diff options
Diffstat (limited to 'test/results/flow-info/default/windowsupdate_over_http.pcap.out')
-rw-r--r-- | test/results/flow-info/default/windowsupdate_over_http.pcap.out | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/test/results/flow-info/default/windowsupdate_over_http.pcap.out b/test/results/flow-info/default/windowsupdate_over_http.pcap.out new file mode 100644 index 000000000..53d0330f1 --- /dev/null +++ b/test/results/flow-info/default/windowsupdate_over_http.pcap.out @@ -0,0 +1,9 @@ + DAEMON-EVENT: init + new: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] + detected: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][SoftwareUpdate][Safe][151.99.72.125] + RISK: HTTP/TLS/QUIC Numeric Hostname/SNI + detection-update: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][Download][Safe][151.99.72.125] + RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, Binary File/Data Transfer (Attempt) + idle: [.....1] [ip4][..tcp] [......10.0.2.15][49815] -> [..151.99.72.125][...80] [HTTP.WindowsUpdate][Unknown][Download][Safe][151.99.72.125] + RISK: HTTP/TLS/QUIC Numeric Hostname/SNI, Binary File/Data Transfer (Attempt) + DAEMON-EVENT: shutdown |