DAEMON-EVENT: init new: [.....1] [ip4][..tcp] [....192.168.0.1][.8787] -> [.....10.10.10.1][32177] detected: [.....1] [ip4][..tcp] [....192.168.0.1][.8787] -> [.....10.10.10.1][32177] [TeamViewer][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port analyse: [.....1] [ip4][..tcp] [....192.168.0.1][.8787] -> [.....10.10.10.1][32177] [TeamViewer][Unknown][RemoteAccess][Acceptable] min| max| avg| stddev| variance| entropy [IAT.........: < 0.001| 0.274| 0.067| 0.088| 7794.386| 3.800] [PKTLEN......: 40.000| 1500.000| 369.000| 516.400| 266637.300| 3.800] [BINS(c->s)..: 5,3,1,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,2,0,0] [BINS(s->c)..: 11,1,0,0,1,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,1,0,0,0,0,0,0,1,0,0] [DIRECTIONS..: 0,1,0,0,1,0,1,0,0,1,1,1,0,1,0,1,1,0,0,1,1,0,1,1,0,1,0,1,0,0,1,1] [IATS(ms)....: 136.3,137.2,0.6,1.8,12.1,11.9,35.7,0.1,35.8,0.0,88.3,88.6,11.6,11.6,151.9,0.1,152.0,35.7,35.9,255.8,274.4,18.6,256.5,257.6,1.1,0.3,0.3,28.9,0.0,29.1,0.0] [PKTLENS.....: 60,44,46,77,40,106,40,1500,418,40,40,88,46,187,46,1500,1276,46,1118,40,1129,1141,40,480,96,40,88,40,1500,415,40,40] [ENTROPIES...: 4.6,4.6,4.3,4.6,4.6,4.0,4.5,7.6,7.4,4.4,4.6,4.9,4.4,3.8,4.4,7.7,7.8,4.3,7.7,4.6,7.5,7.7,4.6,6.5,4.5,4.6,3.8,4.6,7.5,7.3,4.6,4.6] DAEMON-EVENT: [Processed: 59 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 1|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....2] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] new: [.....3] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] detected: [.....2] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] [Usenet][Unknown][Web][Acceptable] detected: [.....3] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] idle: [.....1] [ip4][..tcp] [....192.168.0.1][.8787] -> [.....10.10.10.1][32177] [TeamViewer][Unknown][RemoteAccess][Acceptable] RISK: Known Proto on Non Std Port DAEMON-EVENT: [Processed: 71 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 3|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....4] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] new: [.....5] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] detected: [.....5] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] idle: [.....2] [ip4][..tcp] [.172.26.235.166][55630] -> [...172.30.92.62][..119] [Usenet][Unknown][Web][Acceptable] idle: [.....3] [ip4][..tcp] [.192.168.190.20][55630] -> [..192.168.190.5][..119] [Usenet][Unknown][Web][Acceptable] DAEMON-EVENT: [Processed: 75 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 2 / 5|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0] new: [.....6] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] detected: [.....6] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] idle: [.....5] [ip4][..udp] [.......10.9.0.1][43462] -> [.......10.9.0.2][51820] [WireGuard][Unknown][VPN][Acceptable] guessed: [.....4] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] [WireGuard][Unknown][VPN][Acceptable] idle: [.....4] [ip4][..udp] [..10.147.205.42][43462] -> [..10.45.123.132][51820] DAEMON-EVENT: [Processed: 85 pkts][ZLib][compressions: 0|diff: 0 / 0] DAEMON-EVENT: [Flows][active: 1 / 6|skipped: 0|!detected: 0|guessed: 1|detection-updates: 0|updates: 0] new: [.....7] [ip4][..tcp] [......127.0.0.1][54898] -> [......127.0.0.1][.1299] detected: [.....7] [ip4][..tcp] [......127.0.0.1][54898] -> [......127.0.0.1][.1299] [TruPhone][Unknown][VoIP][Acceptable] end: [.....6] [ip4][..tcp] [..172.16.20.244][59038] -> [...172.16.20.75][.5432] [PostgreSQL][Unknown][Database][Acceptable] new: [.....8] [ip4][..tcp] [......127.0.0.1][55536] -> [......127.0.0.1][.1299] detected: [.....8] [ip4][..tcp] [......127.0.0.1][55536] -> [......127.0.0.1][.1299] [TruPhone][Unknown][VoIP][Acceptable] end: [.....7] [ip4][..tcp] [......127.0.0.1][54898] -> [......127.0.0.1][.1299] [TruPhone][Unknown][VoIP][Acceptable] end: [.....8] [ip4][..tcp] [......127.0.0.1][55536] -> [......127.0.0.1][.1299] [TruPhone][Unknown][VoIP][Acceptable] DAEMON-EVENT: shutdown