [162.247.243.188][..443] detected: [....20] [ip4][..tcp] [.......10.8.0.1][48222] -> [162.247.243.188][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads][mobile-collector.newrelic.com] detection-update: [....18] [ip4][..tcp] [.......10.8.0.1][33846] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] detection-update: [....17] [ip4][..tcp] [.......10.8.0.1][33842] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] @@ -103,7 +103,7 @@ [IATS(ms)....: 4.1,5.3,2.0,3.4,237.7,240.1,0.0,2.4,9.3,9.4,0.2,0.1,1.4,1.5,0.1,0.1,0.1,0.1,100.5,152.6,52.3,7.0,20.6,16.0,10.0,8.0,0.8,1.3,7.0,6.2,340.4] [PKTLENS.....: 60,40,40,557,40,196,40,91,40,93,40,126,40,576,40,576,40,165,40,109,78,40,78,361,40,576,40,148,40,363,40,2940] [ENTROPIES...: 4.5,4.5,4.5,6.1,4.6,6.0,4.6,5.4,4.6,5.5,4.6,5.9,4.5,7.6,4.5,7.6,4.6,6.8,4.5,5.9,5.3,4.6,5.3,7.2,4.6,7.6,4.6,6.5,4.6,7.3,4.5,7.9] - new: [....21] [ip4][..tcp] [.......10.8.0.1][33858] -> [..104.17.114.40][..443] + new: [....21] [ip4][..tcp] [.......10.8.0.1][33858] -> [..104.17.114.40][..443] detected: [....21] [ip4][..tcp] [.......10.8.0.1][33858] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable][api.polargrizzly.com] idle: [....13] [ip4][..tcp] [.......10.8.0.1][47046] -> [.74.125.200.188][.5228] [TLS.GoogleServices][Google][Web][Acceptable] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS @@ -113,7 +113,7 @@ RISK: TLS (probably) Not Carrying HTTPS idle: [....20] [ip4][..tcp] [.......10.8.0.1][48222] -> [162.247.243.188][..443] [TLS.ADS_Analytic_Track][Unknown][Advertisement][Tracker/Ads] guessed: [....10] [ip4][..tcp] [..10.158.132.91][51120] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][] - end: [....10] [ip4][..tcp] [..10.158.132.91][51120] -> [........8.8.8.8][...53] + end: [....10] [ip4][..tcp] [..10.158.132.91][51120] -> [........8.8.8.8][...53] idle: [....12] [ip4][..tcp] [.......10.8.0.1][47594] -> [..99.83.135.170][..443] [TLS][AmazonAWS][Web][Safe] RISK: TLS (probably) Not Carrying HTTPS end: [.....9] [ip4][..tcp] [..10.158.132.91][38398] -> [..104.17.114.40][..443] [TLS.TunnelBear][Cloudflare][VPN][Acceptable] diff --git a/test/results/flow-info/default/tuya_lp.pcap.out b/test/results/flow-info/default/tuya_lp.pcap.out index 49f886ee4..00242faa3 100644 --- a/test/results/flow-info/default/tuya_lp.pcap.out +++ b/test/results/flow-info/default/tuya_lp.pcap.out @@ -1,31 +1,31 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [192.168.242.181][49154] -> [255.255.255.255][.6667] + new: [.....1] [ip4][..udp] [192.168.242.181][49154] -> [255.255.255.255][.6667] detected: [.....1] [ip4][..udp] [192.168.242.181][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....2] [ip4][..udp] [192.168.242.174][49154] -> [255.255.255.255][.6667] + new: [.....2] [ip4][..udp] [192.168.242.174][49154] -> [255.255.255.255][.6667] detected: [.....2] [ip4][..udp] [192.168.242.174][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....3] [ip4][..udp] [192.168.242.202][59727] -> [255.255.255.255][.6667] + new: [.....3] [ip4][..udp] [192.168.242.202][59727] -> [255.255.255.255][.6667] detected: [.....3] [ip4][..udp] [192.168.242.202][59727] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....4] [ip4][..udp] [192.168.242.177][49154] -> [255.255.255.255][.6667] + new: [.....4] [ip4][..udp] [192.168.242.177][49154] -> [255.255.255.255][.6667] detected: [.....4] [ip4][..udp] [192.168.242.177][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....5] [ip4][..udp] [192.168.242.170][49154] -> [255.255.255.255][.6667] + new: [.....5] [ip4][..udp] [192.168.242.170][49154] -> [255.255.255.255][.6667] detected: [.....5] [ip4][..udp] [192.168.242.170][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....6] [ip4][..udp] [192.168.242.179][49153] -> [255.255.255.255][.6667] + new: [.....6] [ip4][..udp] [192.168.242.179][49153] -> [255.255.255.255][.6667] detected: [.....6] [ip4][..udp] [192.168.242.179][49153] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....7] [ip4][..udp] [192.168.242.172][49154] -> [255.255.255.255][.6667] + new: [.....7] [ip4][..udp] [192.168.242.172][49154] -> [255.255.255.255][.6667] detected: [.....7] [ip4][..udp] [192.168.242.172][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....8] [ip4][..udp] [192.168.242.175][49154] -> [255.255.255.255][.6667] + new: [.....8] [ip4][..udp] [192.168.242.175][49154] -> [255.255.255.255][.6667] detected: [.....8] [ip4][..udp] [192.168.242.175][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [.....9] [ip4][..udp] [192.168.242.178][49154] -> [255.255.255.255][.6667] + new: [.....9] [ip4][..udp] [192.168.242.178][49154] -> [255.255.255.255][.6667] detected: [.....9] [ip4][..udp] [192.168.242.178][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [....10] [ip4][..udp] [192.168.242.180][49153] -> [255.255.255.255][.6667] + new: [....10] [ip4][..udp] [192.168.242.180][49153] -> [255.255.255.255][.6667] detected: [....10] [ip4][..udp] [192.168.242.180][49153] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [....11] [ip4][..udp] [192.168.242.240][59727] -> [255.255.255.255][.6667] + new: [....11] [ip4][..udp] [192.168.242.240][59727] -> [255.255.255.255][.6667] detected: [....11] [ip4][..udp] [192.168.242.240][59727] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [....12] [ip4][..udp] [192.168.242.234][59727] -> [255.255.255.255][.6667] + new: [....12] [ip4][..udp] [192.168.242.234][59727] -> [255.255.255.255][.6667] detected: [....12] [ip4][..udp] [192.168.242.234][59727] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] - new: [....13] [ip4][..udp] [192.168.242.176][49154] -> [255.255.255.255][.6667] + new: [....13] [ip4][..udp] [192.168.242.176][49154] -> [255.255.255.255][.6667] detected: [....13] [ip4][..udp] [192.168.242.176][49154] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] idle: [....10] [ip4][..udp] [192.168.242.180][49153] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] idle: [.....6] [ip4][..udp] [192.168.242.179][49153] -> [255.255.255.255][.6667] [TuyaLP][Unknown][IoT-Scada][Acceptable] diff --git a/test/results/flow-info/default/ubntac2.pcap.out b/test/results/flow-info/default/ubntac2.pcap.out index 969b35233..5adc2f582 100644 --- a/test/results/flow-info/default/ubntac2.pcap.out +++ b/test/results/flow-info/default/ubntac2.pcap.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.1.1][34085] -> [255.255.255.255][10001] + new: [.....1] [ip4][..udp] [....192.168.1.1][34085] -> [255.255.255.255][10001] detected: [.....1] [ip4][..udp] [....192.168.1.1][34085] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....2] [ip4][..udp] [....192.168.1.1][44641] -> [255.255.255.255][10001] + new: [.....2] [ip4][..udp] [....192.168.1.1][44641] -> [255.255.255.255][10001] detected: [.....2] [ip4][..udp] [....192.168.1.1][44641] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....3] [ip4][..udp] [....192.168.1.1][55321] -> [255.255.255.255][10001] + new: [.....3] [ip4][..udp] [....192.168.1.1][55321] -> [255.255.255.255][10001] detected: [.....3] [ip4][..udp] [....192.168.1.1][55321] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....4] [ip4][..udp] [....192.168.1.1][47871] -> [255.255.255.255][10001] + new: [.....4] [ip4][..udp] [....192.168.1.1][47871] -> [255.255.255.255][10001] detected: [.....4] [ip4][..udp] [....192.168.1.1][47871] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....5] [ip4][..udp] [....192.168.1.1][59772] -> [255.255.255.255][10001] + new: [.....5] [ip4][..udp] [....192.168.1.1][59772] -> [255.255.255.255][10001] detected: [.....5] [ip4][..udp] [....192.168.1.1][59772] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....6] [ip4][..udp] [....192.168.1.1][52220] -> [255.255.255.255][10001] + new: [.....6] [ip4][..udp] [....192.168.1.1][52220] -> [255.255.255.255][10001] detected: [.....6] [ip4][..udp] [....192.168.1.1][52220] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] update: [.....1] [ip4][..udp] [....192.168.1.1][34085] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....7] [ip4][..udp] [....192.168.1.1][47746] -> [255.255.255.255][10001] + new: [.....7] [ip4][..udp] [....192.168.1.1][47746] -> [255.255.255.255][10001] detected: [.....7] [ip4][..udp] [....192.168.1.1][47746] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] update: [.....2] [ip4][..udp] [....192.168.1.1][44641] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] - new: [.....8] [ip4][..udp] [....192.168.1.1][42838] -> [255.255.255.255][10001] + new: [.....8] [ip4][..udp] [....192.168.1.1][42838] -> [255.255.255.255][10001] detected: [.....8] [ip4][..udp] [....192.168.1.1][42838] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] idle: [.....5] [ip4][..udp] [....192.168.1.1][59772] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] idle: [.....7] [ip4][..udp] [....192.168.1.1][47746] -> [255.255.255.255][10001] [UBNTAC2][Unknown][Network][Safe] diff --git a/test/results/flow-info/default/ultrasurf.pcap.out b/test/results/flow-info/default/ultrasurf.pcap.out index 7e9de5a2f..2beb7390e 100644 --- a/test/results/flow-info/default/ultrasurf.pcap.out +++ b/test/results/flow-info/default/ultrasurf.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....65.49.68.25][50053] -> [....10.132.0.23][37898] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....65.49.68.25][50053] -> [....10.132.0.23][37898] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [....65.49.68.25][50053] -> [....10.132.0.23][37898] [UltraSurf][Unknown][VPN][Acceptable] analyse: [.....1] [ip4][..tcp] [....65.49.68.25][50053] -> [....10.132.0.23][37898] [UltraSurf][Unknown][VPN][Acceptable] min| max| avg| stddev| variance| entropy @@ -13,7 +13,7 @@ [IATS(ms)....: 0.0,21.3,0.0,11.0,29.1,61.5,0.0,10.8,0.0,9.2,30.8,10.8,0.0,20.0,0.0,29.3,0.0,0.0,0.0,9.3,30.6,150.5,0.0,11.9,141.8,0.0,17.9,20.0,0.0,20.0,10.1] [PKTLENS.....: 2628,2628,1340,1340,2628,2628,80,80,1340,1340,2628,80,1340,1340,1332,2628,80,80,80,80,1340,80,1340,1340,2628,80,80,2628,1340,1340,2628,2628] [ENTROPIES...: 7.9,7.9,7.8,7.8,7.9,7.9,5.5,5.4,7.9,7.9,7.9,5.5,7.9,7.9,7.8,7.9,5.5,5.3,5.4,5.4,7.8,5.5,7.8,7.9,7.9,5.5,5.5,7.9,7.9,7.9,7.9,7.9] - new: [.....2] [ip4][..tcp] [....10.132.0.23][38120] -> [....65.49.68.25][50053] + new: [.....2] [ip4][..tcp] [....10.132.0.23][38120] -> [....65.49.68.25][50053] detected: [.....2] [ip4][..tcp] [....10.132.0.23][38120] -> [....65.49.68.25][50053] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....2] [ip4][..tcp] [....10.132.0.23][38120] -> [....65.49.68.25][50053] [TLS][Unknown][Web][Safe][] @@ -28,7 +28,7 @@ [IATS(ms)....: 211.2,260.4,0.0,269.6,0.0,10.1,9.9,260.4,0.0,20.0,20.0,10.9,0.0,270.8,9.7,0.0,10.3,229.5,0.0,20.0,40.1,29.9,0.0,10.1,29.9,210.9,0.0,0.0,0.0,9.4,0.0] [PKTLENS.....: 60,60,52,569,52,1340,1340,1256,52,52,52,116,138,690,107,87,83,108,83,52,94,1400,86,1148,680,650,52,87,244,187,87,113] [ENTROPIES...: 4.7,5.2,5.3,6.1,5.1,7.8,7.8,7.8,5.2,5.2,5.2,6.1,6.4,7.7,6.3,5.9,5.7,6.1,5.8,5.2,6.0,7.9,5.9,7.8,7.7,7.7,5.2,5.9,6.9,6.8,5.9,6.2] - new: [.....3] [ip4][..tcp] [....10.132.0.23][38152] -> [....65.49.68.25][50053] + new: [.....3] [ip4][..tcp] [....10.132.0.23][38152] -> [....65.49.68.25][50053] detected: [.....3] [ip4][..tcp] [....10.132.0.23][38152] -> [....65.49.68.25][50053] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....3] [ip4][..tcp] [....10.132.0.23][38152] -> [....65.49.68.25][50053] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/default/upnp.pcap.out b/test/results/flow-info/default/upnp.pcap.out index 97f20a733..01d451d28 100644 --- a/test/results/flow-info/default/upnp.pcap.out +++ b/test/results/flow-info/default/upnp.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [..............fe80::3441:3d24:6d30:a807][58932] -> [................................ff02::c][.3702] + new: [.....1] [ip6][..udp] [..............fe80::3441:3d24:6d30:a807][58932] -> [................................ff02::c][.3702] detected: [.....1] [ip6][..udp] [..............fe80::3441:3d24:6d30:a807][58932] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [..192.168.61.66][58931] -> [239.255.255.250][.3702] + new: [.....2] [ip4][..udp] [..192.168.61.66][58931] -> [239.255.255.250][.3702] detected: [.....2] [ip4][..udp] [..192.168.61.66][58931] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] idle: [.....1] [ip6][..udp] [..............fe80::3441:3d24:6d30:a807][58932] -> [................................ff02::c][.3702] [WSD][Unknown][Network][Acceptable] idle: [.....2] [ip4][..udp] [..192.168.61.66][58931] -> [239.255.255.250][.3702] [WSD][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/viber.pcap.out b/test/results/flow-info/default/viber.pcap.out index 3e5d62ea8..90fb7922c 100644 --- a/test/results/flow-info/default/viber.pcap.out +++ b/test/results/flow-info/default/viber.pcap.out @@ -1,34 +1,34 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [MIDSTREAM] - new: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] + new: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [MIDSTREAM] + new: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] detected: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][Unknown][Network][Fun][graph.facebook.com] detection-update: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][Unknown][Network][Fun][graph.facebook.com] - new: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] + new: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] detected: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS.ADS_Analytic_Track][Unknown][Network][Tracker/Ads][app.adjust.com] detection-update: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS.ADS_Analytic_Track][Unknown][Network][Tracker/Ads][app.adjust.com] - new: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] + new: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] detected: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable][mapi.apptimize.com] detection-update: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable][mapi.apptimize.com] - new: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] + new: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] detected: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe][mapi.apptimize.com] detection-update: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe][mapi.apptimize.com] detection-update: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe][mapi.apptimize.com] - new: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] + new: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] detected: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe][mapi.apptimize.com] detection-update: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe][mapi.apptimize.com] - new: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] + new: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] detected: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun][media.cdn.viber.com] detection-update: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun][media.cdn.viber.com] - new: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] + new: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] detected: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][AmazonAWS][Chat][Fun][media.cdn.viber.com] detection-update: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][AmazonAWS][Chat][Fun][media.cdn.viber.com] detection-update: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][AmazonAWS][Chat][Fun][media.cdn.viber.com] - new: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] + new: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] detected: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun][dl-media.viber.com] detection-update: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun][dl-media.viber.com] - new: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] + new: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] detected: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][AmazonAWS][Chat][Fun][dl-media.viber.com] detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][AmazonAWS][Chat][Fun][dl-media.viber.com] detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][AmazonAWS][Chat][Fun][dl-media.viber.com] @@ -43,24 +43,24 @@ [PKTLENS.....: 60,60,52,235,52,1500,1500,1500,397,52,52,52,52,178,294,760,1500,1500,1500,1500,1500,1500,1500,1500,1500,1500,794,52,52,52,52,52] [ENTROPIES...: 4.6,5.2,5.2,5.6,5.1,7.2,7.5,7.5,7.3,5.1,5.2,5.2,5.2,6.4,7.2,7.7,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.9,7.7,5.2,5.2,5.1,5.2,5.1] detection-update: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][AmazonAWS][Chat][Fun][dl-media.viber.com] - new: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] - new: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] + new: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] + new: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] detected: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] [DNS.Google][Unknown][Network][Acceptable][app-measurement.com] detection-update: [....12] [ip4][..udp] [...192.168.0.17][35331] -> [...192.168.0.15][...53] [DNS.Google][Unknown][Network][Acceptable][app-measurement.com] - new: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] + new: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] detected: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] [TLS.Google][Google][Web][Acceptable][app-measurement.com] detection-update: [....13] [ip4][..tcp] [...192.168.0.17][43702] -> [..172.217.23.78][..443] [TLS.Google][Google][Web][Acceptable][app-measurement.com] - new: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353] + new: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353] detected: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_805741c9._sub._googlecast._tcp.local] - new: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] + new: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] detected: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] + new: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] detected: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable][venetia.iad.appboy.com] detection-update: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable][venetia.iad.appboy.com] - new: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] + new: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] detected: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Unknown][Web][Safe][venetia.iad.appboy.com] detection-update: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Unknown][Web][Safe][venetia.iad.appboy.com] - analyse: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] + analyse: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 10.702| 1.934| 2.902| 8424002.683| 3.500] [PKTLEN......: 52.000| 582.000| 141.700| 133.200| 17739.800| 4.500] @@ -70,12 +70,12 @@ [IATS(ms)....: 54.2,95.9,0.3,44.0,41.8,57.0,16.1,92.1,91.6,10563.9,10701.7,4192.1,4152.7,4422.1,4422.1,309.5,309.6,21.6,197.0,0.1,215.0,3974.5,3934.9,3635.3,52.6,3635.3,52.6,12.7,140.8,167.5,4361.2] [PKTLENS.....: 153,108,52,128,52,494,116,52,120,52,149,52,146,52,146,52,391,52,150,52,136,52,146,52,146,410,52,52,150,136,52,582] [ENTROPIES...: 6.4,6.0,4.8,6.2,5.0,7.6,6.1,5.0,6.1,4.9,6.3,4.9,6.4,5.0,6.5,4.9,7.4,5.0,6.5,5.0,6.3,5.0,6.5,5.0,6.4,7.4,5.0,5.0,6.5,6.4,5.0,7.6] - new: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] - new: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] + new: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] + new: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] detected: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] [Viber][AmazonAWS][VoIP][Fun] - new: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] + new: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] detected: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] [Viber][AmazonAWS][VoIP][Fun] - new: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] + new: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] detected: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS][AmazonAWS][Web][Safe][brahe.apptimize.com] detection-update: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS][AmazonAWS][Web][Safe][brahe.apptimize.com] detection-update: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS][AmazonAWS][Web][Safe][brahe.apptimize.com] @@ -89,10 +89,10 @@ [IATS(ms)....: 0.1,33.1,500.3,500.3,503.5,15.2,503.2,15.3,516.1,515.7,477.7,477.6,36.8,36.8,525.0,525.0,440.4,440.7,68.1,67.8,523.1,523.2,412.0,411.8,84.1,84.2,517.8,517.8,399.8,399.7,114.8] [PKTLENS.....: 285,48,104,285,104,48,285,62,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285,104,285,104,48,62,285] [ENTROPIES...: 6.4,5.1,3.4,6.5,3.5,5.1,6.5,4.0,3.5,6.5,3.5,5.1,4.0,6.4,3.5,6.5,3.4,5.0,4.0,6.4,3.5,6.4,3.5,5.1,4.0,6.5,3.5,6.4,3.5,5.1,4.0,6.5] - new: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] - new: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] + new: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] + new: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] detected: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][AmazonAWS][VoIP][Fun] - new: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987] + new: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987] detected: [....24] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7987] [Viber][AmazonAWS][VoIP][Fun] update: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] analyse: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][AmazonAWS][VoIP][Fun] @@ -105,29 +105,29 @@ [IATS(ms)....: 2.5,0.1,31.7,2.3,505.5,505.7,496.9,2.1,6.7,496.6,8.7,505.3,505.4,490.8,0.1,15.0,490.7,15.1,513.2,513.2,531.4,0.1,0.0,531.4,0.2,492.9,493.0,448.2,0.1,448.1,58.4] [PKTLENS.....: 285,46,48,104,62,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,285,62,104,285,104,48,40,62,285] [ENTROPIES...: 6.3,4.5,5.0,3.5,4.0,6.4,3.5,5.1,4.4,6.4,4.0,3.5,6.3,3.5,5.0,4.4,6.3,3.9,3.4,6.4,3.5,5.0,4.4,6.3,3.9,3.5,6.4,3.5,5.0,4.4,4.0,6.4] - new: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] + new: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] detected: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] - new: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] + new: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] detected: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] [ICMP][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [...192.168.0.17][35283] -> [...192.168.0.15][...53] [DNS.ADS_Analytic_Track][Unknown][Network][Tracker/Ads] update: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][Unknown][Network][Fun] update: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 420 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 26 / 26|skipped: 0|!detected: 0|guessed: 0|detection-updates: 20|updates: 4] - new: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244] + new: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244] detected: [....27] [ip4][..tcp] [..192.168.2.100][48690] -> [...52.0.252.145][.4244] [Viber][Viber][VoIP][Fun] end: [.....5] [ip4][..tcp] [...192.168.0.17][36986] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe] end: [.....6] [ip4][..tcp] [...192.168.0.17][36988] -> [..54.69.166.226][..443] [TLS][AmazonAWS][Web][Safe] guessed: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] [QUIC][Google][Web][Acceptable] - idle: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] + idle: [....11] [ip4][..udp] [...192.168.0.17][41993] -> [.172.217.23.106][..443] idle: [....19] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7985] [Viber][AmazonAWS][VoIP][Fun] idle: [....20] [ip4][..udp] [...192.168.0.17][47171] -> [....18.201.4.32][.7987] [Viber][AmazonAWS][VoIP][Fun] idle: [.....8] [ip4][..tcp] [...192.168.0.17][57520] -> [...54.230.93.96][..443] [TLS.Viber][AmazonAWS][Chat][Fun] idle: [....26] [ip4][.icmp] [...192.168.0.17] -> [...192.168.0.15] [ICMP][Unknown][Network][Acceptable] idle: [....17] [ip4][..tcp] [...192.168.0.17][55746] -> [..151.101.1.130][..443] [TLS][Unknown][Web][Safe] guessed: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] [Viber][Viber][VoIP][Fun] - idle: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] + idle: [.....1] [ip4][..tcp] [...192.168.0.17][33208] -> [...52.0.253.101][.4244] idle: [....10] [ip4][..tcp] [...192.168.0.17][53934] -> [...54.230.93.53][..443] [TLS.Viber][AmazonAWS][Chat][Fun] idle: [....15] [ip6][icmp6] [..............fe80::3207:4dff:fea3:5fa7] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] idle: [....14] [ip4][..udp] [...192.168.0.17][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] @@ -136,7 +136,7 @@ idle: [.....7] [ip4][..udp] [...192.168.0.17][37418] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun] idle: [.....2] [ip4][..udp] [...192.168.0.17][45743] -> [...192.168.0.15][...53] [DNS.Facebook][Unknown][Network][Fun] guessed: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] [TLS][AmazonAWS][Web][Safe] - end: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] + end: [....18] [ip4][..tcp] [...192.168.0.17][45424] -> [....18.201.4.32][..443] end: [....21] [ip4][..tcp] [...192.168.0.17][49048] -> [..54.187.91.182][..443] [TLS][AmazonAWS][Web][Safe] idle: [....25] [ip4][..udp] [...192.168.0.17][50097] -> [...192.168.0.15][...53] [DNS.Google][Unknown][Network][Acceptable] idle: [....23] [ip4][..udp] [...192.168.0.17][38190] -> [.....18.201.4.3][.7985] [Viber][AmazonAWS][VoIP][Fun] @@ -145,15 +145,15 @@ idle: [....16] [ip4][..udp] [...192.168.0.17][44376] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable] idle: [.....4] [ip4][..udp] [...192.168.0.17][62872] -> [...192.168.0.15][...53] [DNS][Unknown][Network][Acceptable] guessed: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] [TLS][AmazonAWS][Web][Safe] - end: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] + end: [....22] [ip4][..tcp] [...192.168.0.17][33744] -> [.....18.201.4.3][..443] idle: [.....9] [ip4][..udp] [...192.168.0.17][40445] -> [...192.168.0.15][...53] [DNS.Viber][Unknown][Network][Fun] DAEMON-EVENT: [Processed: 435 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 27|skipped: 0|!detected: 0|guessed: 4|detection-updates: 20|updates: 4] - new: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] + new: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] detected: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] [Viber][Viber][VoIP][Fun] DAEMON-EVENT: [Processed: 446 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 28|skipped: 0|!detected: 0|guessed: 4|detection-updates: 20|updates: 4] - new: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [MIDSTREAM] + new: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [MIDSTREAM] detected: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [Viber][AmazonAWS][VoIP][Fun] idle: [....29] [ip4][..tcp] [..192.168.2.100][42900] -> [..44.192.202.74][.4244] [Viber][AmazonAWS][VoIP][Fun] end: [....28] [ip4][..tcp] [..192.168.2.100][41184] -> [.....52.0.252.2][.5242] [Viber][Viber][VoIP][Fun] diff --git a/test/results/flow-info/default/vk.pcapng.out b/test/results/flow-info/default/vk.pcapng.out index add1cba01..7b314a3a8 100644 --- a/test/results/flow-info/default/vk.pcapng.out +++ b/test/results/flow-info/default/vk.pcapng.out @@ -1,15 +1,15 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.249][33904] -> [.87.240.129.131][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.249][33904] -> [.87.240.129.131][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.249][33904] -> [.87.240.129.131][..443] [TLS][VK][Web][Safe] - new: [.....2] [ip4][..tcp] [..192.168.1.249][40344] -> [.87.240.129.140][..443] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [..192.168.1.249][40344] -> [.87.240.129.140][..443] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.1.249][40344] -> [.87.240.129.140][..443] [TLS][VK][Web][Safe] detection-update: [.....2] [ip4][..tcp] [..192.168.1.249][40344] -> [.87.240.129.140][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....1] [ip4][..tcp] [..192.168.1.249][33904] -> [.87.240.129.131][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic - new: [.....3] [ip4][..tcp] [..192.168.1.249][60436] -> [..87.240.132.78][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.1.249][60436] -> [..87.240.132.78][..443] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [..192.168.1.249][60436] -> [..87.240.132.78][..443] [TLS][VK][Web][Safe] detection-update: [.....3] [ip4][..tcp] [..192.168.1.249][60436] -> [..87.240.132.78][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic @@ -25,13 +25,13 @@ [ENTROPIES...: 7.7,7.8,5.2,7.6,7.6,5.2,5.2,5.2,5.3,5.3,5.2,5.2,5.2,5.3,5.2,5.1,5.3,5.2,5.2,5.2,5.2,5.3,5.3,5.2,5.3,5.3,5.2,5.3,5.2,5.2,5.2,5.2] detection-update: [.....3] [ip4][..tcp] [..192.168.1.249][60436] -> [..87.240.132.78][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic - new: [.....4] [ip4][..tcp] [..192.168.1.249][59154] -> [.87.240.185.137][..443] - new: [.....5] [ip4][..tcp] [..192.168.1.249][32990] -> [..87.240.169.10][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.249][59154] -> [.87.240.185.137][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.249][32990] -> [..87.240.169.10][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.249][59154] -> [.87.240.185.137][..443] [TLS.VK][VK][SocialNetwork][Fun][sun9-10.userapi.com] RISK: Unidirectional Traffic detected: [.....5] [ip4][..tcp] [..192.168.1.249][32990] -> [..87.240.169.10][..443] [TLS.VK][VK][SocialNetwork][Fun][sun9-87.userapi.com] RISK: Unidirectional Traffic - new: [.....6] [ip4][..tcp] [..192.168.1.249][56504] -> [.87.240.129.135][..443] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.249][56504] -> [.87.240.129.135][..443] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..192.168.1.249][56504] -> [.87.240.129.135][..443] [TLS][VK][Web][Safe] detection-update: [.....6] [ip4][..tcp] [..192.168.1.249][56504] -> [.87.240.129.135][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic @@ -47,17 +47,17 @@ [ENTROPIES...: 7.2,7.4,5.2,5.2,7.0,7.7,7.6,5.1,5.2,7.4,7.6,7.3,7.6,7.8,5.1,5.1,5.1,5.1,5.1,5.1,5.1,5.1,7.1,7.3,5.1,5.1,5.2,5.1,7.2,7.6,7.5,5.1] detection-update: [.....2] [ip4][..tcp] [..192.168.1.249][40344] -> [.87.240.129.140][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic - new: [.....7] [ip4][..tcp] [..192.168.1.249][47934] -> [...87.240.169.3][..443] - new: [.....8] [ip4][..tcp] [..192.168.1.249][59722] -> [..87.240.169.11][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.249][47934] -> [...87.240.169.3][..443] + new: [.....8] [ip4][..tcp] [..192.168.1.249][59722] -> [..87.240.169.11][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.249][47934] -> [...87.240.169.3][..443] [TLS.VK][VK][SocialNetwork][Fun][sun9-80.userapi.com] RISK: Unidirectional Traffic detected: [.....8] [ip4][..tcp] [..192.168.1.249][59722] -> [..87.240.169.11][..443] [TLS.VK][VK][SocialNetwork][Fun][sun9-88.userapi.com] RISK: Unidirectional Traffic - new: [.....9] [ip4][..tcp] [..192.168.1.249][43938] -> [.87.240.129.135][..443] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..192.168.1.249][43938] -> [.87.240.129.135][..443] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..192.168.1.249][43938] -> [.87.240.129.135][..443] [TLS][VK][Web][Safe] detection-update: [.....9] [ip4][..tcp] [..192.168.1.249][43938] -> [.87.240.129.135][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic - new: [....10] [ip4][..tcp] [..192.168.1.249][43644] -> [..87.240.132.67][..443] [MIDSTREAM] + new: [....10] [ip4][..tcp] [..192.168.1.249][43644] -> [..87.240.132.67][..443] [MIDSTREAM] detected: [....10] [ip4][..tcp] [..192.168.1.249][43644] -> [..87.240.132.67][..443] [TLS][VK][Web][Safe] detection-update: [....10] [ip4][..tcp] [..192.168.1.249][43644] -> [..87.240.132.67][..443] [TLS][VK][Web][Safe] RISK: Unidirectional Traffic diff --git a/test/results/flow-info/default/vnc.pcap.out b/test/results/flow-info/default/vnc.pcap.out index e5665a19c..103280e15 100644 --- a/test/results/flow-info/default/vnc.pcap.out +++ b/test/results/flow-info/default/vnc.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] + new: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] detected: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port, Desktop/File Sharing analyse: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable] @@ -14,7 +14,7 @@ [IATS(ms)....: 0.5,38.8,49.9,50.3,38.8,37.1,157.8,7.0,164.5,0.7,37.5,0.2,0.0,36.4,0.0,37.3,1.2,0.0,0.2,0.7,0.0,0.7,0.5,199.0,310.3,0.0,0.1,545.3,0.7,22.3,59.5] [PKTLENS.....: 52,52,46,52,52,48,46,40,59,46,69,74,74,62,46,75,40,74,72,40,68,72,40,63,40,70,68,72,46,46,67,40] [ENTROPIES...: 4.6,4.9,4.6,5.0,5.1,5.0,4.8,4.7,5.3,4.6,5.6,5.6,5.9,5.4,4.6,5.8,4.7,5.8,5.7,4.7,5.7,5.7,4.6,5.6,4.7,5.6,5.6,5.5,4.5,4.5,5.6,4.7] - new: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] + new: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] detected: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port, Desktop/File Sharing analyse: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable] diff --git a/test/results/flow-info/default/vrrp3.pcapng.out b/test/results/flow-info/default/vrrp3.pcapng.out index 4885a55e3..59b0cb661 100644 --- a/test/results/flow-info/default/vrrp3.pcapng.out +++ b/test/results/flow-info/default/vrrp3.pcapng.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..112] [................................fe80::2] -> [...............................ff02::12] + new: [.....1] [ip6][..112] [................................fe80::2] -> [...............................ff02::12] detected: [.....1] [ip6][..112] [................................fe80::2] -> [...............................ff02::12] [VRRP][Unknown][Network][Acceptable] - new: [.....2] [ip6][..112] [................................fe80::1] -> [...............................ff02::12] + new: [.....2] [ip6][..112] [................................fe80::1] -> [...............................ff02::12] detected: [.....2] [ip6][..112] [................................fe80::1] -> [...............................ff02::12] [VRRP][Unknown][Network][Acceptable] idle: [.....2] [ip6][..112] [................................fe80::1] -> [...............................ff02::12] [VRRP][Unknown][Network][Acceptable] idle: [.....1] [ip6][..112] [................................fe80::2] -> [...............................ff02::12] [VRRP][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/vxlan.pcap.out b/test/results/flow-info/default/vxlan.pcap.out index 58539ccea..9b818baa0 100644 --- a/test/results/flow-info/default/vxlan.pcap.out +++ b/test/results/flow-info/default/vxlan.pcap.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.22.4][60887] -> [...192.168.22.5][.4789] + new: [.....1] [ip4][..udp] [...192.168.22.4][60887] -> [...192.168.22.5][.4789] detected: [.....1] [ip4][..udp] [...192.168.22.4][60887] -> [...192.168.22.5][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.22.5][43866] -> [...192.168.22.4][.4789] + new: [.....2] [ip4][..udp] [...192.168.22.5][43866] -> [...192.168.22.4][.4789] detected: [.....2] [ip4][..udp] [...192.168.22.5][43866] -> [...192.168.22.4][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [...192.168.22.4][49762] -> [...192.168.22.5][.4789] + new: [.....3] [ip4][..udp] [...192.168.22.4][49762] -> [...192.168.22.5][.4789] detected: [.....3] [ip4][..udp] [...192.168.22.4][49762] -> [...192.168.22.5][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....4] [ip4][..udp] [...192.168.22.5][60230] -> [...192.168.22.4][.4789] + new: [.....4] [ip4][..udp] [...192.168.22.5][60230] -> [...192.168.22.4][.4789] detected: [.....4] [ip4][..udp] [...192.168.22.5][60230] -> [...192.168.22.4][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....5] [ip4][..udp] [...192.168.22.4][60351] -> [...192.168.22.5][.4789] + new: [.....5] [ip4][..udp] [...192.168.22.4][60351] -> [...192.168.22.5][.4789] detected: [.....5] [ip4][..udp] [...192.168.22.4][60351] -> [...192.168.22.5][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....6] [ip4][..udp] [...192.168.22.5][50251] -> [...192.168.22.4][.4789] + new: [.....6] [ip4][..udp] [...192.168.22.5][50251] -> [...192.168.22.4][.4789] detected: [.....6] [ip4][..udp] [...192.168.22.5][50251] -> [...192.168.22.4][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....7] [ip4][..udp] [...192.168.22.4][40646] -> [...192.168.22.5][.4789] + new: [.....7] [ip4][..udp] [...192.168.22.4][40646] -> [...192.168.22.5][.4789] detected: [.....7] [ip4][..udp] [...192.168.22.4][40646] -> [...192.168.22.5][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....8] [ip4][..udp] [...192.168.22.5][36286] -> [...192.168.22.4][.4789] + new: [.....8] [ip4][..udp] [...192.168.22.5][36286] -> [...192.168.22.4][.4789] detected: [.....8] [ip4][..udp] [...192.168.22.5][36286] -> [...192.168.22.4][.4789] [VXLAN][Unknown][Network][Acceptable] - new: [.....9] [ip4][..udp] [...192.168.22.4][60230] -> [...192.168.22.5][.4789] + new: [.....9] [ip4][..udp] [...192.168.22.4][60230] -> [...192.168.22.5][.4789] detected: [.....9] [ip4][..udp] [...192.168.22.4][60230] -> [...192.168.22.5][.4789] [VXLAN][Unknown][Network][Acceptable] analyse: [.....8] [ip4][..udp] [...192.168.22.5][36286] -> [...192.168.22.4][.4789] [VXLAN][Unknown][Network][Acceptable] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/wa_video.pcap.out b/test/results/flow-info/default/wa_video.pcap.out index 40f9032ae..1207919c0 100644 --- a/test/results/flow-info/default/wa_video.pcap.out +++ b/test/results/flow-info/default/wa_video.pcap.out @@ -1,22 +1,22 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [MIDSTREAM] - new: [.....3] [ip4][..udp] [...192.168.2.12][53688] -> [....31.13.86.48][.3478] + new: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [MIDSTREAM] + new: [.....3] [ip4][..udp] [...192.168.2.12][53688] -> [....31.13.86.48][.3478] detected: [.....3] [ip4][..udp] [...192.168.2.12][53688] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....4] [ip4][..udp] [...192.168.2.12][53688] -> [..185.60.216.51][.3478] + new: [.....4] [ip4][..udp] [...192.168.2.12][53688] -> [..185.60.216.51][.3478] detected: [.....4] [ip4][..udp] [...192.168.2.12][53688] -> [..185.60.216.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....5] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.193.48][.3478] + new: [.....5] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.193.48][.3478] detected: [.....5] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.193.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....6] [ip4][..udp] [...192.168.2.12][53688] -> [..179.60.192.48][.3478] + new: [.....6] [ip4][..udp] [...192.168.2.12][53688] -> [..179.60.192.48][.3478] detected: [.....6] [ip4][..udp] [...192.168.2.12][53688] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....7] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.196.62][.3478] + new: [.....7] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.196.62][.3478] detected: [.....7] [ip4][..udp] [...192.168.2.12][53688] -> [.157.240.196.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....8] [ip4][..udp] [...192.168.2.12][51277] -> [239.255.255.250][.1900] + new: [.....8] [ip4][..udp] [...192.168.2.12][51277] -> [239.255.255.250][.1900] detected: [.....8] [ip4][..udp] [...192.168.2.12][51277] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - analyse: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] + analyse: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 2.404| 0.176| 0.474| 224629.621| 2.400] [PKTLEN......: 52.000| 1440.000| 268.400| 335.200| 112371.900| 4.200] @@ -36,12 +36,12 @@ [IATS(ms)....: 0.1,13.1,1.1,548.2,0.8,550.1,16.2,0.1,20.3,0.1,23.6,0.6,14.5,1.0,0.1,79.3,29.6,0.1,23.2,0.2,20.0,0.3,24.4,3.5,104.4,150.5,15.9,197.6,75.4,2.5,68.2] [PKTLENS.....: 154,154,72,72,154,500,72,500,500,500,500,500,500,34,500,500,30,500,500,500,500,500,500,500,154,72,48,500,48,500,500,48] [ENTROPIES...: 6.5,6.5,5.2,5.3,6.5,7.4,5.3,7.5,7.5,7.5,7.5,7.4,7.5,4.6,7.5,7.5,4.5,7.5,7.5,7.5,7.4,7.5,7.4,7.4,6.5,5.3,3.8,7.3,3.8,7.4,7.4,4.2] - new: [.....9] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....9] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....9] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [....10] [ip4][..udp] [...192.168.2.12][53688] -> [.....1.60.78.64][59491] + new: [....10] [ip4][..udp] [...192.168.2.12][53688] -> [.....1.60.78.64][59491] detected: [....10] [ip4][..udp] [...192.168.2.12][53688] -> [.....1.60.78.64][59491] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....11] [ip4][..udp] [...192.168.2.12][53688] -> [...91.252.56.51][32641] + new: [....11] [ip4][..udp] [...192.168.2.12][53688] -> [...91.252.56.51][32641] detected: [....11] [ip4][..udp] [...192.168.2.12][53688] -> [...91.252.56.51][32641] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....11] [ip4][..udp] [...192.168.2.12][53688] -> [...91.252.56.51][32641] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] @@ -54,11 +54,11 @@ [IATS(ms)....: 707.1,619.8,619.1,1979.4,36.3,69.7,132.0,26.4,100.1,1.5,36.5,24.6,0.1,0.2,0.3,0.3,10.7,26.1,102.4,15.1,0.3,0.6,0.5,0.9,0.2,0.8,7.6,0.9,0.1,0.6,131.2] [PKTLENS.....: 72,72,72,72,72,72,72,156,72,165,150,130,899,899,899,898,1146,194,143,198,1022,1022,1022,1022,1022,1020,150,920,920,920,1048,210] [ENTROPIES...: 5.6,5.7,5.5,5.6,5.4,5.5,5.6,6.6,5.7,6.7,6.5,6.4,7.7,7.8,7.8,7.8,7.8,6.7,6.4,6.9,7.8,7.8,7.8,7.8,7.8,7.8,6.6,7.8,7.8,7.8,7.8,7.0] - new: [....12] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [....12] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [....12] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....13] [ip4][..udp] [...192.168.2.12][65025] -> [239.255.255.250][.1900] + new: [....13] [ip4][..udp] [...192.168.2.12][65025] -> [239.255.255.250][.1900] detected: [....13] [ip4][..udp] [...192.168.2.12][65025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....14] [ip4][..udp] [...192.168.2.12][51458] -> [239.255.255.250][.1900] + new: [....14] [ip4][..udp] [...192.168.2.12][51458] -> [239.255.255.250][.1900] detected: [....14] [ip4][..udp] [...192.168.2.12][51458] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] idle: [.....8] [ip4][..udp] [...192.168.2.12][51277] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [.....9] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -74,7 +74,7 @@ idle: [....11] [ip4][..udp] [...192.168.2.12][53688] -> [...91.252.56.51][32641] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port guessed: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] - idle: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] + idle: [.....2] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] idle: [....10] [ip4][..udp] [...192.168.2.12][53688] -> [.....1.60.78.64][59491] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/wa_voice.pcap.out b/test/results/flow-info/default/wa_voice.pcap.out index 3768fa808..05d0b1b12 100644 --- a/test/results/flow-info/default/wa_voice.pcap.out +++ b/test/results/flow-info/default/wa_voice.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] + new: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] detected: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] - new: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] + new: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] detected: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][g.whatsapp.net] detection-update: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][g.whatsapp.net] - new: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [ApplePush][Apple][Cloud][Acceptable] - new: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] + new: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] detected: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] analyse: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -23,10 +23,10 @@ [IATS(ms)....: 40.7,137.0,170.4,304.1,130.2,0.1,31.0,5.3,0.0,0.4,0.0,0.2,0.0,1.2,210.1,0.3,0.0,0.0,0.2,0.0,0.3,41.4,129.9,0.1,0.0,0.0,0.0,1.0,24.3,131.9,0.0] [PKTLENS.....: 64,60,52,308,52,109,103,137,1440,92,1440,155,1440,164,1440,52,52,52,52,52,52,52,1045,84,98,119,82,111,52,338,52,52] [ENTROPIES...: 4.5,5.1,5.0,7.2,5.1,6.1,6.0,6.5,7.9,5.9,7.9,6.7,7.9,6.7,7.9,5.0,5.0,5.0,5.1,5.1,5.1,5.0,7.8,5.6,5.9,6.2,5.7,6.2,5.0,7.3,5.0,5.0] - new: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] + new: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] detected: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable][media-mxp1-1.cdn.whatsapp.net] detection-update: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable][media-mxp1-1.cdn.whatsapp.net] - new: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] + new: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] detected: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] detection-update: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] analyse: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable] @@ -39,34 +39,34 @@ [IATS(ms)....: 19.7,127.7,2.8,126.3,2.9,0.0,0.0,21.0,0.2,145.2,0.0,0.0,0.0,0.0,0.0,163.3,0.0,0.0,0.0,0.2,0.0,0.0,17.5,0.3,0.0,0.0,2.4,0.3,0.1,0.4,0.6] [PKTLENS.....: 64,60,52,569,52,1440,1440,335,52,52,116,98,95,87,388,311,52,223,126,83,52,100,484,52,52,52,52,1440,52,1440,1440,83] [ENTROPIES...: 4.5,5.2,5.0,5.0,5.1,7.8,7.9,7.4,5.0,5.1,6.0,6.0,6.0,5.7,7.3,7.2,5.1,7.0,6.3,5.8,5.0,6.0,7.5,4.9,5.0,5.0,4.9,7.9,5.0,7.9,7.9,5.7] - new: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [TLS][Apple][Web][Safe] - new: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] + new: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] detected: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] + new: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] detected: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] + new: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] detected: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] + new: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] detected: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] + new: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] detected: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] + new: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] detected: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] + new: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] detected: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] + new: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] detected: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] + new: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] detected: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] + new: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] detected: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] + new: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] detected: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][pps.whatsapp.net] detection-update: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][pps.whatsapp.net] - new: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] + new: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] detected: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] detection-update: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] analyse: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable] @@ -79,9 +79,9 @@ [IATS(ms)....: 37.2,39.0,11.1,51.5,1.0,0.1,0.0,42.8,0.1,34.6,3.8,0.4,0.2,0.3,76.2,0.0,34.9,0.4,0.3,3.6,0.0,2.9,1.3,3.4,77.4,53.7,129.1,1.4,0.0,0.2,0.1] [PKTLENS.....: 64,60,52,569,52,1440,1440,333,52,52,116,98,95,87,244,223,126,52,52,83,52,83,52,87,52,52,502,52,1440,1440,1440,1440] [ENTROPIES...: 4.4,5.1,4.9,4.8,5.0,7.8,7.9,7.3,4.9,4.9,6.1,5.9,5.9,5.8,7.0,7.0,6.4,4.9,4.9,5.6,5.1,5.8,5.0,5.9,4.9,5.0,7.6,4.9,7.9,7.9,7.8,7.8] - new: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] + new: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] detected: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] @@ -94,7 +94,7 @@ [IATS(ms)....: 0.1,13.4,0.1,12194.2,12196.2,104.4,0.1,105.1,0.0,108.6,104.6,3043.3,3048.9,3100.9,3096.0,3015.3,3016.6,2001.9,2.2,107.1,164.0,190.1,88.5,28.8,198.6,134.0,3008.1,91.0,35.6,0.3,36.5] [PKTLENS.....: 154,154,72,72,34,30,154,154,72,72,34,30,34,30,34,30,34,30,74,54,232,261,240,150,306,234,302,34,30,154,154,72] [ENTROPIES...: 6.5,6.5,5.3,5.3,4.6,4.5,6.5,6.5,5.2,5.1,4.6,4.5,4.6,4.5,4.6,4.5,4.6,4.5,5.7,5.2,7.0,7.1,7.1,6.6,7.3,7.0,7.2,4.6,4.5,6.5,6.5,5.2] - new: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] + new: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] detected: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] @@ -109,20 +109,20 @@ [ENTROPIES...: 5.5,5.6,5.5,5.6,5.5,5.6,6.9,7.1,6.7,6.6,7.3,6.5,6.7,6.6,6.5,6.6,6.5,6.6,6.7,6.8,6.7,6.7,6.7,6.7,6.5,5.2,6.6,6.6,6.7,6.6,6.6,6.8] detection-update: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] detection-update: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [MIDSTREAM] + new: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [MIDSTREAM] update: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] update: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable] - new: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] + new: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] detected: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] + new: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] detected: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] + new: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] detected: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] [ICMP][Unknown][Network][Acceptable] idle: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [ApplePush][Apple][Cloud][Acceptable] not-detected: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [Unknown][Unknown][Unrated] - idle: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] + idle: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] end: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable] idle: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] idle: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] diff --git a/test/results/flow-info/default/waze.pcap.out b/test/results/flow-info/default/waze.pcap.out index 54fc47ee4..9645f3526 100644 --- a/test/results/flow-info/default/waze.pcap.out +++ b/test/results/flow-info/default/waze.pcap.out @@ -1,16 +1,16 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...10.16.37.157][42256] -> [..174.37.231.81][.5222] [MIDSTREAM] - new: [.....2] [ip4][..udp] [.......10.8.0.1][46214] -> [..200.89.75.198][..123] + new: [.....1] [ip4][..tcp] [...10.16.37.157][42256] -> [..174.37.231.81][.5222] [MIDSTREAM] + new: [.....2] [ip4][..udp] [.......10.8.0.1][46214] -> [..200.89.75.198][..123] detected: [.....2] [ip4][..udp] [.......10.8.0.1][46214] -> [..200.89.75.198][..123] [NTP][Unknown][System][Acceptable] - new: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] + new: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] detected: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] [HTTP][Unknown][Web][Acceptable][xtra1.gpsonextra.net] - new: [.....4] [ip4][..tcp] [.......10.8.0.1][45529] -> [.54.230.227.172][...80] - new: [.....5] [ip4][..tcp] [.......10.8.0.1][36100] -> [..46.51.173.182][..443] - new: [.....6] [ip4][..tcp] [.......10.8.0.1][36102] -> [..46.51.173.182][..443] + new: [.....4] [ip4][..tcp] [.......10.8.0.1][45529] -> [.54.230.227.172][...80] + new: [.....5] [ip4][..tcp] [.......10.8.0.1][36100] -> [..46.51.173.182][..443] + new: [.....6] [ip4][..tcp] [.......10.8.0.1][36102] -> [..46.51.173.182][..443] detected: [.....4] [ip4][..tcp] [.......10.8.0.1][45529] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][roadshields.waze.com] - new: [.....7] [ip4][..tcp] [.......10.8.0.1][36585] -> [.173.194.118.48][..443] + new: [.....7] [ip4][..tcp] [.......10.8.0.1][36585] -> [.173.194.118.48][..443] detected: [.....5] [ip4][..tcp] [.......10.8.0.1][36100] -> [..46.51.173.182][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [.....7] [ip4][..tcp] [.......10.8.0.1][36585] -> [.173.194.118.48][..443] [TLS][Google][Web][Safe][] @@ -19,7 +19,7 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [.....7] [ip4][..tcp] [.......10.8.0.1][36585] -> [.173.194.118.48][..443] [TLS][Google][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [.....8] [ip4][..tcp] [.......10.8.0.1][45536] -> [.54.230.227.172][...80] + new: [.....8] [ip4][..tcp] [.......10.8.0.1][45536] -> [.54.230.227.172][...80] detected: [.....8] [ip4][..tcp] [.......10.8.0.1][45536] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][cres.waze.com] detection-update: [.....6] [ip4][..tcp] [.......10.8.0.1][36102] -> [..46.51.173.182][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher @@ -29,15 +29,15 @@ RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher detection-update: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] [HTTP][Unknown][Download][Acceptable][xtra1.gpsonextra.net] RISK: Binary App Transfer - new: [.....9] [ip4][..tcp] [.......10.8.0.1][45538] -> [.54.230.227.172][...80] - new: [....10] [ip4][..tcp] [.......10.8.0.1][45540] -> [.54.230.227.172][...80] + new: [.....9] [ip4][..tcp] [.......10.8.0.1][45538] -> [.54.230.227.172][...80] + new: [....10] [ip4][..tcp] [.......10.8.0.1][45540] -> [.54.230.227.172][...80] detected: [.....9] [ip4][..tcp] [.......10.8.0.1][45538] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][cres.waze.com] detected: [....10] [ip4][..tcp] [.......10.8.0.1][45540] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][roadshields.waze.com] - new: [....11] [ip4][..tcp] [.......10.8.0.1][51049] -> [.176.34.103.105][..443] - new: [....12] [ip4][..tcp] [.......10.8.0.1][51050] -> [.176.34.103.105][..443] - new: [....13] [ip4][..tcp] [.......10.8.0.1][51051] -> [.176.34.103.105][..443] - new: [....14] [ip4][..tcp] [.......10.8.0.1][39010] -> [..52.17.114.219][..443] - new: [....15] [ip4][..tcp] [.......10.8.0.1][45546] -> [.54.230.227.172][...80] + new: [....11] [ip4][..tcp] [.......10.8.0.1][51049] -> [.176.34.103.105][..443] + new: [....12] [ip4][..tcp] [.......10.8.0.1][51050] -> [.176.34.103.105][..443] + new: [....13] [ip4][..tcp] [.......10.8.0.1][51051] -> [.176.34.103.105][..443] + new: [....14] [ip4][..tcp] [.......10.8.0.1][39010] -> [..52.17.114.219][..443] + new: [....15] [ip4][..tcp] [.......10.8.0.1][45546] -> [.54.230.227.172][...80] detected: [....11] [ip4][..tcp] [.......10.8.0.1][51049] -> [.176.34.103.105][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....12] [ip4][..tcp] [.......10.8.0.1][51050] -> [.176.34.103.105][..443] [TLS][AmazonAWS][Web][Safe][] @@ -47,7 +47,7 @@ detected: [....14] [ip4][..tcp] [.......10.8.0.1][39010] -> [..52.17.114.219][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....15] [ip4][..tcp] [.......10.8.0.1][45546] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][cres.waze.com] - new: [....16] [ip4][..tcp] [.......10.8.0.1][45552] -> [.54.230.227.172][...80] + new: [....16] [ip4][..tcp] [.......10.8.0.1][45552] -> [.54.230.227.172][...80] detected: [....16] [ip4][..tcp] [.......10.8.0.1][45552] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][cres.waze.com] detection-update: [....13] [ip4][..tcp] [.......10.8.0.1][51051] -> [.176.34.103.105][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) @@ -55,7 +55,7 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....14] [ip4][..tcp] [.......10.8.0.1][39010] -> [..52.17.114.219][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older) - new: [....17] [ip4][..tcp] [.......10.8.0.1][45554] -> [.54.230.227.172][...80] + new: [....17] [ip4][..tcp] [.......10.8.0.1][45554] -> [.54.230.227.172][...80] detected: [....17] [ip4][..tcp] [.......10.8.0.1][45554] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable][cres.waze.com] analyse: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] [HTTP][Unknown][Download][Acceptable] min| max| avg| stddev| variance| entropy @@ -87,24 +87,24 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....11] [ip4][..tcp] [.......10.8.0.1][51049] -> [.176.34.103.105][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older) - new: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] + new: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] detected: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....19] [ip4][..tcp] [.......10.8.0.1][36312] -> [.176.34.186.180][..443] + new: [....19] [ip4][..tcp] [.......10.8.0.1][36312] -> [.176.34.186.180][..443] detection-update: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older) detected: [....19] [ip4][..tcp] [.......10.8.0.1][36312] -> [.176.34.186.180][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....20] [ip4][..tcp] [.......10.8.0.1][36314] -> [.176.34.186.180][..443] + new: [....20] [ip4][..tcp] [.......10.8.0.1][36314] -> [.176.34.186.180][..443] detection-update: [....19] [ip4][..tcp] [.......10.8.0.1][36312] -> [.176.34.186.180][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....19] [ip4][..tcp] [.......10.8.0.1][36312] -> [.176.34.186.180][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older) detected: [....20] [ip4][..tcp] [.......10.8.0.1][36314] -> [.176.34.186.180][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....21] [ip4][..tcp] [.......10.8.0.1][36316] -> [.176.34.186.180][..443] + new: [....21] [ip4][..tcp] [.......10.8.0.1][36316] -> [.176.34.186.180][..443] detection-update: [....20] [ip4][..tcp] [.......10.8.0.1][36314] -> [.176.34.186.180][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....20] [ip4][..tcp] [.......10.8.0.1][36314] -> [.176.34.186.180][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] @@ -113,15 +113,15 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....21] [ip4][..tcp] [.......10.8.0.1][36316] -> [.176.34.186.180][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older) - new: [....22] [ip4][..tcp] [...10.16.37.157][43991] -> [...200.160.4.31][...80] [MIDSTREAM] - new: [....23] [ip4][..tcp] [...10.16.37.157][46473] -> [...200.160.4.49][...80] [MIDSTREAM] - new: [....24] [ip4][..tcp] [...10.16.37.157][41823] -> [...200.160.4.49][...80] [MIDSTREAM] - new: [....25] [ip4][..tcp] [.......10.8.0.1][45169] -> [..200.160.4.198][...80] [MIDSTREAM] - new: [....26] [ip4][..tcp] [...10.16.37.157][52953] -> [...200.160.4.49][...80] [MIDSTREAM] - new: [....27] [ip4][..tcp] [...10.16.37.157][52746] -> [...200.160.4.49][...80] [MIDSTREAM] - new: [....28] [ip4][..tcp] [.......10.8.0.1][60574] -> [...200.160.4.49][...80] [MIDSTREAM] - new: [....29] [ip4][..tcp] [.......10.8.0.1][43089] -> [..200.160.4.198][..443] [MIDSTREAM] - new: [....30] [ip4][..tcp] [.......10.8.0.1][60479] -> [...200.160.4.49][..443] [MIDSTREAM] + new: [....22] [ip4][..tcp] [...10.16.37.157][43991] -> [...200.160.4.31][...80] [MIDSTREAM] + new: [....23] [ip4][..tcp] [...10.16.37.157][46473] -> [...200.160.4.49][...80] [MIDSTREAM] + new: [....24] [ip4][..tcp] [...10.16.37.157][41823] -> [...200.160.4.49][...80] [MIDSTREAM] + new: [....25] [ip4][..tcp] [.......10.8.0.1][45169] -> [..200.160.4.198][...80] [MIDSTREAM] + new: [....26] [ip4][..tcp] [...10.16.37.157][52953] -> [...200.160.4.49][...80] [MIDSTREAM] + new: [....27] [ip4][..tcp] [...10.16.37.157][52746] -> [...200.160.4.49][...80] [MIDSTREAM] + new: [....28] [ip4][..tcp] [.......10.8.0.1][60574] -> [...200.160.4.49][...80] [MIDSTREAM] + new: [....29] [ip4][..tcp] [.......10.8.0.1][43089] -> [..200.160.4.198][..443] [MIDSTREAM] + new: [....30] [ip4][..tcp] [.......10.8.0.1][60479] -> [...200.160.4.49][..443] [MIDSTREAM] analyse: [....18] [ip4][..tcp] [.......10.8.0.1][39021] -> [..52.17.114.219][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.416| 0.170| 0.135| 18249.146| 4.400] @@ -154,14 +154,14 @@ [IATS(ms)....: 9.1,9.5,461.2,462.1,319.2,370.8,51.5,0.6,58.7,59.3,267.3,318.5,5838.7,5890.9,1.9,3.1,232.7,285.9,1892.6,1892.4,50.9,52.2,293.0,345.1,0.6,0.4,1258.6,1310.0,5014.8,5014.5,51.5] [PKTLENS.....: 60,40,40,222,40,1052,40,2175,40,366,40,274,40,221,40,541,40,93,40,1052,40,3646,40,189,40,301,40,317,40,77,40,40] [ENTROPIES...: 4.3,4.7,4.7,5.2,4.6,7.0,4.7,7.5,4.6,7.3,4.7,7.0,4.7,7.0,4.7,7.5,4.7,6.1,4.7,7.8,4.7,7.9,4.7,6.8,4.7,7.2,4.7,7.3,4.7,5.7,4.6,4.7] - new: [....31] [ip4][..tcp] [.......10.8.0.1][36134] -> [..46.51.173.182][..443] + new: [....31] [ip4][..tcp] [.......10.8.0.1][36134] -> [..46.51.173.182][..443] detected: [....31] [ip4][..tcp] [.......10.8.0.1][36134] -> [..46.51.173.182][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....31] [ip4][..tcp] [.......10.8.0.1][36134] -> [..46.51.173.182][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....32] [ip4][..tcp] [.......10.8.0.1][50828] -> [108.168.176.228][..443] + new: [....32] [ip4][..tcp] [.......10.8.0.1][50828] -> [108.168.176.228][..443] detected: [....32] [ip4][..tcp] [.......10.8.0.1][50828] -> [108.168.176.228][..443] [WhatsApp][Unknown][Chat][Acceptable] - new: [....33] [ip4][..tcp] [.......10.8.0.1][36137] -> [..46.51.173.182][..443] + new: [....33] [ip4][..tcp] [.......10.8.0.1][36137] -> [..46.51.173.182][..443] detected: [....33] [ip4][..tcp] [.......10.8.0.1][36137] -> [..46.51.173.182][..443] [TLS][AmazonAWS][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....33] [ip4][..tcp] [.......10.8.0.1][36137] -> [..46.51.173.182][..443] [TLS][AmazonAWS][Web][Safe][] @@ -169,7 +169,7 @@ detection-update: [....33] [ip4][..tcp] [.......10.8.0.1][36137] -> [..46.51.173.182][..443] [TLS.Waze][AmazonAWS][Web][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher guessed: [....26] [ip4][..tcp] [...10.16.37.157][52953] -> [...200.160.4.49][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....26] [ip4][..tcp] [...10.16.37.157][52953] -> [...200.160.4.49][...80] + end: [....26] [ip4][..tcp] [...10.16.37.157][52953] -> [...200.160.4.49][...80] end: [.....4] [ip4][..tcp] [.......10.8.0.1][45529] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable] end: [.....8] [ip4][..tcp] [.......10.8.0.1][45536] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable] end: [.....9] [ip4][..tcp] [.......10.8.0.1][45538] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable] @@ -179,7 +179,7 @@ end: [....17] [ip4][..tcp] [.......10.8.0.1][45554] -> [.54.230.227.172][...80] [HTTP.Waze][AmazonAWS][Web][Acceptable] idle: [....32] [ip4][..tcp] [.......10.8.0.1][50828] -> [108.168.176.228][..443] [WhatsApp][Unknown][Chat][Acceptable] guessed: [....25] [ip4][..tcp] [.......10.8.0.1][45169] -> [..200.160.4.198][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....25] [ip4][..tcp] [.......10.8.0.1][45169] -> [..200.160.4.198][...80] + end: [....25] [ip4][..tcp] [.......10.8.0.1][45169] -> [..200.160.4.198][...80] end: [.....5] [ip4][..tcp] [.......10.8.0.1][36100] -> [..46.51.173.182][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher end: [.....6] [ip4][..tcp] [.......10.8.0.1][36102] -> [..46.51.173.182][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] @@ -195,7 +195,7 @@ end: [....21] [ip4][..tcp] [.......10.8.0.1][36316] -> [.176.34.186.180][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older) guessed: [....29] [ip4][..tcp] [.......10.8.0.1][43089] -> [..200.160.4.198][..443] [TLS][Unknown][Web][Safe] - end: [....29] [ip4][..tcp] [.......10.8.0.1][43089] -> [..200.160.4.198][..443] + end: [....29] [ip4][..tcp] [.......10.8.0.1][43089] -> [..200.160.4.198][..443] end: [....14] [ip4][..tcp] [.......10.8.0.1][39010] -> [..52.17.114.219][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older) idle: [.....7] [ip4][..tcp] [.......10.8.0.1][36585] -> [.173.194.118.48][..443] [TLS][Google][Web][Safe] @@ -209,20 +209,20 @@ end: [....13] [ip4][..tcp] [.......10.8.0.1][51051] -> [.176.34.103.105][..443] [TLS.Waze][AmazonAWS][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older) guessed: [....24] [ip4][..tcp] [...10.16.37.157][41823] -> [...200.160.4.49][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....24] [ip4][..tcp] [...10.16.37.157][41823] -> [...200.160.4.49][...80] + end: [....24] [ip4][..tcp] [...10.16.37.157][41823] -> [...200.160.4.49][...80] guessed: [....22] [ip4][..tcp] [...10.16.37.157][43991] -> [...200.160.4.31][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....22] [ip4][..tcp] [...10.16.37.157][43991] -> [...200.160.4.31][...80] + end: [....22] [ip4][..tcp] [...10.16.37.157][43991] -> [...200.160.4.31][...80] guessed: [....28] [ip4][..tcp] [.......10.8.0.1][60574] -> [...200.160.4.49][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....28] [ip4][..tcp] [.......10.8.0.1][60574] -> [...200.160.4.49][...80] + end: [....28] [ip4][..tcp] [.......10.8.0.1][60574] -> [...200.160.4.49][...80] end: [.....3] [ip4][..tcp] [.......10.8.0.1][54915] -> [..65.39.128.135][...80] [HTTP][Unknown][Download][Acceptable] RISK: Binary App Transfer guessed: [....23] [ip4][..tcp] [...10.16.37.157][46473] -> [...200.160.4.49][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....23] [ip4][..tcp] [...10.16.37.157][46473] -> [...200.160.4.49][...80] + end: [....23] [ip4][..tcp] [...10.16.37.157][46473] -> [...200.160.4.49][...80] guessed: [....30] [ip4][..tcp] [.......10.8.0.1][60479] -> [...200.160.4.49][..443] [TLS][Unknown][Web][Safe] - end: [....30] [ip4][..tcp] [.......10.8.0.1][60479] -> [...200.160.4.49][..443] + end: [....30] [ip4][..tcp] [.......10.8.0.1][60479] -> [...200.160.4.49][..443] idle: [.....2] [ip4][..udp] [.......10.8.0.1][46214] -> [..200.89.75.198][..123] [NTP][Unknown][System][Acceptable] guessed: [....27] [ip4][..tcp] [...10.16.37.157][52746] -> [...200.160.4.49][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....27] [ip4][..tcp] [...10.16.37.157][52746] -> [...200.160.4.49][...80] + end: [....27] [ip4][..tcp] [...10.16.37.157][52746] -> [...200.160.4.49][...80] not-detected: [.....1] [ip4][..tcp] [...10.16.37.157][42256] -> [..174.37.231.81][.5222] [Unknown][Unknown][Unrated] - end: [.....1] [ip4][..tcp] [...10.16.37.157][42256] -> [..174.37.231.81][.5222] + end: [.....1] [ip4][..tcp] [...10.16.37.157][42256] -> [..174.37.231.81][.5222] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/webex.pcap.out b/test/results/flow-info/default/webex.pcap.out index 84c084e80..2041598f0 100644 --- a/test/results/flow-info/default/webex.pcap.out +++ b/test/results/flow-info/default/webex.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.8.0.1][41346] -> [..64.68.105.103][..443] + new: [.....1] [ip4][..tcp] [.......10.8.0.1][41346] -> [..64.68.105.103][..443] detected: [.....1] [ip4][..tcp] [.......10.8.0.1][41346] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [.......10.8.0.1][41346] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] @@ -18,13 +18,13 @@ [ENTROPIES...: 4.4,4.7,4.7,5.5,4.7,7.3,4.8,7.1,4.7,7.2,4.6,5.6,4.6,7.7,4.5,6.3,4.6,7.9,4.7,7.8,4.8,7.6,4.6,7.3,4.7,7.9,4.7,7.7,4.7,7.6,4.5,7.6] detection-update: [.....1] [ip4][..tcp] [.......10.8.0.1][41346] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....2] [ip4][..tcp] [.......10.8.0.1][41348] -> [..64.68.105.103][..443] + new: [.....2] [ip4][..tcp] [.......10.8.0.1][41348] -> [..64.68.105.103][..443] detected: [.....2] [ip4][..tcp] [.......10.8.0.1][41348] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....2] [ip4][..tcp] [.......10.8.0.1][41348] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] RISK: TLS (probably) Not Carrying HTTPS - new: [.....3] [ip4][..tcp] [.......10.8.0.1][41350] -> [..64.68.105.103][..443] - new: [.....4] [ip4][..tcp] [.......10.8.0.1][41351] -> [..64.68.105.103][..443] + new: [.....3] [ip4][..tcp] [.......10.8.0.1][41350] -> [..64.68.105.103][..443] + new: [.....4] [ip4][..tcp] [.......10.8.0.1][41351] -> [..64.68.105.103][..443] detected: [.....3] [ip4][..tcp] [.......10.8.0.1][41350] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] RISK: TLS (probably) Not Carrying HTTPS detected: [.....4] [ip4][..tcp] [.......10.8.0.1][41351] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][radcom.webex.com] @@ -43,19 +43,19 @@ [IATS(ms)....: 5.6,6.8,0.2,1.5,404.7,455.3,0.6,51.3,245.8,245.9,0.4,0.3,223.3,274.8,51.6,0.4,0.3,283.1,286.1,84.1,131.8,50.9,51.2,56.8,56.7,181.0,181.0,56.1,58.6,54.5,58.4] [PKTLENS.....: 60,40,40,267,40,169,40,83,40,576,40,519,40,1644,576,40,489,40,6840,40,1400,40,9463,40,1400,40,1400,40,18006,40,6857,40] [ENTROPIES...: 4.4,4.7,4.6,5.9,4.7,6.4,4.7,5.6,4.6,7.6,4.7,7.6,4.7,7.9,7.6,4.6,7.6,4.7,8.0,4.6,7.9,4.6,8.0,4.6,7.9,4.7,7.9,4.6,8.0,4.6,8.0,4.7] - new: [.....5] [ip4][..tcp] [..10.133.206.47][54651] -> [..185.63.147.10][..443] [MIDSTREAM] - new: [.....6] [ip4][..tcp] [..10.133.206.47][59447] -> [..107.20.242.44][..443] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [.......10.8.0.1][41354] -> [..64.68.105.103][..443] + new: [.....5] [ip4][..tcp] [..10.133.206.47][54651] -> [..185.63.147.10][..443] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..10.133.206.47][59447] -> [..107.20.242.44][..443] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [.......10.8.0.1][41354] -> [..64.68.105.103][..443] detected: [.....7] [ip4][..tcp] [.......10.8.0.1][41354] -> [..64.68.105.103][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....7] [ip4][..tcp] [.......10.8.0.1][41354] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [.....8] [ip4][..tcp] [.......10.8.0.1][49048] -> [..23.44.253.243][..443] + new: [.....8] [ip4][..tcp] [.......10.8.0.1][49048] -> [..23.44.253.243][..443] detected: [.....8] [ip4][..tcp] [.......10.8.0.1][49048] -> [..23.44.253.243][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....8] [ip4][..tcp] [.......10.8.0.1][49048] -> [..23.44.253.243][..443] [TLS.Webex][Unknown][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [.....9] [ip4][..tcp] [.......10.8.0.1][41358] -> [..64.68.105.103][..443] + new: [.....9] [ip4][..tcp] [.......10.8.0.1][41358] -> [..64.68.105.103][..443] detected: [.....9] [ip4][..tcp] [.......10.8.0.1][41358] -> [..64.68.105.103][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [.....9] [ip4][..tcp] [.......10.8.0.1][41358] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][] @@ -70,46 +70,46 @@ [IATS(ms)....: 3.1,3.2,1.9,2.2,397.0,448.1,52.0,52.1,0.4,52.4,209.8,261.8,51.8,1.3,1.0,979.9,1031.5,52.6,53.5,94.1,93.8,53.1,53.9,119.1,117.5,148.4,147.8,51.4,51.4,96.7,96.6] [PKTLENS.....: 60,40,40,103,40,1400,40,2619,40,366,40,99,576,40,74,40,1400,40,8157,40,1400,40,8887,40,173,40,1400,40,6717,40,1400,40] [ENTROPIES...: 4.4,4.7,4.7,5.3,4.6,7.2,4.7,7.2,4.6,7.3,4.6,6.0,7.6,4.5,5.7,4.6,7.9,4.7,8.0,4.7,7.9,4.7,8.0,4.7,6.8,4.6,7.9,4.6,8.0,4.7,7.9,4.7] - new: [....10] [ip4][..tcp] [.......10.8.0.1][41726] -> [.114.29.213.212][..443] - new: [....11] [ip4][..tcp] [.......10.8.0.1][51646] -> [..114.29.204.49][..443] + new: [....10] [ip4][..tcp] [.......10.8.0.1][41726] -> [.114.29.213.212][..443] + new: [....11] [ip4][..tcp] [.......10.8.0.1][51646] -> [..114.29.204.49][..443] detected: [....10] [ip4][..tcp] [.......10.8.0.1][41726] -> [.114.29.213.212][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....11] [ip4][..tcp] [.......10.8.0.1][51646] -> [..114.29.204.49][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....12] [ip4][..tcp] [.......10.8.0.1][47498] -> [209.197.222.159][..443] + new: [....12] [ip4][..tcp] [.......10.8.0.1][47498] -> [209.197.222.159][..443] detected: [....12] [ip4][..tcp] [.......10.8.0.1][47498] -> [209.197.222.159][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....13] [ip4][..tcp] [.......10.8.0.1][57647] -> [..64.68.121.153][..443] + new: [....13] [ip4][..tcp] [.......10.8.0.1][57647] -> [..64.68.121.153][..443] detected: [....13] [ip4][..tcp] [.......10.8.0.1][57647] -> [..64.68.121.153][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....14] [ip4][..tcp] [.......10.8.0.1][45814] -> [...62.109.231.3][..443] + new: [....14] [ip4][..tcp] [.......10.8.0.1][45814] -> [...62.109.231.3][..443] detected: [....14] [ip4][..tcp] [.......10.8.0.1][45814] -> [...62.109.231.3][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....15] [ip4][..tcp] [.......10.8.0.1][44492] -> [..64.68.104.140][..443] - new: [....16] [ip4][..tcp] [.......10.8.0.1][47116] -> [.114.29.202.139][..443] - new: [....17] [ip4][..tcp] [.......10.8.0.1][52730] -> [...173.243.4.76][..443] - new: [....18] [ip4][..tcp] [.......10.8.0.1][52219] -> [..64.68.121.100][..443] - new: [....19] [ip4][..tcp] [.......10.8.0.1][55969] -> [...64.68.121.99][..443] + new: [....15] [ip4][..tcp] [.......10.8.0.1][44492] -> [..64.68.104.140][..443] + new: [....16] [ip4][..tcp] [.......10.8.0.1][47116] -> [.114.29.202.139][..443] + new: [....17] [ip4][..tcp] [.......10.8.0.1][52730] -> [...173.243.4.76][..443] + new: [....18] [ip4][..tcp] [.......10.8.0.1][52219] -> [..64.68.121.100][..443] + new: [....19] [ip4][..tcp] [.......10.8.0.1][55969] -> [...64.68.121.99][..443] detected: [....15] [ip4][..tcp] [.......10.8.0.1][44492] -> [..64.68.104.140][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....16] [ip4][..tcp] [.......10.8.0.1][47116] -> [.114.29.202.139][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....17] [ip4][..tcp] [.......10.8.0.1][52730] -> [...173.243.4.76][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....20] [ip4][..tcp] [.......10.8.0.1][47841] -> [..114.29.200.11][..443] + new: [....20] [ip4][..tcp] [.......10.8.0.1][47841] -> [..114.29.200.11][..443] detected: [....18] [ip4][..tcp] [.......10.8.0.1][52219] -> [..64.68.121.100][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....19] [ip4][..tcp] [.......10.8.0.1][55969] -> [...64.68.121.99][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....20] [ip4][..tcp] [.......10.8.0.1][47841] -> [..114.29.200.11][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....21] [ip4][..tcp] [.......10.8.0.1][51370] -> [...64.68.105.97][..443] - new: [....22] [ip4][..tcp] [.......10.8.0.1][37129] -> [...64.68.105.98][..443] + new: [....21] [ip4][..tcp] [.......10.8.0.1][51370] -> [...64.68.105.97][..443] + new: [....22] [ip4][..tcp] [.......10.8.0.1][37129] -> [...64.68.105.98][..443] detected: [....21] [ip4][..tcp] [.......10.8.0.1][51370] -> [...64.68.105.97][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....22] [ip4][..tcp] [.......10.8.0.1][37129] -> [...64.68.105.98][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....23] [ip4][..tcp] [.......10.8.0.1][41386] -> [..64.68.105.103][..443] + new: [....23] [ip4][..tcp] [.......10.8.0.1][41386] -> [..64.68.105.103][..443] detected: [....23] [ip4][..tcp] [.......10.8.0.1][41386] -> [..64.68.105.103][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....14] [ip4][..tcp] [.......10.8.0.1][45814] -> [...62.109.231.3][..443] [TLS.Webex][Webex][VoIP][Acceptable][] @@ -134,26 +134,26 @@ RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher detection-update: [....11] [ip4][..tcp] [.......10.8.0.1][51646] -> [..114.29.204.49][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....24] [ip4][..udp] [.......10.8.0.1][64538] -> [....172.16.1.75][.5060] + new: [....24] [ip4][..udp] [.......10.8.0.1][64538] -> [....172.16.1.75][.5060] detected: [....24] [ip4][..udp] [.......10.8.0.1][64538] -> [....172.16.1.75][.5060] [SIP][Unknown][VoIP][Acceptable] detection-update: [....16] [ip4][..tcp] [.......10.8.0.1][47116] -> [.114.29.202.139][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher detection-update: [....20] [ip4][..tcp] [.......10.8.0.1][47841] -> [..114.29.200.11][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....25] [ip4][..tcp] [.......10.8.0.1][43433] -> [..216.58.208.40][..443] + new: [....25] [ip4][..tcp] [.......10.8.0.1][43433] -> [..216.58.208.40][..443] detected: [....25] [ip4][..tcp] [.......10.8.0.1][43433] -> [..216.58.208.40][..443] [TLS.Google][Google][Advertisement][Acceptable][ssl.google-analytics.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....26] [ip4][..tcp] [.......10.8.0.1][47135] -> [.114.29.202.139][..443] - new: [....27] [ip4][..tcp] [.......10.8.0.1][41757] -> [.114.29.213.212][..443] - new: [....28] [ip4][..tcp] [.......10.8.0.1][51676] -> [..114.29.204.49][..443] - new: [....29] [ip4][..tcp] [.......10.8.0.1][37139] -> [...64.68.105.98][..443] - new: [....30] [ip4][..tcp] [.......10.8.0.1][41394] -> [..64.68.105.103][..443] - new: [....31] [ip4][..tcp] [.......10.8.0.1][51134] -> [.62.109.224.120][..443] - new: [....32] [ip4][..tcp] [.......10.8.0.1][51135] -> [.62.109.224.120][..443] - new: [....33] [ip4][..tcp] [..10.133.206.47][33459] -> [...80.74.110.68][..443] [MIDSTREAM] + new: [....26] [ip4][..tcp] [.......10.8.0.1][47135] -> [.114.29.202.139][..443] + new: [....27] [ip4][..tcp] [.......10.8.0.1][41757] -> [.114.29.213.212][..443] + new: [....28] [ip4][..tcp] [.......10.8.0.1][51676] -> [..114.29.204.49][..443] + new: [....29] [ip4][..tcp] [.......10.8.0.1][37139] -> [...64.68.105.98][..443] + new: [....30] [ip4][..tcp] [.......10.8.0.1][41394] -> [..64.68.105.103][..443] + new: [....31] [ip4][..tcp] [.......10.8.0.1][51134] -> [.62.109.224.120][..443] + new: [....32] [ip4][..tcp] [.......10.8.0.1][51135] -> [.62.109.224.120][..443] + new: [....33] [ip4][..tcp] [..10.133.206.47][33459] -> [...80.74.110.68][..443] [MIDSTREAM] detected: [....33] [ip4][..tcp] [..10.133.206.47][33459] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe] - new: [....34] [ip4][..tcp] [.......10.8.0.1][33511] -> [...80.74.110.68][..443] - new: [....35] [ip4][..tcp] [.......10.8.0.1][33512] -> [...80.74.110.68][..443] + new: [....34] [ip4][..tcp] [.......10.8.0.1][33511] -> [...80.74.110.68][..443] + new: [....35] [ip4][..tcp] [.......10.8.0.1][33512] -> [...80.74.110.68][..443] detected: [....26] [ip4][..tcp] [.......10.8.0.1][47135] -> [.114.29.202.139][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....27] [ip4][..tcp] [.......10.8.0.1][41757] -> [.114.29.213.212][..443] [TLS][Webex][Web][Safe][] @@ -176,8 +176,8 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....35] [ip4][..tcp] [.......10.8.0.1][33512] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....36] [ip4][..tcp] [.......10.8.0.1][51154] -> [.62.109.224.120][..443] - new: [....37] [ip4][..tcp] [.......10.8.0.1][51155] -> [.62.109.224.120][..443] + new: [....36] [ip4][..tcp] [.......10.8.0.1][51154] -> [.62.109.224.120][..443] + new: [....37] [ip4][..tcp] [.......10.8.0.1][51155] -> [.62.109.224.120][..443] detected: [....36] [ip4][..tcp] [.......10.8.0.1][51154] -> [.62.109.224.120][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....37] [ip4][..tcp] [.......10.8.0.1][51155] -> [.62.109.224.120][..443] [TLS][Webex][Web][Safe][] @@ -186,12 +186,12 @@ RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher detection-update: [....37] [ip4][..tcp] [.......10.8.0.1][51155] -> [.62.109.224.120][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....38] [ip4][..tcp] [.......10.8.0.1][41419] -> [..64.68.105.103][..443] + new: [....38] [ip4][..tcp] [.......10.8.0.1][41419] -> [..64.68.105.103][..443] detected: [....38] [ip4][..tcp] [.......10.8.0.1][41419] -> [..64.68.105.103][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....38] [ip4][..tcp] [.......10.8.0.1][41419] -> [..64.68.105.103][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....39] [ip4][..tcp] [.......10.8.0.1][55665] -> [..173.243.0.110][..443] + new: [....39] [ip4][..tcp] [.......10.8.0.1][55665] -> [..173.243.0.110][..443] detected: [....39] [ip4][..tcp] [.......10.8.0.1][55665] -> [..173.243.0.110][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) analyse: [....37] [ip4][..tcp] [.......10.8.0.1][51155] -> [.62.109.224.120][..443] [TLS.Webex][Webex][VoIP][Acceptable] @@ -216,28 +216,28 @@ [IATS(ms)....: 9.1,24.1,0.4,16.5,915.3,917.4,50.7,52.7,154.6,206.6,52.4,7.9,9.4,3.3,2.1,963.3,962.0,0.5,0.4,0.4,0.3,562.0,562.1,368.6,368.5,0.7,0.6,2270.1,2270.1,1.0,1.0] [PKTLENS.....: 60,40,40,103,40,3947,40,366,40,99,546,40,576,40,122,40,576,40,576,40,386,40,386,40,576,40,154,40,576,40,250,40] [ENTROPIES...: 4.4,4.7,4.6,5.4,4.7,7.3,4.8,7.3,4.8,6.0,7.6,4.8,7.6,4.8,6.5,4.8,7.6,4.8,7.6,4.8,7.4,4.8,7.4,4.7,7.6,4.7,6.5,4.7,7.6,4.7,7.0,4.8] - new: [....40] [ip4][..tcp] [.......10.8.0.1][51833] -> [.62.109.229.158][..443] + new: [....40] [ip4][..tcp] [.......10.8.0.1][51833] -> [.62.109.229.158][..443] detected: [....40] [ip4][..tcp] [.......10.8.0.1][51833] -> [.62.109.229.158][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....41] [ip4][..tcp] [.......10.8.0.1][55669] -> [..173.243.0.110][..443] + new: [....41] [ip4][..tcp] [.......10.8.0.1][55669] -> [..173.243.0.110][..443] detected: [....41] [ip4][..tcp] [.......10.8.0.1][55669] -> [..173.243.0.110][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....41] [ip4][..tcp] [.......10.8.0.1][55669] -> [..173.243.0.110][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher update: [....24] [ip4][..udp] [.......10.8.0.1][64538] -> [....172.16.1.75][.5060] [SIP][Unknown][VoIP][Acceptable] - new: [....42] [ip4][..tcp] [.......10.8.0.1][55671] -> [..173.243.0.110][..443] + new: [....42] [ip4][..tcp] [.......10.8.0.1][55671] -> [..173.243.0.110][..443] detected: [....42] [ip4][..tcp] [.......10.8.0.1][55671] -> [..173.243.0.110][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....42] [ip4][..tcp] [.......10.8.0.1][55671] -> [..173.243.0.110][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....43] [ip4][..tcp] [.......10.8.0.1][51839] -> [.62.109.229.158][..443] + new: [....43] [ip4][..tcp] [.......10.8.0.1][51839] -> [.62.109.229.158][..443] detected: [....43] [ip4][..tcp] [.......10.8.0.1][51839] -> [.62.109.229.158][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....44] [ip4][..tcp] [.......10.8.0.1][46211] -> [...54.241.32.14][..443] + new: [....44] [ip4][..tcp] [.......10.8.0.1][46211] -> [...54.241.32.14][..443] detected: [....44] [ip4][..tcp] [.......10.8.0.1][46211] -> [...54.241.32.14][..443] [TLS][AmazonAWS][Web][Safe][api.crittercism.com] RISK: Obsolete TLS (v1.1 or older) - new: [....45] [ip4][..tcp] [.......10.8.0.1][59756] -> [...78.46.237.91][...80] - new: [....46] [ip4][..tcp] [.......10.8.0.1][59757] -> [...78.46.237.91][...80] + new: [....45] [ip4][..tcp] [.......10.8.0.1][59756] -> [...78.46.237.91][...80] + new: [....46] [ip4][..tcp] [.......10.8.0.1][59757] -> [...78.46.237.91][...80] detected: [....45] [ip4][..tcp] [.......10.8.0.1][59756] -> [...78.46.237.91][...80] [HTTP][Unknown][Web][Acceptable][cp.pushwoosh.com] detected: [....46] [ip4][..tcp] [.......10.8.0.1][59757] -> [...78.46.237.91][...80] [HTTP][Unknown][Web][Acceptable][cp.pushwoosh.com] detection-update: [....45] [ip4][..tcp] [.......10.8.0.1][59756] -> [...78.46.237.91][...80] [HTTP][Unknown][Web][Acceptable][cp.pushwoosh.com] @@ -248,13 +248,13 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....44] [ip4][..tcp] [.......10.8.0.1][46211] -> [...54.241.32.14][..443] [TLS][AmazonAWS][Web][Safe][api.crittercism.com] RISK: Obsolete TLS (v1.1 or older) - new: [....47] [ip4][..tcp] [.......10.8.0.1][33551] -> [...80.74.110.68][..443] + new: [....47] [ip4][..tcp] [.......10.8.0.1][33551] -> [...80.74.110.68][..443] detected: [....47] [ip4][..tcp] [.......10.8.0.1][33551] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....47] [ip4][..tcp] [.......10.8.0.1][33551] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....48] [ip4][..tcp] [.......10.8.0.1][33553] -> [...80.74.110.68][..443] - new: [....49] [ip4][..tcp] [.......10.8.0.1][33554] -> [...80.74.110.68][..443] + new: [....48] [ip4][..tcp] [.......10.8.0.1][33553] -> [...80.74.110.68][..443] + new: [....49] [ip4][..tcp] [.......10.8.0.1][33554] -> [...80.74.110.68][..443] detected: [....48] [ip4][..tcp] [.......10.8.0.1][33553] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....49] [ip4][..tcp] [.......10.8.0.1][33554] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] @@ -263,23 +263,23 @@ RISK: Obsolete TLS (v1.1 or older) detection-update: [....49] [ip4][..tcp] [.......10.8.0.1][33554] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....50] [ip4][..tcp] [.......10.8.0.1][55687] -> [..173.243.0.110][..443] + new: [....50] [ip4][..tcp] [.......10.8.0.1][55687] -> [..173.243.0.110][..443] detected: [....50] [ip4][..tcp] [.......10.8.0.1][55687] -> [..173.243.0.110][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....50] [ip4][..tcp] [.......10.8.0.1][55687] -> [..173.243.0.110][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....51] [ip4][..tcp] [.......10.8.0.1][33559] -> [...80.74.110.68][..443] + new: [....51] [ip4][..tcp] [.......10.8.0.1][33559] -> [...80.74.110.68][..443] detected: [....51] [ip4][..tcp] [.......10.8.0.1][33559] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....51] [ip4][..tcp] [.......10.8.0.1][33559] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....52] [ip4][..tcp] [.......10.8.0.1][51857] -> [.62.109.229.158][..443] + new: [....52] [ip4][..tcp] [.......10.8.0.1][51857] -> [.62.109.229.158][..443] detected: [....52] [ip4][..tcp] [.......10.8.0.1][51857] -> [.62.109.229.158][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detection-update: [....52] [ip4][..tcp] [.......10.8.0.1][51857] -> [.62.109.229.158][..443] [TLS.Webex][Webex][VoIP][Acceptable][] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher - new: [....53] [ip4][..udp] [.......10.8.0.1][51772] -> [.62.109.229.158][.9000] - new: [....54] [ip4][..tcp] [.......10.8.0.1][51859] -> [.62.109.229.158][..443] + new: [....53] [ip4][..udp] [.......10.8.0.1][51772] -> [.62.109.229.158][.9000] + new: [....54] [ip4][..tcp] [.......10.8.0.1][51859] -> [.62.109.229.158][..443] analyse: [....52] [ip4][..tcp] [.......10.8.0.1][51857] -> [.62.109.229.158][..443] [TLS.Webex][Webex][VoIP][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 1.367| 0.190| 0.352| 124124.103| 3.400] @@ -290,11 +290,11 @@ [IATS(ms)....: 4.2,5.0,6.4,7.6,1312.6,1366.7,17.5,71.4,145.7,199.0,0.3,53.7,129.5,180.9,0.2,51.5,121.2,172.3,51.5,51.2,125.5,176.2,50.8,50.8,0.5,1.0,264.3,263.8,0.8,0.9,1006.9] [PKTLENS.....: 60,40,40,227,40,3947,40,366,40,99,40,114,40,77,40,418,40,109,40,529,40,130,40,194,40,162,40,162,40,146,40,109] [ENTROPIES...: 4.5,4.8,4.8,5.2,4.7,7.3,4.8,7.3,4.8,6.0,4.8,6.2,4.8,5.7,4.8,7.5,4.8,6.2,4.8,7.4,4.8,6.4,4.8,6.8,4.7,6.6,4.6,6.6,4.8,6.4,4.7,6.2] - new: [....55] [ip4][..tcp] [.......10.8.0.1][51190] -> [.62.109.224.120][..443] + new: [....55] [ip4][..tcp] [.......10.8.0.1][51190] -> [.62.109.224.120][..443] detected: [....55] [ip4][..tcp] [.......10.8.0.1][51190] -> [.62.109.224.120][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) - new: [....56] [ip4][..tcp] [.......10.8.0.1][51194] -> [.62.109.224.120][..443] - new: [....57] [ip4][..tcp] [.......10.8.0.1][51195] -> [.62.109.224.120][..443] + new: [....56] [ip4][..tcp] [.......10.8.0.1][51194] -> [.62.109.224.120][..443] + new: [....57] [ip4][..tcp] [.......10.8.0.1][51195] -> [.62.109.224.120][..443] detected: [....56] [ip4][..tcp] [.......10.8.0.1][51194] -> [.62.109.224.120][..443] [TLS][Webex][Web][Safe][] RISK: Obsolete TLS (v1.1 or older) detected: [....57] [ip4][..tcp] [.......10.8.0.1][51195] -> [.62.109.224.120][..443] [TLS][Webex][Web][Safe][] @@ -323,7 +323,7 @@ RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher guessed: [....54] [ip4][..tcp] [.......10.8.0.1][51859] -> [.62.109.229.158][..443] [TLS][Webex][Web][Safe] RISK: TCP Connection Issues - end: [....54] [ip4][..tcp] [.......10.8.0.1][51859] -> [.62.109.229.158][..443] + end: [....54] [ip4][..tcp] [.......10.8.0.1][51859] -> [.62.109.229.158][..443] end: [....14] [ip4][..tcp] [.......10.8.0.1][45814] -> [...62.109.231.3][..443] [TLS.Webex][Webex][VoIP][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher end: [....18] [ip4][..tcp] [.......10.8.0.1][52219] -> [..64.68.121.100][..443] [TLS.Webex][Webex][VoIP][Acceptable] @@ -335,16 +335,16 @@ end: [....27] [ip4][..tcp] [.......10.8.0.1][41757] -> [.114.29.213.212][..443] [TLS][Webex][Web][Safe] RISK: Obsolete TLS (v1.1 or older) guessed: [....53] [ip4][..udp] [.......10.8.0.1][51772] -> [.62.109.229.158][.9000] [Webex][Webex][VoIP][Acceptable] - idle: [....53] [ip4][..udp] [.......10.8.0.1][51772] -> [.62.109.229.158][.9000] + idle: [....53] [ip4][..udp] [.......10.8.0.1][51772] -> [.62.109.229.158][.9000] guessed: [.....6] [ip4][..tcp] [..10.133.206.47][59447] -> [..107.20.242.44][..443] [TLS][AmazonAWS][Web][Safe] - end: [.....6] [ip4][..tcp] [..10.133.206.47][59447] -> [..107.20.242.44][..443] + end: [.....6] [ip4][..tcp] [..10.133.206.47][59447] -> [..107.20.242.44][..443] end: [....17] [ip4][..tcp] [.......10.8.0.1][52730] -> [...173.243.4.76][..443] [TLS.Webex][Webex][VoIP][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher end: [....33] [ip4][..tcp] [..10.133.206.47][33459] -> [...80.74.110.68][..443] [TLS][Unknown][Web][Safe] end: [....15] [ip4][..tcp] [.......10.8.0.1][44492] -> [..64.68.104.140][..443] [TLS.Webex][Webex][VoIP][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher guessed: [.....5] [ip4][..tcp] [..10.133.206.47][54651] -> [..185.63.147.10][..443] [TLS][Unknown][Web][Safe] - end: [.....5] [ip4][..tcp] [..10.133.206.47][54651] -> [..185.63.147.10][..443] + end: [.....5] [ip4][..tcp] [..10.133.206.47][54651] -> [..185.63.147.10][..443] end: [.....8] [ip4][..tcp] [.......10.8.0.1][49048] -> [..23.44.253.243][..443] [TLS.Webex][Unknown][VoIP][Acceptable] RISK: Obsolete TLS (v1.1 or older), Weak TLS Cipher idle: [....25] [ip4][..tcp] [.......10.8.0.1][43433] -> [..216.58.208.40][..443] [TLS.Google][Google][Advertisement][Acceptable] diff --git a/test/results/flow-info/default/websocket.pcap.out b/test/results/flow-info/default/websocket.pcap.out index f075e7f27..7fab66573 100644 --- a/test/results/flow-info/default/websocket.pcap.out +++ b/test/results/flow-info/default/websocket.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.43.135][12345] -> [...192.168.43.1][50999] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [.192.168.43.135][12345] -> [...192.168.43.1][50999] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [.192.168.43.135][12345] -> [...192.168.43.1][50999] [WebSocket][Unknown][Web][Acceptable] idle: [.....1] [ip4][..tcp] [.192.168.43.135][12345] -> [...192.168.43.1][50999] [WebSocket][Unknown][Web][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/wechat.pcap.out b/test/results/flow-info/default/wechat.pcap.out index 0930a42ab..c72d396b7 100644 --- a/test/results/flow-info/default/wechat.pcap.out +++ b/test/results/flow-info/default/wechat.pcap.out @@ -1,42 +1,42 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54084] [MIDSTREAM] - new: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] + new: [.....1] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54084] [MIDSTREAM] + new: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] detected: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] + new: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] detected: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [.....4] [ip4][..udp] [..192.168.1.103][53734] -> [..192.168.1.254][...53] + new: [.....4] [ip4][..udp] [..192.168.1.103][53734] -> [..192.168.1.254][...53] detected: [.....4] [ip4][..udp] [..192.168.1.103][53734] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][safebrowsing.googleusercontent.com] detection-update: [.....4] [ip4][..udp] [..192.168.1.103][53734] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][safebrowsing.googleusercontent.com] - new: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] [TLS.Google][Google][Web][Acceptable][safebrowsing.googleusercontent.com] detection-update: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] [TLS.Google][Google][Web][Acceptable][safebrowsing.googleusercontent.com] detection-update: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] [TLS.Google][Google][Web][Acceptable][safebrowsing.googleusercontent.com] - new: [.....6] [ip4][..tcp] [..192.168.1.103][47627] -> [..216.58.205.78][..443] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [..192.168.1.103][53220] -> [..172.217.23.78][..443] [MIDSTREAM] - new: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] + new: [.....6] [ip4][..tcp] [..192.168.1.103][47627] -> [..216.58.205.78][..443] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [..192.168.1.103][53220] -> [..172.217.23.78][..443] [MIDSTREAM] + new: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] detected: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][ssl.gstatic.com] detection-update: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][ssl.gstatic.com] - new: [.....9] [ip4][..udp] [..192.168.1.103][51507] -> [..172.217.23.67][..443] + new: [.....9] [ip4][..udp] [..192.168.1.103][51507] -> [..172.217.23.67][..443] detected: [.....9] [ip4][..udp] [..192.168.1.103][51507] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable][ssl.gstatic.com] - new: [....10] [ip4][..udp] [..192.168.1.103][55862] -> [..192.168.1.254][...53] + new: [....10] [ip4][..udp] [..192.168.1.103][55862] -> [..192.168.1.254][...53] detected: [....10] [ip4][..udp] [..192.168.1.103][55862] -> [..192.168.1.254][...53] [DNS.GoogleDocs][Unknown][Network][Acceptable][docs.google.com] detection-update: [....10] [ip4][..udp] [..192.168.1.103][55862] -> [..192.168.1.254][...53] [DNS.GoogleDocs][Unknown][Network][Acceptable][docs.google.com] - new: [....11] [ip4][..udp] [..192.168.1.103][57591] -> [..216.58.198.46][..443] + new: [....11] [ip4][..udp] [..192.168.1.103][57591] -> [..216.58.198.46][..443] detected: [....11] [ip4][..udp] [..192.168.1.103][57591] -> [..216.58.198.46][..443] [QUIC.GoogleDocs][Google][Collaborative][Acceptable][docs.google.com] - new: [....12] [ip4][..tcp] [..192.168.1.103][36017] -> [.64.233.167.188][.5228] [MIDSTREAM] - new: [....13] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54058] [MIDSTREAM] + new: [....12] [ip4][..tcp] [..192.168.1.103][36017] -> [.64.233.167.188][.5228] [MIDSTREAM] + new: [....13] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54058] [MIDSTREAM] detected: [....13] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54058] [TLS][Unknown][Web][Safe] - new: [....14] [ip4][..tcp] [..192.168.1.103][40741] -> [203.205.151.211][..443] [MIDSTREAM] - new: [....15] [ip4][..tcp] [..192.168.1.103][54085] -> [203.205.151.162][..443] [MIDSTREAM] - new: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] - new: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] + new: [....14] [ip4][..tcp] [..192.168.1.103][40741] -> [203.205.151.211][..443] [MIDSTREAM] + new: [....15] [ip4][..tcp] [..192.168.1.103][54085] -> [203.205.151.162][..443] [MIDSTREAM] + new: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] + new: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] detected: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....18] [ip4][..tcp] [..192.168.1.103][54091] -> [203.205.151.162][..443] + new: [....18] [ip4][..tcp] [..192.168.1.103][54091] -> [203.205.151.162][..443] detection-update: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....18] [ip4][..tcp] [..192.168.1.103][54091] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] @@ -54,25 +54,25 @@ detection-update: [....18] [ip4][..tcp] [..192.168.1.103][54091] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [.....6] [ip4][..tcp] [..192.168.1.103][47627] -> [..216.58.205.78][..443] [TLS][Google][Web][Safe] detected: [.....7] [ip4][..tcp] [..192.168.1.103][53220] -> [..172.217.23.78][..443] [TLS][Google][Web][Safe] - new: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] - new: [....20] [ip4][..tcp] [..192.168.1.103][54093] -> [203.205.151.162][..443] + new: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] + new: [....20] [ip4][..tcp] [..192.168.1.103][54093] -> [203.205.151.162][..443] detected: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....21] [ip4][..tcp] [..192.168.1.103][49787] -> [.216.58.205.142][..443] [MIDSTREAM] - new: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] - new: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] + new: [....21] [ip4][..tcp] [..192.168.1.103][49787] -> [.216.58.205.142][..443] [MIDSTREAM] + new: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] + new: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] detected: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] + new: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] detection-update: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....25] [ip4][..tcp] [..192.168.1.103][40740] -> [203.205.151.211][..443] [MIDSTREAM] + new: [....25] [ip4][..tcp] [..192.168.1.103][40740] -> [203.205.151.211][..443] [MIDSTREAM] analyse: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 4.544| 0.482| 1.044| 1090167.570| 3.200] @@ -110,8 +110,8 @@ update: [.....9] [ip4][..udp] [..192.168.1.103][51507] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable] update: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....11] [ip4][..udp] [..192.168.1.103][57591] -> [..216.58.198.46][..443] [QUIC.GoogleDocs][Google][Collaborative][Acceptable] - new: [....26] [ip4][..tcp] [..192.168.1.103][54097] -> [203.205.151.162][..443] - new: [....27] [ip4][..tcp] [..192.168.1.103][54098] -> [203.205.151.162][..443] + new: [....26] [ip4][..tcp] [..192.168.1.103][54097] -> [203.205.151.162][..443] + new: [....27] [ip4][..tcp] [..192.168.1.103][54098] -> [203.205.151.162][..443] detected: [....26] [ip4][..tcp] [..192.168.1.103][54097] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....26] [ip4][..tcp] [..192.168.1.103][54097] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....26] [ip4][..tcp] [..192.168.1.103][54097] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] @@ -149,31 +149,31 @@ [IATS(ms)....: 48.2,48.2,0.2,52.5,0.7,53.0,2.4,2.4,0.5,0.5,4.5,7.9,13.6,51.2,2.8,0.1,28.0,0.3,26.1,2.8,10.1,38.9,0.4,0.8,0.2,45.4,2.8,45043.9,45047.5,45056.0,45052.9] [PKTLENS.....: 60,60,52,274,52,1470,52,1470,52,1428,52,137,97,881,322,100,86,52,82,52,82,558,52,90,90,86,52,52,52,52,52,52] [ENTROPIES...: 4.6,5.3,4.9,5.7,5.0,6.4,4.9,7.1,4.9,7.4,4.9,6.1,5.9,7.7,7.1,6.0,5.8,4.9,5.7,5.0,5.6,7.6,4.9,5.9,5.7,5.6,5.0,5.0,4.9,5.0,4.9,5.0] - new: [....28] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] + new: [....28] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] detected: [....28] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [....29] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] + new: [....29] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] detected: [....29] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] update: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....30] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] + new: [....30] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] detected: [....30] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [..192.168.1.103][53734] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....10] [ip4][..udp] [..192.168.1.103][55862] -> [..192.168.1.254][...53] [DNS.GoogleDocs][Unknown][Network][Acceptable] update: [.....9] [ip4][..udp] [..192.168.1.103][51507] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable] update: [.....8] [ip4][..udp] [..192.168.1.103][46078] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....11] [ip4][..udp] [..192.168.1.103][57591] -> [..216.58.198.46][..443] [QUIC.GoogleDocs][Google][Collaborative][Acceptable] - new: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] - new: [....32] [ip4][..tcp] [..192.168.1.103][54100] -> [203.205.151.162][..443] + new: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] + new: [....32] [ip4][..tcp] [..192.168.1.103][54100] -> [203.205.151.162][..443] detected: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....32] [ip4][..tcp] [..192.168.1.103][54100] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....33] [ip4][..tcp] [..192.168.1.103][54101] -> [203.205.151.162][..443] - new: [....34] [ip4][..tcp] [..192.168.1.103][54102] -> [203.205.151.162][..443] + new: [....33] [ip4][..tcp] [..192.168.1.103][54101] -> [203.205.151.162][..443] + new: [....34] [ip4][..tcp] [..192.168.1.103][54102] -> [203.205.151.162][..443] detection-update: [....32] [ip4][..tcp] [..192.168.1.103][54100] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....32] [ip4][..tcp] [..192.168.1.103][54100] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....34] [ip4][..tcp] [..192.168.1.103][54102] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....35] [ip4][..tcp] [..192.168.1.103][54103] -> [203.205.151.162][..443] + new: [....35] [ip4][..tcp] [..192.168.1.103][54103] -> [203.205.151.162][..443] detected: [....33] [ip4][..tcp] [..192.168.1.103][54101] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....34] [ip4][..tcp] [..192.168.1.103][54102] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detected: [....35] [ip4][..tcp] [..192.168.1.103][54103] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] @@ -181,7 +181,7 @@ detection-update: [....33] [ip4][..tcp] [..192.168.1.103][54101] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....35] [ip4][..tcp] [..192.168.1.103][54103] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....35] [ip4][..tcp] [..192.168.1.103][54103] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....36] [ip4][..tcp] [..192.168.1.103][54104] -> [203.205.151.162][..443] + new: [....36] [ip4][..tcp] [..192.168.1.103][54104] -> [203.205.151.162][..443] analyse: [....31] [ip4][..tcp] [..192.168.1.103][54099] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.469| 0.183| 0.190| 36094.243| 4.000] @@ -217,25 +217,25 @@ [PKTLENS.....: 60,60,52,290,52,1480,52,1740,52,178,103,1225,429,52,250,1292,527,52,1480,216,52,1225,429,52,250,52,1140,1480,52,1480,52,1480] [ENTROPIES...: 4.7,5.2,5.1,5.9,5.1,6.8,5.0,7.6,5.0,6.4,6.1,7.8,7.4,5.1,7.1,7.8,7.6,5.1,7.9,7.0,5.0,7.8,7.4,5.1,7.1,5.0,7.8,7.9,5.1,7.9,5.1,7.9] guessed: [.....1] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54084] [TLS][Unknown][Web][Safe] - end: [.....1] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54084] + end: [.....1] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54084] guessed: [....15] [ip4][..tcp] [..192.168.1.103][54085] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....15] [ip4][..tcp] [..192.168.1.103][54085] -> [203.205.151.162][..443] + end: [....15] [ip4][..tcp] [..192.168.1.103][54085] -> [203.205.151.162][..443] guessed: [....14] [ip4][..tcp] [..192.168.1.103][40741] -> [203.205.151.211][..443] [TLS][Unknown][Web][Safe] - end: [....14] [ip4][..tcp] [..192.168.1.103][40741] -> [203.205.151.211][..443] - new: [....37] [ip4][..tcp] [..192.168.1.103][54109] -> [203.205.151.162][..443] [MIDSTREAM] - new: [....38] [ip4][..tcp] [..192.168.1.103][54110] -> [203.205.151.162][..443] [MIDSTREAM] - new: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] - new: [....40] [ip4][..tcp] [..192.168.1.103][54112] -> [203.205.151.162][..443] + end: [....14] [ip4][..tcp] [..192.168.1.103][40741] -> [203.205.151.211][..443] + new: [....37] [ip4][..tcp] [..192.168.1.103][54109] -> [203.205.151.162][..443] [MIDSTREAM] + new: [....38] [ip4][..tcp] [..192.168.1.103][54110] -> [203.205.151.162][..443] [MIDSTREAM] + new: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] + new: [....40] [ip4][..tcp] [..192.168.1.103][54112] -> [203.205.151.162][..443] detected: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....41] [ip4][..tcp] [..192.168.1.103][54106] -> [203.205.151.162][..443] [MIDSTREAM] + new: [....41] [ip4][..tcp] [..192.168.1.103][54106] -> [203.205.151.162][..443] [MIDSTREAM] end: [....16] [ip4][..tcp] [..192.168.1.103][54089] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] end: [....17] [ip4][..tcp] [..192.168.1.103][54090] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] end: [....18] [ip4][..tcp] [..192.168.1.103][54091] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] end: [....19] [ip4][..tcp] [..192.168.1.103][54092] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] guessed: [....20] [ip4][..tcp] [..192.168.1.103][54093] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....20] [ip4][..tcp] [..192.168.1.103][54093] -> [203.205.151.162][..443] + end: [....20] [ip4][..tcp] [..192.168.1.103][54093] -> [203.205.151.162][..443] end: [....22] [ip4][..tcp] [..192.168.1.103][54094] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] end: [....23] [ip4][..tcp] [..192.168.1.103][54095] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] end: [....24] [ip4][..tcp] [..192.168.1.103][54096] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] @@ -260,16 +260,16 @@ update: [....29] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] update: [....30] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] - new: [....43] [ip4][..tcp] [..192.168.1.103][54114] -> [203.205.151.162][..443] + new: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] + new: [....43] [ip4][..tcp] [..192.168.1.103][54114] -> [203.205.151.162][..443] detected: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] - new: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] + new: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] detected: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] [DNS.QQ][Unknown][Network][Fun][res.wx.qq.com] detection-update: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] [DNS.QQ][Unknown][Network][Fun][res.wx.qq.com] - new: [....45] [ip4][..tcp] [..192.168.1.103][43850] -> [.203.205.158.34][..443] - new: [....46] [ip4][..tcp] [..192.168.1.103][43851] -> [.203.205.158.34][..443] + new: [....45] [ip4][..tcp] [..192.168.1.103][43850] -> [.203.205.158.34][..443] + new: [....46] [ip4][..tcp] [..192.168.1.103][43851] -> [.203.205.158.34][..443] detected: [....45] [ip4][..tcp] [..192.168.1.103][43850] -> [.203.205.158.34][..443] [TLS.QQ][Unknown][Chat][Fun][res.wx.qq.com] analyse: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] min| max| avg| stddev| variance| entropy @@ -285,18 +285,18 @@ RISK: Weak TLS Cipher detection-update: [....45] [ip4][..tcp] [..192.168.1.103][43850] -> [.203.205.158.34][..443] [TLS.QQ][Unknown][Chat][Fun][res.wx.qq.com] RISK: Weak TLS Cipher - new: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] + new: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] detected: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][ssl.gstatic.com] detection-update: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][ssl.gstatic.com] - new: [....48] [ip4][..udp] [..192.168.1.103][35601] -> [..172.217.23.67][..443] + new: [....48] [ip4][..udp] [..192.168.1.103][35601] -> [..172.217.23.67][..443] detected: [....48] [ip4][..udp] [..192.168.1.103][35601] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable][ssl.gstatic.com] - new: [....49] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] + new: [....49] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] detected: [....49] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][giovanni-pc] RISK: Unsafe Protocol update: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....50] [ip4][..tcp] [..192.168.1.103][54117] -> [203.205.151.162][..443] - new: [....51] [ip4][..tcp] [..192.168.1.103][54118] -> [203.205.151.162][..443] + new: [....50] [ip4][..tcp] [..192.168.1.103][54117] -> [203.205.151.162][..443] + new: [....51] [ip4][..tcp] [..192.168.1.103][54118] -> [203.205.151.162][..443] detected: [....50] [ip4][..tcp] [..192.168.1.103][54117] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....50] [ip4][..tcp] [..192.168.1.103][54117] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....50] [ip4][..tcp] [..192.168.1.103][54117] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] @@ -336,8 +336,8 @@ [IATS(ms)....: 0.3,1000.4,2000.4,14687.4,0.3,1000.3,2000.4,21831.5,0.4,1000.6,2000.8,26318.9,0.4,1000.4,2000.5,41917.1,0.3,1000.2,2000.8,183800.4,0.3,1001.0,2001.0,33299.7,0.4,1000.7,2000.5,29036.9,0.3,1000.3,2000.7] [PKTLENS.....: 88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88,88] [ENTROPIES...: 3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8,3.8] - new: [....52] [ip4][..tcp] [..192.168.1.103][54119] -> [203.205.151.162][..443] - new: [....53] [ip4][..tcp] [..192.168.1.103][54120] -> [203.205.151.162][..443] + new: [....52] [ip4][..tcp] [..192.168.1.103][54119] -> [203.205.151.162][..443] + new: [....53] [ip4][..tcp] [..192.168.1.103][54120] -> [203.205.151.162][..443] detected: [....52] [ip4][..tcp] [..192.168.1.103][54119] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....52] [ip4][..tcp] [..192.168.1.103][54119] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] detection-update: [....52] [ip4][..tcp] [..192.168.1.103][54119] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun][web.wechat.com] @@ -359,25 +359,25 @@ [PKTLENS.....: 60,60,52,290,52,1480,52,1480,52,312,52,178,103,1292,527,52,1480,112,52,1225,429,52,249,1292,527,52,989,52,1113,52,1480,52] [ENTROPIES...: 4.6,5.1,4.8,5.8,5.0,6.8,5.0,7.5,4.9,7.2,4.9,6.3,5.9,7.8,7.5,5.1,7.9,6.2,4.8,7.8,7.5,5.1,7.1,7.8,7.6,5.1,7.8,4.9,7.8,5.0,7.9,4.9] guessed: [....37] [ip4][..tcp] [..192.168.1.103][54109] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....37] [ip4][..tcp] [..192.168.1.103][54109] -> [203.205.151.162][..443] + end: [....37] [ip4][..tcp] [..192.168.1.103][54109] -> [203.205.151.162][..443] guessed: [....38] [ip4][..tcp] [..192.168.1.103][54110] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....38] [ip4][..tcp] [..192.168.1.103][54110] -> [203.205.151.162][..443] + end: [....38] [ip4][..tcp] [..192.168.1.103][54110] -> [203.205.151.162][..443] update: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] [DNS.QQ][Unknown][Network][Fun] update: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....48] [ip4][..udp] [..192.168.1.103][35601] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable] - new: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] + new: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] detected: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][web.wechat.com] detection-update: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][web.wechat.com] - new: [....55] [ip4][..tcp] [..192.168.1.103][58036] -> [203.205.147.171][..443] - new: [....56] [ip4][..tcp] [..192.168.1.103][58037] -> [203.205.147.171][..443] + new: [....55] [ip4][..tcp] [..192.168.1.103][58036] -> [203.205.147.171][..443] + new: [....56] [ip4][..tcp] [..192.168.1.103][58037] -> [203.205.147.171][..443] detected: [....55] [ip4][..tcp] [..192.168.1.103][58036] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....55] [ip4][..tcp] [..192.168.1.103][58036] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....55] [ip4][..tcp] [..192.168.1.103][58036] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] end: [....39] [ip4][..tcp] [..192.168.1.103][54111] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] guessed: [....40] [ip4][..tcp] [..192.168.1.103][54112] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....40] [ip4][..tcp] [..192.168.1.103][54112] -> [203.205.151.162][..443] - new: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] - new: [....58] [ip4][..tcp] [..192.168.1.103][58039] -> [203.205.147.171][..443] + end: [....40] [ip4][..tcp] [..192.168.1.103][54112] -> [203.205.151.162][..443] + new: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] + new: [....58] [ip4][..tcp] [..192.168.1.103][58039] -> [203.205.147.171][..443] detected: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] @@ -393,7 +393,7 @@ [ENTROPIES...: 4.7,5.3,5.1,5.9,5.1,6.8,5.0,7.6,5.0,6.3,5.9,7.8,7.5,5.1,7.8,7.8,7.4,5.1,7.1,5.0,7.8,7.6,5.1,7.8,4.9,7.8,7.6,5.1,7.9,4.9,7.8,7.4] guessed: [....41] [ip4][..tcp] [..192.168.1.103][54106] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - end: [....41] [ip4][..tcp] [..192.168.1.103][54106] -> [203.205.151.162][..443] + end: [....41] [ip4][..tcp] [..192.168.1.103][54106] -> [203.205.151.162][..443] update: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] update: [....28] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] update: [....29] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] @@ -401,32 +401,32 @@ update: [....49] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol update: [.....2] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....59] [ip4][..udp] [..192.168.1.100][.5353] -> [....224.0.0.251][.5353] + new: [....59] [ip4][..udp] [..192.168.1.100][.5353] -> [....224.0.0.251][.5353] detected: [....59] [ip4][..udp] [..192.168.1.100][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] + new: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] detected: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....61] [ip4][..udp] [..192.168.1.100][54124] -> [....224.0.0.252][.5355] + new: [....61] [ip4][..udp] [..192.168.1.100][54124] -> [....224.0.0.252][.5355] detected: [....61] [ip4][..udp] [..192.168.1.100][54124] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....62] [ip4][..udp] [..192.168.1.100][49832] -> [....224.0.0.252][.5355] + new: [....62] [ip4][..udp] [..192.168.1.100][49832] -> [....224.0.0.252][.5355] detected: [....62] [ip4][..udp] [..192.168.1.100][49832] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] + new: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] detected: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] + new: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] detected: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....65] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][49195] -> [..............................ff02::1:3][.5355] + new: [....65] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][49195] -> [..............................ff02::1:3][.5355] detected: [....65] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][49195] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....66] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50577] -> [..............................ff02::1:3][.5355] + new: [....66] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50577] -> [..............................ff02::1:3][.5355] detected: [....66] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50577] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....67] [ip4][..udp] [..192.168.1.100][..137] -> [..192.168.1.255][..137] + new: [....67] [ip4][..udp] [..192.168.1.100][..137] -> [..192.168.1.255][..137] detected: [....67] [ip4][..udp] [..192.168.1.100][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][lbjamwptxz] end: [....42] [ip4][..tcp] [..192.168.1.103][54113] -> [203.205.151.162][..443] [TLS.WeChat][Unknown][Chat][Fun] update: [....44] [ip4][..udp] [..192.168.1.103][19041] -> [..192.168.1.254][...53] [DNS.QQ][Unknown][Network][Fun] update: [....47] [ip4][..udp] [..192.168.1.103][60562] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] update: [....48] [ip4][..udp] [..192.168.1.103][35601] -> [..172.217.23.67][..443] [QUIC.Google][Google][Web][Acceptable] guessed: [....46] [ip4][..tcp] [..192.168.1.103][43851] -> [.203.205.158.34][..443] [TLS][Unknown][Web][Safe] - end: [....46] [ip4][..tcp] [..192.168.1.103][43851] -> [.203.205.158.34][..443] + end: [....46] [ip4][..tcp] [..192.168.1.103][43851] -> [.203.205.158.34][..443] guessed: [....43] [ip4][..tcp] [..192.168.1.103][54114] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - end: [....43] [ip4][..tcp] [..192.168.1.103][54114] -> [203.205.151.162][..443] + end: [....43] [ip4][..tcp] [..192.168.1.103][54114] -> [203.205.151.162][..443] update: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun] end: [....45] [ip4][..tcp] [..192.168.1.103][43850] -> [.203.205.158.34][..443] [TLS.QQ][Unknown][Chat][Fun] RISK: Weak TLS Cipher @@ -448,16 +448,16 @@ update: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] update: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....68] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [................................ff02::2] + new: [....68] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [................................ff02::2] detected: [....68] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] - new: [....69] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....69] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....69] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][iphonedimonica] - new: [....70] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff86:6c5b] + new: [....70] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff86:6c5b] detected: [....70] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff86:6c5b] [ICMPV6][Unknown][Network][Acceptable] - new: [....71] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [...............................ff02::16] + new: [....71] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [...............................ff02::16] detected: [....71] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [...............................ff02::16] [ICMPV6][Unknown][Network][Acceptable] - new: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] - new: [....73] [ip4][..tcp] [..192.168.1.103][58041] -> [203.205.147.171][..443] + new: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] + new: [....73] [ip4][..tcp] [..192.168.1.103][58041] -> [203.205.147.171][..443] detected: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] @@ -496,21 +496,21 @@ update: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] update: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] - new: [....75] [ip4][..tcp] [..192.168.1.103][58043] -> [203.205.147.171][..443] + new: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] + new: [....75] [ip4][..tcp] [..192.168.1.103][58043] -> [203.205.147.171][..443] detected: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] detection-update: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun][web.wechat.com] guessed: [....56] [ip4][..tcp] [..192.168.1.103][58037] -> [203.205.147.171][..443] [TLS][Tencent][Web][Safe] - end: [....56] [ip4][..tcp] [..192.168.1.103][58037] -> [203.205.147.171][..443] + end: [....56] [ip4][..tcp] [..192.168.1.103][58037] -> [203.205.147.171][..443] update: [....70] [ip6][icmp6] [.....................................::] -> [......................ff02::1:ff86:6c5b] [ICMPV6][Unknown][Network][Acceptable] update: [....54] [ip4][..udp] [..192.168.1.103][60356] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun] update: [....68] [ip6][icmp6] [...............fe80::842:a3f3:a286:6c5b] -> [................................ff02::2] [ICMPV6][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 1552 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 30 / 75|skipped: 0|!detected: 0|guessed: 11|detection-updates: 63|updates: 72] - new: [....76] [ip4][..tcp] [..192.168.1.103][54183] -> [203.205.151.162][..443] [MIDSTREAM] + new: [....76] [ip4][..tcp] [..192.168.1.103][54183] -> [203.205.151.162][..443] [MIDSTREAM] detected: [....76] [ip4][..tcp] [..192.168.1.103][54183] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] - new: [....77] [ip4][..tcp] [..192.168.1.103][54205] -> [.64.233.167.188][..443] [MIDSTREAM] + new: [....77] [ip4][..tcp] [..192.168.1.103][54205] -> [.64.233.167.188][..443] [MIDSTREAM] idle: [....66] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50577] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [.....3] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] idle: [....69] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -525,7 +525,7 @@ idle: [....65] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][49195] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] end: [....57] [ip4][..tcp] [..192.168.1.103][58038] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun] guessed: [....58] [ip4][..tcp] [..192.168.1.103][58039] -> [203.205.147.171][..443] [TLS][Tencent][Web][Safe] - end: [....58] [ip4][..tcp] [..192.168.1.103][58039] -> [203.205.147.171][..443] + end: [....58] [ip4][..tcp] [..192.168.1.103][58039] -> [203.205.147.171][..443] end: [....72] [ip4][..tcp] [..192.168.1.103][58040] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun] end: [....73] [ip4][..tcp] [..192.168.1.103][58041] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun] end: [....74] [ip4][..tcp] [..192.168.1.103][58042] -> [203.205.147.171][..443] [TLS.WeChat][Tencent][Chat][Fun] @@ -538,41 +538,41 @@ idle: [....63] [ip4][..udp] [..192.168.1.100][57401] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....60] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] idle: [....64] [ip6][..udp] [..............fe80::91f9:3df3:7436:6cd6][50440] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....78] [ip4][..tcp] [..192.168.1.103][39207] -> [...95.101.34.34][...80] [MIDSTREAM] - new: [....79] [ip4][..tcp] [..192.168.1.103][34996] -> [...95.101.34.33][...80] [MIDSTREAM] - new: [....80] [ip4][..tcp] [..192.168.1.103][34999] -> [...95.101.34.33][...80] [MIDSTREAM] - new: [....81] [ip4][..tcp] [..192.168.1.103][35000] -> [...95.101.34.33][...80] [MIDSTREAM] - new: [....82] [ip4][..tcp] [..192.168.1.103][39231] -> [...95.101.34.34][...80] [MIDSTREAM] - new: [....83] [ip4][..tcp] [..192.168.1.103][34981] -> [...95.101.34.33][...80] [MIDSTREAM] - new: [....84] [ip4][..udp] [..192.168.1.103][37578] -> [193.204.114.233][..123] + new: [....78] [ip4][..tcp] [..192.168.1.103][39207] -> [...95.101.34.34][...80] [MIDSTREAM] + new: [....79] [ip4][..tcp] [..192.168.1.103][34996] -> [...95.101.34.33][...80] [MIDSTREAM] + new: [....80] [ip4][..tcp] [..192.168.1.103][34999] -> [...95.101.34.33][...80] [MIDSTREAM] + new: [....81] [ip4][..tcp] [..192.168.1.103][35000] -> [...95.101.34.33][...80] [MIDSTREAM] + new: [....82] [ip4][..tcp] [..192.168.1.103][39231] -> [...95.101.34.34][...80] [MIDSTREAM] + new: [....83] [ip4][..tcp] [..192.168.1.103][34981] -> [...95.101.34.33][...80] [MIDSTREAM] + new: [....84] [ip4][..udp] [..192.168.1.103][37578] -> [193.204.114.233][..123] detected: [....84] [ip4][..udp] [..192.168.1.103][37578] -> [193.204.114.233][..123] [NTP][Unknown][System][Acceptable] detection-update: [....76] [ip4][..tcp] [..192.168.1.103][54183] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic - new: [....85] [ip4][..tcp] [..192.168.1.103][58143] -> [.216.58.205.131][..443] [MIDSTREAM] - new: [....86] [ip4][..tcp] [..192.168.1.103][39195] -> [...95.101.34.34][...80] [MIDSTREAM] - new: [....87] [ip4][..tcp] [..192.168.1.103][52020] -> [.95.101.180.179][...80] [MIDSTREAM] - new: [....88] [ip4][..tcp] [..192.168.1.103][58226] -> [203.205.147.171][..443] [MIDSTREAM] - new: [....89] [ip4][..udp] [..192.168.1.103][58165] -> [..192.168.1.254][...53] + new: [....85] [ip4][..tcp] [..192.168.1.103][58143] -> [.216.58.205.131][..443] [MIDSTREAM] + new: [....86] [ip4][..tcp] [..192.168.1.103][39195] -> [...95.101.34.34][...80] [MIDSTREAM] + new: [....87] [ip4][..tcp] [..192.168.1.103][52020] -> [.95.101.180.179][...80] [MIDSTREAM] + new: [....88] [ip4][..tcp] [..192.168.1.103][58226] -> [203.205.147.171][..443] [MIDSTREAM] + new: [....89] [ip4][..udp] [..192.168.1.103][58165] -> [..192.168.1.254][...53] detected: [....89] [ip4][..udp] [..192.168.1.103][58165] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] - new: [....90] [ip4][..udp] [..192.168.1.103][43317] -> [..192.168.1.254][...53] + new: [....90] [ip4][..udp] [..192.168.1.103][43317] -> [..192.168.1.254][...53] detected: [....90] [ip4][..udp] [..192.168.1.103][43317] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] - new: [....91] [ip4][..udp] [..192.168.1.103][56367] -> [..192.168.1.254][...53] + new: [....91] [ip4][..udp] [..192.168.1.103][56367] -> [..192.168.1.254][...53] detected: [....91] [ip4][..udp] [..192.168.1.103][56367] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] detection-update: [....91] [ip4][..udp] [..192.168.1.103][56367] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] RISK: Unidirectional Traffic - new: [....92] [ip4][..udp] [..192.168.1.103][33915] -> [..192.168.1.254][...53] + new: [....92] [ip4][..udp] [..192.168.1.103][33915] -> [..192.168.1.254][...53] detected: [....92] [ip4][..udp] [..192.168.1.103][33915] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] - new: [....93] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] + new: [....93] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] detected: [....93] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] - new: [....94] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] + new: [....94] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] detected: [....94] [ip4][....2] [..192.168.1.103] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [....95] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] + new: [....95] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] detected: [....95] [ip4][....2] [..192.168.1.100] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [....96] [ip4][....2] [..192.168.1.108] -> [.....224.0.0.22] + new: [....96] [ip4][....2] [..192.168.1.108] -> [.....224.0.0.22] detected: [....96] [ip4][....2] [..192.168.1.108] -> [.....224.0.0.22] [IGMP][Unknown][Network][Acceptable] - new: [....97] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] + new: [....97] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] detected: [....97] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....98] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] + new: [....98] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] detected: [....98] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] update: [....84] [ip4][..udp] [..192.168.1.103][37578] -> [193.204.114.233][..123] [NTP][Unknown][System][Acceptable] update: [....90] [ip4][..udp] [..192.168.1.103][43317] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun] @@ -582,40 +582,40 @@ update: [....92] [ip4][..udp] [..192.168.1.103][33915] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun] detected: [....85] [ip4][..tcp] [..192.168.1.103][58143] -> [.216.58.205.131][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic - new: [....99] [ip4][..udp] [..192.168.1.103][45366] -> [..192.168.1.254][...53] + new: [....99] [ip4][..udp] [..192.168.1.103][45366] -> [..192.168.1.254][...53] detected: [....99] [ip4][..udp] [..192.168.1.103][45366] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] - new: [...100] [ip4][..udp] [..192.168.1.103][59567] -> [..192.168.1.254][...53] + new: [...100] [ip4][..udp] [..192.168.1.103][59567] -> [..192.168.1.254][...53] detected: [...100] [ip4][..udp] [..192.168.1.103][59567] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][ssl.gstatic.com.lan] - new: [...101] [ip4][..udp] [..192.168.1.103][42074] -> [..192.168.1.254][...53] + new: [...101] [ip4][..udp] [..192.168.1.103][42074] -> [..192.168.1.254][...53] detected: [...101] [ip4][..udp] [..192.168.1.103][42074] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][ssl.gstatic.com.lan] - new: [...102] [ip4][..udp] [..192.168.1.103][43705] -> [..192.168.1.254][...53] + new: [...102] [ip4][..udp] [..192.168.1.103][43705] -> [..192.168.1.254][...53] detected: [...102] [ip4][..udp] [..192.168.1.103][43705] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][webpush.web.wechat.com.lan] - new: [...103] [ip4][..udp] [..192.168.1.103][44063] -> [..192.168.1.254][...53] + new: [...103] [ip4][..udp] [..192.168.1.103][44063] -> [..192.168.1.254][...53] detected: [...103] [ip4][..udp] [..192.168.1.103][44063] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][1.debian.pool.ntp.org] detection-update: [...103] [ip4][..udp] [..192.168.1.103][44063] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][1.debian.pool.ntp.org] RISK: Unidirectional Traffic - new: [...104] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] + new: [...104] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] detected: [...104] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][giovanni-pc] RISK: Unsafe Protocol detection-update: [....99] [ip4][..udp] [..192.168.1.103][45366] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun][webpush.web.wechat.com] RISK: Unidirectional Traffic - new: [...105] [ip4][..udp] [..192.168.1.103][42589] -> [..192.168.1.254][...53] + new: [...105] [ip4][..udp] [..192.168.1.103][42589] -> [..192.168.1.254][...53] detected: [...105] [ip4][..udp] [..192.168.1.103][42589] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable][ssl.gstatic.com] detection-update: [...101] [ip4][..udp] [..192.168.1.103][42074] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][ssl.gstatic.com.lan] RISK: Unidirectional Traffic detection-update: [...102] [ip4][..udp] [..192.168.1.103][43705] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][webpush.web.wechat.com.lan] RISK: Unidirectional Traffic - new: [...106] [ip4][..udp] [..192.168.1.103][42856] -> [..192.168.1.254][...53] + new: [...106] [ip4][..udp] [..192.168.1.103][42856] -> [..192.168.1.254][...53] detected: [...106] [ip4][..udp] [..192.168.1.103][42856] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][1.debian.pool.ntp.org.lan] detection-update: [...106] [ip4][..udp] [..192.168.1.103][42856] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][1.debian.pool.ntp.org.lan] RISK: Unidirectional Traffic - new: [...107] [ip4][..udp] [..192.168.1.103][44346] -> [..192.168.1.254][...53] + new: [...107] [ip4][..udp] [..192.168.1.103][44346] -> [..192.168.1.254][...53] detected: [...107] [ip4][..udp] [..192.168.1.103][44346] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][webpush.web.wechat.com.lan] - new: [...108] [ip4][..udp] [..192.168.1.103][41759] -> [..192.168.1.254][...53] + new: [...108] [ip4][..udp] [..192.168.1.103][41759] -> [..192.168.1.254][...53] detected: [...108] [ip4][..udp] [..192.168.1.103][41759] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][2.debian.pool.ntp.org] detection-update: [...108] [ip4][..udp] [..192.168.1.103][41759] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][2.debian.pool.ntp.org] RISK: Unidirectional Traffic - new: [...109] [ip4][..udp] [..192.168.1.103][53515] -> [..192.168.1.254][...53] + new: [...109] [ip4][..udp] [..192.168.1.103][53515] -> [..192.168.1.254][...53] detected: [...109] [ip4][..udp] [..192.168.1.103][53515] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable][webpush.web.wechat.com.lan] idle: [...105] [ip4][..udp] [..192.168.1.103][42589] -> [..192.168.1.254][...53] [DNS.Google][Unknown][Network][Acceptable] idle: [....98] [ip6][..udp] [..............fe80::7a92:9cff:fe0f:a88e][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] @@ -630,7 +630,7 @@ idle: [....93] [ip4][....2] [..192.168.1.254] -> [......224.0.0.1] [IGMP][Unknown][Network][Acceptable] guessed: [....87] [ip4][..tcp] [..192.168.1.103][52020] -> [.95.101.180.179][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....87] [ip4][..tcp] [..192.168.1.103][52020] -> [.95.101.180.179][...80] + end: [....87] [ip4][..tcp] [..192.168.1.103][52020] -> [.95.101.180.179][...80] idle: [...100] [ip4][..udp] [..192.168.1.103][59567] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] idle: [...104] [ip4][..udp] [..192.168.1.100][..138] -> [..192.168.1.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous] RISK: Unsafe Protocol @@ -639,15 +639,15 @@ idle: [....99] [ip4][..udp] [..192.168.1.103][45366] -> [..192.168.1.254][...53] [DNS.WeChat][Unknown][Network][Fun] RISK: Unidirectional Traffic guessed: [....75] [ip4][..tcp] [..192.168.1.103][58043] -> [203.205.147.171][..443] [TLS][Tencent][Web][Safe] - idle: [....75] [ip4][..tcp] [..192.168.1.103][58043] -> [203.205.147.171][..443] + idle: [....75] [ip4][..tcp] [..192.168.1.103][58043] -> [203.205.147.171][..443] guessed: [....12] [ip4][..tcp] [..192.168.1.103][36017] -> [.64.233.167.188][.5228] [Google][Google][Web][Acceptable] - idle: [....12] [ip4][..tcp] [..192.168.1.103][36017] -> [.64.233.167.188][.5228] + idle: [....12] [ip4][..tcp] [..192.168.1.103][36017] -> [.64.233.167.188][.5228] idle: [.....5] [ip4][..tcp] [..192.168.1.103][38657] -> [..172.217.22.14][..443] [TLS.Google][Google][Web][Acceptable] idle: [....13] [ip4][..tcp] [203.205.151.162][..443] -> [..192.168.1.103][54058] [TLS][Unknown][Web][Safe] idle: [....97] [ip4][..udp] [..192.168.1.103][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] guessed: [....88] [ip4][..tcp] [..192.168.1.103][58226] -> [203.205.147.171][..443] [TLS][Tencent][Web][Safe] RISK: Unidirectional Traffic - end: [....88] [ip4][..tcp] [..192.168.1.103][58226] -> [203.205.147.171][..443] + end: [....88] [ip4][..tcp] [..192.168.1.103][58226] -> [203.205.147.171][..443] idle: [....76] [ip4][..tcp] [..192.168.1.103][54183] -> [203.205.151.162][..443] [TLS][Unknown][Web][Safe] RISK: Unidirectional Traffic idle: [...102] [ip4][..udp] [..192.168.1.103][43705] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] @@ -665,28 +665,28 @@ idle: [...107] [ip4][..udp] [..192.168.1.103][44346] -> [..192.168.1.254][...53] [DNS][Unknown][Network][Acceptable] guessed: [....83] [ip4][..tcp] [..192.168.1.103][34981] -> [...95.101.34.33][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....83] [ip4][..tcp] [..192.168.1.103][34981] -> [...95.101.34.33][...80] + end: [....83] [ip4][..tcp] [..192.168.1.103][34981] -> [...95.101.34.33][...80] guessed: [....79] [ip4][..tcp] [..192.168.1.103][34996] -> [...95.101.34.33][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....79] [ip4][..tcp] [..192.168.1.103][34996] -> [...95.101.34.33][...80] + end: [....79] [ip4][..tcp] [..192.168.1.103][34996] -> [...95.101.34.33][...80] guessed: [....80] [ip4][..tcp] [..192.168.1.103][34999] -> [...95.101.34.33][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....80] [ip4][..tcp] [..192.168.1.103][34999] -> [...95.101.34.33][...80] + end: [....80] [ip4][..tcp] [..192.168.1.103][34999] -> [...95.101.34.33][...80] guessed: [....81] [ip4][..tcp] [..192.168.1.103][35000] -> [...95.101.34.33][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....81] [ip4][..tcp] [..192.168.1.103][35000] -> [...95.101.34.33][...80] + end: [....81] [ip4][..tcp] [..192.168.1.103][35000] -> [...95.101.34.33][...80] guessed: [....77] [ip4][..tcp] [..192.168.1.103][54205] -> [.64.233.167.188][..443] [TLS][Google][Web][Safe] RISK: Unidirectional Traffic - idle: [....77] [ip4][..tcp] [..192.168.1.103][54205] -> [.64.233.167.188][..443] + idle: [....77] [ip4][..tcp] [..192.168.1.103][54205] -> [.64.233.167.188][..443] guessed: [....86] [ip4][..tcp] [..192.168.1.103][39195] -> [...95.101.34.34][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....86] [ip4][..tcp] [..192.168.1.103][39195] -> [...95.101.34.34][...80] + end: [....86] [ip4][..tcp] [..192.168.1.103][39195] -> [...95.101.34.34][...80] guessed: [....78] [ip4][..tcp] [..192.168.1.103][39207] -> [...95.101.34.34][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....78] [ip4][..tcp] [..192.168.1.103][39207] -> [...95.101.34.34][...80] + end: [....78] [ip4][..tcp] [..192.168.1.103][39207] -> [...95.101.34.34][...80] guessed: [....82] [ip4][..tcp] [..192.168.1.103][39231] -> [...95.101.34.34][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....82] [ip4][..tcp] [..192.168.1.103][39231] -> [...95.101.34.34][...80] + end: [....82] [ip4][..tcp] [..192.168.1.103][39231] -> [...95.101.34.34][...80] guessed: [....21] [ip4][..tcp] [..192.168.1.103][49787] -> [.216.58.205.142][..443] [TLS][Google][Web][Safe] - idle: [....21] [ip4][..tcp] [..192.168.1.103][49787] -> [.216.58.205.142][..443] + idle: [....21] [ip4][..tcp] [..192.168.1.103][49787] -> [.216.58.205.142][..443] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/weibo.pcap.out b/test/results/flow-info/default/weibo.pcap.out index 15aaa3de1..8a2212c85 100644 --- a/test/results/flow-info/default/weibo.pcap.out +++ b/test/results/flow-info/default/weibo.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..216.58.210.14][..443] -> [..192.168.1.105][49361] - new: [.....2] [ip4][..tcp] [..192.168.1.105][58480] -> [..216.58.214.78][..443] [MIDSTREAM] - new: [.....3] [ip4][..tcp] [..192.168.1.105][58481] -> [..216.58.214.78][..443] [MIDSTREAM] - new: [.....4] [ip4][..udp] [..192.168.1.105][53656] -> [.216.58.210.227][..443] - new: [.....5] [ip4][..udp] [..192.168.1.105][54988] -> [....192.168.1.1][...53] + new: [.....1] [ip4][..udp] [..216.58.210.14][..443] -> [..192.168.1.105][49361] + new: [.....2] [ip4][..tcp] [..192.168.1.105][58480] -> [..216.58.214.78][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [..192.168.1.105][58481] -> [..216.58.214.78][..443] [MIDSTREAM] + new: [.....4] [ip4][..udp] [..192.168.1.105][53656] -> [.216.58.210.227][..443] + new: [.....5] [ip4][..udp] [..192.168.1.105][54988] -> [....192.168.1.1][...53] detected: [.....5] [ip4][..udp] [..192.168.1.105][54988] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][weibo.com] detection-update: [.....5] [ip4][..udp] [..192.168.1.105][54988] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][weibo.com] - new: [.....6] [ip4][..tcp] [..192.168.1.105][59119] -> [.114.134.80.162][...80] - new: [.....7] [ip4][..tcp] [..192.168.1.105][59120] -> [.114.134.80.162][...80] - new: [.....8] [ip4][..tcp] [..192.168.1.105][59121] -> [.114.134.80.162][...80] - new: [.....9] [ip4][..tcp] [..192.168.1.105][35154] -> [.216.58.210.206][..443] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [..192.168.1.105][59119] -> [.114.134.80.162][...80] + new: [.....7] [ip4][..tcp] [..192.168.1.105][59120] -> [.114.134.80.162][...80] + new: [.....8] [ip4][..tcp] [..192.168.1.105][59121] -> [.114.134.80.162][...80] + new: [.....9] [ip4][..tcp] [..192.168.1.105][35154] -> [.216.58.210.206][..443] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [..192.168.1.105][59119] -> [.114.134.80.162][...80] [HTTP][Unknown][Web][Acceptable][weibo.com] - new: [....10] [ip4][..udp] [..192.168.1.105][.7148] -> [....192.168.1.1][...53] + new: [....10] [ip4][..udp] [..192.168.1.105][.7148] -> [....192.168.1.1][...53] detected: [....10] [ip4][..udp] [..192.168.1.105][.7148] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun][www.weibo.com] detection-update: [....10] [ip4][..udp] [..192.168.1.105][.7148] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun][www.weibo.com] - new: [....11] [ip4][..tcp] [..192.168.1.105][51698] -> [.93.188.134.137][...80] + new: [....11] [ip4][..tcp] [..192.168.1.105][51698] -> [.93.188.134.137][...80] detected: [....11] [ip4][..tcp] [..192.168.1.105][51698] -> [.93.188.134.137][...80] [HTTP.SinaWeibo][Unknown][SocialNetwork][Fun][www.weibo.com] - new: [....12] [ip4][..tcp] [..192.168.1.105][37802] -> [..216.58.212.69][..443] [MIDSTREAM] - new: [....13] [ip4][..tcp] [..192.168.1.105][40440] -> [.54.225.163.210][..443] [MIDSTREAM] - new: [....14] [ip4][..tcp] [..192.168.1.105][34699] -> [..216.58.212.65][..443] [MIDSTREAM] + new: [....12] [ip4][..tcp] [..192.168.1.105][37802] -> [..216.58.212.69][..443] [MIDSTREAM] + new: [....13] [ip4][..tcp] [..192.168.1.105][40440] -> [.54.225.163.210][..443] [MIDSTREAM] + new: [....14] [ip4][..tcp] [..192.168.1.105][34699] -> [..216.58.212.65][..443] [MIDSTREAM] analyse: [....11] [ip4][..tcp] [..192.168.1.105][51698] -> [.93.188.134.137][...80] [HTTP.SinaWeibo][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.482| 0.042| 0.114| 12948.299| 2.500] @@ -31,17 +31,17 @@ [IATS(ms)....: 29.2,29.2,0.3,28.2,454.5,482.4,0.1,0.1,13.2,13.2,0.1,0.0,0.0,0.0,8.4,8.4,0.1,0.1,0.0,0.0,0.0,0.0,0.0,0.0,15.4,15.4,68.3,68.3,0.1,0.0,54.8] [PKTLENS.....: 60,60,52,502,52,57,64,1488,64,1488,64,54,72,1064,64,58,64,2924,64,280,72,54,72,1488,64,805,52,58,52,1488,52,1488] [ENTROPIES...: 4.7,5.2,5.0,5.9,5.1,5.1,5.1,7.9,5.1,7.9,5.1,5.1,5.1,7.8,5.1,5.2,5.1,7.9,5.1,7.2,5.1,5.1,5.2,7.8,5.1,5.8,5.1,5.2,5.0,7.9,4.9,7.9] - new: [....15] [ip4][..udp] [..192.168.1.105][53543] -> [....192.168.1.1][...53] + new: [....15] [ip4][..udp] [..192.168.1.105][53543] -> [....192.168.1.1][...53] detected: [....15] [ip4][..udp] [..192.168.1.105][53543] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][img.t.sinajs.cn] detection-update: [....15] [ip4][..udp] [..192.168.1.105][53543] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][img.t.sinajs.cn] RISK: Minor Issues - new: [....16] [ip4][..tcp] [..192.168.1.105][35803] -> [.93.188.134.246][...80] - new: [....17] [ip4][..tcp] [..192.168.1.105][35804] -> [.93.188.134.246][...80] - new: [....18] [ip4][..tcp] [..192.168.1.105][35805] -> [.93.188.134.246][...80] + new: [....16] [ip4][..tcp] [..192.168.1.105][35803] -> [.93.188.134.246][...80] + new: [....17] [ip4][..tcp] [..192.168.1.105][35804] -> [.93.188.134.246][...80] + new: [....18] [ip4][..tcp] [..192.168.1.105][35805] -> [.93.188.134.246][...80] detected: [....16] [ip4][..tcp] [..192.168.1.105][35803] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] detected: [....17] [ip4][..tcp] [..192.168.1.105][35804] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] detected: [....18] [ip4][..tcp] [..192.168.1.105][35805] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] - new: [....19] [ip4][..udp] [..192.168.1.105][41352] -> [....192.168.1.1][...53] + new: [....19] [ip4][..udp] [..192.168.1.105][41352] -> [....192.168.1.1][...53] detected: [....19] [ip4][..udp] [..192.168.1.105][41352] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][js.t.sinajs.cn] analyse: [....17] [ip4][..tcp] [..192.168.1.105][35804] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy @@ -63,53 +63,53 @@ [IATS(ms)....: 26.7,26.8,0.2,28.2,372.4,400.5,6.7,6.7,6.6,6.6,15.5,15.5,6.6,6.6,9.2,9.2,23.4,23.4,49.3,49.3,71.7,71.7,3.3,3.3,2.9,2.9,2.8,2.8,5.5,5.5,3.7] [PKTLENS.....: 60,60,52,472,52,567,52,1488,52,4360,52,1488,52,4360,52,2924,52,567,64,567,64,1488,52,1488,52,1488,64,1488,64,1488,64,1488] [ENTROPIES...: 4.6,5.1,4.9,5.9,5.0,5.7,4.8,7.8,4.9,8.0,4.9,7.9,4.8,8.0,4.9,7.9,4.9,5.7,5.0,5.7,5.0,7.9,4.9,7.9,4.9,7.9,5.0,7.9,5.0,7.9,5.0,7.8] - new: [....20] [ip4][..udp] [..192.168.1.105][18035] -> [....192.168.1.1][...53] + new: [....20] [ip4][..udp] [..192.168.1.105][18035] -> [....192.168.1.1][...53] detected: [....20] [ip4][..udp] [..192.168.1.105][18035] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][u1.img.mobile.sina.cn] - new: [....21] [ip4][..udp] [..192.168.1.105][50640] -> [....192.168.1.1][...53] + new: [....21] [ip4][..udp] [..192.168.1.105][50640] -> [....192.168.1.1][...53] detected: [....21] [ip4][..udp] [..192.168.1.105][50640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][acjstb.aliyun.com] RISK: Susp DGA Domain name - new: [....22] [ip4][..udp] [..192.168.1.105][51440] -> [....192.168.1.1][...53] + new: [....22] [ip4][..udp] [..192.168.1.105][51440] -> [....192.168.1.1][...53] detected: [....22] [ip4][..udp] [..192.168.1.105][51440] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable][g.alicdn.com] - new: [....23] [ip4][..udp] [..192.168.1.105][53466] -> [....192.168.1.1][...53] + new: [....23] [ip4][..udp] [..192.168.1.105][53466] -> [....192.168.1.1][...53] detected: [....23] [ip4][..udp] [..192.168.1.105][53466] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable][log.mmstat.com] - new: [....24] [ip4][..udp] [..192.168.1.105][33822] -> [....192.168.1.1][...53] + new: [....24] [ip4][..udp] [..192.168.1.105][33822] -> [....192.168.1.1][...53] detected: [....24] [ip4][..udp] [..192.168.1.105][33822] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][login.taobao.com] - new: [....25] [ip4][..tcp] [..192.168.1.105][35806] -> [.93.188.134.246][...80] - new: [....26] [ip4][..tcp] [..192.168.1.105][35807] -> [.93.188.134.246][...80] - new: [....27] [ip4][..tcp] [..192.168.1.105][35808] -> [.93.188.134.246][...80] - new: [....28] [ip4][..tcp] [..192.168.1.105][35809] -> [.93.188.134.246][...80] + new: [....25] [ip4][..tcp] [..192.168.1.105][35806] -> [.93.188.134.246][...80] + new: [....26] [ip4][..tcp] [..192.168.1.105][35807] -> [.93.188.134.246][...80] + new: [....27] [ip4][..tcp] [..192.168.1.105][35808] -> [.93.188.134.246][...80] + new: [....28] [ip4][..tcp] [..192.168.1.105][35809] -> [.93.188.134.246][...80] detected: [....25] [ip4][..tcp] [..192.168.1.105][35806] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] detected: [....26] [ip4][..tcp] [..192.168.1.105][35807] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] detected: [....28] [ip4][..tcp] [..192.168.1.105][35809] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][img.t.sinajs.cn] detection-update: [....20] [ip4][..udp] [..192.168.1.105][18035] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][u1.img.mobile.sina.cn] - new: [....29] [ip4][..udp] [..192.168.1.105][11798] -> [....192.168.1.1][...53] + new: [....29] [ip4][..udp] [..192.168.1.105][11798] -> [....192.168.1.1][...53] detected: [....29] [ip4][..udp] [..192.168.1.105][11798] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun][account.weibo.com] - new: [....30] [ip4][..tcp] [..192.168.1.105][42275] -> [...222.73.28.96][...80] + new: [....30] [ip4][..tcp] [..192.168.1.105][42275] -> [...222.73.28.96][...80] detection-update: [....19] [ip4][..udp] [..192.168.1.105][41352] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun][js.t.sinajs.cn] - new: [....31] [ip4][..udp] [..192.168.1.105][16804] -> [....192.168.1.1][...53] + new: [....31] [ip4][..udp] [..192.168.1.105][16804] -> [....192.168.1.1][...53] detected: [....31] [ip4][..udp] [..192.168.1.105][16804] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun][c.weibo.cn] - new: [....32] [ip4][..tcp] [..192.168.1.105][35811] -> [.93.188.134.246][...80] + new: [....32] [ip4][..tcp] [..192.168.1.105][35811] -> [.93.188.134.246][...80] detection-update: [....22] [ip4][..udp] [..192.168.1.105][51440] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable][g.alicdn.com] - new: [....33] [ip4][..udp] [..192.168.1.105][50533] -> [....192.168.1.1][...53] + new: [....33] [ip4][..udp] [..192.168.1.105][50533] -> [....192.168.1.1][...53] detected: [....33] [ip4][..udp] [..192.168.1.105][50533] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun][data.weibo.com] - new: [....34] [ip4][..tcp] [..192.168.1.105][50827] -> [...47.89.65.229][..443] + new: [....34] [ip4][..tcp] [..192.168.1.105][50827] -> [...47.89.65.229][..443] detection-update: [....23] [ip4][..udp] [..192.168.1.105][53466] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable][log.mmstat.com] - new: [....35] [ip4][..tcp] [..192.168.1.105][48352] -> [..140.205.174.1][..443] - new: [....36] [ip4][..tcp] [..192.168.1.105][48353] -> [..140.205.174.1][..443] - new: [....37] [ip4][..tcp] [..192.168.1.105][42280] -> [...222.73.28.96][...80] - new: [....38] [ip4][..tcp] [..192.168.1.105][50831] -> [...47.89.65.229][..443] - new: [....39] [ip4][..tcp] [..192.168.1.105][48356] -> [..140.205.174.1][..443] + new: [....35] [ip4][..tcp] [..192.168.1.105][48352] -> [..140.205.174.1][..443] + new: [....36] [ip4][..tcp] [..192.168.1.105][48353] -> [..140.205.174.1][..443] + new: [....37] [ip4][..tcp] [..192.168.1.105][42280] -> [...222.73.28.96][...80] + new: [....38] [ip4][..tcp] [..192.168.1.105][50831] -> [...47.89.65.229][..443] + new: [....39] [ip4][..tcp] [..192.168.1.105][48356] -> [..140.205.174.1][..443] detected: [....32] [ip4][..tcp] [..192.168.1.105][35811] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][js.t.sinajs.cn] detected: [....34] [ip4][..tcp] [..192.168.1.105][50827] -> [...47.89.65.229][..443] [TLS.Alibaba][Unknown][Web][Acceptable][g.alicdn.com] detection-update: [....21] [ip4][..udp] [..192.168.1.105][50640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][acjstb.aliyun.com] RISK: Susp DGA Domain name, Risky Domain Name - new: [....40] [ip4][..tcp] [..192.168.1.105][52271] -> [..42.156.184.19][..443] - new: [....41] [ip4][..tcp] [..192.168.1.105][52272] -> [..42.156.184.19][..443] + new: [....40] [ip4][..tcp] [..192.168.1.105][52271] -> [..42.156.184.19][..443] + new: [....41] [ip4][..tcp] [..192.168.1.105][52272] -> [..42.156.184.19][..443] detection-update: [....24] [ip4][..udp] [..192.168.1.105][33822] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][login.taobao.com] - new: [....42] [ip4][..tcp] [..192.168.1.105][47721] -> [.140.205.170.63][..443] + new: [....42] [ip4][..tcp] [..192.168.1.105][47721] -> [.140.205.170.63][..443] detected: [....30] [ip4][..tcp] [..192.168.1.105][42275] -> [...222.73.28.96][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun][u1.img.mobile.sina.cn] - new: [....43] [ip4][..tcp] [..192.168.1.105][52274] -> [..42.156.184.19][..443] - new: [....44] [ip4][..tcp] [..192.168.1.105][47723] -> [.140.205.170.63][..443] + new: [....43] [ip4][..tcp] [..192.168.1.105][52274] -> [..42.156.184.19][..443] + new: [....44] [ip4][..tcp] [..192.168.1.105][47723] -> [.140.205.170.63][..443] analyse: [....18] [ip4][..tcp] [..192.168.1.105][35805] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.439| 0.087| 0.119| 14239.990| 3.800] @@ -143,74 +143,74 @@ idle: [....30] [ip4][..tcp] [..192.168.1.105][42275] -> [...222.73.28.96][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] guessed: [....37] [ip4][..tcp] [..192.168.1.105][42280] -> [...222.73.28.96][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - idle: [....37] [ip4][..tcp] [..192.168.1.105][42280] -> [...222.73.28.96][...80] + idle: [....37] [ip4][..tcp] [..192.168.1.105][42280] -> [...222.73.28.96][...80] idle: [....20] [ip4][..udp] [..192.168.1.105][18035] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun] idle: [.....5] [ip4][..udp] [..192.168.1.105][54988] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] guessed: [....12] [ip4][..tcp] [..192.168.1.105][37802] -> [..216.58.212.69][..443] [TLS][Google][Web][Safe] - idle: [....12] [ip4][..tcp] [..192.168.1.105][37802] -> [..216.58.212.69][..443] + idle: [....12] [ip4][..tcp] [..192.168.1.105][37802] -> [..216.58.212.69][..443] idle: [....16] [ip4][..tcp] [..192.168.1.105][35803] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] idle: [....17] [ip4][..tcp] [..192.168.1.105][35804] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] idle: [....18] [ip4][..tcp] [..192.168.1.105][35805] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] idle: [....25] [ip4][..tcp] [..192.168.1.105][35806] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] idle: [....26] [ip4][..tcp] [..192.168.1.105][35807] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] guessed: [....27] [ip4][..tcp] [..192.168.1.105][35808] -> [.93.188.134.246][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [....27] [ip4][..tcp] [..192.168.1.105][35808] -> [.93.188.134.246][...80] + idle: [....27] [ip4][..tcp] [..192.168.1.105][35808] -> [.93.188.134.246][...80] idle: [....28] [ip4][..tcp] [..192.168.1.105][35809] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] idle: [....32] [ip4][..tcp] [..192.168.1.105][35811] -> [.93.188.134.246][...80] [HTTP.Sina][Unknown][SocialNetwork][Fun] guessed: [....13] [ip4][..tcp] [..192.168.1.105][40440] -> [.54.225.163.210][..443] [TLS][AmazonAWS][Web][Safe] - idle: [....13] [ip4][..tcp] [..192.168.1.105][40440] -> [.54.225.163.210][..443] + idle: [....13] [ip4][..tcp] [..192.168.1.105][40440] -> [.54.225.163.210][..443] guessed: [.....2] [ip4][..tcp] [..192.168.1.105][58480] -> [..216.58.214.78][..443] [TLS][Google][Web][Safe] - idle: [.....2] [ip4][..tcp] [..192.168.1.105][58480] -> [..216.58.214.78][..443] + idle: [.....2] [ip4][..tcp] [..192.168.1.105][58480] -> [..216.58.214.78][..443] guessed: [.....3] [ip4][..tcp] [..192.168.1.105][58481] -> [..216.58.214.78][..443] [TLS][Google][Web][Safe] - idle: [.....3] [ip4][..tcp] [..192.168.1.105][58481] -> [..216.58.214.78][..443] + idle: [.....3] [ip4][..tcp] [..192.168.1.105][58481] -> [..216.58.214.78][..443] idle: [....34] [ip4][..tcp] [..192.168.1.105][50827] -> [...47.89.65.229][..443] [TLS.Alibaba][Unknown][Web][Acceptable] guessed: [....38] [ip4][..tcp] [..192.168.1.105][50831] -> [...47.89.65.229][..443] [TLS][Unknown][Web][Safe] - idle: [....38] [ip4][..tcp] [..192.168.1.105][50831] -> [...47.89.65.229][..443] + idle: [....38] [ip4][..tcp] [..192.168.1.105][50831] -> [...47.89.65.229][..443] guessed: [....42] [ip4][..tcp] [..192.168.1.105][47721] -> [.140.205.170.63][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....42] [ip4][..tcp] [..192.168.1.105][47721] -> [.140.205.170.63][..443] + idle: [....42] [ip4][..tcp] [..192.168.1.105][47721] -> [.140.205.170.63][..443] guessed: [....44] [ip4][..tcp] [..192.168.1.105][47723] -> [.140.205.170.63][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....44] [ip4][..tcp] [..192.168.1.105][47723] -> [.140.205.170.63][..443] + idle: [....44] [ip4][..tcp] [..192.168.1.105][47723] -> [.140.205.170.63][..443] idle: [....23] [ip4][..udp] [..192.168.1.105][53466] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable] idle: [....22] [ip4][..udp] [..192.168.1.105][51440] -> [....192.168.1.1][...53] [DNS.Alibaba][Unknown][Network][Acceptable] guessed: [....40] [ip4][..tcp] [..192.168.1.105][52271] -> [..42.156.184.19][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....40] [ip4][..tcp] [..192.168.1.105][52271] -> [..42.156.184.19][..443] + idle: [....40] [ip4][..tcp] [..192.168.1.105][52271] -> [..42.156.184.19][..443] guessed: [....41] [ip4][..tcp] [..192.168.1.105][52272] -> [..42.156.184.19][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....41] [ip4][..tcp] [..192.168.1.105][52272] -> [..42.156.184.19][..443] + idle: [....41] [ip4][..tcp] [..192.168.1.105][52272] -> [..42.156.184.19][..443] guessed: [....43] [ip4][..tcp] [..192.168.1.105][52274] -> [..42.156.184.19][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....43] [ip4][..tcp] [..192.168.1.105][52274] -> [..42.156.184.19][..443] + idle: [....43] [ip4][..tcp] [..192.168.1.105][52274] -> [..42.156.184.19][..443] idle: [....15] [ip4][..udp] [..192.168.1.105][53543] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun] RISK: Minor Issues idle: [....19] [ip4][..udp] [..192.168.1.105][41352] -> [....192.168.1.1][...53] [DNS.Sina][Unknown][Network][Fun] idle: [....31] [ip4][..udp] [..192.168.1.105][16804] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun] guessed: [....14] [ip4][..tcp] [..192.168.1.105][34699] -> [..216.58.212.65][..443] [TLS][Google][Web][Safe] - idle: [....14] [ip4][..tcp] [..192.168.1.105][34699] -> [..216.58.212.65][..443] + idle: [....14] [ip4][..tcp] [..192.168.1.105][34699] -> [..216.58.212.65][..443] guessed: [....35] [ip4][..tcp] [..192.168.1.105][48352] -> [..140.205.174.1][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....35] [ip4][..tcp] [..192.168.1.105][48352] -> [..140.205.174.1][..443] + idle: [....35] [ip4][..tcp] [..192.168.1.105][48352] -> [..140.205.174.1][..443] guessed: [....36] [ip4][..tcp] [..192.168.1.105][48353] -> [..140.205.174.1][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....36] [ip4][..tcp] [..192.168.1.105][48353] -> [..140.205.174.1][..443] + idle: [....36] [ip4][..tcp] [..192.168.1.105][48353] -> [..140.205.174.1][..443] guessed: [....39] [ip4][..tcp] [..192.168.1.105][48356] -> [..140.205.174.1][..443] [TLS][Alibaba][Web][Safe] RISK: Unidirectional Traffic - idle: [....39] [ip4][..tcp] [..192.168.1.105][48356] -> [..140.205.174.1][..443] + idle: [....39] [ip4][..tcp] [..192.168.1.105][48356] -> [..140.205.174.1][..443] idle: [....10] [ip4][..udp] [..192.168.1.105][.7148] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun] idle: [....24] [ip4][..udp] [..192.168.1.105][33822] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] guessed: [.....1] [ip4][..udp] [..216.58.210.14][..443] -> [..192.168.1.105][49361] [QUIC][Google][Web][Acceptable] - idle: [.....1] [ip4][..udp] [..216.58.210.14][..443] -> [..192.168.1.105][49361] + idle: [.....1] [ip4][..udp] [..216.58.210.14][..443] -> [..192.168.1.105][49361] end: [.....6] [ip4][..tcp] [..192.168.1.105][59119] -> [.114.134.80.162][...80] [HTTP][Unknown][Web][Acceptable] guessed: [.....7] [ip4][..tcp] [..192.168.1.105][59120] -> [.114.134.80.162][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [.....7] [ip4][..tcp] [..192.168.1.105][59120] -> [.114.134.80.162][...80] + idle: [.....7] [ip4][..tcp] [..192.168.1.105][59120] -> [.114.134.80.162][...80] guessed: [.....8] [ip4][..tcp] [..192.168.1.105][59121] -> [.114.134.80.162][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [.....8] [ip4][..tcp] [..192.168.1.105][59121] -> [.114.134.80.162][...80] + idle: [.....8] [ip4][..tcp] [..192.168.1.105][59121] -> [.114.134.80.162][...80] guessed: [.....9] [ip4][..tcp] [..192.168.1.105][35154] -> [.216.58.210.206][..443] [TLS][Google][Web][Safe] - idle: [.....9] [ip4][..tcp] [..192.168.1.105][35154] -> [.216.58.210.206][..443] + idle: [.....9] [ip4][..tcp] [..192.168.1.105][35154] -> [.216.58.210.206][..443] guessed: [.....4] [ip4][..udp] [..192.168.1.105][53656] -> [.216.58.210.227][..443] [QUIC][Google][Web][Acceptable] - idle: [.....4] [ip4][..udp] [..192.168.1.105][53656] -> [.216.58.210.227][..443] + idle: [.....4] [ip4][..udp] [..192.168.1.105][53656] -> [.216.58.210.227][..443] idle: [....33] [ip4][..udp] [..192.168.1.105][50533] -> [....192.168.1.1][...53] [DNS.SinaWeibo][Unknown][Network][Fun] idle: [....11] [ip4][..tcp] [..192.168.1.105][51698] -> [.93.188.134.137][...80] [HTTP.SinaWeibo][Unknown][SocialNetwork][Fun] idle: [....21] [ip4][..udp] [..192.168.1.105][50640] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/whatsapp.pcap.out b/test/results/flow-info/default/whatsapp.pcap.out index 467cdd1db..4860f7f81 100644 --- a/test/results/flow-info/default/whatsapp.pcap.out +++ b/test/results/flow-info/default/whatsapp.pcap.out @@ -1,61 +1,61 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][44804] -> [..179.60.195.49][.5222] + new: [.....1] [ip4][..tcp] [..192.168.2.100][44804] -> [..179.60.195.49][.5222] detected: [.....1] [ip4][..tcp] [..192.168.2.100][44804] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 9 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.2.100][40084] -> [..179.60.195.49][.5222] + new: [.....2] [ip4][..tcp] [..192.168.2.100][40084] -> [..179.60.195.49][.5222] detected: [.....2] [ip4][..tcp] [..192.168.2.100][40084] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [.....3] [ip4][..tcp] [..192.168.2.100][42272] -> [..179.60.195.49][.5222] + new: [.....3] [ip4][..tcp] [..192.168.2.100][42272] -> [..179.60.195.49][.5222] detected: [.....3] [ip4][..tcp] [..192.168.2.100][42272] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 25 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....4] [ip4][..tcp] [..192.168.2.100][42436] -> [..179.60.195.49][.5222] + new: [.....4] [ip4][..tcp] [..192.168.2.100][42436] -> [..179.60.195.49][.5222] detected: [.....4] [ip4][..tcp] [..192.168.2.100][42436] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 33 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][40178] -> [..179.60.195.49][.5222] + new: [.....5] [ip4][..tcp] [..192.168.2.100][40178] -> [..179.60.195.49][.5222] detected: [.....5] [ip4][..tcp] [..192.168.2.100][40178] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [.....6] [ip4][..tcp] [..192.168.2.100][42646] -> [..179.60.195.49][.5222] + new: [.....6] [ip4][..tcp] [..192.168.2.100][42646] -> [..179.60.195.49][.5222] detected: [.....6] [ip4][..tcp] [..192.168.2.100][42646] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [.....7] [ip4][..tcp] [..192.168.2.100][40204] -> [..179.60.195.49][.5222] + new: [.....7] [ip4][..tcp] [..192.168.2.100][40204] -> [..179.60.195.49][.5222] detected: [.....7] [ip4][..tcp] [..192.168.2.100][40204] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 57 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 7|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....8] [ip4][..tcp] [..192.168.2.100][45932] -> [..179.60.195.49][.5222] + new: [.....8] [ip4][..tcp] [..192.168.2.100][45932] -> [..179.60.195.49][.5222] detected: [.....8] [ip4][..tcp] [..192.168.2.100][45932] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 65 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 8|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....9] [ip4][..tcp] [..192.168.2.100][40954] -> [..179.60.195.49][.5222] + new: [.....9] [ip4][..tcp] [..192.168.2.100][40954] -> [..179.60.195.49][.5222] detected: [.....9] [ip4][..tcp] [..192.168.2.100][40954] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 73 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 9 / 9|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....10] [ip4][..tcp] [..192.168.2.100][41214] -> [..179.60.195.49][.5222] + new: [....10] [ip4][..tcp] [..192.168.2.100][41214] -> [..179.60.195.49][.5222] detected: [....10] [ip4][..tcp] [..192.168.2.100][41214] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....11] [ip4][..tcp] [..192.168.2.100][49026] -> [..179.60.195.33][.5222] + new: [....11] [ip4][..tcp] [..192.168.2.100][49026] -> [..179.60.195.33][.5222] detected: [....11] [ip4][..tcp] [..192.168.2.100][49026] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 89 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 11|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....12] [ip4][..tcp] [..192.168.2.100][41288] -> [..179.60.195.49][.5222] + new: [....12] [ip4][..tcp] [..192.168.2.100][41288] -> [..179.60.195.49][.5222] detected: [....12] [ip4][..tcp] [..192.168.2.100][41288] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [.....1] [ip4][..tcp] [..192.168.2.100][44804] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 97 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 12|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....13] [ip4][..tcp] [..192.168.2.100][41610] -> [..179.60.195.49][.5222] + new: [....13] [ip4][..tcp] [..192.168.2.100][41610] -> [..179.60.195.49][.5222] detected: [....13] [ip4][..tcp] [..192.168.2.100][41610] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [.....6] [ip4][..tcp] [..192.168.2.100][42646] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -72,31 +72,31 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 105 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 13|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....14] [ip4][..tcp] [..192.168.2.100][41808] -> [..179.60.195.49][.5222] + new: [....14] [ip4][..tcp] [..192.168.2.100][41808] -> [..179.60.195.49][.5222] detected: [....14] [ip4][..tcp] [..192.168.2.100][41808] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [.....8] [ip4][..tcp] [..192.168.2.100][45932] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 113 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 14|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....15] [ip4][..tcp] [..192.168.2.100][37482] -> [..179.60.195.33][.5222] + new: [....15] [ip4][..tcp] [..192.168.2.100][37482] -> [..179.60.195.33][.5222] detected: [....15] [ip4][..tcp] [..192.168.2.100][37482] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 121 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 15|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....16] [ip4][..tcp] [..192.168.2.100][37582] -> [..179.60.195.33][.5222] + new: [....16] [ip4][..tcp] [..192.168.2.100][37582] -> [..179.60.195.33][.5222] detected: [....16] [ip4][..tcp] [..192.168.2.100][37582] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 129 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 16|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....17] [ip4][..tcp] [..192.168.2.100][45754] -> [..179.60.195.49][.5222] + new: [....17] [ip4][..tcp] [..192.168.2.100][45754] -> [..179.60.195.49][.5222] detected: [....17] [ip4][..tcp] [..192.168.2.100][45754] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [.....9] [ip4][..tcp] [..192.168.2.100][40954] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 137 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 17|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....18] [ip4][..tcp] [..192.168.2.100][45824] -> [..179.60.195.49][.5222] + new: [....18] [ip4][..tcp] [..192.168.2.100][45824] -> [..179.60.195.49][.5222] detected: [....18] [ip4][..tcp] [..192.168.2.100][45824] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....11] [ip4][..tcp] [..192.168.2.100][49026] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] @@ -105,7 +105,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 145 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 18|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....19] [ip4][..tcp] [..192.168.2.100][46406] -> [..179.60.195.49][.5222] + new: [....19] [ip4][..tcp] [..192.168.2.100][46406] -> [..179.60.195.49][.5222] detected: [....19] [ip4][..tcp] [..192.168.2.100][46406] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....12] [ip4][..tcp] [..192.168.2.100][41288] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -114,61 +114,61 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 153 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 19|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....20] [ip4][..tcp] [..192.168.2.100][40224] -> [....31.13.83.49][.5222] + new: [....20] [ip4][..tcp] [..192.168.2.100][40224] -> [....31.13.83.49][.5222] detected: [....20] [ip4][..tcp] [..192.168.2.100][40224] -> [....31.13.83.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....14] [ip4][..tcp] [..192.168.2.100][41808] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....21] [ip4][..tcp] [..192.168.2.100][45470] -> [..179.60.195.33][.5222] + new: [....21] [ip4][..tcp] [..192.168.2.100][45470] -> [..179.60.195.33][.5222] detected: [....21] [ip4][..tcp] [..192.168.2.100][45470] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....15] [ip4][..tcp] [..192.168.2.100][37482] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 169 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 21|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....22] [ip4][..tcp] [..192.168.2.100][43084] -> [..179.60.195.49][.5222] + new: [....22] [ip4][..tcp] [..192.168.2.100][43084] -> [..179.60.195.49][.5222] detected: [....22] [ip4][..tcp] [..192.168.2.100][43084] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....23] [ip4][..tcp] [..192.168.2.100][45602] -> [..179.60.195.33][.5222] + new: [....23] [ip4][..tcp] [..192.168.2.100][45602] -> [..179.60.195.33][.5222] detected: [....23] [ip4][..tcp] [..192.168.2.100][45602] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....16] [ip4][..tcp] [..192.168.2.100][37582] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 184 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 23|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....24] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.49][.5222] + new: [....24] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.49][.5222] detected: [....24] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....25] [ip4][..tcp] [..192.168.2.100][46042] -> [..179.60.195.33][.5222] + new: [....25] [ip4][..tcp] [..192.168.2.100][46042] -> [..179.60.195.33][.5222] detected: [....25] [ip4][..tcp] [..192.168.2.100][46042] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....17] [ip4][..tcp] [..192.168.2.100][45754] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 200 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 25|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....26] [ip4][..tcp] [..192.168.2.100][43206] -> [..179.60.195.49][.5222] + new: [....26] [ip4][..tcp] [..192.168.2.100][43206] -> [..179.60.195.49][.5222] detected: [....26] [ip4][..tcp] [..192.168.2.100][43206] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 208 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 9 / 26|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....27] [ip4][..tcp] [..192.168.2.100][43230] -> [..179.60.195.49][.5222] + new: [....27] [ip4][..tcp] [..192.168.2.100][43230] -> [..179.60.195.49][.5222] detected: [....27] [ip4][..tcp] [..192.168.2.100][43230] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....18] [ip4][..tcp] [..192.168.2.100][45824] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 216 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 9 / 27|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....28] [ip4][..tcp] [..192.168.2.100][46468] -> [..179.60.195.33][.5222] + new: [....28] [ip4][..tcp] [..192.168.2.100][46468] -> [..179.60.195.33][.5222] detected: [....28] [ip4][..tcp] [..192.168.2.100][46468] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 224 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 10 / 28|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....29] [ip4][..tcp] [..192.168.2.100][47360] -> [..179.60.195.33][.5222] + new: [....29] [ip4][..tcp] [..192.168.2.100][47360] -> [..179.60.195.33][.5222] detected: [....29] [ip4][..tcp] [..192.168.2.100][47360] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 232 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 29|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....30] [ip4][..tcp] [..192.168.2.100][39828] -> [..179.60.195.33][.5222] + new: [....30] [ip4][..tcp] [..192.168.2.100][39828] -> [..179.60.195.33][.5222] detected: [....30] [ip4][..tcp] [..192.168.2.100][39828] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....22] [ip4][..tcp] [..192.168.2.100][43084] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -183,7 +183,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 240 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 30|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....31] [ip4][..tcp] [..192.168.2.100][40108] -> [..179.60.195.33][.5222] + new: [....31] [ip4][..tcp] [..192.168.2.100][40108] -> [..179.60.195.33][.5222] detected: [....31] [ip4][..tcp] [..192.168.2.100][40108] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....24] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -194,69 +194,69 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 249 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 31|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....32] [ip4][..tcp] [..192.168.2.100][43954] -> [..179.60.195.49][.5222] + new: [....32] [ip4][..tcp] [..192.168.2.100][43954] -> [..179.60.195.49][.5222] detected: [....32] [ip4][..tcp] [..192.168.2.100][43954] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....27] [ip4][..tcp] [..192.168.2.100][43230] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....33] [ip4][..tcp] [..192.168.2.100][49096] -> [....31.13.93.54][.5222] + new: [....33] [ip4][..tcp] [..192.168.2.100][49096] -> [....31.13.93.54][.5222] detected: [....33] [ip4][..tcp] [..192.168.2.100][49096] -> [....31.13.93.54][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 265 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 33|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....34] [ip4][..tcp] [..192.168.2.100][43978] -> [..179.60.195.49][.5222] + new: [....34] [ip4][..tcp] [..192.168.2.100][43978] -> [..179.60.195.49][.5222] detected: [....34] [ip4][..tcp] [..192.168.2.100][43978] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....28] [ip4][..tcp] [..192.168.2.100][46468] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 273 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 34|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....35] [ip4][..tcp] [..192.168.2.100][40990] -> [..179.60.195.33][.5222] + new: [....35] [ip4][..tcp] [..192.168.2.100][40990] -> [..179.60.195.33][.5222] detected: [....35] [ip4][..tcp] [..192.168.2.100][40990] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 281 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 35|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....36] [ip4][..tcp] [..192.168.2.100][45290] -> [..179.60.195.49][.5222] + new: [....36] [ip4][..tcp] [..192.168.2.100][45290] -> [..179.60.195.49][.5222] detected: [....36] [ip4][..tcp] [..192.168.2.100][45290] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....29] [ip4][..tcp] [..192.168.2.100][47360] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 289 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 36|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....37] [ip4][..tcp] [..192.168.2.100][51544] -> [..179.60.195.49][.5222] + new: [....37] [ip4][..tcp] [..192.168.2.100][51544] -> [..179.60.195.49][.5222] detected: [....37] [ip4][..tcp] [..192.168.2.100][51544] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 297 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 37|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....38] [ip4][..tcp] [..192.168.2.100][47948] -> [..179.60.195.49][.5222] + new: [....38] [ip4][..tcp] [..192.168.2.100][47948] -> [..179.60.195.49][.5222] detected: [....38] [ip4][..tcp] [..192.168.2.100][47948] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....39] [ip4][..tcp] [..192.168.2.100][51724] -> [..179.60.195.49][.5222] + new: [....39] [ip4][..tcp] [..192.168.2.100][51724] -> [..179.60.195.49][.5222] detected: [....39] [ip4][..tcp] [..192.168.2.100][51724] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 312 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 10 / 39|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....40] [ip4][..tcp] [..192.168.2.100][45334] -> [..179.60.195.49][.5222] + new: [....40] [ip4][..tcp] [..192.168.2.100][45334] -> [..179.60.195.49][.5222] detected: [....40] [ip4][..tcp] [..192.168.2.100][45334] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....30] [ip4][..tcp] [..192.168.2.100][39828] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....41] [ip4][..tcp] [..192.168.2.100][52152] -> [..179.60.195.49][.5222] + new: [....41] [ip4][..tcp] [..192.168.2.100][52152] -> [..179.60.195.49][.5222] detected: [....41] [ip4][..tcp] [..192.168.2.100][52152] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....31] [ip4][..tcp] [..192.168.2.100][40108] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 328 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 10 / 41|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....42] [ip4][..tcp] [..192.168.2.100][41664] -> [..179.60.195.33][.5222] + new: [....42] [ip4][..tcp] [..192.168.2.100][41664] -> [..179.60.195.33][.5222] detected: [....42] [ip4][..tcp] [..192.168.2.100][41664] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....43] [ip4][..tcp] [..192.168.2.100][52294] -> [..179.60.195.49][.5222] + new: [....43] [ip4][..tcp] [..192.168.2.100][52294] -> [..179.60.195.49][.5222] detected: [....43] [ip4][..tcp] [..192.168.2.100][52294] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 344 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 43|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....44] [ip4][..tcp] [..192.168.2.100][41722] -> [..179.60.195.33][.5222] + new: [....44] [ip4][..tcp] [..192.168.2.100][41722] -> [..179.60.195.33][.5222] detected: [....44] [ip4][..tcp] [..192.168.2.100][41722] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....33] [ip4][..tcp] [..192.168.2.100][49096] -> [....31.13.93.54][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -265,22 +265,22 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 352 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 44|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....45] [ip4][..tcp] [..192.168.2.100][48234] -> [..179.60.195.49][.5222] + new: [....45] [ip4][..tcp] [..192.168.2.100][48234] -> [..179.60.195.49][.5222] detected: [....45] [ip4][..tcp] [..192.168.2.100][48234] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....35] [ip4][..tcp] [..192.168.2.100][40990] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....34] [ip4][..tcp] [..192.168.2.100][43978] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....46] [ip4][..tcp] [..192.168.2.100][55038] -> [..179.60.195.49][.5222] + new: [....46] [ip4][..tcp] [..192.168.2.100][55038] -> [..179.60.195.49][.5222] detected: [....46] [ip4][..tcp] [..192.168.2.100][55038] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....47] [ip4][..tcp] [..192.168.2.100][55476] -> [....31.13.70.50][.5222] + new: [....47] [ip4][..tcp] [..192.168.2.100][55476] -> [....31.13.70.50][.5222] detected: [....47] [ip4][..tcp] [..192.168.2.100][55476] -> [....31.13.70.50][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 373 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 47|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....48] [ip4][..tcp] [..192.168.2.100][48538] -> [..179.60.195.49][.5222] + new: [....48] [ip4][..tcp] [..192.168.2.100][48538] -> [..179.60.195.49][.5222] detected: [....48] [ip4][..tcp] [..192.168.2.100][48538] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....36] [ip4][..tcp] [..192.168.2.100][45290] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -293,25 +293,25 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 381 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 9 / 48|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....49] [ip4][..tcp] [..192.168.2.100][45850] -> [..179.60.195.49][.5222] + new: [....49] [ip4][..tcp] [..192.168.2.100][45850] -> [..179.60.195.49][.5222] detected: [....49] [ip4][..tcp] [..192.168.2.100][45850] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....50] [ip4][..tcp] [..192.168.2.100][42622] -> [..179.60.195.33][.5222] + new: [....50] [ip4][..tcp] [..192.168.2.100][42622] -> [..179.60.195.33][.5222] detected: [....50] [ip4][..tcp] [..192.168.2.100][42622] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....51] [ip4][..tcp] [..192.168.2.100][58198] -> [..179.60.195.49][.5222] + new: [....51] [ip4][..tcp] [..192.168.2.100][58198] -> [..179.60.195.49][.5222] detected: [....51] [ip4][..tcp] [..192.168.2.100][58198] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 405 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 51|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....52] [ip4][..tcp] [..192.168.2.100][42796] -> [..179.60.195.33][.5222] + new: [....52] [ip4][..tcp] [..192.168.2.100][42796] -> [..179.60.195.33][.5222] detected: [....52] [ip4][..tcp] [..192.168.2.100][42796] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....40] [ip4][..tcp] [..192.168.2.100][45334] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 413 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 52|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....53] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.33][.5222] + new: [....53] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.33][.5222] detected: [....53] [ip4][..tcp] [..192.168.2.100][43152] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....42] [ip4][..tcp] [..192.168.2.100][41664] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] @@ -320,13 +320,13 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 421 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 53|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....54] [ip4][..tcp] [..192.168.2.100][46732] -> [..179.60.195.49][.5222] + new: [....54] [ip4][..tcp] [..192.168.2.100][46732] -> [..179.60.195.49][.5222] detected: [....54] [ip4][..tcp] [..192.168.2.100][46732] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....55] [ip4][..tcp] [..192.168.2.100][58882] -> [..179.60.195.49][.5222] + new: [....55] [ip4][..tcp] [..192.168.2.100][58882] -> [..179.60.195.49][.5222] detected: [....55] [ip4][..tcp] [..192.168.2.100][58882] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....56] [ip4][..tcp] [..192.168.2.100][46598] -> [..179.60.195.49][.5222] + new: [....56] [ip4][..tcp] [..192.168.2.100][46598] -> [..179.60.195.49][.5222] detected: [....56] [ip4][..tcp] [..192.168.2.100][46598] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....44] [ip4][..tcp] [..192.168.2.100][41722] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] @@ -335,7 +335,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 441 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 12 / 56|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....57] [ip4][..tcp] [..192.168.2.100][46768] -> [..179.60.195.49][.5222] + new: [....57] [ip4][..tcp] [..192.168.2.100][46768] -> [..179.60.195.49][.5222] detected: [....57] [ip4][..tcp] [..192.168.2.100][46768] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....46] [ip4][..tcp] [..192.168.2.100][55038] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -344,12 +344,12 @@ RISK: Unidirectional Traffic idle: [....45] [ip4][..tcp] [..192.168.2.100][48234] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....58] [ip4][..tcp] [..192.168.2.100][45130] -> [..179.60.195.33][.5222] + new: [....58] [ip4][..tcp] [..192.168.2.100][45130] -> [..179.60.195.33][.5222] detected: [....58] [ip4][..tcp] [..192.168.2.100][45130] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 457 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 58|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....59] [ip4][..tcp] [..192.168.2.100][60328] -> [..179.60.195.49][.5222] + new: [....59] [ip4][..tcp] [..192.168.2.100][60328] -> [..179.60.195.49][.5222] detected: [....59] [ip4][..tcp] [..192.168.2.100][60328] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....50] [ip4][..tcp] [..192.168.2.100][42622] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] @@ -366,7 +366,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 465 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 59|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....60] [ip4][..tcp] [..192.168.2.100][32798] -> [..179.60.195.49][.5222] + new: [....60] [ip4][..tcp] [..192.168.2.100][32798] -> [..179.60.195.49][.5222] detected: [....60] [ip4][..tcp] [..192.168.2.100][32798] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....54] [ip4][..tcp] [..192.168.2.100][46732] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -381,24 +381,24 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 473 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 60|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....61] [ip4][..tcp] [..192.168.2.100][47086] -> [..179.60.195.49][.5222] + new: [....61] [ip4][..tcp] [..192.168.2.100][47086] -> [..179.60.195.49][.5222] detected: [....61] [ip4][..tcp] [..192.168.2.100][47086] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 481 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 61|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....62] [ip4][..tcp] [..192.168.2.100][49182] -> [..179.60.195.49][.5222] + new: [....62] [ip4][..tcp] [..192.168.2.100][49182] -> [..179.60.195.49][.5222] detected: [....62] [ip4][..tcp] [..192.168.2.100][49182] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 488 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 62|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....63] [ip4][..tcp] [..192.168.2.100][49232] -> [..179.60.195.49][.5222] + new: [....63] [ip4][..tcp] [..192.168.2.100][49232] -> [..179.60.195.49][.5222] detected: [....63] [ip4][..tcp] [..192.168.2.100][49232] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....59] [ip4][..tcp] [..192.168.2.100][60328] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 496 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 63|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....64] [ip4][..tcp] [..192.168.2.100][47350] -> [..179.60.195.49][.5222] + new: [....64] [ip4][..tcp] [..192.168.2.100][47350] -> [..179.60.195.49][.5222] detected: [....64] [ip4][..tcp] [..192.168.2.100][47350] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....61] [ip4][..tcp] [..192.168.2.100][47086] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -407,104 +407,104 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 504 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 64|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....65] [ip4][..tcp] [..192.168.2.100][49238] -> [..179.60.195.49][.5222] + new: [....65] [ip4][..tcp] [..192.168.2.100][49238] -> [..179.60.195.49][.5222] detected: [....65] [ip4][..tcp] [..192.168.2.100][49238] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....62] [ip4][..tcp] [..192.168.2.100][49182] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 512 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 65|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....66] [ip4][..tcp] [..192.168.2.100][49250] -> [..179.60.195.49][.5222] + new: [....66] [ip4][..tcp] [..192.168.2.100][49250] -> [..179.60.195.49][.5222] detected: [....66] [ip4][..tcp] [..192.168.2.100][49250] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 520 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 66|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....67] [ip4][..tcp] [..192.168.2.100][47296] -> [..179.60.195.49][.5222] + new: [....67] [ip4][..tcp] [..192.168.2.100][47296] -> [..179.60.195.49][.5222] detected: [....67] [ip4][..tcp] [..192.168.2.100][47296] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 528 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 67|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....68] [ip4][..tcp] [..192.168.2.100][47900] -> [..179.60.195.49][.5222] + new: [....68] [ip4][..tcp] [..192.168.2.100][47900] -> [..179.60.195.49][.5222] detected: [....68] [ip4][..tcp] [..192.168.2.100][47900] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....63] [ip4][..tcp] [..192.168.2.100][49232] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 536 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 68|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....69] [ip4][..tcp] [..192.168.2.100][47590] -> [..179.60.195.49][.5222] + new: [....69] [ip4][..tcp] [..192.168.2.100][47590] -> [..179.60.195.49][.5222] detected: [....69] [ip4][..tcp] [..192.168.2.100][47590] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....70] [ip4][..tcp] [..192.168.2.100][49428] -> [..179.60.195.49][.5222] + new: [....70] [ip4][..tcp] [..192.168.2.100][49428] -> [..179.60.195.49][.5222] detected: [....70] [ip4][..tcp] [..192.168.2.100][49428] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....64] [ip4][..tcp] [..192.168.2.100][47350] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 552 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 6 / 70|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....71] [ip4][..tcp] [..192.168.2.100][47634] -> [..179.60.195.49][.5222] + new: [....71] [ip4][..tcp] [..192.168.2.100][47634] -> [..179.60.195.49][.5222] detected: [....71] [ip4][..tcp] [..192.168.2.100][47634] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 560 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 7 / 71|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....72] [ip4][..tcp] [..192.168.2.100][49610] -> [..179.60.195.49][.5222] + new: [....72] [ip4][..tcp] [..192.168.2.100][49610] -> [..179.60.195.49][.5222] detected: [....72] [ip4][..tcp] [..192.168.2.100][49610] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....65] [ip4][..tcp] [..192.168.2.100][49238] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....66] [ip4][..tcp] [..192.168.2.100][49250] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....73] [ip4][..tcp] [..192.168.2.100][37378] -> [..179.60.195.49][.5222] + new: [....73] [ip4][..tcp] [..192.168.2.100][37378] -> [..179.60.195.49][.5222] detected: [....73] [ip4][..tcp] [..192.168.2.100][37378] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....74] [ip4][..tcp] [..192.168.2.100][47738] -> [..179.60.195.49][.5222] + new: [....74] [ip4][..tcp] [..192.168.2.100][47738] -> [..179.60.195.49][.5222] detected: [....74] [ip4][..tcp] [..192.168.2.100][47738] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 584 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 74|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....75] [ip4][..tcp] [..192.168.2.100][37404] -> [..179.60.195.49][.5222] + new: [....75] [ip4][..tcp] [..192.168.2.100][37404] -> [..179.60.195.49][.5222] detected: [....75] [ip4][..tcp] [..192.168.2.100][37404] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....67] [ip4][..tcp] [..192.168.2.100][47296] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 592 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 8 / 75|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....76] [ip4][..tcp] [..192.168.2.100][47776] -> [..179.60.195.49][.5222] + new: [....76] [ip4][..tcp] [..192.168.2.100][47776] -> [..179.60.195.49][.5222] detected: [....76] [ip4][..tcp] [..192.168.2.100][47776] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 600 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 9 / 76|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....77] [ip4][..tcp] [..192.168.2.100][37766] -> [..179.60.195.49][.5222] + new: [....77] [ip4][..tcp] [..192.168.2.100][37766] -> [..179.60.195.49][.5222] detected: [....77] [ip4][..tcp] [..192.168.2.100][37766] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....78] [ip4][..tcp] [..192.168.2.100][37674] -> [..179.60.195.49][.5222] + new: [....78] [ip4][..tcp] [..192.168.2.100][37674] -> [..179.60.195.49][.5222] detected: [....78] [ip4][..tcp] [..192.168.2.100][37674] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 616 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 78|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....79] [ip4][..tcp] [..192.168.2.100][47810] -> [..179.60.195.49][.5222] + new: [....79] [ip4][..tcp] [..192.168.2.100][47810] -> [..179.60.195.49][.5222] detected: [....79] [ip4][..tcp] [..192.168.2.100][47810] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....68] [ip4][..tcp] [..192.168.2.100][47900] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....80] [ip4][..tcp] [..192.168.2.100][46394] -> [..179.60.195.33][.5222] + new: [....80] [ip4][..tcp] [..192.168.2.100][46394] -> [..179.60.195.33][.5222] detected: [....80] [ip4][..tcp] [..192.168.2.100][46394] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....81] [ip4][..tcp] [..192.168.2.100][37822] -> [..179.60.195.49][.5222] + new: [....81] [ip4][..tcp] [..192.168.2.100][37822] -> [..179.60.195.49][.5222] detected: [....81] [ip4][..tcp] [..192.168.2.100][37822] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic - new: [....82] [ip4][..tcp] [..192.168.2.100][46576] -> [..179.60.195.33][.5222] + new: [....82] [ip4][..tcp] [..192.168.2.100][46576] -> [..179.60.195.33][.5222] detected: [....82] [ip4][..tcp] [..192.168.2.100][46576] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 647 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 14 / 82|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....83] [ip4][..tcp] [..192.168.2.100][38234] -> [..179.60.195.49][.5222] + new: [....83] [ip4][..tcp] [..192.168.2.100][38234] -> [..179.60.195.49][.5222] detected: [....83] [ip4][..tcp] [..192.168.2.100][38234] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....69] [ip4][..tcp] [..192.168.2.100][47590] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 655 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 14 / 83|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....84] [ip4][..tcp] [..192.168.2.100][47284] -> [..179.60.195.33][.5222] + new: [....84] [ip4][..tcp] [..192.168.2.100][47284] -> [..179.60.195.33][.5222] detected: [....84] [ip4][..tcp] [..192.168.2.100][47284] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....70] [ip4][..tcp] [..192.168.2.100][49428] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -513,7 +513,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 663 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 13 / 84|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....85] [ip4][..tcp] [..192.168.2.100][39334] -> [..179.60.195.49][.5222] + new: [....85] [ip4][..tcp] [..192.168.2.100][39334] -> [..179.60.195.49][.5222] detected: [....85] [ip4][..tcp] [..192.168.2.100][39334] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....72] [ip4][..tcp] [..192.168.2.100][49610] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] @@ -524,7 +524,7 @@ RISK: Unidirectional Traffic DAEMON-EVENT: [Processed: 671 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 11 / 85|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [....86] [ip4][..tcp] [..192.168.2.100][40006] -> [..179.60.195.49][.5222] + new: [....86] [ip4][..tcp] [..192.168.2.100][40006] -> [..179.60.195.49][.5222] detected: [....86] [ip4][..tcp] [..192.168.2.100][40006] -> [..179.60.195.49][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] RISK: Unidirectional Traffic idle: [....84] [ip4][..tcp] [..192.168.2.100][47284] -> [..179.60.195.33][.5222] [WhatsApp][Facebook][Chat][Acceptable] diff --git a/test/results/flow-info/default/whatsapp_login_call.pcap.out b/test/results/flow-info/default/whatsapp_login_call.pcap.out index b47f13ad6..13c30c1bd 100644 --- a/test/results/flow-info/default/whatsapp_login_call.pcap.out +++ b/test/results/flow-info/default/whatsapp_login_call.pcap.out @@ -1,34 +1,34 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....192.168.2.4][49199] -> [..17.172.100.70][..993] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....192.168.2.4][49199] -> [..17.172.100.70][..993] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [....192.168.2.4][49199] -> [..17.172.100.70][..993] [IMAPS][Apple][Email][Safe] RISK: Unidirectional Traffic detection-update: [.....1] [ip4][..tcp] [....192.168.2.4][49199] -> [..17.172.100.70][..993] [IMAPS][Apple][Email][Safe] - new: [.....2] [ip4][..tcp] [....192.168.2.4][49166] -> [..17.154.66.121][..443] [MIDSTREAM] - new: [.....3] [ip4][..tcp] [....192.168.2.4][49163] -> [..17.154.66.111][..443] [MIDSTREAM] - new: [.....4] [ip4][..tcp] [....192.168.2.4][49169] -> [..17.173.66.102][..443] [MIDSTREAM] - new: [.....5] [ip4][..tcp] [....192.168.2.4][49173] -> [..93.186.135.82][...80] [MIDSTREAM] - new: [.....6] [ip4][..tcp] [....192.168.2.4][49172] -> [..23.50.148.228][..443] [MIDSTREAM] - new: [.....7] [ip4][..tcp] [....192.168.2.4][49174] -> [....5.178.42.26][...80] [MIDSTREAM] + new: [.....2] [ip4][..tcp] [....192.168.2.4][49166] -> [..17.154.66.121][..443] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [....192.168.2.4][49163] -> [..17.154.66.111][..443] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....192.168.2.4][49169] -> [..17.173.66.102][..443] [MIDSTREAM] + new: [.....5] [ip4][..tcp] [....192.168.2.4][49173] -> [..93.186.135.82][...80] [MIDSTREAM] + new: [.....6] [ip4][..tcp] [....192.168.2.4][49172] -> [..23.50.148.228][..443] [MIDSTREAM] + new: [.....7] [ip4][..tcp] [....192.168.2.4][49174] -> [....5.178.42.26][...80] [MIDSTREAM] detected: [.....6] [ip4][..tcp] [....192.168.2.4][49172] -> [..23.50.148.228][..443] [TLS][Unknown][Web][Safe] - new: [.....8] [ip4][..tcp] [....192.168.2.4][49175] -> [..17.172.100.53][..443] [MIDSTREAM] - new: [.....9] [ip4][..tcp] [....192.168.2.4][49165] -> [..17.172.100.55][..443] [MIDSTREAM] - new: [....10] [ip4][..tcp] [....192.168.2.4][49176] -> [..17.130.137.77][..443] [MIDSTREAM] - new: [....11] [ip4][..udp] [....192.168.2.4][51897] -> [....192.168.2.1][...53] + new: [.....8] [ip4][..tcp] [....192.168.2.4][49175] -> [..17.172.100.53][..443] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [....192.168.2.4][49165] -> [..17.172.100.55][..443] [MIDSTREAM] + new: [....10] [ip4][..tcp] [....192.168.2.4][49176] -> [..17.130.137.77][..443] [MIDSTREAM] + new: [....11] [ip4][..udp] [....192.168.2.4][51897] -> [....192.168.2.1][...53] detected: [....11] [ip4][..udp] [....192.168.2.4][51897] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][query.ess.apple.com] detection-update: [....11] [ip4][..udp] [....192.168.2.4][51897] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe][query.ess.apple.com] - new: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] + new: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] detected: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][e13.whatsapp.net] - new: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] + new: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] detection-update: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][e13.whatsapp.net] - new: [....14] [ip4][..tcp] [....192.168.2.4][49202] -> [.184.173.179.37][.5222] - new: [....15] [ip4][..tcp] [....192.168.2.4][49203] -> [..17.178.104.14][..443] + new: [....14] [ip4][..tcp] [....192.168.2.4][49202] -> [.184.173.179.37][.5222] + new: [....15] [ip4][..tcp] [....192.168.2.4][49203] -> [..17.178.104.14][..443] detected: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] [TLS.Apple][Apple][Web][Safe][query.ess.apple.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] [TLS.Apple][Apple][Web][Safe][query.ess.apple.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....16] [ip4][..tcp] [....192.168.2.4][49193] -> [..17.110.229.14][.5223] [MIDSTREAM] + new: [....16] [ip4][..tcp] [....192.168.2.4][49193] -> [..17.110.229.14][.5223] [MIDSTREAM] detected: [....16] [ip4][..tcp] [....192.168.2.4][49193] -> [..17.110.229.14][.5223] [ApplePush][Apple][Cloud][Acceptable] detected: [....14] [ip4][..tcp] [....192.168.2.4][49202] -> [.184.173.179.37][.5222] [WhatsApp][Unknown][Chat][Acceptable] analyse: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] [TLS.Apple][Apple][Web][Safe] @@ -43,7 +43,7 @@ [ENTROPIES...: 4.5,4.9,4.7,5.6,7.2,7.4,6.9,4.9,4.9,4.9,4.8,7.2,4.8,5.7,4.8,4.8,4.8,5.8,4.9,7.9,7.9,6.7,4.7,4.7,7.9,7.8,4.9,7.9,7.8,6.7,4.8,4.8] detection-update: [....13] [ip4][..tcp] [....192.168.2.4][49201] -> [..17.178.104.12][..443] [TLS.Apple][Apple][Web][Safe][query.ess.apple.com] RISK: TLS (probably) Not Carrying HTTPS - new: [....17] [ip4][..tcp] [....192.168.2.4][49204] -> [..17.173.66.102][..443] + new: [....17] [ip4][..tcp] [....192.168.2.4][49204] -> [..17.173.66.102][..443] analyse: [....14] [ip4][..tcp] [....192.168.2.4][49202] -> [.184.173.179.37][.5222] [WhatsApp][Unknown][Chat][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.709| 0.193| 0.172| 29610.717| 4.400] @@ -68,40 +68,40 @@ [IATS(ms)....: 139.3,206.5,8.2,215.7,0.1,2.7,195.5,0.8,0.3,0.0,1.9,0.3,2.1,191.6,2.4,13.1,3.7,6.4,14.7,0.0,200.9,0.3,63.3,0.3,2.2,246.3,5.3,14.9,0.0,241.0,0.2] [PKTLENS.....: 64,52,40,267,40,132,77,40,40,46,77,1480,517,596,40,40,40,40,40,988,386,40,40,1480,526,596,40,40,988,386,40,40] [ENTROPIES...: 4.5,4.8,4.7,6.0,4.7,6.0,5.7,4.9,4.9,4.7,5.6,7.8,7.6,7.6,4.8,4.8,4.7,4.8,4.7,7.8,7.4,4.8,4.8,7.9,7.6,7.6,4.6,4.7,7.8,7.5,4.8,4.8] - new: [....18] [ip4][..tcp] [....192.168.2.4][49192] -> [...93.186.135.8][...80] [MIDSTREAM] - new: [....19] [ip4][..tcp] [....192.168.2.4][49191] -> [..17.172.100.49][..443] [MIDSTREAM] - new: [....20] [ip4][..tcp] [....192.168.2.4][49182] -> [..17.172.100.52][..443] [MIDSTREAM] - new: [....21] [ip4][..tcp] [....192.168.2.4][49181] -> [..17.172.100.37][..443] [MIDSTREAM] - new: [....22] [ip4][..tcp] [....192.168.2.4][49180] -> [..17.172.100.59][..443] [MIDSTREAM] - new: [....23] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.100.14][.3478] + new: [....18] [ip4][..tcp] [....192.168.2.4][49192] -> [...93.186.135.8][...80] [MIDSTREAM] + new: [....19] [ip4][..tcp] [....192.168.2.4][49191] -> [..17.172.100.49][..443] [MIDSTREAM] + new: [....20] [ip4][..tcp] [....192.168.2.4][49182] -> [..17.172.100.52][..443] [MIDSTREAM] + new: [....21] [ip4][..tcp] [....192.168.2.4][49181] -> [..17.172.100.37][..443] [MIDSTREAM] + new: [....22] [ip4][..tcp] [....192.168.2.4][49180] -> [..17.172.100.59][..443] [MIDSTREAM] + new: [....23] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.100.14][.3478] detected: [....23] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.100.14][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....24] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.70.48][.3478] + new: [....24] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.70.48][.3478] detected: [....24] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.70.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....25] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.64.48][.3478] + new: [....25] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.64.48][.3478] detected: [....25] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.64.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....26] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.85.48][.3478] + new: [....26] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.85.48][.3478] detected: [....26] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.85.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....27] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.91.48][.3478] + new: [....27] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.91.48][.3478] detected: [....27] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.91.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....28] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.79.192][.3478] + new: [....28] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.79.192][.3478] detected: [....28] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....29] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.93.48][.3478] + new: [....29] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.93.48][.3478] detected: [....29] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....30] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.73.48][.3478] + new: [....30] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.73.48][.3478] detected: [....30] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....31] [ip4][..tcp] [....192.168.2.4][49164] -> [..17.167.142.31][..443] [MIDSTREAM] - new: [....32] [ip4][..tcp] [....192.168.2.4][49167] -> [...17.172.100.8][..443] [MIDSTREAM] - new: [....33] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [....31] [ip4][..tcp] [....192.168.2.4][49164] -> [..17.167.142.31][..443] [MIDSTREAM] + new: [....32] [ip4][..tcp] [....192.168.2.4][49167] -> [...17.172.100.8][..443] [MIDSTREAM] + new: [....33] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [....33] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [....34] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [....34] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [....34] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [....35] [ip4][..tcp] [....192.168.2.4][49194] -> [..93.62.150.157][..443] [MIDSTREAM] - new: [....36] [ip4][..tcp] [....192.168.2.4][49198] -> [..17.167.142.13][..443] [MIDSTREAM] - new: [....37] [ip4][..tcp] [....192.168.2.4][49200] -> [..17.167.142.13][..443] [MIDSTREAM] - new: [....38] [ip4][..udp] [....192.168.2.4][51518] -> [...1.194.90.191][60312] + new: [....35] [ip4][..tcp] [....192.168.2.4][49194] -> [..93.62.150.157][..443] [MIDSTREAM] + new: [....36] [ip4][..tcp] [....192.168.2.4][49198] -> [..17.167.142.13][..443] [MIDSTREAM] + new: [....37] [ip4][..tcp] [....192.168.2.4][49200] -> [..17.167.142.13][..443] [MIDSTREAM] + new: [....38] [ip4][..udp] [....192.168.2.4][51518] -> [...1.194.90.191][60312] detected: [....38] [ip4][..udp] [....192.168.2.4][51518] -> [...1.194.90.191][60312] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....39] [ip4][..udp] [....192.168.2.4][51518] -> [..91.253.176.65][.9344] + new: [....39] [ip4][..udp] [....192.168.2.4][51518] -> [..91.253.176.65][.9344] detected: [....39] [ip4][..udp] [....192.168.2.4][51518] -> [..91.253.176.65][.9344] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....39] [ip4][..udp] [....192.168.2.4][51518] -> [..91.253.176.65][.9344] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] @@ -114,19 +114,19 @@ [IATS(ms)....: 85.5,95.2,66.1,60.4,102.7,208.4,184.1,159.6,139.1,188.5,352.4,23.4,152.9,55.1,31.1,91.6,0.1,141.2,0.0,163.2,159.2,188.6,161.9,163.6,162.1,156.8,164.9,143.2,181.6,163.3,123.9] [PKTLENS.....: 72,72,328,72,72,301,211,297,234,301,206,134,50,235,185,134,123,54,246,54,260,120,337,103,301,103,305,229,306,317,315,291] [ENTROPIES...: 5.6,5.7,7.3,5.6,5.6,7.3,6.9,7.2,7.0,7.3,6.9,6.5,5.1,7.0,6.8,6.4,6.4,5.2,7.1,5.1,7.1,6.4,7.3,6.1,7.4,6.1,7.3,7.0,7.3,7.3,7.3,7.2] - new: [....40] [ip4][.icmp] [....192.168.2.4] -> [..91.253.176.65] + new: [....40] [ip4][.icmp] [....192.168.2.4] -> [..91.253.176.65] detected: [....40] [ip4][.icmp] [....192.168.2.4] -> [..91.253.176.65] [ICMP][Unknown][Network][Acceptable] - new: [....41] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....41] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....41] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] update: [....11] [ip4][..udp] [....192.168.2.4][51897] -> [....192.168.2.1][...53] [DNS.Apple][Unknown][Network][Safe] update: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable] - new: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] + new: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] detected: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] - new: [....43] [ip6][..udp] [................fe80::da30:62ff:fe56:1c][.5353] -> [...............................ff02::fb][.5353] + new: [....43] [ip6][..udp] [................fe80::da30:62ff:fe56:1c][.5353] -> [...............................ff02::fb][.5353] detected: [....43] [ip6][..udp] [................fe80::da30:62ff:fe56:1c][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] - new: [....44] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] + new: [....44] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] detected: [....44] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] - new: [....45] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] + new: [....45] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] detected: [....45] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] detection-update: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] detection-update: [....44] [ip4][..udp] [....192.168.2.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][lucas-imac.local] @@ -140,28 +140,28 @@ update: [....27] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.91.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [....28] [ip4][..udp] [....192.168.2.4][51518] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [....29] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] - new: [....46] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.73.48][.3478] + new: [....46] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.73.48][.3478] detected: [....46] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....47] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.93.48][.3478] + new: [....47] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.93.48][.3478] detected: [....47] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....48] [ip4][..udp] [....192.168.2.4][52794] -> [...31.13.79.192][.3478] + new: [....48] [ip4][..udp] [....192.168.2.4][52794] -> [...31.13.79.192][.3478] detected: [....48] [ip4][..udp] [....192.168.2.4][52794] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....49] [ip4][..udp] [....192.168.2.4][52794] -> [..179.60.192.48][.3478] + new: [....49] [ip4][..udp] [....192.168.2.4][52794] -> [..179.60.192.48][.3478] detected: [....49] [ip4][..udp] [....192.168.2.4][52794] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....50] [ip4][..udp] [....192.168.2.4][52794] -> [..173.252.114.1][.3478] + new: [....50] [ip4][..udp] [....192.168.2.4][52794] -> [..173.252.114.1][.3478] detected: [....50] [ip4][..udp] [....192.168.2.4][52794] -> [..173.252.114.1][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....51] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.90.48][.3478] + new: [....51] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.90.48][.3478] detected: [....51] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.90.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....52] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.74.48][.3478] + new: [....52] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.74.48][.3478] detected: [....52] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.74.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....53] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.84.48][.3478] + new: [....53] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.84.48][.3478] detected: [....53] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.84.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] update: [....33] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [....34] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [....54] [ip4][..udp] [....192.168.2.4][52794] -> [...1.194.90.191][51727] + new: [....54] [ip4][..udp] [....192.168.2.4][52794] -> [...1.194.90.191][51727] detected: [....54] [ip4][..udp] [....192.168.2.4][52794] -> [...1.194.90.191][51727] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port - new: [....55] [ip4][..udp] [....192.168.2.4][52794] -> [..91.253.176.65][.9665] + new: [....55] [ip4][..udp] [....192.168.2.4][52794] -> [..91.253.176.65][.9665] detected: [....55] [ip4][..udp] [....192.168.2.4][52794] -> [..91.253.176.65][.9665] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....55] [ip4][..udp] [....192.168.2.4][52794] -> [..91.253.176.65][.9665] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] @@ -179,7 +179,7 @@ update: [....40] [ip4][.icmp] [....192.168.2.4] -> [..91.253.176.65] [ICMP][Unknown][Network][Acceptable] update: [....38] [ip4][..udp] [....192.168.2.4][51518] -> [...1.194.90.191][60312] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port - new: [....56] [ip4][..tcp] [....192.168.2.4][49197] -> [..17.167.142.39][..443] [MIDSTREAM] + new: [....56] [ip4][..tcp] [....192.168.2.4][49197] -> [..17.167.142.39][..443] [MIDSTREAM] update: [....41] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] update: [....45] [ip6][..udp] [...............fe80::c42c:3ff:fe60:6a64][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] @@ -195,7 +195,7 @@ update: [....29] [ip4][..udp] [....192.168.2.4][51518] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable] update: [....43] [ip6][..udp] [................fe80::da30:62ff:fe56:1c][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] - new: [....57] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] + new: [....57] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] detected: [....57] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [TLS.AppleStore][Apple][SoftwareUpdate][Safe][p53-buy.itunes.apple.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....57] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [TLS.AppleStore][Apple][SoftwareUpdate][Safe][p53-buy.itunes.apple.com] @@ -211,31 +211,31 @@ [PKTLENS.....: 64,52,40,267,40,132,77,40,40,46,77,1480,516,596,40,40,40,40,40,988,386,40,40,1480,526,596,40,40,988,386,40,40] [ENTROPIES...: 4.5,4.8,4.7,5.9,4.8,6.0,5.8,4.9,4.9,4.8,5.7,7.9,7.6,7.7,4.8,4.9,4.9,4.8,4.8,7.8,7.5,4.9,4.9,7.9,7.6,7.7,4.8,4.9,7.8,7.4,4.9,4.9] guessed: [.....7] [ip4][..tcp] [....192.168.2.4][49174] -> [....5.178.42.26][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....7] [ip4][..tcp] [....192.168.2.4][49174] -> [....5.178.42.26][...80] + end: [.....7] [ip4][..tcp] [....192.168.2.4][49174] -> [....5.178.42.26][...80] guessed: [.....5] [ip4][..tcp] [....192.168.2.4][49173] -> [..93.186.135.82][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....5] [ip4][..tcp] [....192.168.2.4][49173] -> [..93.186.135.82][...80] + end: [.....5] [ip4][..tcp] [....192.168.2.4][49173] -> [..93.186.135.82][...80] guessed: [....18] [ip4][..tcp] [....192.168.2.4][49192] -> [...93.186.135.8][...80] [HTTP][Unknown][Web][Acceptable][] - end: [....18] [ip4][..tcp] [....192.168.2.4][49192] -> [...93.186.135.8][...80] + end: [....18] [ip4][..tcp] [....192.168.2.4][49192] -> [...93.186.135.8][...80] guessed: [.....3] [ip4][..tcp] [....192.168.2.4][49163] -> [..17.154.66.111][..443] [TLS][Apple][Web][Safe] - end: [.....3] [ip4][..tcp] [....192.168.2.4][49163] -> [..17.154.66.111][..443] + end: [.....3] [ip4][..tcp] [....192.168.2.4][49163] -> [..17.154.66.111][..443] guessed: [.....2] [ip4][..tcp] [....192.168.2.4][49166] -> [..17.154.66.121][..443] [TLS][Apple][Web][Safe] - end: [.....2] [ip4][..tcp] [....192.168.2.4][49166] -> [..17.154.66.121][..443] + end: [.....2] [ip4][..tcp] [....192.168.2.4][49166] -> [..17.154.66.121][..443] guessed: [....10] [ip4][..tcp] [....192.168.2.4][49176] -> [..17.130.137.77][..443] [TLS][Apple][Web][Safe] - end: [....10] [ip4][..tcp] [....192.168.2.4][49176] -> [..17.130.137.77][..443] + end: [....10] [ip4][..tcp] [....192.168.2.4][49176] -> [..17.130.137.77][..443] end: [.....6] [ip4][..tcp] [....192.168.2.4][49172] -> [..23.50.148.228][..443] [TLS][Unknown][Web][Safe] guessed: [....15] [ip4][..tcp] [....192.168.2.4][49203] -> [..17.178.104.14][..443] [TLS][Apple][Web][Safe] RISK: TCP Connection Issues - end: [....15] [ip4][..tcp] [....192.168.2.4][49203] -> [..17.178.104.14][..443] + end: [....15] [ip4][..tcp] [....192.168.2.4][49203] -> [..17.178.104.14][..443] guessed: [.....9] [ip4][..tcp] [....192.168.2.4][49165] -> [..17.172.100.55][..443] [TLS][Apple][Web][Safe] - end: [.....9] [ip4][..tcp] [....192.168.2.4][49165] -> [..17.172.100.55][..443] + end: [.....9] [ip4][..tcp] [....192.168.2.4][49165] -> [..17.172.100.55][..443] guessed: [.....8] [ip4][..tcp] [....192.168.2.4][49175] -> [..17.172.100.53][..443] [TLS][Apple][Web][Safe] - end: [.....8] [ip4][..tcp] [....192.168.2.4][49175] -> [..17.172.100.53][..443] + end: [.....8] [ip4][..tcp] [....192.168.2.4][49175] -> [..17.172.100.53][..443] guessed: [....20] [ip4][..tcp] [....192.168.2.4][49182] -> [..17.172.100.52][..443] [TLS][Apple][Web][Safe] - end: [....20] [ip4][..tcp] [....192.168.2.4][49182] -> [..17.172.100.52][..443] + end: [....20] [ip4][..tcp] [....192.168.2.4][49182] -> [..17.172.100.52][..443] guessed: [....19] [ip4][..tcp] [....192.168.2.4][49191] -> [..17.172.100.49][..443] [TLS][Apple][Web][Safe] - end: [....19] [ip4][..tcp] [....192.168.2.4][49191] -> [..17.172.100.49][..443] + end: [....19] [ip4][..tcp] [....192.168.2.4][49191] -> [..17.172.100.49][..443] guessed: [.....4] [ip4][..tcp] [....192.168.2.4][49169] -> [..17.173.66.102][..443] [TLS][Apple][Web][Safe] - end: [.....4] [ip4][..tcp] [....192.168.2.4][49169] -> [..17.173.66.102][..443] + end: [.....4] [ip4][..tcp] [....192.168.2.4][49169] -> [..17.173.66.102][..443] update: [....50] [ip4][..udp] [....192.168.2.4][52794] -> [..173.252.114.1][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [....49] [ip4][..udp] [....192.168.2.4][52794] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [....46] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] @@ -258,14 +258,14 @@ idle: [....41] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [....192.168.2.4][49199] -> [..17.172.100.70][..993] [IMAPS][Apple][Email][Safe] guessed: [....35] [ip4][..tcp] [....192.168.2.4][49194] -> [..93.62.150.157][..443] [TLS][Unknown][Web][Safe] - end: [....35] [ip4][..tcp] [....192.168.2.4][49194] -> [..93.62.150.157][..443] + end: [....35] [ip4][..tcp] [....192.168.2.4][49194] -> [..93.62.150.157][..443] idle: [....50] [ip4][..udp] [....192.168.2.4][52794] -> [..173.252.114.1][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] idle: [....49] [ip4][..udp] [....192.168.2.4][52794] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] idle: [....42] [ip4][..udp] [169.254.166.207][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] guessed: [....31] [ip4][..tcp] [....192.168.2.4][49164] -> [..17.167.142.31][..443] [TLS][Apple][Web][Safe] - end: [....31] [ip4][..tcp] [....192.168.2.4][49164] -> [..17.167.142.31][..443] + end: [....31] [ip4][..tcp] [....192.168.2.4][49164] -> [..17.167.142.31][..443] guessed: [....56] [ip4][..tcp] [....192.168.2.4][49197] -> [..17.167.142.39][..443] [TLS][Apple][Web][Safe] - end: [....56] [ip4][..tcp] [....192.168.2.4][49197] -> [..17.167.142.39][..443] + end: [....56] [ip4][..tcp] [....192.168.2.4][49197] -> [..17.167.142.39][..443] idle: [....48] [ip4][..udp] [....192.168.2.4][52794] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] idle: [....53] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.84.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] idle: [....52] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.74.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] @@ -273,9 +273,9 @@ idle: [....47] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] idle: [....46] [ip4][..udp] [....192.168.2.4][52794] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] guessed: [....36] [ip4][..tcp] [....192.168.2.4][49198] -> [..17.167.142.13][..443] [TLS][Apple][Web][Safe] - end: [....36] [ip4][..tcp] [....192.168.2.4][49198] -> [..17.167.142.13][..443] + end: [....36] [ip4][..tcp] [....192.168.2.4][49198] -> [..17.167.142.13][..443] guessed: [....37] [ip4][..tcp] [....192.168.2.4][49200] -> [..17.167.142.13][..443] [TLS][Apple][Web][Safe] - end: [....37] [ip4][..tcp] [....192.168.2.4][49200] -> [..17.167.142.13][..443] + end: [....37] [ip4][..tcp] [....192.168.2.4][49200] -> [..17.167.142.13][..443] idle: [....55] [ip4][..udp] [....192.168.2.4][52794] -> [..91.253.176.65][.9665] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port idle: [....33] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] @@ -302,11 +302,11 @@ idle: [....12] [ip4][..udp] [....192.168.2.4][52190] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable] idle: [....40] [ip4][.icmp] [....192.168.2.4] -> [..91.253.176.65] [ICMP][Unknown][Network][Acceptable] guessed: [....32] [ip4][..tcp] [....192.168.2.4][49167] -> [...17.172.100.8][..443] [TLS][Apple][Web][Safe] - end: [....32] [ip4][..tcp] [....192.168.2.4][49167] -> [...17.172.100.8][..443] + end: [....32] [ip4][..tcp] [....192.168.2.4][49167] -> [...17.172.100.8][..443] guessed: [....22] [ip4][..tcp] [....192.168.2.4][49180] -> [..17.172.100.59][..443] [TLS][Apple][Web][Safe] - end: [....22] [ip4][..tcp] [....192.168.2.4][49180] -> [..17.172.100.59][..443] + end: [....22] [ip4][..tcp] [....192.168.2.4][49180] -> [..17.172.100.59][..443] guessed: [....21] [ip4][..tcp] [....192.168.2.4][49181] -> [..17.172.100.37][..443] [TLS][Apple][Web][Safe] - end: [....21] [ip4][..tcp] [....192.168.2.4][49181] -> [..17.172.100.37][..443] + end: [....21] [ip4][..tcp] [....192.168.2.4][49181] -> [..17.172.100.37][..443] idle: [....43] [ip6][..udp] [................fe80::da30:62ff:fe56:1c][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable] idle: [....38] [ip4][..udp] [....192.168.2.4][51518] -> [...1.194.90.191][60312] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] RISK: Known Proto on Non Std Port diff --git a/test/results/flow-info/default/whatsapp_login_chat.pcap.out b/test/results/flow-info/default/whatsapp_login_chat.pcap.out index 76c289de0..3da7a6517 100644 --- a/test/results/flow-info/default/whatsapp_login_chat.pcap.out +++ b/test/results/flow-info/default/whatsapp_login_chat.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....1] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....2] [ip4][..udp] [....192.168.2.4][61697] -> [....192.168.2.1][...53] + new: [.....2] [ip4][..udp] [....192.168.2.4][61697] -> [....192.168.2.1][...53] detected: [.....2] [ip4][..udp] [....192.168.2.4][61697] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][e12.whatsapp.net] detection-update: [.....2] [ip4][..udp] [....192.168.2.4][61697] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][e12.whatsapp.net] - new: [.....3] [ip4][..tcp] [....192.168.2.4][49206] -> [...158.85.58.15][.5222] + new: [.....3] [ip4][..tcp] [....192.168.2.4][49206] -> [...158.85.58.15][.5222] detected: [.....3] [ip4][..tcp] [....192.168.2.4][49206] -> [...158.85.58.15][.5222] [WhatsApp][Unknown][Chat][Acceptable] - new: [.....4] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [TLS][Apple][Web][Safe] RISK: Unidirectional Traffic detection-update: [.....4] [ip4][..tcp] [....192.168.2.4][49205] -> [..17.173.66.102][..443] [TLS][Apple][Web][Safe] @@ -22,15 +22,15 @@ [IATS(ms)....: 0.3,0.1,156.1,6.0,20.6,0.0,205.0,0.2,59.6,0.4,0.1,237.8,6.4,13.7,0.0,246.4,0.2,2803.2,0.7,0.1,0.2,0.2,0.1,3030.6,5.8,14.0,0.0,0.0,10.3,10.4,268.2] [PKTLENS.....: 1480,517,596,40,40,986,386,40,40,1480,524,596,40,40,988,386,40,40,1480,517,596,1480,1240,1240,40,40,988,386,40,40,40,113] [ENTROPIES...: 7.8,7.6,7.7,4.9,4.8,7.8,7.3,4.8,4.9,7.9,7.6,7.6,4.8,4.9,7.8,7.4,4.9,4.9,7.9,7.6,7.7,7.9,7.8,7.9,4.9,4.9,7.8,7.4,4.8,4.8,4.8,6.4] - new: [.....5] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [.....5] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [.....5] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....6] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....6] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....6] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [.....7] [ip4][..udp] [....192.168.2.4][.5353] -> [....224.0.0.251][.5353] + new: [.....7] [ip4][..udp] [....192.168.2.4][.5353] -> [....224.0.0.251][.5353] detected: [.....7] [ip4][..udp] [....192.168.2.4][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [.....8] [ip6][..udp] [...............fe80::189c:c31b:1298:224][.5353] -> [...............................ff02::fb][.5353] + new: [.....8] [ip6][..udp] [...............fe80::189c:c31b:1298:224][.5353] -> [...............................ff02::fb][.5353] detected: [.....8] [ip6][..udp] [...............fe80::189c:c31b:1298:224][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [.....9] [ip4][..tcp] [..17.110.229.14][.5223] -> [....192.168.2.4][49193] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [..17.110.229.14][.5223] -> [....192.168.2.4][49193] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [..17.110.229.14][.5223] -> [....192.168.2.4][49193] [TLS][Apple][Web][Safe] RISK: Known Proto on Non Std Port detection-update: [.....9] [ip4][..tcp] [..17.110.229.14][.5223] -> [....192.168.2.4][49193] [TLS][Apple][Web][Safe] diff --git a/test/results/flow-info/default/whatsapp_voice_and_message.pcap.out b/test/results/flow-info/default/whatsapp_voice_and_message.pcap.out index 7c4e0b95c..75952471c 100644 --- a/test/results/flow-info/default/whatsapp_voice_and_message.pcap.out +++ b/test/results/flow-info/default/whatsapp_voice_and_message.pcap.out @@ -1,23 +1,23 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.......10.8.0.1][35480] -> [.184.173.179.46][..443] + new: [.....1] [ip4][..tcp] [.......10.8.0.1][35480] -> [.184.173.179.46][..443] detected: [.....1] [ip4][..tcp] [.......10.8.0.1][35480] -> [.184.173.179.46][..443] [WhatsApp][Unknown][Chat][Acceptable] - new: [.....2] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.84.48][.3478] + new: [.....2] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.84.48][.3478] detected: [.....2] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.84.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....3] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.74.48][.3478] + new: [.....3] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.74.48][.3478] detected: [.....3] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.74.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....4] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.64.48][.3478] + new: [.....4] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.64.48][.3478] detected: [.....4] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.64.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....5] [ip4][..udp] [.......10.8.0.1][53620] -> [..173.252.121.1][.3478] + new: [.....5] [ip4][..udp] [.......10.8.0.1][53620] -> [..173.252.121.1][.3478] detected: [.....5] [ip4][..udp] [.......10.8.0.1][53620] -> [..173.252.121.1][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....6] [ip4][..udp] [.......10.8.0.1][53620] -> [..179.60.192.48][.3478] + new: [.....6] [ip4][..udp] [.......10.8.0.1][53620] -> [..179.60.192.48][.3478] detected: [.....6] [ip4][..udp] [.......10.8.0.1][53620] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....7] [ip4][..udp] [.......10.8.0.1][53620] -> [...31.13.79.192][.3478] + new: [.....7] [ip4][..udp] [.......10.8.0.1][53620] -> [...31.13.79.192][.3478] detected: [.....7] [ip4][..udp] [.......10.8.0.1][53620] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....8] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.93.48][.3478] + new: [.....8] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.93.48][.3478] detected: [.....8] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [.....9] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.73.48][.3478] + new: [.....9] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.73.48][.3478] detected: [.....9] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] analyse: [.....1] [ip4][..tcp] [.......10.8.0.1][35480] -> [.184.173.179.46][..443] [WhatsApp][Unknown][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -29,9 +29,9 @@ [IATS(ms)....: 61.0,61.1,147.7,147.9,346.8,397.2,0.1,50.5,310.1,310.1,199.8,397.9,0.1,198.2,50.5,50.6,386.7,386.7,54.1,104.5,50.5,50.4,398.3,400.0,10696.7,10748.9,0.3,0.2,0.2,0.3,0.2] [PKTLENS.....: 60,40,40,217,40,118,40,70,40,63,40,209,40,72,40,90,40,396,40,63,40,61,40,455,40,119,40,119,40,119,40,119] [ENTROPIES...: 4.4,4.5,4.7,6.6,4.6,6.1,4.7,5.6,4.6,5.2,4.6,6.9,4.7,5.7,4.6,5.9,4.6,7.4,4.6,5.4,4.7,5.3,4.7,7.5,4.6,6.3,4.6,6.3,4.6,6.3,4.6,6.3] - new: [....10] [ip4][..tcp] [.......10.8.0.1][44819] -> [...158.85.58.42][.5222] + new: [....10] [ip4][..tcp] [.......10.8.0.1][44819] -> [...158.85.58.42][.5222] detected: [....10] [ip4][..tcp] [.......10.8.0.1][44819] -> [...158.85.58.42][.5222] [WhatsApp][Unknown][Chat][Acceptable] - new: [....11] [ip4][..tcp] [.......10.8.0.1][42241] -> [173.192.222.189][.5222] + new: [....11] [ip4][..tcp] [.......10.8.0.1][42241] -> [173.192.222.189][.5222] detected: [....11] [ip4][..tcp] [.......10.8.0.1][42241] -> [173.192.222.189][.5222] [WhatsApp][Unknown][Chat][Acceptable] analyse: [....11] [ip4][..tcp] [.......10.8.0.1][42241] -> [173.192.222.189][.5222] [WhatsApp][Unknown][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -51,7 +51,7 @@ update: [.....9] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [.....7] [ip4][..udp] [.......10.8.0.1][53620] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [.....8] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] - new: [....12] [ip4][..tcp] [.......10.8.0.1][49721] -> [..158.85.58.109][.5222] + new: [....12] [ip4][..tcp] [.......10.8.0.1][49721] -> [..158.85.58.109][.5222] detected: [....12] [ip4][..tcp] [.......10.8.0.1][49721] -> [..158.85.58.109][.5222] [WhatsApp][Unknown][Chat][Acceptable] analyse: [....12] [ip4][..tcp] [.......10.8.0.1][49721] -> [..158.85.58.109][.5222] [WhatsApp][Unknown][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -71,7 +71,7 @@ update: [.....9] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.73.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [.....7] [ip4][..udp] [.......10.8.0.1][53620] -> [...31.13.79.192][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] update: [.....8] [ip4][..udp] [.......10.8.0.1][53620] -> [....31.13.93.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] - new: [....13] [ip4][..tcp] [.......10.8.0.1][51570] -> [...158.85.5.199][..443] + new: [....13] [ip4][..tcp] [.......10.8.0.1][51570] -> [...158.85.5.199][..443] detected: [....13] [ip4][..tcp] [.......10.8.0.1][51570] -> [...158.85.5.199][..443] [WhatsApp][Unknown][Chat][Acceptable] idle: [....13] [ip4][..tcp] [.......10.8.0.1][51570] -> [...158.85.5.199][..443] [WhatsApp][Unknown][Chat][Acceptable] end: [....10] [ip4][..tcp] [.......10.8.0.1][44819] -> [...158.85.58.42][.5222] [WhatsApp][Unknown][Chat][Acceptable] diff --git a/test/results/flow-info/default/whatsappfiles.pcap.out b/test/results/flow-info/default/whatsappfiles.pcap.out index 5987a435a..bd411d693 100644 --- a/test/results/flow-info/default/whatsappfiles.pcap.out +++ b/test/results/flow-info/default/whatsappfiles.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.2.29][49674] -> [..185.60.216.53][..443] + new: [.....1] [ip4][..tcp] [...192.168.2.29][49674] -> [..185.60.216.53][..443] detected: [.....1] [ip4][..tcp] [...192.168.2.29][49674] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][mmg-fna.whatsapp.net] detection-update: [.....1] [ip4][..tcp] [...192.168.2.29][49674] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][mmg-fna.whatsapp.net] detection-update: [.....1] [ip4][..tcp] [...192.168.2.29][49674] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][mmg-fna.whatsapp.net] @@ -15,7 +15,7 @@ [IATS(ms)....: 90.0,91.9,3.0,95.6,1.4,1.2,0.0,95.9,1.0,78.9,282.8,460.9,0.0,97.9,0.0,4.0,7.0,1.0,0.0,0.0,115.1,0.0,1.2,0.0,102.9,1.0,41.1,24639.8,5.0,6.0,3.0] [PKTLENS.....: 64,60,52,295,52,1450,1450,464,52,52,52,178,310,133,52,52,105,102,94,235,90,52,90,52,162,52,52,52,275,1450,1450,1450] [ENTROPIES...: 4.4,5.2,5.0,5.6,5.2,6.9,7.3,7.4,5.1,5.1,4.9,6.3,7.1,6.4,5.0,5.0,5.6,5.7,5.4,6.9,5.4,5.2,5.9,5.2,6.6,5.0,5.1,5.2,7.0,7.9,7.8,7.9] - new: [.....2] [ip4][..tcp] [...192.168.2.29][49698] -> [..185.60.216.53][..443] + new: [.....2] [ip4][..tcp] [...192.168.2.29][49698] -> [..185.60.216.53][..443] detected: [.....2] [ip4][..tcp] [...192.168.2.29][49698] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][mmg-fna.whatsapp.net] detection-update: [.....2] [ip4][..tcp] [...192.168.2.29][49698] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][mmg-fna.whatsapp.net] analyse: [.....2] [ip4][..tcp] [...192.168.2.29][49698] -> [..185.60.216.53][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable] diff --git a/test/results/flow-info/default/whois.pcapng.out b/test/results/flow-info/default/whois.pcapng.out index 6faaeefa8..9cdcdb43b 100644 --- a/test/results/flow-info/default/whois.pcapng.out +++ b/test/results/flow-info/default/whois.pcapng.out @@ -1,11 +1,11 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [......10.0.2.15][44188] -> [....192.0.47.59][...43] + new: [.....1] [ip4][..tcp] [......10.0.2.15][44188] -> [....192.0.47.59][...43] detected: [.....1] [ip4][..tcp] [......10.0.2.15][44188] -> [....192.0.47.59][...43] [Whois-DAS][Unknown][Network][Acceptable][example.com] DAEMON-EVENT: [Processed: 11 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [...10.17.34.139][64016] -> [.....10.17.51.8][.4343] + new: [.....2] [ip4][..tcp] [...10.17.34.139][64016] -> [.....10.17.51.8][.4343] detected: [.....2] [ip4][..tcp] [...10.17.34.139][64016] -> [.....10.17.51.8][.4343] [TLS][Unknown][Web][Safe][] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....2] [ip4][..tcp] [...10.17.34.139][64016] -> [.....10.17.51.8][.4343] [TLS][Unknown][Web][Safe][] @@ -13,10 +13,10 @@ end: [.....1] [ip4][..tcp] [......10.0.2.15][44188] -> [....192.0.47.59][...43] [Whois-DAS][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 18 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....3] [ip4][..tcp] [...192.30.45.30][...43] -> [..10.160.63.128][53217] + new: [.....3] [ip4][..tcp] [...192.30.45.30][...43] -> [..10.160.63.128][53217] idle: [.....2] [ip4][..tcp] [...10.17.34.139][64016] -> [.....10.17.51.8][.4343] [TLS][Unknown][Web][Safe] RISK: Known Proto on Non Std Port, Missing SNI TLS Extn, ALPN/SNI Mismatch guessed: [.....3] [ip4][..tcp] [...192.30.45.30][...43] -> [..10.160.63.128][53217] [Whois-DAS][Unknown][Network][Acceptable][] RISK: Unidirectional Traffic - end: [.....3] [ip4][..tcp] [...192.30.45.30][...43] -> [..10.160.63.128][53217] + end: [.....3] [ip4][..tcp] [...192.30.45.30][...43] -> [..10.160.63.128][53217] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/windowsupdate_over_http.pcap.out b/test/results/flow-info/default/windowsupdate_over_http.pcap.out index a43f16ba4..f1718be34 100644 --- a/test/results/flow-info/default/windowsupdate_over_http.pcap.out +++ b/test/results/flow-info/default/windowsupdate_over_http.pcap.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] + new: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] detected: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][SoftwareUpdate][Safe][151.99.72.125] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][Download][Safe][151.99.72.125] diff --git a/test/results/flow-info/default/wireguard.pcap.out b/test/results/flow-info/default/wireguard.pcap.out index d1b926904..06da4addc 100644 --- a/test/results/flow-info/default/wireguard.pcap.out +++ b/test/results/flow-info/default/wireguard.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] + new: [.....1] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] detected: [.....1] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] update: [.....1] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] DAEMON-EVENT: [Processed: 22 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 1] - new: [.....2] [ip4][..udp] [139.162.192.157][51820] -> [...192.168.0.14][36116] + new: [.....2] [ip4][..udp] [139.162.192.157][51820] -> [...192.168.0.14][36116] detected: [.....2] [ip4][..udp] [139.162.192.157][51820] -> [...192.168.0.14][36116] [WireGuard][Unknown][VPN][Acceptable] idle: [.....2] [ip4][..udp] [139.162.192.157][51820] -> [...192.168.0.14][36116] [WireGuard][Unknown][VPN][Acceptable] idle: [.....1] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] diff --git a/test/results/flow-info/default/wow.pcap.out b/test/results/flow-info/default/wow.pcap.out index ee9d6a922..38fa8b297 100644 --- a/test/results/flow-info/default/wow.pcap.out +++ b/test/results/flow-info/default/wow.pcap.out @@ -1,21 +1,21 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.192.168.178.20][39309] -> [..12.129.222.53][...80] - new: [.....2] [ip4][..tcp] [.192.168.178.20][39312] -> [...24.105.29.21][...80] + new: [.....1] [ip4][..tcp] [.192.168.178.20][39309] -> [..12.129.222.53][...80] + new: [.....2] [ip4][..tcp] [.192.168.178.20][39312] -> [...24.105.29.21][...80] detected: [.....1] [ip4][..tcp] [.192.168.178.20][39309] -> [..12.129.222.53][...80] [HTTP.WorldOfWarcraft][Unknown][Game][Fun][us.scan.worldofwarcraft.com] RISK: HTTP Susp User-Agent detected: [.....2] [ip4][..tcp] [.192.168.178.20][39312] -> [...24.105.29.21][...80] [HTTP.WorldOfWarcraft][Starcraft][Game][Fun][launcher.worldofwarcraft.com] RISK: HTTP Susp User-Agent detection-update: [.....1] [ip4][..tcp] [.192.168.178.20][39309] -> [..12.129.222.53][...80] [HTTP.WorldOfWarcraft][Unknown][Game][Fun][us.scan.worldofwarcraft.com] RISK: HTTP Susp User-Agent, HTTP Obsolete Server - new: [.....3] [ip4][..tcp] [.192.168.178.20][39329] -> [.12.129.228.153][.3724] + new: [.....3] [ip4][..tcp] [.192.168.178.20][39329] -> [.12.129.228.153][.3724] detected: [.....3] [ip4][..tcp] [.192.168.178.20][39329] -> [.12.129.228.153][.3724] [WorldOfWarcraft][Unknown][Game][Fun] - new: [.....4] [ip4][..tcp] [.192.168.178.20][39364] -> [.12.129.228.153][.3724] + new: [.....4] [ip4][..tcp] [.192.168.178.20][39364] -> [.12.129.228.153][.3724] detected: [.....4] [ip4][..tcp] [.192.168.178.20][39364] -> [.12.129.228.153][.3724] [WorldOfWarcraft][Unknown][Game][Fun] DAEMON-EVENT: [Processed: 82 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 4 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 1|updates: 0] - new: [.....5] [ip4][..tcp] [.192.168.178.20][39593] -> [.12.129.228.152][.3724] + new: [.....5] [ip4][..tcp] [.192.168.178.20][39593] -> [.12.129.228.152][.3724] detected: [.....5] [ip4][..tcp] [.192.168.178.20][39593] -> [.12.129.228.152][.3724] [WorldOfWarcraft][Unknown][Game][Fun] idle: [.....3] [ip4][..tcp] [.192.168.178.20][39329] -> [.12.129.228.153][.3724] [WorldOfWarcraft][Unknown][Game][Fun] idle: [.....4] [ip4][..tcp] [.192.168.178.20][39364] -> [.12.129.228.153][.3724] [WorldOfWarcraft][Unknown][Game][Fun] diff --git a/test/results/flow-info/default/xdmcp.pcap.out b/test/results/flow-info/default/xdmcp.pcap.out index b4125ff9d..22e9db0f8 100644 --- a/test/results/flow-info/default/xdmcp.pcap.out +++ b/test/results/flow-info/default/xdmcp.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [.......10.1.2.2][61426] -> [.......10.1.2.4][..177] + new: [.....1] [ip4][..udp] [.......10.1.2.2][61426] -> [.......10.1.2.4][..177] detected: [.....1] [ip4][..udp] [.......10.1.2.2][61426] -> [.......10.1.2.4][..177] [XDMCP][Unknown][RemoteAccess][Acceptable] idle: [.....1] [ip4][..udp] [.......10.1.2.2][61426] -> [.......10.1.2.4][..177] [XDMCP][Unknown][RemoteAccess][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/xiaomi.pcap.out b/test/results/flow-info/default/xiaomi.pcap.out index 6412d5fe3..0339e3e04 100644 --- a/test/results/flow-info/default/xiaomi.pcap.out +++ b/test/results/flow-info/default/xiaomi.pcap.out @@ -1,32 +1,32 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [....47.241.7.88][.5222] -> [..10.52.151.160][39180] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [....47.241.7.88][.5222] -> [..10.52.151.160][39180] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [....47.241.7.88][.5222] -> [..10.52.151.160][39180] [Xiaomi][Alibaba][Web][Acceptable][] DAEMON-EVENT: [Processed: 1 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [.115.164.74.232][.5222] -> [192.168.244.219][45904] + new: [.....2] [ip4][..tcp] [.115.164.74.232][.5222] -> [192.168.244.219][45904] detected: [.....2] [ip4][..tcp] [.115.164.74.232][.5222] -> [192.168.244.219][45904] [Xiaomi][Unknown][Web][Acceptable][47.241.35.73] - new: [.....3] [ip4][..tcp] [.115.164.74.232][.5222] -> [.192.168.247.13][38018] + new: [.....3] [ip4][..tcp] [.115.164.74.232][.5222] -> [.192.168.247.13][38018] detected: [.....3] [ip4][..tcp] [.115.164.74.232][.5222] -> [.192.168.247.13][38018] [Xiaomi][Unknown][Web][Acceptable][47.241.35.73] idle: [.....1] [ip4][..tcp] [....47.241.7.88][.5222] -> [..10.52.151.160][39180] [Xiaomi][Alibaba][Web][Acceptable] - new: [.....4] [ip4][..tcp] [..97.39.119.172][.5222] -> [..192.168.93.59][51488] + new: [.....4] [ip4][..tcp] [..97.39.119.172][.5222] -> [..192.168.93.59][51488] detected: [.....4] [ip4][..tcp] [..97.39.119.172][.5222] -> [..192.168.93.59][51488] [Xiaomi][Unknown][Web][Acceptable][47.241.59.87] DAEMON-EVENT: [Processed: 18 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 3 / 4|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.2.100][37708] -> [...3.127.176.74][.5222] + new: [.....5] [ip4][..tcp] [..192.168.2.100][37708] -> [...3.127.176.74][.5222] detected: [.....5] [ip4][..tcp] [..192.168.2.100][37708] -> [...3.127.176.74][.5222] [Xiaomi][AmazonAWS][Web][Acceptable][fr-app-chat-global-xiaomi-net1-1667981913.eu-central-1.elb.amazonaws.com] idle: [.....2] [ip4][..tcp] [.115.164.74.232][.5222] -> [192.168.244.219][45904] [Xiaomi][Unknown][Web][Acceptable] idle: [.....4] [ip4][..tcp] [..97.39.119.172][.5222] -> [..192.168.93.59][51488] [Xiaomi][Unknown][Web][Acceptable] idle: [.....3] [ip4][..tcp] [.115.164.74.232][.5222] -> [.192.168.247.13][38018] [Xiaomi][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 33 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.2.100][45106] -> [.18.193.233.122][.5222] + new: [.....6] [ip4][..tcp] [..192.168.2.100][45106] -> [.18.193.233.122][.5222] detected: [.....6] [ip4][..tcp] [..192.168.2.100][45106] -> [.18.193.233.122][.5222] [Xiaomi][AmazonAWS][Web][Acceptable][fr-app-chat-global-xiaomi-net2-2117517874.eu-central-1.elb.amazonaws.com] idle: [.....5] [ip4][..tcp] [..192.168.2.100][37708] -> [...3.127.176.74][.5222] [Xiaomi][AmazonAWS][Web][Acceptable] DAEMON-EVENT: [Processed: 48 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....7] [ip4][..tcp] [..192.168.2.100][48698] -> [...203.107.1.65][...80] + new: [.....7] [ip4][..tcp] [..192.168.2.100][48698] -> [...203.107.1.65][...80] detected: [.....7] [ip4][..tcp] [..192.168.2.100][48698] -> [...203.107.1.65][...80] [HTTP.Xiaomi][Alibaba][Web][Acceptable][203.107.1.65] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI idle: [.....7] [ip4][..tcp] [..192.168.2.100][48698] -> [...203.107.1.65][...80] [HTTP.Xiaomi][Alibaba][Web][Acceptable] diff --git a/test/results/flow-info/default/xss.pcap.out b/test/results/flow-info/default/xss.pcap.out index 49f4ac429..614f51d8d 100644 --- a/test/results/flow-info/default/xss.pcap.out +++ b/test/results/flow-info/default/xss.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.3.109][53514] -> [..192.168.3.107][...80] - new: [.....2] [ip4][..tcp] [..192.168.3.109][53516] -> [..192.168.3.107][...80] + new: [.....1] [ip4][..tcp] [..192.168.3.109][53514] -> [..192.168.3.107][...80] + new: [.....2] [ip4][..tcp] [..192.168.3.109][53516] -> [..192.168.3.107][...80] detected: [.....1] [ip4][..tcp] [..192.168.3.109][53514] -> [..192.168.3.107][...80] [HTTP][Unknown][Web][Acceptable][192.168.3.107] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI idle: [.....1] [ip4][..tcp] [..192.168.3.109][53514] -> [..192.168.3.107][...80] [HTTP][Unknown][Web][Acceptable] RISK: XSS Attack, HTTP/TLS/QUIC Numeric Hostname/SNI guessed: [.....2] [ip4][..tcp] [..192.168.3.109][53516] -> [..192.168.3.107][...80] [HTTP][Unknown][Web][Acceptable][] - idle: [.....2] [ip4][..tcp] [..192.168.3.109][53516] -> [..192.168.3.107][...80] + idle: [.....2] [ip4][..tcp] [..192.168.3.109][53516] -> [..192.168.3.107][...80] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/default/yandex.pcapng.out b/test/results/flow-info/default/yandex.pcapng.out index 1bd70ea33..6a48a2dee 100644 --- a/test/results/flow-info/default/yandex.pcapng.out +++ b/test/results/flow-info/default/yandex.pcapng.out @@ -1,38 +1,38 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.249][40218] -> [213.180.204.186][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.249][40218] -> [213.180.204.186][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.249][40218] -> [213.180.204.186][..443] [TLS.YandexMusic][Yandex][Music][Fun][music.yandex.kz] detection-update: [.....1] [ip4][..tcp] [..192.168.1.249][40218] -> [213.180.204.186][..443] [TLS.YandexMusic][Yandex][Music][Fun][music.yandex.kz] detection-update: [.....1] [ip4][..tcp] [..192.168.1.249][40218] -> [213.180.204.186][..443] [TLS.YandexMusic][Yandex][Music][Fun][music.yandex.kz] DAEMON-EVENT: [Processed: 18 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 2|updates: 0] - new: [.....2] [ip4][..tcp] [..192.168.1.249][57126] -> [178.154.131.216][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.249][57126] -> [178.154.131.216][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.249][57126] -> [178.154.131.216][..443] [TLS.Yandex][Yandex][Web][Safe][yastatic.net] RISK: Unidirectional Traffic - new: [.....3] [ip4][..tcp] [..192.168.1.249][42102] -> [178.154.131.216][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.249][42102] -> [178.154.131.216][..443] detected: [.....3] [ip4][..tcp] [..192.168.1.249][42102] -> [178.154.131.216][..443] [TLS.Yandex][Yandex][Web][Safe][yastatic.net] RISK: Unidirectional Traffic - new: [.....4] [ip4][..tcp] [..192.168.1.249][40870] -> [..87.250.251.22][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.249][40870] -> [..87.250.251.22][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.249][40870] -> [..87.250.251.22][..443] [TLS.YandexMarket][Yandex][Shopping][Safe][fenek.market.yandex.ru] RISK: Unidirectional Traffic - new: [.....5] [ip4][..tcp] [..192.168.1.249][57322] -> [.87.250.250.108][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.249][57322] -> [.87.250.250.108][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.249][57322] -> [.87.250.250.108][..443] [TLS.YandexCloud][Yandex][Cloud][Safe][cloud.yandex.ru] detection-update: [.....5] [ip4][..tcp] [..192.168.1.249][57322] -> [.87.250.250.108][..443] [TLS.YandexCloud][Yandex][Cloud][Safe][cloud.yandex.ru] DAEMON-EVENT: [Processed: 67 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 5 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 3|updates: 0] - new: [.....6] [ip4][..tcp] [..192.168.1.249][58832] -> [.87.250.250.134][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.249][58832] -> [.87.250.250.134][..443] detected: [.....6] [ip4][..tcp] [..192.168.1.249][58832] -> [.87.250.250.134][..443] [TLS.YandexDirect][Yandex][Advertisement][Tracker/Ads][direct.yandex.kz] detection-update: [.....6] [ip4][..tcp] [..192.168.1.249][58832] -> [.87.250.250.134][..443] [TLS.YandexDirect][Yandex][Advertisement][Tracker/Ads][direct.yandex.kz] - new: [.....7] [ip4][..tcp] [..192.168.1.249][42954] -> [...77.88.21.127][..443] + new: [.....7] [ip4][..tcp] [..192.168.1.249][42954] -> [...77.88.21.127][..443] detected: [.....7] [ip4][..tcp] [..192.168.1.249][42954] -> [...77.88.21.127][..443] [TLS.YandexDisk][Yandex][Cloud][Safe][1.downloader.disk.yandex.kz] detection-update: [.....7] [ip4][..tcp] [..192.168.1.249][42954] -> [...77.88.21.127][..443] [TLS.YandexDisk][Yandex][Cloud][Safe][1.downloader.disk.yandex.kz] detection-update: [.....7] [ip4][..tcp] [..192.168.1.249][42954] -> [...77.88.21.127][..443] [TLS.YandexDisk][Yandex][Cloud][Safe][1.downloader.disk.yandex.kz] RISK: TLS Cert About To Expire - new: [.....8] [ip4][..tcp] [..192.168.1.249][45224] -> [....77.88.21.37][..443] + new: [.....8] [ip4][..tcp] [..192.168.1.249][45224] -> [....77.88.21.37][..443] detected: [.....8] [ip4][..tcp] [..192.168.1.249][45224] -> [....77.88.21.37][..443] [TLS.YandexMail][Yandex][Email][Safe][mail.yandex.kz] RISK: Unidirectional Traffic - new: [.....9] [ip4][..tcp] [..192.168.1.249][51462] -> [..87.250.251.77][..443] + new: [.....9] [ip4][..tcp] [..192.168.1.249][51462] -> [..87.250.251.77][..443] detected: [.....9] [ip4][..tcp] [..192.168.1.249][51462] -> [..87.250.251.77][..443] [TLS.YandexMetrika][Yandex][Web][Safe][metrika.yandex.kz] detection-update: [.....9] [ip4][..tcp] [..192.168.1.249][51462] -> [..87.250.251.77][..443] [TLS.YandexMetrika][Yandex][Web][Safe][metrika.yandex.kz] idle: [.....3] [ip4][..tcp] [..192.168.1.249][42102] -> [178.154.131.216][..443] [TLS.Yandex][Yandex][Web][Safe] diff --git a/test/results/flow-info/default/youtube_quic.pcap.out b/test/results/flow-info/default/youtube_quic.pcap.out index 507ee47cd..7b35b932f 100644 --- a/test/results/flow-info/default/youtube_quic.pcap.out +++ b/test/results/flow-info/default/youtube_quic.pcap.out @@ -1,9 +1,9 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [....192.168.1.7][54997] -> [..216.58.205.66][..443] + new: [.....1] [ip4][..udp] [....192.168.1.7][54997] -> [..216.58.205.66][..443] detected: [.....1] [ip4][..udp] [....192.168.1.7][54997] -> [..216.58.205.66][..443] [QUIC.Google][Google][Advertisement][Acceptable][pagead2.googlesyndication.com] - new: [.....2] [ip4][..udp] [....192.168.1.7][56074] -> [..216.58.198.33][..443] + new: [.....2] [ip4][..udp] [....192.168.1.7][56074] -> [..216.58.198.33][..443] detected: [.....2] [ip4][..udp] [....192.168.1.7][56074] -> [..216.58.198.33][..443] [QUIC.YouTube][Google][Media][Fun][yt3.ggpht.com] analyse: [.....2] [ip4][..udp] [....192.168.1.7][56074] -> [..216.58.198.33][..443] [QUIC.YouTube][Google][Media][Fun] min| max| avg| stddev| variance| entropy @@ -15,7 +15,7 @@ [IATS(ms)....: 43.7,0.6,47.4,0.3,0.2,0.0,22.6,22.3,0.0,41.9,0.1,4.3,1.2,5.2,1.0,1.2,2.1,1.0,1.2,2.2,1.1,0.9,2.0,1.3,1.0,2.3,0.9,1.3,2.3,0.6,7.7] [PKTLENS.....: 1378,1378,1378,1378,445,163,164,63,1378,59,69,69,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1378,1378,66,1016,1378] [ENTROPIES...: 2.5,7.5,2.6,5.5,7.5,6.7,6.7,5.2,7.9,5.3,5.5,5.6,7.8,7.8,5.6,7.9,7.9,5.6,7.9,7.9,5.5,7.9,7.9,5.6,7.9,7.9,5.6,7.9,7.9,5.5,7.8,7.9] - new: [.....3] [ip4][..udp] [....192.168.1.7][53859] -> [..216.58.205.66][..443] + new: [.....3] [ip4][..udp] [....192.168.1.7][53859] -> [..216.58.205.66][..443] detected: [.....3] [ip4][..udp] [....192.168.1.7][53859] -> [..216.58.205.66][..443] [QUIC.Google][Google][Advertisement][Acceptable][googleads.g.doubleclick.net] idle: [.....2] [ip4][..udp] [....192.168.1.7][56074] -> [..216.58.198.33][..443] [QUIC.YouTube][Google][Media][Fun] idle: [.....1] [ip4][..udp] [....192.168.1.7][54997] -> [..216.58.205.66][..443] [QUIC.Google][Google][Advertisement][Acceptable] diff --git a/test/results/flow-info/default/youtubeupload.pcap.out b/test/results/flow-info/default/youtubeupload.pcap.out index 264140750..961d9bab1 100644 --- a/test/results/flow-info/default/youtubeupload.pcap.out +++ b/test/results/flow-info/default/youtubeupload.pcap.out @@ -1,13 +1,13 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.2.27][51925] -> [.172.217.23.111][..443] + new: [.....1] [ip4][..udp] [...192.168.2.27][51925] -> [.172.217.23.111][..443] detected: [.....1] [ip4][..udp] [...192.168.2.27][51925] -> [.172.217.23.111][..443] [QUIC.YouTubeUpload][Google][Media][Fun][upload.youtube.com] - new: [.....2] [ip4][..tcp] [...192.168.2.27][57452] -> [.172.217.23.111][..443] + new: [.....2] [ip4][..tcp] [...192.168.2.27][57452] -> [.172.217.23.111][..443] detected: [.....2] [ip4][..tcp] [...192.168.2.27][57452] -> [.172.217.23.111][..443] [TLS.YouTubeUpload][Google][Media][Fun][upload.youtube.com] detection-update: [.....2] [ip4][..tcp] [...192.168.2.27][57452] -> [.172.217.23.111][..443] [TLS.YouTubeUpload][Google][Media][Fun][upload.youtube.com] detection-update: [.....2] [ip4][..tcp] [...192.168.2.27][57452] -> [.172.217.23.111][..443] [TLS.YouTubeUpload][Google][Media][Fun][upload.youtube.com] - new: [.....3] [ip4][..udp] [...192.168.2.27][62232] -> [.172.217.23.111][..443] + new: [.....3] [ip4][..udp] [...192.168.2.27][62232] -> [.172.217.23.111][..443] detected: [.....3] [ip4][..udp] [...192.168.2.27][62232] -> [.172.217.23.111][..443] [QUIC.YouTubeUpload][Google][Media][Fun][upload.youtube.com] analyse: [.....1] [ip4][..udp] [...192.168.2.27][51925] -> [.172.217.23.111][..443] [QUIC.YouTubeUpload][Google][Media][Fun] min| max| avg| stddev| variance| entropy diff --git a/test/results/flow-info/default/z3950.pcapng.out b/test/results/flow-info/default/z3950.pcapng.out index cd38fefd7..8e75e00a9 100644 --- a/test/results/flow-info/default/z3950.pcapng.out +++ b/test/results/flow-info/default/z3950.pcapng.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][58921] -> [.193.174.240.93][..210] + new: [.....1] [ip4][..tcp] [..192.168.2.100][58921] -> [.193.174.240.93][..210] DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [...192.168.0.20][46524] -> [.129.187.139.43][.9991] + new: [.....2] [ip4][..tcp] [...192.168.0.20][46524] -> [.129.187.139.43][.9991] guessed: [.....1] [ip4][..tcp] [..192.168.2.100][58921] -> [.193.174.240.93][..210] [Z3950][Unknown][Network][Acceptable] - end: [.....1] [ip4][..tcp] [..192.168.2.100][58921] -> [.193.174.240.93][..210] + end: [.....1] [ip4][..tcp] [..192.168.2.100][58921] -> [.193.174.240.93][..210] detected: [.....2] [ip4][..tcp] [...192.168.0.20][46524] -> [.129.187.139.43][.9991] [Z3950][Unknown][Network][Acceptable] RISK: Known Proto on Non Std Port end: [.....2] [ip4][..tcp] [...192.168.0.20][46524] -> [.129.187.139.43][.9991] [Z3950][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/zabbix.pcap.out b/test/results/flow-info/default/zabbix.pcap.out index c22da72c8..6be242c81 100644 --- a/test/results/flow-info/default/zabbix.pcap.out +++ b/test/results/flow-info/default/zabbix.pcap.out @@ -1,61 +1,61 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.67.98][57162] -> [..192.168.67.25][10050] + new: [.....1] [ip4][..tcp] [..192.168.67.98][57162] -> [..192.168.67.25][10050] detected: [.....1] [ip4][..tcp] [..192.168.67.98][57162] -> [..192.168.67.25][10050] [Zabbix][Unknown][Network][Acceptable] DAEMON-EVENT: [Processed: 10 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....2] [ip4][..tcp] [...192.168.7.16][36699] -> [...192.168.7.17][10051] + new: [.....2] [ip4][..tcp] [...192.168.7.16][36699] -> [...192.168.7.17][10051] detected: [.....2] [ip4][..tcp] [...192.168.7.16][36699] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....3] [ip4][..tcp] [...192.168.7.16][54089] -> [...192.168.7.17][10051] + new: [.....3] [ip4][..tcp] [...192.168.7.16][54089] -> [...192.168.7.17][10051] detected: [.....3] [ip4][..tcp] [...192.168.7.16][54089] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....4] [ip4][..tcp] [...192.168.7.16][37781] -> [...192.168.7.17][10051] + new: [.....4] [ip4][..tcp] [...192.168.7.16][37781] -> [...192.168.7.17][10051] detected: [.....4] [ip4][..tcp] [...192.168.7.16][37781] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....1] [ip4][..tcp] [..192.168.67.98][57162] -> [..192.168.67.25][10050] [Zabbix][Unknown][Network][Acceptable] - new: [.....5] [ip4][..tcp] [...192.168.7.16][58079] -> [...192.168.7.17][10051] + new: [.....5] [ip4][..tcp] [...192.168.7.16][58079] -> [...192.168.7.17][10051] detected: [.....5] [ip4][..tcp] [...192.168.7.16][58079] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....6] [ip4][..tcp] [...192.168.7.16][33661] -> [...192.168.7.17][10051] + new: [.....6] [ip4][..tcp] [...192.168.7.16][33661] -> [...192.168.7.17][10051] detected: [.....6] [ip4][..tcp] [...192.168.7.16][33661] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....7] [ip4][..tcp] [...192.168.7.16][40553] -> [...192.168.7.17][10051] + new: [.....7] [ip4][..tcp] [...192.168.7.16][40553] -> [...192.168.7.17][10051] detected: [.....7] [ip4][..tcp] [...192.168.7.16][40553] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....8] [ip4][..tcp] [...192.168.7.16][36755] -> [...192.168.7.17][10051] + new: [.....8] [ip4][..tcp] [...192.168.7.16][36755] -> [...192.168.7.17][10051] detected: [.....8] [ip4][..tcp] [...192.168.7.16][36755] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [.....9] [ip4][..tcp] [...192.168.7.16][43395] -> [...192.168.7.17][10051] + new: [.....9] [ip4][..tcp] [...192.168.7.16][43395] -> [...192.168.7.17][10051] detected: [.....9] [ip4][..tcp] [...192.168.7.16][43395] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....10] [ip4][..tcp] [...192.168.7.16][45197] -> [...192.168.7.17][10051] - new: [....11] [ip4][..tcp] [...192.168.7.16][35243] -> [...192.168.7.17][10051] + new: [....10] [ip4][..tcp] [...192.168.7.16][45197] -> [...192.168.7.17][10051] + new: [....11] [ip4][..tcp] [...192.168.7.16][35243] -> [...192.168.7.17][10051] detected: [....10] [ip4][..tcp] [...192.168.7.16][45197] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] detected: [....11] [ip4][..tcp] [...192.168.7.16][35243] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....12] [ip4][..tcp] [...192.168.7.16][36623] -> [...192.168.7.17][10051] + new: [....12] [ip4][..tcp] [...192.168.7.16][36623] -> [...192.168.7.17][10051] detected: [....12] [ip4][..tcp] [...192.168.7.16][36623] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....13] [ip4][..tcp] [...192.168.7.16][35627] -> [...192.168.7.17][10051] + new: [....13] [ip4][..tcp] [...192.168.7.16][35627] -> [...192.168.7.17][10051] detected: [....13] [ip4][..tcp] [...192.168.7.16][35627] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....14] [ip4][..tcp] [...192.168.7.16][49215] -> [...192.168.7.17][10051] + new: [....14] [ip4][..tcp] [...192.168.7.16][49215] -> [...192.168.7.17][10051] detected: [....14] [ip4][..tcp] [...192.168.7.16][49215] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....15] [ip4][..tcp] [...192.168.7.16][55759] -> [...192.168.7.17][10051] + new: [....15] [ip4][..tcp] [...192.168.7.16][55759] -> [...192.168.7.17][10051] detected: [....15] [ip4][..tcp] [...192.168.7.16][55759] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....16] [ip4][..tcp] [...192.168.7.16][50639] -> [...192.168.7.17][10051] + new: [....16] [ip4][..tcp] [...192.168.7.16][50639] -> [...192.168.7.17][10051] detected: [....16] [ip4][..tcp] [...192.168.7.16][50639] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....17] [ip4][..tcp] [...192.168.7.16][41309] -> [...192.168.7.17][10051] + new: [....17] [ip4][..tcp] [...192.168.7.16][41309] -> [...192.168.7.17][10051] detected: [....17] [ip4][..tcp] [...192.168.7.16][41309] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....18] [ip4][..tcp] [...192.168.7.16][60217] -> [...192.168.7.17][10051] - new: [....19] [ip4][..tcp] [...192.168.7.16][43677] -> [...192.168.7.17][10051] + new: [....18] [ip4][..tcp] [...192.168.7.16][60217] -> [...192.168.7.17][10051] + new: [....19] [ip4][..tcp] [...192.168.7.16][43677] -> [...192.168.7.17][10051] detected: [....19] [ip4][..tcp] [...192.168.7.16][43677] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] detected: [....18] [ip4][..tcp] [...192.168.7.16][60217] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....20] [ip4][..tcp] [...192.168.7.16][48677] -> [...192.168.7.17][10051] + new: [....20] [ip4][..tcp] [...192.168.7.16][48677] -> [...192.168.7.17][10051] detected: [....20] [ip4][..tcp] [...192.168.7.16][48677] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....2] [ip4][..tcp] [...192.168.7.16][36699] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....3] [ip4][..tcp] [...192.168.7.16][54089] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....21] [ip4][..tcp] [...192.168.7.16][52901] -> [...192.168.7.17][10051] + new: [....21] [ip4][..tcp] [...192.168.7.16][52901] -> [...192.168.7.17][10051] detected: [....21] [ip4][..tcp] [...192.168.7.16][52901] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....22] [ip4][..tcp] [...192.168.7.16][48017] -> [...192.168.7.17][10051] + new: [....22] [ip4][..tcp] [...192.168.7.16][48017] -> [...192.168.7.17][10051] detected: [....22] [ip4][..tcp] [...192.168.7.16][48017] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....5] [ip4][..tcp] [...192.168.7.16][58079] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....4] [ip4][..tcp] [...192.168.7.16][37781] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....23] [ip4][..tcp] [...192.168.7.16][39595] -> [...192.168.7.17][10051] + new: [....23] [ip4][..tcp] [...192.168.7.16][39595] -> [...192.168.7.17][10051] detected: [....23] [ip4][..tcp] [...192.168.7.16][39595] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....6] [ip4][..tcp] [...192.168.7.16][33661] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] - new: [....24] [ip4][..tcp] [...192.168.7.16][36763] -> [...192.168.7.17][10051] + new: [....24] [ip4][..tcp] [...192.168.7.16][36763] -> [...192.168.7.17][10051] detected: [....24] [ip4][..tcp] [...192.168.7.16][36763] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [.....8] [ip4][..tcp] [...192.168.7.16][36755] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] end: [....24] [ip4][..tcp] [...192.168.7.16][36763] -> [...192.168.7.17][10051] [Zabbix][Unknown][Network][Acceptable] diff --git a/test/results/flow-info/default/zattoo.pcap.out b/test/results/flow-info/default/zattoo.pcap.out index b973ca1e2..eea84433d 100644 --- a/test/results/flow-info/default/zattoo.pcap.out +++ b/test/results/flow-info/default/zattoo.pcap.out @@ -1,12 +1,12 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [.....10.101.0.2][.2930] -> [.....10.102.0.2][..443] + new: [.....1] [ip4][..tcp] [.....10.101.0.2][.2930] -> [.....10.102.0.2][..443] detected: [.....1] [ip4][..tcp] [.....10.101.0.2][.2930] -> [.....10.102.0.2][..443] [TLS.Zattoo][Unknown][Video][Fun][zattoo.com] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [.....10.101.0.2][.2930] -> [.....10.102.0.2][..443] [TLS.Zattoo][Unknown][Video][Fun][zattoo.com] RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, TLS Cert Validity Too Long - new: [.....2] [ip4][..tcp] [.....10.101.0.2][.2936] -> [.....10.102.0.2][...80] + new: [.....2] [ip4][..tcp] [.....10.101.0.2][.2936] -> [.....10.102.0.2][...80] detected: [.....2] [ip4][..tcp] [.....10.101.0.2][.2936] -> [.....10.102.0.2][...80] [HTTP.Zattoo][Unknown][Video][Fun][zattosecurehd2-f.akamaihd.net] end: [.....1] [ip4][..tcp] [.....10.101.0.2][.2930] -> [.....10.102.0.2][..443] [TLS.Zattoo][Unknown][Video][Fun] RISK: Weak TLS Cipher, TLS (probably) Not Carrying HTTPS, TLS Cert Validity Too Long diff --git a/test/results/flow-info/default/zcash.pcap.out b/test/results/flow-info/default/zcash.pcap.out index 3367a3be8..3f16615a3 100644 --- a/test/results/flow-info/default/zcash.pcap.out +++ b/test/results/flow-info/default/zcash.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [...192.168.2.92][55190] -> [.178.32.196.217][.9050] + new: [.....1] [ip4][..tcp] [...192.168.2.92][55190] -> [.178.32.196.217][.9050] detected: [.....1] [ip4][..tcp] [...192.168.2.92][55190] -> [.178.32.196.217][.9050] [Mining][Unknown][Mining][Unsafe] RISK: Unsafe Protocol analyse: [.....1] [ip4][..tcp] [...192.168.2.92][55190] -> [.178.32.196.217][.9050] [Mining][Unknown][Mining][Unsafe] diff --git a/test/results/flow-info/default/zoom.pcap.out b/test/results/flow-info/default/zoom.pcap.out index f4b075f0e..9cdf50b3c 100644 --- a/test/results/flow-info/default/zoom.pcap.out +++ b/test/results/flow-info/default/zoom.pcap.out @@ -1,61 +1,61 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.117][54854] -> [..172.217.21.72][..443] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.1.117][54854] -> [..172.217.21.72][..443] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [..192.168.1.117][54854] -> [..172.217.21.72][..443] [TLS.GoogleServices][Google][Web][Acceptable][www.googletagmanager.com] RISK: Obsolete TLS (v1.1 or older) - new: [.....2] [ip4][..udp] [..192.168.1.117][.5353] -> [....224.0.0.251][.5353] + new: [.....2] [ip4][..udp] [..192.168.1.117][.5353] -> [....224.0.0.251][.5353] detected: [.....2] [ip4][..udp] [..192.168.1.117][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_spotify-connect._tcp.local] - new: [.....3] [ip4][..tcp] [..192.168.1.117][54863] -> [.167.99.215.164][.4434] + new: [.....3] [ip4][..tcp] [..192.168.1.117][54863] -> [.167.99.215.164][.4434] detected: [.....3] [ip4][..tcp] [..192.168.1.117][54863] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS detection-update: [.....3] [ip4][..tcp] [..192.168.1.117][54863] -> [.167.99.215.164][.4434] [TLS.ntop][Unknown][Network][Safe][dati.ntop.org] RISK: Known Proto on Non Std Port, TLS (probably) Not Carrying HTTPS ERROR-EVENT: Unknown packet type [1/16] - new: [.....4] [ip4][..tcp] [..192.168.1.117][54341] -> [.62.149.152.153][..993] [MIDSTREAM] + new: [.....4] [ip4][..tcp] [..192.168.1.117][54341] -> [.62.149.152.153][..993] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [..192.168.1.117][54341] -> [.62.149.152.153][..993] [IMAPS][Unknown][Email][Safe] detection-update: [.....1] [ip4][..tcp] [..192.168.1.117][54854] -> [..172.217.21.72][..443] [TLS.GoogleServices][Google][Web][Acceptable][www.googletagmanager.com] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic - new: [.....5] [ip4][..udp] [..192.168.1.117][57025] -> [239.255.255.250][.1900] + new: [.....5] [ip4][..udp] [..192.168.1.117][57025] -> [239.255.255.250][.1900] detected: [.....5] [ip4][..udp] [..192.168.1.117][57025] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....6] [ip4][..udp] [..192.168.1.117][..137] -> [..192.168.1.255][..137] + new: [.....6] [ip4][..udp] [..192.168.1.117][..137] -> [..192.168.1.255][..137] detected: [.....6] [ip4][..udp] [..192.168.1.117][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable][workgroup] - new: [.....7] [ip4][..udp] [..192.168.1.117][64352] -> [....192.168.1.1][...53] + new: [.....7] [ip4][..udp] [..192.168.1.117][64352] -> [....192.168.1.1][...53] detected: [.....7] [ip4][..udp] [..192.168.1.117][64352] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][log.zoom.us] detection-update: [.....7] [ip4][..udp] [..192.168.1.117][64352] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][log.zoom.us] - new: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] - new: [.....9] [ip4][..udp] [..192.168.1.117][65394] -> [....192.168.1.1][...53] + new: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] + new: [.....9] [ip4][..udp] [..192.168.1.117][65394] -> [....192.168.1.1][...53] detected: [.....9] [ip4][..udp] [..192.168.1.117][65394] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][local] detection-update: [.....9] [ip4][..udp] [..192.168.1.117][65394] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable][local] RISK: Error Code - new: [....10] [ip4][.icmp] [..192.168.1.117] -> [....192.168.1.1] + new: [....10] [ip4][.icmp] [..192.168.1.117] -> [....192.168.1.1] detected: [....10] [ip4][.icmp] [..192.168.1.117] -> [....192.168.1.1] [ICMP][Unknown][Network][Acceptable] - new: [....11] [ip4][..tcp] [..192.168.1.117][54798] -> [..13.225.84.182][..443] [MIDSTREAM] + new: [....11] [ip4][..tcp] [..192.168.1.117][54798] -> [..13.225.84.182][..443] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] [TLS.Zoom][Zoom][Video][Acceptable][log.zoom.us] - new: [....12] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.37.14][.3478] + new: [....12] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.37.14][.3478] detected: [....12] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.37.14][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] detection-update: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] [TLS.Zoom][Zoom][Video][Acceptable][log.zoom.us] detection-update: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] [TLS.Zoom][Zoom][Video][Acceptable][log.zoom.us] - new: [....13] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3478] + new: [....13] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3478] detected: [....13] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] - new: [....14] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3479] + new: [....14] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3479] detected: [....14] [ip4][..udp] [..192.168.1.117][23903] -> [..162.255.38.14][.3479] [STUN.Zoom][Zoom][Video][Acceptable][] RISK: Known Proto on Non Std Port - new: [....15] [ip4][..tcp] [..192.168.1.117][53867] -> [..104.199.65.42][...80] [MIDSTREAM] - new: [....16] [ip4][..tcp] [..192.168.1.117][53872] -> [..35.186.224.53][..443] [MIDSTREAM] + new: [....15] [ip4][..tcp] [..192.168.1.117][53867] -> [..104.199.65.42][...80] [MIDSTREAM] + new: [....16] [ip4][..tcp] [..192.168.1.117][53872] -> [..35.186.224.53][..443] [MIDSTREAM] detected: [....16] [ip4][..tcp] [..192.168.1.117][53872] -> [..35.186.224.53][..443] [TLS][GoogleCloud][Web][Safe] RISK: Unidirectional Traffic detection-update: [....16] [ip4][..tcp] [..192.168.1.117][53872] -> [..35.186.224.53][..443] [TLS][GoogleCloud][Web][Safe] - new: [....17] [ip4][.icmp] [..192.168.1.117] -> [..162.255.38.14] + new: [....17] [ip4][.icmp] [..192.168.1.117] -> [..162.255.38.14] detected: [....17] [ip4][.icmp] [..192.168.1.117] -> [..162.255.38.14] [ICMP][Zoom][Network][Acceptable] ERROR-EVENT: Unknown packet type [2/16] - new: [....18] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] + new: [....18] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] detected: [....18] [ip4][..udp] [....192.168.0.1][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][tl-sg116e] - new: [....19] [ip4][..tcp] [..192.168.1.117][54865] -> [..52.202.62.196][..443] - new: [....20] [ip4][..udp] [..192.168.1.117][62988] -> [....192.168.1.1][...53] + new: [....19] [ip4][..tcp] [..192.168.1.117][54865] -> [..52.202.62.196][..443] + new: [....20] [ip4][..udp] [..192.168.1.117][62988] -> [....192.168.1.1][...53] detected: [....20] [ip4][..udp] [..192.168.1.117][62988] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][www3.zoom.us] detection-update: [....20] [ip4][..udp] [..192.168.1.117][62988] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][www3.zoom.us] - new: [....21] [ip4][..tcp] [..192.168.1.117][54866] -> [..52.202.62.236][..443] + new: [....21] [ip4][..tcp] [..192.168.1.117][54866] -> [..52.202.62.236][..443] detected: [....19] [ip4][..tcp] [..192.168.1.117][54865] -> [..52.202.62.196][..443] [TLS][Zoom][Web][Safe][zoom.us] detected: [....21] [ip4][..tcp] [..192.168.1.117][54866] -> [..52.202.62.236][..443] [TLS.Zoom][Zoom][Video][Acceptable][www3.zoom.us] detection-update: [....19] [ip4][..tcp] [..192.168.1.117][54865] -> [..52.202.62.196][..443] [TLS][Zoom][Web][Safe][zoom.us] @@ -73,20 +73,20 @@ [PKTLENS.....: 64,52,40,557,46,1492,1492,1492,40,1292,40,40,231,91,40,731,850,46,1492,1492,1492,40,40,1492,1492,40,1492,1492,40,1492,445,40] [ENTROPIES...: 4.4,4.9,4.5,4.1,4.5,7.1,7.3,7.3,4.7,7.6,4.6,4.7,6.9,5.7,4.7,7.7,7.7,4.5,7.9,7.9,7.9,4.7,4.6,7.9,7.9,4.7,7.9,7.9,4.6,7.9,7.5,4.6] detection-update: [....21] [ip4][..tcp] [..192.168.1.117][54866] -> [..52.202.62.236][..443] [TLS.Zoom][Zoom][Video][Acceptable][www3.zoom.us] - new: [....22] [ip4][..udp] [..192.168.1.117][57621] -> [..192.168.1.255][57621] + new: [....22] [ip4][..udp] [..192.168.1.117][57621] -> [..192.168.1.255][57621] detected: [....22] [ip4][..udp] [..192.168.1.117][57621] -> [..192.168.1.255][57621] [Spotify][Unknown][Music][Fun] - new: [....23] [ip4][..udp] [..192.168.1.117][62563] -> [....192.168.1.1][...53] + new: [....23] [ip4][..udp] [..192.168.1.117][62563] -> [....192.168.1.1][...53] detected: [....23] [ip4][..udp] [..192.168.1.117][62563] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfr85zc.zoom.us] - new: [....24] [ip4][..udp] [..192.168.1.117][58063] -> [....192.168.1.1][...53] + new: [....24] [ip4][..udp] [..192.168.1.117][58063] -> [....192.168.1.1][...53] detected: [....24] [ip4][..udp] [..192.168.1.117][58063] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfr84zc.zoom.us] - new: [....25] [ip4][..tcp] [..192.168.1.117][54867] -> [.213.19.144.105][..443] - new: [....26] [ip4][..tcp] [..192.168.1.117][54868] -> [.213.19.144.104][..443] + new: [....25] [ip4][..tcp] [..192.168.1.117][54867] -> [.213.19.144.105][..443] + new: [....26] [ip4][..tcp] [..192.168.1.117][54868] -> [.213.19.144.104][..443] detection-update: [....23] [ip4][..udp] [..192.168.1.117][62563] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfr85zc.zoom.us] - new: [....27] [ip4][..tcp] [..192.168.1.117][54869] -> [.213.244.140.85][..443] + new: [....27] [ip4][..tcp] [..192.168.1.117][54869] -> [.213.244.140.85][..443] detected: [....25] [ip4][..tcp] [..192.168.1.117][54867] -> [.213.19.144.105][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomam105zc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....24] [ip4][..udp] [..192.168.1.117][58063] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfr84zc.zoom.us] - new: [....28] [ip4][..tcp] [..192.168.1.117][54870] -> [.213.244.140.84][..443] + new: [....28] [ip4][..tcp] [..192.168.1.117][54870] -> [.213.244.140.84][..443] detected: [....26] [ip4][..tcp] [..192.168.1.117][54868] -> [.213.19.144.104][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomam104zc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS detected: [....27] [ip4][..tcp] [..192.168.1.117][54869] -> [.213.244.140.85][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomfr85zc.zoom.us] @@ -109,10 +109,10 @@ RISK: TLS (probably) Not Carrying HTTPS detection-update: [....28] [ip4][..tcp] [..192.168.1.117][54870] -> [.213.244.140.84][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomfr84zc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS - new: [....29] [ip4][..udp] [..192.168.1.117][51185] -> [....192.168.1.1][...53] + new: [....29] [ip4][..udp] [..192.168.1.117][51185] -> [....192.168.1.1][...53] detected: [....29] [ip4][..udp] [..192.168.1.117][51185] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfrn99mmr.zoom.us] detection-update: [....29] [ip4][..udp] [..192.168.1.117][51185] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable][zoomfrn99mmr.zoom.us] - new: [....30] [ip4][..tcp] [..192.168.1.117][54871] -> [..109.94.160.99][..443] + new: [....30] [ip4][..tcp] [..192.168.1.117][54871] -> [..109.94.160.99][..443] detected: [....30] [ip4][..tcp] [..192.168.1.117][54871] -> [..109.94.160.99][..443] [TLS.Zoom][Unknown][Video][Acceptable][zoomfrn99mmr.zoom.us] RISK: TLS (probably) Not Carrying HTTPS detection-update: [....30] [ip4][..tcp] [..192.168.1.117][54871] -> [..109.94.160.99][..443] [TLS.Zoom][Unknown][Video][Acceptable][zoomfrn99mmr.zoom.us] @@ -131,10 +131,10 @@ [IATS(ms)....: 31.6,31.8,0.2,32.7,2.0,0.1,0.0,34.5,0.0,10.5,0.0,10.6,60.1,93.9,33.8,0.4,31.3,30.9,4.6,0.0,36.6,6.2,38.2,156.1,156.1,0.1,0.0,0.1,10.6,59.1,3.1] [PKTLENS.....: 64,60,52,569,52,1492,1492,1268,52,52,1492,79,52,178,294,52,192,118,52,1492,533,52,90,52,1317,52,1492,146,52,90,202,223] [ENTROPIES...: 4.4,5.3,5.0,4.3,5.2,7.1,7.3,7.3,5.0,5.1,7.6,5.6,5.1,6.6,7.1,5.1,6.9,6.3,5.1,7.9,7.6,5.1,5.9,5.1,7.9,5.1,7.9,6.6,5.1,5.8,6.9,7.0] - new: [....31] [ip4][..udp] [..192.168.1.117][58327] -> [..109.94.160.99][.8801] + new: [....31] [ip4][..udp] [..192.168.1.117][58327] -> [..109.94.160.99][.8801] detected: [....31] [ip4][..udp] [..192.168.1.117][58327] -> [..109.94.160.99][.8801] [Zoom][Unknown][Video][Acceptable] ERROR-EVENT: Unknown packet type [3/16] - new: [....32] [ip4][..udp] [..192.168.1.117][60620] -> [..109.94.160.99][.8801] + new: [....32] [ip4][..udp] [..192.168.1.117][60620] -> [..109.94.160.99][.8801] detected: [....32] [ip4][..udp] [..192.168.1.117][60620] -> [..109.94.160.99][.8801] [Zoom][Unknown][Video][Acceptable] analyse: [....31] [ip4][..udp] [..192.168.1.117][58327] -> [..109.94.160.99][.8801] [Zoom][Unknown][Video][Acceptable] min| max| avg| stddev| variance| entropy @@ -146,7 +146,7 @@ [IATS(ms)....: 32.0,0.0,32.2,4.7,35.6,13.8,10.3,10.2,10.0,0.1,10.1,10.3,10.0,10.0,0.1,9.9,10.2,10.3,10.3,0.1,10.1,10.0,10.1,10.5,0.0,10.0,10.3,9.7,10.3,0.4,9.8] [PKTLENS.....: 135,63,46,41,91,71,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057,1057] [ENTROPIES...: 5.9,4.8,4.4,4.6,5.1,4.8,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5,0.5] - new: [....33] [ip4][..udp] [..192.168.1.117][61731] -> [..109.94.160.99][.8801] + new: [....33] [ip4][..udp] [..192.168.1.117][61731] -> [..109.94.160.99][.8801] detected: [....33] [ip4][..udp] [..192.168.1.117][61731] -> [..109.94.160.99][.8801] [Zoom][Unknown][Video][Acceptable] idle: [....17] [ip4][.icmp] [..192.168.1.117] -> [..162.255.38.14] [ICMP][Zoom][Network][Acceptable] idle: [.....9] [ip4][..udp] [..192.168.1.117][65394] -> [....192.168.1.1][...53] [DNS][Unknown][Network][Acceptable] @@ -155,14 +155,14 @@ idle: [....10] [ip4][.icmp] [..192.168.1.117] -> [....192.168.1.1] [ICMP][Unknown][Network][Acceptable] guessed: [....11] [ip4][..tcp] [..192.168.1.117][54798] -> [..13.225.84.182][..443] [TLS][AmazonAWS][Web][Safe] RISK: TCP Connection Issues - end: [....11] [ip4][..tcp] [..192.168.1.117][54798] -> [..13.225.84.182][..443] + end: [....11] [ip4][..tcp] [..192.168.1.117][54798] -> [..13.225.84.182][..443] idle: [....29] [ip4][..udp] [..192.168.1.117][51185] -> [....192.168.1.1][...53] [DNS.Zoom][Unknown][Network][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.1.117][54854] -> [..172.217.21.72][..443] [TLS.GoogleServices][Google][Web][Acceptable] RISK: Obsolete TLS (v1.1 or older), Unidirectional Traffic idle: [.....6] [ip4][..udp] [..192.168.1.117][..137] -> [..192.168.1.255][..137] [NetBIOS][Unknown][System][Acceptable] idle: [....33] [ip4][..udp] [..192.168.1.117][61731] -> [..109.94.160.99][.8801] [Zoom][Unknown][Video][Acceptable] guessed: [....15] [ip4][..tcp] [..192.168.1.117][53867] -> [..104.199.65.42][...80] [HTTP][Google][Web][Acceptable][] - idle: [....15] [ip4][..tcp] [..192.168.1.117][53867] -> [..104.199.65.42][...80] + idle: [....15] [ip4][..tcp] [..192.168.1.117][53867] -> [..104.199.65.42][...80] idle: [.....8] [ip4][..tcp] [..192.168.1.117][54864] -> [..52.202.62.238][..443] [TLS.Zoom][Zoom][Video][Acceptable] idle: [....19] [ip4][..tcp] [..192.168.1.117][54865] -> [..52.202.62.196][..443] [TLS.Zoom][Zoom][Video][Acceptable] idle: [....21] [ip4][..tcp] [..192.168.1.117][54866] -> [..52.202.62.236][..443] [TLS.Zoom][Zoom][Video][Acceptable] diff --git a/test/results/flow-info/default/zoom2.pcap.out b/test/results/flow-info/default/zoom2.pcap.out index 9a9785bcd..4739595b2 100644 --- a/test/results/flow-info/default/zoom2.pcap.out +++ b/test/results/flow-info/default/zoom2.pcap.out @@ -1,14 +1,14 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomsjccv154mmr.sjc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomsjccv154mmr.sjc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS detection-update: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Zoom][Video][Acceptable][zoomsjccv154mmr.sjc.zoom.us] RISK: TLS (probably) Not Carrying HTTPS - new: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] + new: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] detected: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] analyse: [.....2] [ip4][..udp] [..192.168.1.178][60653] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] min| max| avg| stddev| variance| entropy @@ -20,8 +20,8 @@ [IATS(ms)....: 101.4,166.6,0.0,73.0,12.3,100.4,0.0,101.8,73.0,11.9,4.9,10.9,10.5,10.1,0.2,9.2,10.4,10.3,11.4,0.0,0.3,9.4,8.6,5.4,4.9,0.1,10.8,10.0,10.5,9.4,0.2] [PKTLENS.....: 151,151,72,46,156,156,72,46,156,88,88,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,1064,88,1064,1064,1064,1064,1064,1064,1064] [ENTROPIES...: 5.8,5.8,4.9,4.2,5.4,5.6,4.8,4.3,5.6,4.7,4.7,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,0.6,4.8,0.6,0.6,0.6,0.6,0.6,0.6,0.6] - new: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] - new: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] + new: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] + new: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] detected: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] detected: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] analyse: [.....3] [ip4][..udp] [..192.168.1.178][58117] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] @@ -44,7 +44,7 @@ [IATS(ms)....: 102.1,187.6,0.0,105.6,0.1,93.5,0.0,87.6,70.7,0.1,106.0,0.0,21.5,32.8,59.0,0.0,48.4,5.5,49.5,50.2,0.0,0.0,55.2,45.7,56.3,52.4,0.0,59.8,52.1,47.7,58.6] [PKTLENS.....: 153,153,72,46,163,163,72,46,163,163,163,103,103,55,55,171,55,55,103,55,103,103,55,55,55,55,103,55,55,55,55,55] [ENTROPIES...: 5.8,5.9,4.8,4.3,5.5,5.5,4.8,4.4,5.6,5.5,5.6,4.4,4.5,3.6,3.9,5.5,3.6,3.9,4.5,3.7,4.5,4.5,3.9,3.7,4.0,3.7,4.5,3.9,3.7,3.9,3.9,3.7] - new: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154] + new: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154] detected: [.....5] [ip4][.icmp] [..192.168.1.178] -> [.144.195.73.154] [ICMP][Zoom][Network][Acceptable] idle: [.....4] [ip4][..udp] [..192.168.1.178][57953] -> [.144.195.73.154][.8801] [SRTP.Zoom][Zoom][Video][Acceptable] idle: [.....1] [ip4][..tcp] [..192.168.1.178][50076] -> [.144.195.73.154][..443] [TLS.Zoom][Zoom][Video][Acceptable] diff --git a/test/results/flow-info/default/zoom_p2p.pcapng.out b/test/results/flow-info/default/zoom_p2p.pcapng.out index 21313a907..59ecfde05 100644 --- a/test/results/flow-info/default/zoom_p2p.pcapng.out +++ b/test/results/flow-info/default/zoom_p2p.pcapng.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] + new: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] detected: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] + new: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] detected: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_ipps._tcp.local] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] update: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] + new: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] detected: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] - new: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] + new: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] detected: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] - new: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] + new: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] detected: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] + new: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] update: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] update: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] - new: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] - analyse: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] + new: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] + analyse: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.089| 0.026| 0.021| 430.173| 4.500] [PKTLEN......: 113.000| 1277.000| 673.700| 485.600| 235788.400| 4.500] @@ -34,17 +34,17 @@ update: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] update: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - update: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] + update: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] update: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] - update: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] + update: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] update: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] update: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] update: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [.....5] [ip4][.icmp] [.206.247.87.213] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] - update: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] - update: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] + update: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] + update: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] update: [.....2] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] update: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] @@ -52,18 +52,18 @@ update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] guessed: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] [Zoom][Unknown][Video][Acceptable] RISK: Unidirectional Traffic - idle: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] + idle: [.....6] [ip4][..udp] [.192.168.12.156][38453] -> [..192.168.1.226][41036] guessed: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] [Zoom][Unknown][Video][Acceptable] - idle: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] + idle: [.....7] [ip4][..udp] [.192.168.12.156][39065] -> [..192.168.1.226][46757] idle: [.....4] [ip4][..udp] [.192.168.12.156][38453] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] idle: [.....3] [ip4][..udp] [.192.168.12.156][39065] -> [.206.247.87.213][.3478] [STUN.Zoom][Zoom][Video][Acceptable] - new: [.....8] [ip4][..udp] [.192.168.12.156][49579] -> [.206.247.10.253][.3478] + new: [.....8] [ip4][..udp] [.192.168.12.156][49579] -> [.206.247.10.253][.3478] detected: [.....8] [ip4][..udp] [.192.168.12.156][49579] -> [.206.247.10.253][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] - new: [.....9] [ip4][..udp] [.192.168.12.156][42208] -> [.206.247.10.253][.3478] + new: [.....9] [ip4][..udp] [.192.168.12.156][42208] -> [.206.247.10.253][.3478] detected: [.....9] [ip4][..udp] [.192.168.12.156][42208] -> [.206.247.10.253][.3478] [STUN.Zoom][Zoom][Video][Acceptable][] - new: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] + new: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] detected: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] - new: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] + new: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] detected: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_ipps._tcp.local] update: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] analyse: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] @@ -76,10 +76,10 @@ [IATS(ms)....: 0.0,2023.3,0.0,2021.5,0.0,2008.4,0.0,2013.5,0.0,1994.8,0.0,2022.5,0.0,1990.7,0.1,2022.2,0.0,2022.0,0.1,1995.4,0.0,2020.2,0.0,2002.2,3.1,1996.9,3.1,2014.1,0.0,2030.9,0.0] [PKTLENS.....: 100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100,100] [ENTROPIES...: 5.4,5.3,5.2,5.3,5.4,5.3,5.4,5.3,5.4,5.3,5.3,5.4,5.3,5.3,5.3,5.4,5.3,5.4,5.3,5.3,5.3,5.3,5.3,5.3,5.4,5.3,5.3,5.4,5.4,5.3,5.4,5.3] - new: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] - new: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] + new: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] + new: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] update: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] - analyse: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] + analyse: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.052| 0.013| 0.016| 253.890| 4.000] [PKTLEN......: 112.000| 112.000| 112.000| 0.000| 0.000| 5.000] @@ -89,7 +89,7 @@ [IATS(ms)....: 0.2,27.3,11.2,7.7,6.8,1.5,0.1,13.3,6.9,1.7,40.5,0.2,15.5,0.6,33.3,0.2,50.8,0.4,5.9,5.7,52.3,0.4,7.2,2.3,22.7,0.2,31.0,0.2,40.9,0.2,22.6] [PKTLENS.....: 112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112,112] [ENTROPIES...: 5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0,5.0] - analyse: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] + analyse: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.055| 0.027| 0.014| 209.331| 4.700] [PKTLEN......: 112.000| 112.000| 112.000| 0.000| 0.000| 5.000] @@ -102,12 +102,12 @@ idle: [....10] [ip4][.icmp] [.206.247.10.253] -> [.192.168.12.156] [ICMP][Zoom][Network][Acceptable] guessed: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] [Zoom][Unknown][Video][Acceptable] RISK: Unidirectional Traffic - idle: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] + idle: [....13] [ip4][..udp] [.192.168.12.156][49579] -> [...10.78.14.178][49586] idle: [.....1] [ip4][..udp] [...192.168.12.1][17500] -> [.192.168.12.255][17500] [Dropbox][Unknown][Cloud][Acceptable] idle: [.....9] [ip4][..udp] [.192.168.12.156][42208] -> [.206.247.10.253][.3478] [STUN.Zoom][Zoom][Video][Acceptable] idle: [....11] [ip4][..udp] [...192.168.12.1][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] guessed: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] [Zoom][Unknown][Video][Acceptable] RISK: Unidirectional Traffic - idle: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] + idle: [....12] [ip4][..udp] [.192.168.12.156][42208] -> [...10.78.14.178][47312] idle: [.....8] [ip4][..udp] [.192.168.12.156][49579] -> [.206.247.10.253][.3478] [STUN.Zoom][Zoom][Video][Acceptable] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/disable_aggressiveness/ookla.pcap.out b/test/results/flow-info/disable_aggressiveness/ookla.pcap.out index deae2b3f6..d441591d7 100644 --- a/test/results/flow-info/disable_aggressiveness/ookla.pcap.out +++ b/test/results/flow-info/disable_aggressiveness/ookla.pcap.out @@ -1,27 +1,27 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] + new: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] detected: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] - new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + new: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] DAEMON-EVENT: [Processed: 20 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] + new: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] detected: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] detection-update: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe][massarosa-1.speedtest.welcomeitalia.it] RISK: HTTP Obsolete Server - new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] + new: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] detected: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] guessed: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] [Ookla][Unknown][Network][Safe] - idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] + idle: [.....2] [ip4][..tcp] [..192.168.1.192][51156] -> [..89.96.108.170][.8080] idle: [.....1] [ip4][..tcp] [..192.168.1.192][37790] -> [185.157.229.246][.8080] [Ookla][Unknown][Network][Safe] DAEMON-EVENT: [Processed: 70 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 4|skipped: 0|!detected: 0|guessed: 1|detection-updates: 1|updates: 0] - new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] detection-update: [.....5] [ip4][..tcp] [..192.168.1.128][48854] -> [..104.16.209.12][..443] [TLS.Ookla][Cloudflare][Network][Safe][www.speedtest.net] idle: [.....4] [ip4][..tcp] [....192.168.1.7][51215] -> [..46.44.253.187][.8080] [Ookla][Unknown][Network][Safe] end: [.....3] [ip4][..tcp] [....192.168.1.7][51207] -> [..46.44.253.187][...80] [HTTP.Ookla][Unknown][Network][Safe] RISK: HTTP Obsolete Server - new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] + new: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] detected: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] RISK: Known Proto on Non Std Port detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][35830] -> [..89.96.108.170][.8080] [TLS][Unknown][Web][Safe][spd-pub-mi-01-01.fastwebnet.it] diff --git a/test/results/flow-info/disable_protocols/dns_long_domainname.pcap.out b/test/results/flow-info/disable_protocols/dns_long_domainname.pcap.out index 910e48d00..20960db56 100644 --- a/test/results/flow-info/disable_protocols/dns_long_domainname.pcap.out +++ b/test/results/flow-info/disable_protocols/dns_long_domainname.pcap.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] + new: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] detected: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][gmr02c.16.0.fhkfhsdkfhsk.tunnel.example.com] detection-update: [.....1] [ip4][..udp] [..192.168.1.168][65311] -> [........8.8.8.8][...53] [DNS][Google][Network][Acceptable][gmr02c.16.0.fhkfhsdkfhsk.tunnel.example.com] RISK: Error Code diff --git a/test/results/flow-info/disable_protocols/pluralsight.pcap.out b/test/results/flow-info/disable_protocols/pluralsight.pcap.out index 345e38927..740dd4d01 100644 --- a/test/results/flow-info/disable_protocols/pluralsight.pcap.out +++ b/test/results/flow-info/disable_protocols/pluralsight.pcap.out @@ -1,26 +1,26 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] detection-update: [.....1] [ip4][..tcp] [..192.168.1.128][42642] -> [...54.69.188.18][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][pluralsight.com] - new: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] - new: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] + new: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] + new: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] detected: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detected: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] detection-update: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detection-update: [.....2] [ip4][..tcp] [..192.168.1.128][42782] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight2.imgix.net] detection-update: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] detection-update: [.....3] [ip4][..tcp] [..192.168.1.128][42790] -> [..146.75.62.208][..443] [TLS.Pluralsight][Unknown][Streaming][Fun][pluralsight.imgix.net] - new: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] + new: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] detected: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] detection-update: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] detection-update: [.....4] [ip4][..tcp] [..192.168.1.128][42618] -> [..18.203.201.56][..443] [TLS.Pluralsight][AmazonAWS][Streaming][Fun][stt.pluralsight.com] - new: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] + new: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] detected: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][www.pluralsight.com] detection-update: [.....5] [ip4][..tcp] [..192.168.1.128][48948] -> [.104.19.162.127][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][www.pluralsight.com] - new: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] + new: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] detected: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][zn6qzq6caaucudesr-pluralsight.siteintercept.qualtrics.com] detection-update: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun][zn6qzq6caaucudesr-pluralsight.siteintercept.qualtrics.com] idle: [.....6] [ip4][..tcp] [..192.168.1.128][44770] -> [.104.17.209.240][..443] [TLS.Pluralsight][Cloudflare][Streaming][Fun] diff --git a/test/results/flow-info/disable_protocols/quic-mvfst-27.pcapng.out b/test/results/flow-info/disable_protocols/quic-mvfst-27.pcapng.out index 47aa89e61..ffd1d5b83 100644 --- a/test/results/flow-info/disable_protocols/quic-mvfst-27.pcapng.out +++ b/test/results/flow-info/disable_protocols/quic-mvfst-27.pcapng.out @@ -1,5 +1,5 @@ DAEMON-EVENT: init - new: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] + new: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] detected: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun][graph.facebook.com] idle: [.....1] [ip4][..udp] [......10.0.2.15][35957] -> [..69.171.250.15][..443] [QUIC.Facebook][Facebook][SocialNetwork][Fun] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/disable_protocols/soap.pcap.out b/test/results/flow-info/disable_protocols/soap.pcap.out index ec6be6953..fa0eedb0c 100644 --- a/test/results/flow-info/disable_protocols/soap.pcap.out +++ b/test/results/flow-info/disable_protocols/soap.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] - new: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [MIDSTREAM] + new: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] + new: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [HTTP.SOAP][Unknown][Cloud][Acceptable][go.microsoft.com] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 15 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 2|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] + new: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] detected: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] [SOAP][Unknown][RPC][Acceptable] idle: [.....3] [ip4][..tcp] [..185.32.192.30][...80] -> [.85.154.114.113][56028] [SOAP][Unknown][RPC][Acceptable] idle: [.....2] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][.4176] [HTTP.SOAP][Unknown][Cloud][Acceptable] RISK: Known Proto on Non Std Port guessed: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] [HTTP][Unknown][Web][Acceptable][] - end: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] + end: [.....1] [ip4][..tcp] [..192.168.2.100][50100] -> [...23.2.213.165][...80] DAEMON-EVENT: shutdown diff --git a/test/results/flow-info/disable_stun_monitoring/lru_ipv6_caches.pcapng.out b/test/results/flow-info/disable_stun_monitoring/lru_ipv6_caches.pcapng.out index abc6bae1e..a0e16d76a 100644 --- a/test/results/flow-info/disable_stun_monitoring/lru_ipv6_caches.pcapng.out +++ b/test/results/flow-info/disable_stun_monitoring/lru_ipv6_caches.pcapng.out @@ -1,47 +1,47 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] + new: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] detected: [.....1] [ip6][..udp] [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] -> [20ed:470f:6f73:ce60:60be:8b4f:df37:b080][45658] [STUN][Unknown][Network][Acceptable][] - new: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] - new: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] - new: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] + new: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] + new: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] + new: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] detected: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port - new: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] + new: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] detected: [.....5] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2c7f:d7a0:44a9:49e9:e586:fb7f:5b85:9c83][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port detected: [.....3] [ip6][..udp] [.2a2f:8509:1cb2:466d:ecbf:69d6:109c:608][62229] -> [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] + new: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] detected: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port detected: [.....2] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27][60506] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic detection-update: [.....4] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [2fda:1f8a:c107:88a4:e509:d2e1:445f:f34c][.6881] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [.....7] [ip6][..udp] [2118:ec33:112b:7908:2c80:27ff:fef7:d71f][48415] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] - new: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] + new: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] detected: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS][Unknown][Web][Safe][] RISK: Unidirectional Traffic detection-update: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - new: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] + new: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] detected: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [.....9] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44150] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [.....6] [ip6][..udp] [.3991:72d:336e:65ec:c5bf:a5fa:83ad:23de][.6881] -> [.38b2:46b7:27a4:94c3:c134:948:e069:d71f][....1] [BitTorrent][Unknown][Download][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic - new: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] + new: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] detected: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic detection-update: [....10] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44192] [TLS.Cloudflare][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - new: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [....11] [ip6][..udp] [.3297:a1af:5121:cfc:360b:2e07:872f:1ea0][43865] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] - new: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] + new: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] detected: [....12] [ip6][..udp] [.3069:c624:1d42:9469:98b1:67ff:fe43:325][56131] -> [....32fb:f967:681e:e96b:face:b00c::74fd][.3478] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] idle: [.....8] [ip6][..tcp] [........................2001:db8:200::1][..443] -> [..........................2001:db8:1::1][44144] [TLS.Cloudflare][Unknown][Web][Acceptable] RISK: Unidirectional Traffic diff --git a/test/results/flow-info/enable_doh_heuristic/doh.pcapng.out b/test/results/flow-info/enable_doh_heuristic/doh.pcapng.out index 09ea6804f..696f20101 100644 --- a/test/results/flow-info/enable_doh_heuristic/doh.pcapng.out +++ b/test/results/flow-info/enable_doh_heuristic/doh.pcapng.out @@ -1,7 +1,7 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] + new: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] detected: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] RISK: Missing SNI TLS Extn, ALPN/SNI Mismatch detection-update: [.....1] [ip4][..tcp] [..192.168.1.253][35996] -> [........1.1.1.1][..443] [TLS][Unknown][Web][Safe][] diff --git a/test/results/flow-info/enable_payload_stat/1kxun.pcap.out b/test/results/flow-info/enable_payload_stat/1kxun.pcap.out index b6fce33a4..576df79d4 100644 --- a/test/results/flow-info/enable_payload_stat/1kxun.pcap.out +++ b/test/results/flow-info/enable_payload_stat/1kxun.pcap.out @@ -1,78 +1,78 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] + new: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] detected: [.....1] [ip4][..udp] [...192.168.5.44][59571] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] + new: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] detected: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] + new: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] detected: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] + new: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] detected: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] [DHCP][Unknown][Network][Acceptable][] - new: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [MIDSTREAM] - new: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] + new: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] detected: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] + new: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] detected: [.....7] [ip4][..udp] [...192.168.5.41][55312] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][shen] - new: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] + new: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] detected: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] + new: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] detected: [....10] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][61603] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] + new: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] detected: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] + new: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] detected: [....12] [ip4][..udp] [...192.168.5.47][60267] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] + new: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] detected: [....13] [ip4][..udp] [..192.168.115.8][51458] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] + new: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] detected: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] detection-update: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] RISK: Unidirectional Traffic detection-update: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][jp.kankan.1kxun.mobi] - new: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] + new: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] detected: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] - new: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] + new: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] detected: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] detection-update: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] RISK: Unidirectional Traffic - new: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [MIDSTREAM] - new: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] + new: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [MIDSTREAM] + new: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] detected: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][wpad] - new: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] + new: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] detected: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] + new: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] detected: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] + new: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] detected: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] - new: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] - new: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] + new: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + new: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + new: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] detected: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] detection-update: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] RISK: Unidirectional Traffic detection-update: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun][kankan.1kxun.com] - new: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] + new: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] detection-update: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][kankan.1kxun.com] detected: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] [HTTP.1kxun][Unknown][Streaming][Fun][kankan.1kxun.com] - new: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] + new: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] detected: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] detection-update: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] RISK: Unidirectional Traffic detection-update: [....26] [ip4][..udp] [..192.168.115.8][60724] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun][pic.1kxun.com] - new: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] - new: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] - new: [....29] [ip4][..tcp] [..192.168.115.8][49601] -> [.106.187.35.246][...80] - new: [....30] [ip4][..tcp] [..192.168.115.8][49602] -> [.106.187.35.246][...80] - new: [....31] [ip4][..tcp] [..192.168.115.8][49603] -> [.106.187.35.246][...80] - new: [....32] [ip4][..tcp] [..192.168.115.8][49604] -> [.106.187.35.246][...80] - new: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] + new: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] + new: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] + new: [....29] [ip4][..tcp] [..192.168.115.8][49601] -> [.106.187.35.246][...80] + new: [....30] [ip4][..tcp] [..192.168.115.8][49602] -> [.106.187.35.246][...80] + new: [....31] [ip4][..tcp] [..192.168.115.8][49603] -> [.106.187.35.246][...80] + new: [....32] [ip4][..tcp] [..192.168.115.8][49604] -> [.106.187.35.246][...80] + new: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] detected: [....33] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][54888] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] + new: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] detected: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected detected: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] @@ -131,11 +131,11 @@ [IATS(ms)....: 0.1,51.9,52.1,0.0,5.2,0.1,60.5,0.9,0.0,0.0,0.1,0.0,0.4,0.1,0.0,0.1,0.2,85.1,142.0,0.0,40.8,2.5,0.1,0.1,0.1,43.6,0.1,0.4,0.1,0.1,0.0] [PKTLENS.....: 52,52,52,40,40,402,402,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300] [ENTROPIES...: 4.5,4.5,5.0,4.8,4.8,5.8,5.8,4.3,5.6,6.7,7.7,7.8,7.7,7.7,7.7,7.7,7.6,4.1,6.3,4.8,4.8,7.7,7.8,7.7,7.7,7.7,4.8,4.8,7.7,7.7,5.6,3.0] - new: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] + new: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] detected: [....35] [ip4][..udp] [...192.168.5.67][..138] -> [192.168.255.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][sanji-lifebook-] RISK: Unsafe Protocol - new: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] - new: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] + new: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] + new: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] detected: [....36] [ip4][..tcp] [..192.168.115.8][49605] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] RISK: HTTP Susp User-Agent detected: [....37] [ip4][..tcp] [..192.168.115.8][49606] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun][jp.kankan.1kxun.mobi] @@ -150,37 +150,37 @@ [IATS(ms)....: 0.1,37.8,38.0,0.1,1.8,0.1,39.0,109.8,0.2,146.8,0.0,0.3,0.1,0.1,0.1,0.5,0.0,0.2,0.1,0.1,0.4,0.0,0.2,36.3,36.5,0.0,0.4,0.1,0.5,0.1,0.1] [PKTLENS.....: 52,52,52,40,40,397,397,46,1300,1300,40,40,1300,1300,1300,1300,40,40,1300,1300,1300,40,40,1300,1300,40,40,1300,1300,1300,1300,1300] [ENTROPIES...: 4.5,4.5,5.0,4.8,4.8,5.8,5.8,4.3,5.6,5.0,4.8,4.8,4.8,5.3,5.2,5.1,4.7,4.7,6.0,5.1,5.2,4.8,4.8,5.8,5.1,4.7,4.7,4.5,4.7,4.7,5.6,5.2] - new: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] + new: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] detected: [....38] [ip4][..tcp] [..192.168.115.8][49607] -> [218.244.135.170][.9099] [HTTP][Alibaba][Web][Acceptable][218.244.135.170] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] + new: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] detected: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] detection-update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] RISK: Unidirectional Traffic detection-update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun][vv.video.qq.com] - new: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] + new: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] detected: [....40] [ip4][..tcp] [..192.168.115.8][49608] -> [203.205.151.234][...80] [HTTP.QQ][Unknown][Chat][Fun][vv.video.qq.com] - new: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] - new: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + new: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] + new: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] detected: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] [HTTP][Alibaba][Web][Acceptable][42.120.51.152] RISK: Known Proto on Non Std Port, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] + new: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] detected: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] + new: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] detected: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] + new: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] detected: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] - new: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] + new: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] + new: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] detected: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] + new: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] detected: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] detected: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] [HTTP][Unknown][Web][Acceptable][183.131.48.145] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] + new: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] analyse: [....41] [ip4][..tcp] [..192.168.115.8][49609] -> [..42.120.51.152][.8080] [HTTP][Alibaba][Web][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: 0.000| 0.399| 0.070| 0.104| 10878.943| 3.600] @@ -195,114 +195,114 @@ RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI detection-update: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] [HTTP][Unknown][Media][Acceptable][183.131.48.144] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI - new: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] + new: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] detected: [....50] [ip4][..udp] [.192.168.101.33][55485] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] + new: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] detected: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] + new: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] detected: [....52] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][61548] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] + new: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] detected: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] + new: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] detected: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] + new: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] detected: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] [DHCP][Unknown][Network][Acceptable][macbook-air] - new: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] - new: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [MIDSTREAM] - new: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [MIDSTREAM] - new: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] + new: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + new: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [MIDSTREAM] + new: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [MIDSTREAM] + new: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] detected: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] - new: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] + new: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] detection-update: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][api.magicansoft.com] RISK: Error Code - new: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [MIDSTREAM] - new: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] + new: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [MIDSTREAM] + new: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] detected: [....62] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][63659] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] + new: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] detected: [....63] [ip4][..udp] [..192.168.3.236][51714] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] + new: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] detected: [....64] [ip4][..udp] [..192.168.3.236][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][isatap] - new: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] - new: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] - new: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] + new: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] + new: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] + new: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] detected: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][sanji-lifebook-] - new: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] + new: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] detected: [....68] [ip4][..udp] [...192.168.5.45][59461] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][gfile] - new: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] + new: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] detected: [....69] [ip4][..udp] [...192.168.5.45][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][nasfile] - new: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] + new: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] detected: [....70] [ip4][..udp] [...192.168.5.45][..138] -> [192.168.255.255][..138] [NetBIOS.SMBv1][Unknown][System][Dangerous][macbookair-e1d0] RISK: Unsafe Protocol - new: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] - new: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] + new: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] + new: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] detected: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] + new: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] detected: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] + new: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] detected: [....74] [ip4][..udp] [....192.168.5.9][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][joanna-pc] - new: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] + new: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] detected: [....75] [ip4][..udp] [...192.168.5.48][49701] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] + new: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] detected: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_googlecast._tcp.local] - new: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] - new: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] + new: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] + new: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] detected: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] - new: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] + new: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] + new: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] detected: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] + new: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] detected: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] + new: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] detected: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] + new: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] detected: [....83] [ip4][..udp] [...192.168.5.49][.1900] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] + new: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] detected: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable][[ff02::c]:1900] - new: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] + new: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] detected: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] - new: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] + new: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] + new: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] detected: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] - new: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] - new: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] + new: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] + new: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] + new: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] detected: [....90] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][49735] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] + new: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] detected: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] + new: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] detected: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] + new: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] detected: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] - new: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] + new: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] + new: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] detected: [....95] [ip6][..udp] [..............fe80::edf5:240a:c8c0:8312][53962] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] + new: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] detected: [....96] [ip4][..udp] [...192.168.5.47][53962] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] + new: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] detected: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] + new: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] detected: [....98] [ip4][..udp] [...192.168.3.95][51451] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected - new: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] + new: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] detected: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] + new: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] detected: [...100] [ip4][..udp] [..192.168.3.236][56043] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [MIDSTREAM] - new: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] + new: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [MIDSTREAM] + new: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] detected: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] + new: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] detected: [...103] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][64568] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] + new: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] detected: [...104] [ip4][..udp] [...192.168.5.49][64568] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] + new: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] detected: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][kevin-pc] - new: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [MIDSTREAM] + new: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [MIDSTREAM] detected: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] - new: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] + new: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] detection-update: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] RISK: Unidirectional Traffic detection-update: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] @@ -310,26 +310,26 @@ RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [...107] [ip4][..tcp] [...192.168.5.16][53626] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS - new: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] + new: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] detected: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] [DNS.Line][Unknown][Network][Acceptable][dl-obs.official.line.naver.jp] detection-update: [...108] [ip4][..udp] [...192.168.5.16][63372] -> [.....168.95.1.1][...53] [DNS.Line][Unknown][Network][Acceptable][dl-obs.official.line.naver.jp] - new: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] - new: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] + new: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] + new: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] detected: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable][dl-obs.official.line.naver.jp] detected: [...109] [ip4][..tcp] [...192.168.5.16][53627] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable][dl-obs.official.line.naver.jp] - new: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] + new: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] detected: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] + new: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] detected: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [MIDSTREAM] + new: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [MIDSTREAM] detected: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [TLS][Facebook][Web][Safe] - new: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] + new: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] detected: [...114] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][61172] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] + new: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] detected: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] + new: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] detected: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] - new: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] + new: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] detected: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS detection-update: [...117] [ip4][..tcp] [...192.168.5.16][53629] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe][192.168.115.75] @@ -339,7 +339,7 @@ update: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] update: [.....3] [ip4][..udp] [...192.168.5.44][51389] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + update: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] update: [.....4] [ip4][..udp] [..192.168.119.1][...67] -> [255.255.255.255][...68] [DHCP][Unknown][Network][Acceptable] update: [.....2] [ip4][..udp] [...192.168.5.57][55809] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [....18] [ip4][..udp] [..192.168.115.8][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable] @@ -347,7 +347,7 @@ update: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] - update: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + update: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] update: [.....9] [ip6][..udp] [...............fe80::406:55a8:6453:25dd][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] update: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected @@ -367,29 +367,29 @@ [IATS(ms)....: 0.0,54.5,54.6,0.0,4.9,0.0,65.5,0.1,0.1,0.4,0.1,0.1,0.2,0.0,0.0,0.0,0.0,61.5,0.0,69.0,0.1,0.1,0.0,0.7,0.1,0.1,0.1,0.5,70.7,0.0,45001.1] [PKTLENS.....: 52,52,52,40,40,401,401,46,359,1300,1300,1300,1300,1300,1300,1300,1300,1300,40,40,1300,1300,1300,1300,1300,1300,1300,1300,1267,40,40,41] [ENTROPIES...: 4.6,4.6,5.0,4.9,4.9,5.8,5.8,4.4,5.7,7.5,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,4.8,4.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,7.8,4.9,4.9,4.8] - new: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] + new: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] detected: [...118] [ip4][..udp] [..192.168.0.104][..137] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable][sc.arrancar.org] - new: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] + new: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] detected: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] [NTP][Apple][System][Acceptable] - new: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] + new: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] detected: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] + new: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] detected: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] + new: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] detected: [...122] [ip4][..udp] [...192.168.5.57][64428] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] + new: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] detected: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] + new: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] detected: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] + new: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] detected: [...125] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][49766] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] + new: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] detected: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] + new: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] detected: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] + new: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] detected: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] - new: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] + new: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] detected: [...129] [ip4][..udp] [..192.168.3.236][65496] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] update: [....51] [ip4][..udp] [....192.168.5.9][55484] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -401,8 +401,8 @@ update: [....43] [ip4][..udp] [...192.168.5.37][56366] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] update: [....48] [ip4][..udp] [....192.168.5.9][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] - update: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] - update: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + update: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + update: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] update: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected update: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun] @@ -413,24 +413,24 @@ RISK: Non-Printable/Invalid Chars Detected DAEMON-EVENT: [Processed: 1032 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 129 / 129|skipped: 0|!detected: 0|guessed: 0|detection-updates: 19|updates: 38] - new: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...130] [ip4][..tcp] [..192.168.2.126][60962] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...131] [ip4][..tcp] [..192.168.2.126][60972] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [MIDSTREAM] + new: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [MIDSTREAM] detected: [...132] [ip4][..tcp] [..192.168.2.126][60984] -> [..172.104.93.92][.1234] [HTTP.1kxun][Unknown][Streaming][Fun][ws.1kxun.mobi] RISK: Known Proto on Non Std Port - new: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.mobi] - new: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [MIDSTREAM] + new: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [MIDSTREAM] detected: [...134] [ip4][..tcp] [..192.168.2.126][41134] -> [.129.226.107.77][...80] [HTTP.QQ][Tencent][Chat][Fun][cgi.connect.qq.com] detection-update: [...133] [ip4][..tcp] [..192.168.2.126][47230] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Download][Fun][kankan.1kxun.mobi] RISK: Binary App Transfer - new: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...135] [ip4][..tcp] [..192.168.2.126][47246] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.com] - new: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...136] [ip4][..tcp] [..192.168.2.126][47262] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][kankan.1kxun.com] idle: [....44] [ip4][..udp] [...192.168.5.37][57325] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [....78] [ip4][..udp] [...192.168.5.48][59797] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -441,7 +441,7 @@ idle: [...110] [ip4][..tcp] [...192.168.5.16][53628] -> [...203.69.81.73][...80] [HTTP.Line][Unknown][Chat][Acceptable] idle: [....14] [ip4][..udp] [..192.168.115.8][51024] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun] not-detected: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] + idle: [....77] [ip4][..udp] [..192.168.2.186][32768] -> [255.255.255.255][.1947] idle: [....21] [ip4][..udp] [...192.168.3.95][59468] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] idle: [...120] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][57148] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [.....8] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -453,9 +453,9 @@ idle: [...113] [ip4][..tcp] [.....31.13.87.1][..443] -> [...192.168.5.16][53578] [TLS][Facebook][Web][Safe] idle: [...106] [ip4][..tcp] [...192.168.5.16][53580] -> [....31.13.87.36][..443] [TLS][Facebook][Web][Safe] not-detected: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] [Unknown][Unknown][Unrated] - idle: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] + idle: [....66] [ip6][..udp] [.......2001:b020:6::c2a0:bbff:fe73:eb57][62976] -> [................................ff02::1][62976] not-detected: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] [Unknown][Unknown][Unrated] - idle: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] + idle: [....23] [ip6][..udp] [..2001:b030:214:100:c2a0:bbff:fe73:eb47][62976] -> [................................ff02::1][62976] idle: [...126] [ip4][..udp] [...192.168.5.50][49766] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....91] [ip4][..udp] [..192.168.3.236][62069] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...105] [ip4][..udp] [...192.168.5.41][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] @@ -467,7 +467,7 @@ idle: [....97] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][51451] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected not-detected: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] + idle: [....94] [ip4][..udp] [..192.168.119.2][43786] -> [255.255.255.255][.5678] idle: [....85] [ip4][..udp] [...192.168.5.50][50030] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....55] [ip4][..udp] [...192.168.5.16][...68] -> [..192.168.119.1][...67] [DHCP][Unknown][Network][Acceptable] idle: [....54] [ip4][..udp] [...192.168.5.49][51704] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] @@ -495,7 +495,7 @@ idle: [....47] [ip4][..udp] [.192.168.101.33][58456] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....81] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][62756] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] + idle: [....42] [ip4][..udp] [.192.168.10.110][60480] -> [255.255.255.255][62976] idle: [....73] [ip4][..udp] [...192.168.5.41][54470] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....76] [ip4][..udp] [...192.168.5.64][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable] idle: [...102] [ip4][..udp] [...192.168.5.37][54506] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -503,13 +503,13 @@ idle: [....67] [ip4][..udp] [...192.168.5.45][59789] -> [192.168.255.255][..137] [NetBIOS][Unknown][System][Acceptable] guessed: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] + end: [.....5] [ip4][..tcp] [...192.168.5.16][53605] -> [.68.233.253.133][...80] idle: [....82] [ip4][..udp] [...192.168.5.50][62756] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] guessed: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable][] RISK: Unidirectional Traffic - end: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] + end: [....58] [ip4][..tcp] [...192.168.5.16][53613] -> [.68.233.253.133][...80] not-detected: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] + idle: [....56] [ip4][..udp] [.59.120.208.218][50151] -> [255.255.255.255][.1947] end: [....59] [ip4][..tcp] [...192.168.5.16][53624] -> [.68.233.253.133][...80] [HTTP][Unknown][Web][Acceptable] RISK: Error Code idle: [....92] [ip4][..udp] [...192.168.5.44][58702] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -517,7 +517,7 @@ idle: [...112] [ip4][..udp] [....192.168.5.9][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...111] [ip4][..udp] [.192.168.101.33][62822] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] guessed: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] [HTTP][Google][Web][Acceptable][] - idle: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] + idle: [....61] [ip4][..tcp] [..192.168.115.8][49581] -> [.64.233.189.128][...80] idle: [....20] [ip4][..udp] [...192.168.3.95][58779] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected idle: [....15] [ip4][..tcp] [..192.168.115.8][49597] -> [.106.185.35.110][...80] [HTTP.1kxun][Unknown][Streaming][Fun] @@ -527,7 +527,7 @@ RISK: HTTP Susp User-Agent idle: [....25] [ip4][..tcp] [..192.168.115.8][49598] -> [.222.73.254.167][...80] [HTTP.1kxun][Unknown][Streaming][Fun] guessed: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] - end: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] + end: [....17] [ip4][..tcp] [...192.168.5.16][53622] -> [.192.168.115.75][..443] end: [....45] [ip4][..tcp] [...192.168.5.16][53623] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS end: [....87] [ip4][..tcp] [...192.168.5.16][53625] -> [.192.168.115.75][..443] [TLS][Unknown][Web][Safe] @@ -538,17 +538,17 @@ RISK: Weak TLS Cipher, HTTP/TLS/QUIC Numeric Hostname/SNI, TLS (probably) Not Carrying HTTPS idle: [.....6] [ip4][..udp] [...192.168.5.50][64674] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable] not-detected: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] + idle: [....65] [ip4][..udp] [192.168.140.140][62976] -> [255.255.255.255][62976] not-detected: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] + idle: [....71] [ip4][..udp] [...192.168.10.7][62976] -> [255.255.255.255][62976] not-detected: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] [Unknown][Unknown][Unrated] - idle: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] + idle: [....22] [ip4][..udp] [.192.168.125.30][62976] -> [255.255.255.255][62976] idle: [....34] [ip4][..udp] [...192.168.3.95][54888] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected idle: [...123] [ip6][..udp] [...............fe80::e034:7be:d8f9:6197][57143] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....80] [ip4][..udp] [...192.168.5.57][65150] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] + idle: [....88] [ip4][..udp] [..192.168.119.1][56861] -> [255.255.255.255][.5678] idle: [...116] [ip6][..udp] [..............fe80::f65c:89ff:fe89:e607][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] idle: [....72] [ip6][..udp] [..............fe80::4568:efbc:40b1:1346][50194] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...127] [ip4][..udp] [...192.168.5.44][59062] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -556,7 +556,7 @@ idle: [....39] [ip4][..udp] [..192.168.115.8][54420] -> [........8.8.8.8][...53] [DNS.QQ][Google][Network][Fun] idle: [...124] [ip4][..udp] [...192.168.5.50][57143] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] [Unknown][Unknown][Unrated] - idle: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] + idle: [....79] [ip4][..udp] [..192.168.0.100][50925] -> [255.255.255.255][.5678] idle: [....99] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][53938] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....27] [ip4][..tcp] [..192.168.115.8][49599] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun] idle: [....28] [ip4][..tcp] [..192.168.115.8][49600] -> [.106.187.35.246][...80] [HTTP.1kxun][Unknown][Streaming][Fun] @@ -571,20 +571,20 @@ idle: [....19] [ip6][..udp] [..............fe80::e98f:bae2:19f7:6b0f][58779] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] RISK: Non-Printable/Invalid Chars Detected guessed: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] [TLS][Line][Web][Safe] - idle: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] + idle: [...101] [ip4][..tcp] [.119.235.235.84][..443] -> [...192.168.5.16][53406] end: [....46] [ip4][..tcp] [..192.168.115.8][49612] -> [.183.131.48.145][...80] [HTTP][Unknown][Web][Acceptable] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [....49] [ip4][..tcp] [..192.168.115.8][49613] -> [.183.131.48.144][...80] [HTTP][Unknown][Media][Acceptable] RISK: HTTP Susp User-Agent, HTTP/TLS/QUIC Numeric Hostname/SNI idle: [....24] [ip4][..udp] [..192.168.115.8][52723] -> [.....168.95.1.1][...53] [DNS.1kxun][Unknown][Network][Fun] not-detected: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] [Unknown][Unknown][Unrated] - idle: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] + idle: [....89] [ip6][..udp] [................fe80::4e5e:cff:feea:365][.5678] -> [................................ff02::1][.5678] not-detected: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] [Unknown][Unknown][Unrated] - idle: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] + idle: [....60] [ip6][..udp] [...............fe80::4e5e:cff:fe9a:ec54][.5678] -> [................................ff02::1][.5678] idle: [...119] [ip4][..udp] [...192.168.5.16][..123] -> [..17.253.26.125][..123] [NTP][Apple][System][Acceptable] idle: [....16] [ip4][..udp] [..192.168.115.8][52723] -> [........8.8.8.8][...53] [DNS.1kxun][Google][Network][Fun] guessed: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] [TLS][Unknown][Web][Safe] - idle: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] + idle: [....57] [ip4][..tcp] [..192.168.115.8][49596] -> [..203.66.182.87][..443] idle: [....53] [ip4][..udp] [...192.168.5.49][61548] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....93] [ip6][..udp] [..............fe80::beee:7bff:fe0c:b3de][..546] -> [..............................ff02::1:2][..547] [DHCPV6][Unknown][Network][Acceptable] idle: [....11] [ip4][..udp] [...192.168.5.47][61603] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] @@ -599,31 +599,31 @@ idle: [...128] [ip6][..udp] [..............fe80::5d92:62a8:ebde:1319][58468] -> [..............................ff02::1:3][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [...121] [ip4][..udp] [...192.168.5.41][55593] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] not-detected: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] [Unknown][Unknown][Unrated] - idle: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] + idle: [....86] [ip4][..udp] [.59.120.208.212][32768] -> [255.255.255.255][.1947] idle: [...115] [ip4][..udp] [..192.168.3.236][59730] -> [....224.0.0.252][.5355] [LLMNR][Unknown][Network][Acceptable] idle: [....84] [ip6][..udp] [...............fe80::9bd:81dd:2fdc:5750][.1900] -> [................................ff02::c][.1900] [SSDP][Unknown][System][Acceptable] - new: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...137] [ip4][..tcp] [..192.168.2.126][47272] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][messages.1kxun.mobi] - new: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [MIDSTREAM] + new: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [MIDSTREAM] detected: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent detection-update: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent, Unidirectional Traffic detection-update: [...138] [ip4][..tcp] [..192.168.2.126][38834] -> [..119.45.78.184][...80] [HTTP.QQ][Tencent][Chat][Fun][pingma.qq.com] RISK: HTTP Susp User-Agent, Error Code - new: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...139] [ip4][..tcp] [..192.168.2.126][60148] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [MIDSTREAM] + new: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [MIDSTREAM] detected: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [HTTP.1kxun][Unknown][Streaming][Fun][android.yingshi.tcclick.1kxun.com] detection-update: [...140] [ip4][..tcp] [..192.168.2.126][49242] -> [.172.104.119.80][...80] [HTTP.1kxun][Unknown][Streaming][Fun][android.yingshi.tcclick.1kxun.com] RISK: Error Code - new: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...141] [ip4][..tcp] [..192.168.2.126][46184] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...143] [ip4][..tcp] [..192.168.2.126][46200] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...144] [ip4][..tcp] [..192.168.2.126][46212] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] analyse: [...142] [ip4][..tcp] [..192.168.2.126][46170] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -635,23 +635,23 @@ [IATS(ms)....: 356.2,0.1,308.1,0.1,2.4,3.2,0.1,200.2,0.0,0.1,0.0,0.0,0.0,0.0,0.0,1.6,0.1,0.1,0.0,0.0,0.0,0.0,0.0,0.0,895.3,372.0,0.0,1.3,0.1,1.9,0.0] [PKTLENS.....: 264,373,13012,14452,2932,2932,1492,7252,2932,1492,2932,2932,1492,1492,1492,1492,1492,4372,6324,2932,2932,1492,1492,1492,788,260,373,17332,21652,1492,4372,17332] [ENTROPIES...: 5.9,5.7,8.0,8.0,7.9,7.9,7.9,8.0,7.9,7.8,7.9,7.9,7.9,7.8,7.8,7.9,7.8,7.9,7.9,7.9,7.9,7.9,7.8,7.8,7.7,5.8,5.8,8.0,8.0,7.9,7.9,8.0] - new: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [MIDSTREAM] + new: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [MIDSTREAM] detected: [...145] [ip4][..tcp] [..192.168.2.126][35200] -> [...103.29.71.30][...80] [HTTP.1kxun][Unknown][Streaming][Fun][release.bigdata.1kxun.com] - new: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...149] [ip4][..tcp] [..192.168.2.126][45414] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...151] [ip4][..tcp] [..192.168.2.126][45422] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...152] [ip4][..tcp] [..192.168.2.126][45424] -> [..161.117.13.29][...80] [HTTP][Alibaba][Streaming][Acceptable][tcad.wedolook.com] - new: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [MIDSTREAM] + new: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [MIDSTREAM] detected: [...153] [ip4][..tcp] [..192.168.2.126][41390] -> [....18.64.79.37][...80] [HTTP.Google][AmazonAWS][Web][Acceptable][google.open-js.com] analyse: [...146] [ip4][..tcp] [..192.168.2.126][45380] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -663,23 +663,23 @@ [IATS(ms)....: 380.4,4.6,408.6,215.7,0.5,1.0,1.0,178.5,0.3,0.5,379.6,185.4,1.4,0.7,331.7,5.7,174.2,6.1,0.3,0.9,170.5,0.4,6.0,1.1,0.3,0.7,169.5,0.5,0.6,5.3,0.4] [PKTLENS.....: 817,1492,1253,488,1492,1492,7252,4372,1492,1492,2504,476,2932,8692,1492,2932,8692,2932,1492,1492,7252,1492,1492,2932,1492,1492,2932,1492,1492,2932,1492,1492] [ENTROPIES...: 5.9,7.7,7.8,5.9,7.6,7.9,8.0,8.0,7.9,7.9,7.9,5.9,7.8,8.0,7.9,7.9,8.0,7.9,7.9,7.9,8.0,7.9,7.8,7.9,7.8,7.8,7.9,7.9,7.9,7.9,7.9,7.9] - new: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [MIDSTREAM] + new: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [MIDSTREAM] detected: [...154] [ip4][..tcp] [..192.168.2.126][51888] -> [.119.28.164.143][...80] [HTTP][Tencent][Web][Acceptable][qzonestyle.gtimg.cn] - new: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [MIDSTREAM] + new: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [MIDSTREAM] detected: [...155] [ip4][..tcp] [..192.168.2.126][38354] -> [.142.250.186.34][...80] [HTTP.Google][Google][Advertisement][Acceptable][pagead2.googlesyndication.com] - new: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [MIDSTREAM] + new: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [MIDSTREAM] detected: [...156] [ip4][..tcp] [..192.168.2.126][36732] -> [142.250.186.174][...80] [HTTP.Google][Google][Advertisement][Acceptable][www.google-analytics.com] - new: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...157] [ip4][..tcp] [..192.168.2.126][49354] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...158] [ip4][..tcp] [..192.168.2.126][49372] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...159] [ip4][..tcp] [..192.168.2.126][49370] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...161] [ip4][..tcp] [..192.168.2.126][49412] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] - new: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [MIDSTREAM] + new: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [MIDSTREAM] detected: [...162] [ip4][..tcp] [..192.168.2.126][49396] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun][hkbn.content.1kxun.com] analyse: [...160] [ip4][..tcp] [..192.168.2.126][49380] -> [.14.136.136.108][...80] [HTTP.1kxun][Unknown][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -701,17 +701,17 @@ [IATS(ms)....: 205.6,2.1,0.0,0.0,0.0,224.8,0.4,0.3,1.4,0.0,193.7,0.4,0.4,1.7,1.3,1.9,226.0,899.7,238.0,0.0,2.4,199.2,0.5,1.0,1.3,0.0,0.0,407.3,371.5,0.0,1.5] [PKTLENS.....: 566,337,1492,4372,2932,4372,1492,1492,1492,1492,5812,1492,1492,1492,2932,4372,5812,3718,578,337,7252,15892,1492,1492,7252,1492,5812,640,566,337,7787,18772] [ENTROPIES...: 5.9,5.9,7.3,7.9,7.9,7.9,7.8,7.8,7.8,7.9,8.0,7.8,7.8,7.8,7.9,7.9,7.9,7.9,5.9,5.8,8.0,8.0,7.9,7.9,8.0,7.9,8.0,7.7,5.9,5.9,7.9,8.0] - new: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [MIDSTREAM] + new: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [MIDSTREAM] detected: [...163] [ip4][..tcp] [..192.168.2.126][44368] -> [..172.217.18.98][...80] [HTTP.GoogleServices][Google][Web][Acceptable][www.googletagservices.com] - new: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...164] [ip4][..tcp] [..192.168.2.126][50140] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...165] [ip4][..tcp] [..192.168.2.126][50148] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...166] [ip4][..tcp] [..192.168.2.126][50164] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...167] [ip4][..tcp] [..192.168.2.126][50166] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] - new: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [MIDSTREAM] + new: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [MIDSTREAM] detected: [...168] [ip4][..tcp] [..192.168.2.126][50176] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun][mangaweb.1kxun.mobi] analyse: [...150] [ip4][..tcp] [..192.168.2.126][45416] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] min| max| avg| stddev| variance| entropy @@ -723,80 +723,80 @@ [IATS(ms)....: 188.5,0.0,1.4,179.4,1.4,0.7,0.4,2.4,0.7,270.1,0.1,0.0,0.6,0.0,3892.8,3428.9,186.1,186.3,192.6,209.0,367.2,352.3,5253.8,5339.0,3.6,6045.0,5959.1,0.4,0.5,194.9,189.4] [PKTLENS.....: 486,2932,2932,8692,2932,7252,1492,1492,14452,1492,2932,2932,7252,7252,4078,803,695,805,1511,807,1401,803,1516,1065,2932,1130,1155,1492,1492,1575,1166,1083] [ENTROPIES...: 5.9,7.8,7.9,8.0,7.9,8.0,7.9,7.9,8.0,7.9,7.9,7.9,8.0,8.0,8.0,5.9,6.4,5.9,7.5,5.9,6.2,5.9,6.5,5.8,6.5,6.8,5.8,6.4,7.8,7.9,5.8,6.9] - new: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...169] [ip4][..tcp] [..192.168.2.126][38326] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...170] [ip4][..tcp] [..192.168.2.126][38314] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [MIDSTREAM] + new: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [MIDSTREAM] detected: [...171] [ip4][..tcp] [..192.168.2.126][38316] -> [.172.105.121.82][...80] [HTTP.1kxun][Unknown][Streaming][Fun][pic.1kxun.com] - new: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [MIDSTREAM] + new: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [MIDSTREAM] detected: [...172] [ip4][..tcp] [..192.168.2.126][59324] -> [.104.117.221.10][...80] [HTTP][Unknown][Web][Acceptable][m.vpon.com] - new: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...173] [ip4][..tcp] [..192.168.2.126][56094] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...174] [ip4][..tcp] [..192.168.2.126][56098] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...175] [ip4][..tcp] [..192.168.2.126][56096] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [MIDSTREAM] + new: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [MIDSTREAM] detected: [...176] [ip4][..tcp] [..192.168.2.126][56104] -> [....3.72.69.158][...80] [HTTP][AmazonAWS][Web][Acceptable][setting.rayjump.com] - new: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [MIDSTREAM] + new: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [MIDSTREAM] detected: [...177] [ip4][..tcp] [..192.168.2.126][43266] -> [....18.64.79.58][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] - new: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [MIDSTREAM] + new: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [MIDSTREAM] detected: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] detection-update: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] RISK: Unidirectional Traffic detection-update: [...178] [ip4][..tcp] [..192.168.2.126][56826] -> [...8.209.97.107][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] - new: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [MIDSTREAM] + new: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [MIDSTREAM] detected: [...179] [ip4][..tcp] [..192.168.2.126][43272] -> [....18.64.79.58][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] - new: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [MIDSTREAM] + new: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [MIDSTREAM] detected: [...180] [ip4][..tcp] [..192.168.2.126][58758] -> [.202.153.196.53][...80] [HTTP][Unknown][Web][Acceptable][tw.api.vpon.com] - new: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [MIDSTREAM] + new: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [MIDSTREAM] detected: [...181] [ip4][..tcp] [..192.168.2.126][58760] -> [.202.153.196.53][...80] [HTTP][Unknown][Web][Acceptable][tw.api.vpon.com] - new: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [MIDSTREAM] + new: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [MIDSTREAM] detected: [...182] [ip4][..tcp] [..192.168.2.126][35664] -> [.....18.66.2.90][...80] [HTTP][AmazonAWS][Web][Acceptable][cdn.liftoff.io] - new: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [MIDSTREAM] + new: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [MIDSTREAM] detected: [...183] [ip4][..tcp] [..192.168.2.126][35666] -> [.....18.66.2.90][...80] [HTTP.MpegDash][AmazonAWS][Media][Fun][cdn.liftoff.io] - new: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...184] [ip4][..tcp] [..192.168.2.126][36636] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...185] [ip4][..tcp] [..192.168.2.126][36640] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...186] [ip4][..tcp] [..192.168.2.126][36654] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [MIDSTREAM] + new: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [MIDSTREAM] detected: [...187] [ip4][..tcp] [..192.168.2.126][36660] -> [...18.64.103.30][...80] [HTTP][AmazonAWS][Web][Acceptable][hybird.rayjump.com] - new: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [MIDSTREAM] + new: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [MIDSTREAM] detected: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: HTTP Susp User-Agent detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: HTTP Susp User-Agent, Unidirectional Traffic - new: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [MIDSTREAM] + new: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [MIDSTREAM] detected: [...189] [ip4][..tcp] [..192.168.2.126][42554] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][adx-tk.rayjump.com] RISK: Unidirectional Traffic - new: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [MIDSTREAM] + new: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [MIDSTREAM] detected: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][] RISK: Unidirectional Traffic - new: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [MIDSTREAM] + new: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [MIDSTREAM] detected: [...191] [ip4][..tcp] [..192.168.2.126][41940] -> [....18.64.79.50][...80] [HTTP][AmazonAWS][Web][Acceptable][tknet-cdn.rayjump.com] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] RISK: Unidirectional Traffic detection-update: [...188] [ip4][..tcp] [..192.168.2.126][37100] -> [..52.29.177.177][...80] [HTTP][AmazonAWS][Web][Acceptable][adx-tk.rayjump.com] detection-update: [...190] [ip4][..tcp] [..192.168.2.126][42566] -> [...35.156.44.13][...80] [HTTP][AmazonAWS][Web][Acceptable][de01.rayjump.com] - new: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [MIDSTREAM] + new: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [MIDSTREAM] detected: [...192] [ip4][..tcp] [..192.168.2.126][54810] -> [..18.233.123.55][...80] [HTTP][AmazonAWS][Web][Acceptable][impression-east.liftoff.io] - new: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [MIDSTREAM] + new: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [MIDSTREAM] detected: [...193] [ip4][..tcp] [..192.168.2.126][40204] -> [...18.235.204.9][...80] [HTTP][AmazonAWS][Web][Acceptable][adexp.liftoff.io] - new: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [MIDSTREAM] + new: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [MIDSTREAM] detected: [...194] [ip4][..tcp] [..192.168.2.126][53416] -> [.172.217.16.142][...80] [HTTP.Google][Google][Web][Acceptable][play.google.com] - new: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [MIDSTREAM] + new: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [MIDSTREAM] detected: [...195] [ip4][..tcp] [..192.168.2.126][33042] -> [...3.122.190.70][...80] [HTTP][AmazonAWS][Web][Acceptable][click.liftoff.io] - new: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [MIDSTREAM] + new: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [MIDSTREAM] detected: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] detection-update: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] RISK: Unidirectional Traffic detection-update: [...196] [ip4][..tcp] [..192.168.2.126][35426] -> [..8.209.112.118][...80] [HTTP][Alibaba][Web][Acceptable][analytics.rayjump.com] - new: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [MIDSTREAM] + new: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [MIDSTREAM] detected: [...197] [ip4][..tcp] [..192.168.2.126][51686] -> [....18.64.79.64][...80] [HTTP][AmazonAWS][Web][Acceptable][net.rayjump.com] idle: [...147] [ip4][..tcp] [..192.168.2.126][45388] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] idle: [...148] [ip4][..tcp] [..192.168.2.126][45398] -> [..161.117.13.29][...80] [HTTP.1kxun][Alibaba][Streaming][Fun] diff --git a/test/results/flow-info/enable_stun_monitoring_with_subproto/wa_voice.pcap.out b/test/results/flow-info/enable_stun_monitoring_with_subproto/wa_voice.pcap.out index 3768fa808..05d0b1b12 100644 --- a/test/results/flow-info/enable_stun_monitoring_with_subproto/wa_voice.pcap.out +++ b/test/results/flow-info/enable_stun_monitoring_with_subproto/wa_voice.pcap.out @@ -1,17 +1,17 @@ DAEMON-EVENT: init DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] - new: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] + new: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] detected: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] detection-update: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable][www.google.com] - new: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] + new: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] detected: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][g.whatsapp.net] detection-update: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][g.whatsapp.net] - new: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [MIDSTREAM] + new: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [MIDSTREAM] detected: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [ApplePush][Apple][Cloud][Acceptable] - new: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] + new: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] detected: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] - new: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] + new: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] detected: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] analyse: [.....5] [ip4][..tcp] [...192.168.2.12][49355] -> [..157.240.20.53][.5222] [WhatsApp][WhatsApp][Chat][Acceptable] min| max| avg| stddev| variance| entropy @@ -23,10 +23,10 @@ [IATS(ms)....: 40.7,137.0,170.4,304.1,130.2,0.1,31.0,5.3,0.0,0.4,0.0,0.2,0.0,1.2,210.1,0.3,0.0,0.0,0.2,0.0,0.3,41.4,129.9,0.1,0.0,0.0,0.0,1.0,24.3,131.9,0.0] [PKTLENS.....: 64,60,52,308,52,109,103,137,1440,92,1440,155,1440,164,1440,52,52,52,52,52,52,52,1045,84,98,119,82,111,52,338,52,52] [ENTROPIES...: 4.5,5.1,5.0,7.2,5.1,6.1,6.0,6.5,7.9,5.9,7.9,6.7,7.9,6.7,7.9,5.0,5.0,5.0,5.1,5.1,5.1,5.0,7.8,5.6,5.9,6.2,5.7,6.2,5.0,7.3,5.0,5.0] - new: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] + new: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] detected: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable][media-mxp1-1.cdn.whatsapp.net] detection-update: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable][media-mxp1-1.cdn.whatsapp.net] - new: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] + new: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] detected: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] detection-update: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable][media-mxp1-1.cdn.whatsapp.net] analyse: [.....7] [ip4][..tcp] [...192.168.2.12][50503] -> [....31.13.86.51][..443] [TLS.WhatsAppFiles][WhatsApp][Download][Acceptable] @@ -39,34 +39,34 @@ [IATS(ms)....: 19.7,127.7,2.8,126.3,2.9,0.0,0.0,21.0,0.2,145.2,0.0,0.0,0.0,0.0,0.0,163.3,0.0,0.0,0.0,0.2,0.0,0.0,17.5,0.3,0.0,0.0,2.4,0.3,0.1,0.4,0.6] [PKTLENS.....: 64,60,52,569,52,1440,1440,335,52,52,116,98,95,87,388,311,52,223,126,83,52,100,484,52,52,52,52,1440,52,1440,1440,83] [ENTROPIES...: 4.5,5.2,5.0,5.0,5.1,7.8,7.9,7.4,5.0,5.1,6.0,6.0,6.0,5.7,7.3,7.2,5.1,7.0,6.3,5.8,5.0,6.0,7.5,4.9,5.0,5.0,4.9,7.9,5.0,7.9,7.9,5.7] - new: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] + new: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] detected: [.....8] [ip4][..udp] [....192.168.2.1][17500] -> [..192.168.2.255][17500] [Dropbox][Unknown][Cloud][Acceptable] - new: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [MIDSTREAM] + new: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...17.171.47.85][..443] -> [...192.168.2.12][50502] [TLS][Apple][Web][Safe] - new: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] + new: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] detected: [....10] [ip4][..udp] [169.254.162.244][50384] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] + new: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] detected: [....11] [ip4][..udp] [....192.168.2.1][50384] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] + new: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] detected: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] + new: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] detected: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_raop._tcp.local] - new: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] + new: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] detected: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] + new: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] detected: [....15] [ip4][..udp] [...192.168.2.12][56328] -> [..185.60.216.51][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] + new: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] detected: [....16] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.193.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] + new: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] detected: [....17] [ip4][..udp] [...192.168.2.12][56328] -> [..179.60.192.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] + new: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] detected: [....18] [ip4][..udp] [...192.168.2.12][56328] -> [.157.240.196.62][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable][] - new: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] + new: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] detected: [....19] [ip4][..udp] [...192.168.2.12][64716] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] + new: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] detected: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][pps.whatsapp.net] detection-update: [....20] [ip4][..udp] [...192.168.2.12][60549] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable][pps.whatsapp.net] - new: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] + new: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] detected: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] detection-update: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable][pps.whatsapp.net] analyse: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable] @@ -79,9 +79,9 @@ [IATS(ms)....: 37.2,39.0,11.1,51.5,1.0,0.1,0.0,42.8,0.1,34.6,3.8,0.4,0.2,0.3,76.2,0.0,34.9,0.4,0.3,3.6,0.0,2.9,1.3,3.4,77.4,53.7,129.1,1.4,0.0,0.2,0.1] [PKTLENS.....: 64,60,52,569,52,1440,1440,333,52,52,116,98,95,87,244,223,126,52,52,83,52,83,52,87,52,52,502,52,1440,1440,1440,1440] [ENTROPIES...: 4.4,5.1,4.9,4.8,5.0,7.8,7.9,7.3,4.9,4.9,6.1,5.9,5.9,5.8,7.0,7.0,6.4,4.9,4.9,5.6,5.1,5.8,5.0,5.9,4.9,5.0,7.6,4.9,7.9,7.9,7.8,7.8] - new: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] + new: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] detected: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable][lucas-imac] - new: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] + new: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] detected: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....14] [ip4][..udp] [...192.168.2.12][56328] -> [....31.13.86.48][.3478] [STUN.WhatsAppCall][Facebook][VoIP][Acceptable] @@ -94,7 +94,7 @@ [IATS(ms)....: 0.1,13.4,0.1,12194.2,12196.2,104.4,0.1,105.1,0.0,108.6,104.6,3043.3,3048.9,3100.9,3096.0,3015.3,3016.6,2001.9,2.2,107.1,164.0,190.1,88.5,28.8,198.6,134.0,3008.1,91.0,35.6,0.3,36.5] [PKTLENS.....: 154,154,72,72,34,30,154,154,72,72,34,30,34,30,34,30,34,30,74,54,232,261,240,150,306,234,302,34,30,154,154,72] [ENTROPIES...: 6.5,6.5,5.3,5.3,4.6,4.5,6.5,6.5,5.2,5.1,4.6,4.5,4.6,4.5,4.6,4.5,4.6,4.5,5.7,5.2,7.0,7.1,7.1,6.6,7.3,7.0,7.2,4.6,4.5,6.5,6.5,5.2] - new: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] + new: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] detected: [....24] [ip4][..udp] [...192.168.2.12][56328] -> [.....1.60.78.64][64282] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable][] RISK: Known Proto on Non Std Port analyse: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] @@ -109,20 +109,20 @@ [ENTROPIES...: 5.5,5.6,5.5,5.6,5.5,5.6,6.9,7.1,6.7,6.6,7.3,6.5,6.7,6.6,6.5,6.6,6.5,6.6,6.7,6.8,6.7,6.7,6.7,6.7,6.5,5.2,6.6,6.6,6.7,6.6,6.6,6.8] detection-update: [....12] [ip4][..udp] [...192.168.2.12][.5353] -> [....224.0.0.251][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] detection-update: [....13] [ip6][..udp] [...............fe80::414:409d:8afd:9f05][.5353] -> [...............................ff02::fb][.5353] [MDNS][Unknown][Network][Acceptable][_homekit._tcp.local] - new: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [MIDSTREAM] + new: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [MIDSTREAM] update: [.....6] [ip4][..udp] [...192.168.2.12][55296] -> [....192.168.2.1][...53] [DNS.WhatsAppFiles][Unknown][Network][Acceptable] update: [.....1] [ip4][..udp] [...192.168.2.12][51431] -> [....192.168.2.1][...53] [DNS.Google][Unknown][Network][Acceptable] update: [.....4] [ip4][..udp] [....192.168.2.1][57621] -> [..192.168.2.255][57621] [Spotify][Unknown][Music][Fun] update: [.....2] [ip4][..udp] [...192.168.2.12][60765] -> [....192.168.2.1][...53] [DNS.WhatsApp][Unknown][Network][Acceptable] - new: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] + new: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] detected: [....26] [ip4][..udp] [...192.168.2.12][50191] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] + new: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] detected: [....27] [ip4][..udp] [...192.168.2.12][57546] -> [239.255.255.250][.1900] [SSDP][Unknown][System][Acceptable][239.255.255.250:1900] - new: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] + new: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] detected: [....28] [ip4][.icmp] [...192.168.2.12] -> [...91.252.56.51] [ICMP][Unknown][Network][Acceptable] idle: [.....3] [ip4][..tcp] [...192.168.2.12][49354] -> [...17.242.60.84][.5223] [ApplePush][Apple][Cloud][Acceptable] not-detected: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] [Unknown][Unknown][Unrated] - idle: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] + idle: [....25] [ip4][..tcp] [...192.168.2.12][49352] -> [169.254.162.244][49159] end: [....21] [ip4][..tcp] [...192.168.2.12][50504] -> [..157.240.20.52][..443] [TLS.WhatsApp][WhatsApp][Chat][Acceptable] idle: [....22] [ip4][..udp] [........0.0.0.0][...68] -> [255.255.255.255][...67] [DHCP][Unknown][Network][Acceptable] idle: [....23] [ip4][..udp] [...91.252.56.51][32704] -> [...192.168.2.12][56328] [STUN.WhatsAppCall][Unknown][VoIP][Acceptable] |