aboutsummaryrefslogtreecommitdiff
path: root/test/results/default/openvpn_obfuscated.pcapng.out
blob: 70f2b958940a6d2f25a539128923fd8abe1f9b54 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
00576{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","max-flows-per-thread":2048,"max-idle-flows-per-thread":64,"reader-thread-count":1,"flow-scan-interval":10000000,"generic-max-idle-time":600000000,"icmp-max-idle-time":120000000,"udp-max-idle-time":180000000,"tcp-max-idle-time":7560000000,"max-packets-per-flow-to-send":5,"max-packets-per-flow-to-process":32,"max-packets-per-flow-to-analyse":32,"global_ts_usec":0}
00800{"daemon_event_id":4,"daemon_event_name":"status","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","packets-captured":1,"packets-processed":0,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":0,"total-not-detected-flows":0,"total-guessed-flows":0,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":0,"total-idle-flows":0,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":2,"global_ts_usec":1722427237865123}
00788{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427237865123,"flow_dst_last_pkt_time":1722427237865123,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":0,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":0,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1722427237865123,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5}
00567{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_src_last_pkt_time":1722427237865123,"flow_dst_last_pkt_time":1722427237865123,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"thread_ts_usec":1722427237865123,"pkt":"CL6sCxduJjb1W8R1CABFAAA8G7tAAEAGftnAqAycuYAZY5RYAdHRRTx5AAAAAKAC\/\/8WmQAAAgQFtAQCCApRg5vRAAAAAAEDAwk="}
00568{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":2,"flow_src_last_pkt_time":1722427237865123,"flow_dst_last_pkt_time":1722427237885149,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"thread_ts_usec":1722427237885149,"pkt":"Jjb1W8R1CL6sCxduCABFAAA8AABAADEGqZS5gBljwKgMnAHRlFgui1zd0UU8eqAS\/\/\/GVwAAAgQFtAQCCApg+GPPUYOb0QEDAwk="}
00554{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":3,"flow_src_last_pkt_time":1722427237887189,"flow_dst_last_pkt_time":1722427237885149,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"thread_ts_usec":1722427237887189,"pkt":"CL6sCxduJjb1W8R1CABFAAA0G7xAAEAGfuDAqAycuYAZY5RYAdHRRTx6Lotc3oAQAKz0VAAAAQEIClGDm\/Zg+GPP"}
00678{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":4,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":4,"flow_src_last_pkt_time":1722427237893385,"flow_dst_last_pkt_time":1722427237885149,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":154,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":154,"pkt_l4_len":120,"thread_ts_usec":1722427237893385,"pkt":"CL6sCxduJjb1W8R1CABFAACMG71AAEAGfofAqAycuYAZY5RYAdHRRTx6Lotc3oAYAKwGbAAAAQEIClGDm\/xg+GPPAFZMPTMzOTxRGolMICktfVX5d7Govcsy0pVT8mddVpzLWlSz\/wqa4fqnJ7sd1tDiWvK+0bNfYJYw2jC910NC5QLwcabB0lN2lzIDtdibQqo8tesgVT+0oQ=="}
00553{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":5,"flow_src_last_pkt_time":1722427237893385,"flow_dst_last_pkt_time":1722427237913224,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"thread_ts_usec":1722427237913224,"pkt":"Jjb1W8R1CL6sCxduCABFAAA03KxAADEGzO+5gBljwKgMnAHRlFgui1ze0UU80oAQAID0BgAAAQEICmD4Y+tRg5v8"}
02006{"flow_event_id":5,"flow_event_name":"analyse","thread_id":0,"packet_id":32,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":15,"flow_dst_packets_processed":17,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427239098966,"flow_dst_last_pkt_time":1722427239119270,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":749,"flow_dst_max_l4_payload_len":1448,"flow_src_tot_l4_payload_len":2029,"flow_dst_tot_l4_payload_len":6170,"midstream":0,"thread_ts_usec":1722427239119270,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"data_analysis": {"iat": {"min":4,"avg":80257.7,"max":1019751,"stddev":241804.0,"var":58469183488.0,"ent":2.3,"data": [20026,22066,6196,28075,47,21155,1036,26262,32,5,4,27970,122,183,23639,57497,41848,4811,15826,16412,4857,7937,24736,465,24028,23273,24679,66760,1019751,977576,716]},"pktlen": {"min":52,"avg":308.7,"max":1500,"stddev":431.5,"var":186180.0,"ent":4.0,"data": [60,60,52,140,52,152,52,429,148,1500,1500,1500,52,52,152,164,52,52,376,873,52,52,801,52,310,172,395,176,52,199,52,148]},"bins": {"c_to_s": [7,0,1,3,1,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"s_to_c": [7,0,0,4,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,3,0,0]},"directions": [0,1,0,0,1,1,0,0,1,1,1,1,0,0,0,1,0,1,0,1,0,1,0,1,1,0,1,0,1,0,1,1],"entropies": [4.713300705,5.200119972,5.118428230,6.481626511,5.065449238,6.636507511,5.079966068,7.256804943,6.578202248,7.858069420,7.854922771,7.883089542,5.041504383,5.118428230,6.483579159,6.730767250,5.079966068,5.079966068,7.347016811,7.755306244,5.079966545,5.118428230,7.724539757,5.156889439,7.263402939,6.729237556,7.474316120,6.499718189,5.118428230,6.903886318,5.118427753,6.545400143]}}
01081{"flow_event_id":6,"flow_event_name":"guessed","thread_id":0,"packet_id":32,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_src_packets_processed":15,"flow_dst_packets_processed":17,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427239098966,"flow_dst_last_pkt_time":1722427239119270,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":749,"flow_dst_max_l4_payload_len":1448,"flow_src_tot_l4_payload_len":2029,"flow_dst_tot_l4_payload_len":6170,"midstream":0,"thread_ts_usec":1722427239119270,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","ndpi": {"flow_risk": {"51": {"risk":"Fully Encrypted Flow","severity":"Medium","risk_score": {"total":360,"client":240,"server":120}}},"confidence": {"1":"Match by port"},"proto":"SMTPS","proto_id":"29","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Safe","category_id":3,"category":"Email"}}
00794{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":61,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1722427401914491,"flow_src_last_pkt_time":1722427401914491,"flow_dst_last_pkt_time":1722427401914491,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":86,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":86,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":86,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1722427401914491,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"149.102.238.108","src_port":47128,"dst_port":1214,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
00641{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":61,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_src_last_pkt_time":1722427401914491,"flow_dst_last_pkt_time":1722427401914491,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":128,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":128,"pkt_l4_len":94,"thread_ts_usec":1722427401914491,"pkt":"CL6sCxduJjb1W8R1CABFAABy2RxAAEAREEfAqAyclWbubLgYBL4AXry7TD0zMzk8PRWJTCApLX0ztsQlev3YxCWdt7GyYXdyiRGo8bhFf\/cNiCnfxJrQQpJhg10bVRf\/YPtTO9niuqCU7i89LOiqGMxV7ItTQIb1eAp4i9eFVl8="}
00659{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":62,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":2,"flow_src_last_pkt_time":1722427401914491,"flow_dst_last_pkt_time":1722427401921409,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":140,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":140,"pkt_l4_len":106,"thread_ts_usec":1722427401921409,"pkt":"Jjb1W8R1CL6sCxduCABFAAB+OLtAADURu5yVZu5swKgMnAS+uBgAah9pNAkHBzVqBXec3okFUmE\/LQUpLQmDVjIwPTgDGz\/v8c82iAOs+Gw2f07LutXYs10W54XvwsPZQ\/FJezyTZqW58dR09NoJw48Yh7VHR7mXHT13nkq85vgyd2g5LHZYXKmzocY="}
01034{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":63,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":3,"flow_src_last_pkt_time":1722427401924227,"flow_dst_last_pkt_time":1722427401921409,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":417,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":417,"pkt_l4_len":383,"thread_ts_usec":1722427401924227,"pkt":"CL6sCxduJjb1W8R1CABFAAGT2SFAAEARDyHAqAyclWbubLgYBL4Bf+BaVEX2eYIGWZW97B\/uBFKid6MSV9\/02W2\/W+o36cuQNVtmMhAJHTAcbDg7XCMFAl0xHCYeGhojEQ07YGRoa2JiGBURHRlLEx04EAUBFg8EBB4VCR8QQxUVFBYoJyUjKnU9F0geFD5NHRwpDR0JMwQHEBgXGRgREREWHu32uP3s3BELEBsZDBEMEQcEDlgJDwQeFxCIEBhHyxRzBjPkcOAZKQXaF+N3ATvcOcpmAyzAL96OHmPUM\/K30LS6xKT6al3NNNxMChsDEA8uCd46WfS1aCsMHMuFvhUjOGTIBxpU3v\/Hxw6s\/CgKCqKhIJpNENIN2+tGFOfxS7QuGoPC52Q7v9u+NPw8b3vfvXXBBwc5DBYQNxUEGwYXFhEnO2pMT+yE7o8cNhkQEQM5pmcMCREEcDf7xzLpHLLsNx\/zRQ7DT7GnNBoJH96PWo0gzSL9g2Dar\/34qx5dEYO9\/DG3QzVndkG9w4jcVbkhUFWSERwvvUItAJ\/89A5z"}
00653{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":64,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":4,"flow_src_last_pkt_time":1722427401924227,"flow_dst_last_pkt_time":1722427401934060,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":136,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":136,"pkt_l4_len":102,"thread_ts_usec":1722427401934060,"pkt":"Jjb1W8R1CL6sCxduCABFAAB6OL1AADURu56VZu5swKgMnAS+uBgAZvhOXG8GfZrUgA1YMzkxNWQxAbNSOT0tNIAP9idCl\/rehm7YfSBAKj59k9UPRPKVaW0LUqQgzFOtLHumhFDN1Y5hbY3tlOPyWvfVkw6K7l+x6eqyqyRV8MQse1pU+6KRqg=="}
02035{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":65,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_packet_id":5,"flow_src_last_pkt_time":1722427401924227,"flow_dst_last_pkt_time":1722427401934161,"flow_idle_time":200000000,"pkt_datalink":1,"pkt_caplen":1158,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1158,"pkt_l4_len":1124,"thread_ts_usec":1722427401934161,"pkt":"Jjb1W8R1CL6sCxduCABFAAR4OL5AADURt5+VZu5swKgMnAS+uBgEZLQzVLAa0ZHTWfav3aQ6aDiNoVBwHdfIrsumF\/Xi771+6seFvgsgbkxRKAqi+llZx7z81zilj97CxWRsx93kXlTmVZH1P80KGnxXlR7BiJM18BLjNISj+gZaL0RMsbZ\/\/0UWwTMg0BMD+RgWYRcd61hmbZABZnpzMi\/LZRSE50mWCxH9dHqopm4Rzi4Sn7KxkjSWm8BiRUowB\/370WD0qx\/g9JW5UIxB92Ud6V1iTPjtmCgTxngrFqv4udp8FTsD8KNaHIzqNRUDWeNKhdBfywJxLoo8\/p1OGrSOuC\/yUWCOVPBEG0DdNlHBPyeW8SDwcnP4DcidmrJfxLHUg1HGh4+RWLkSFQsr+4W5z29yC41XpvCOCfc\/hn+EAz73kSY1DzJL59r2AXH8G5Rea\/RbEUrobun9NGOeVKCIzmD8Trl96OaqJhX8xal6pdV0sAV5Vo9xPebYVgEG80YaI0ek\/7yknL8W9IBQ2aLOpnFDXpCbdgYsosJ1y5dt6ib8aNJ+M\/xKRCussfhzl6cYKdrj1skMpL6bcbwUuhNt0cz28hf9enP7WBDH0Fxp5kwD+hH3G30EyEpxKuMziqSt\/e4UQR1duSa5VhMDOC98xMmGl0fj5OxMkG6xFP+PlFxbfRIMxgHsORiw87u6+g8HDPXiXIvJH4NZ7GvAgKGx6vPzRzY1kJ62bLlLPsnFFe6u5Lu3S820EMsOgXAFuSfj3yV3Evd+WLk737aUMZpoycfdzpgL1pvr4w3GxN\/TLg48jWGBKotX5zgnS6rvI88rGnHjRpaeOQ9CGYvCXVgO6n0MG2pCKs14CRjfcLqndxUDz5CE0mpW+jUfNJ4ux57J42zD3C+R4ZvY0UqADXZgvIZieAaKP2Qftw4pNwvuYOvK1OYGPbD+e89LxaNtpqyRB1MKVrBbdwgLG5kjU0ZoQUZJ2JOassNku+llFLRYPlNIJdOPFe8lNwX6hfJGdRMMmb4N9pCq8zoPySjjHjxjcpVsIj21jIi6qDUjUIvYwHaz3y0G7hXahyVVr7iDXUaXJGHIL0N4eAIJwH2sxv5+E4rQX5KXSJTnQN0IUM9\/AywsX9qhuZUo9Ozj\/8opy6hdWDTnxIrSvYZ63LEWGZ6GbZq9Um2Ln9uD7D+\/BgaPsoCfTlvt4+mz8wj6pNzsVkxsrWn6iEtKp70qWQsP\/gFGe2Df51awxTQYITw6LzU6Lndgr4Qxly7lJIUUP46pn4P+TJ+8+3QoYuNOQEyg9SneVXtmcVB8Vnt2enN1DntXWXR5brdGfJSMHDslO+anlwsJFXTtGhgL4dS2wSKBjgYjFobKFroyEjVAyw7y9kntCrZphbXffdx2X4Zb1huMN30p83ks9\/SzOTk5Tj82bgcyZR09O24Tj2g3MTAMKUrvJnigQgCd7TGqBAQ2acAFhpTV62J2y9r8nx3tIE\/jhWhChZNaqTMjhHxlENJxKzeOMmtRIMpACoJ6fPzVRSJ+VFr38ZOo"}
00808{"daemon_event_id":4,"daemon_event_name":"status","thread_id":0,"packet_id":91,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","packets-captured":91,"packets-processed":90,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":22584,"total-not-detected-flows":0,"total-guessed-flows":1,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":2,"total-active-flows":2,"total-idle-flows":0,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":17,"global_ts_usec":1722705590754656}
00790{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":91,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":1,"flow_dst_packets_processed":0,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590754656,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":0,"flow_dst_max_l4_payload_len":0,"flow_src_tot_l4_payload_len":0,"flow_dst_tot_l4_payload_len":0,"midstream":0,"thread_ts_usec":1722705590754656,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5}
00568{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":91,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590754656,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"thread_ts_usec":1722705590754656,"pkt":"Jjb1W8R1CL6sCxduCABFAAA8AABAADMGuFNroVaDwKgMnAG7u8glbqt9M+JifKAS\/\/9LzQAAAgQFtAQCCApqqi2Uyg3lpAEDAwI="}
00555{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":92,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":2,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590856725,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"thread_ts_usec":1722705590856725,"pkt":"CL6sCxduJjb1W8R1CABFAAA0KexAAEAGgW\/AqAyca6FWg7vIAbsz4mJ8JW6rfoAQAKx48wAAAQEICsoN5plqqi2U"}
00568{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":93,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":3,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590861565,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":75,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":75,"pkt_l4_len":41,"thread_ts_usec":1722705590861565,"pkt":"CL6sCxduJjb1W8R1CABFAAA9Ke1AAEAGgWXAqAyca6FWg7vIAbsz4mJ8JW6rfoAYAKwRrQAAAQEICsoN5p5qqi2UAFY4ao5vp\/\/4"}
00566{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":94,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":4,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590868065,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":75,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":75,"pkt_l4_len":41,"thread_ts_usec":1722705590868065,"pkt":"CL6sCxduJjb1W8R1CABFAAA9Ke5AAEAGgWTAqAyca6FWg7vIAbsz4mKFJW6rfoAYAKwRUAAAAQEICsoN5qRqqi2UYBhRh3visPuJ"}
00567{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":95,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_packet_id":5,"flow_src_last_pkt_time":1722705590754656,"flow_dst_last_pkt_time":1722705590873564,"flow_idle_time":7580000000,"pkt_datalink":1,"pkt_caplen":75,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":75,"pkt_l4_len":41,"thread_ts_usec":1722705590873564,"pkt":"CL6sCxduJjb1W8R1CABFAAA9Ke9AAEAGgWPAqAyca6FWg7vIAbsz4mKOJW6rfoAYAKyd\/QAAAQEICsoN5qpqqi2UOno3Y591U252"}
01987{"flow_event_id":5,"flow_event_name":"analyse","thread_id":0,"packet_id":122,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":11,"flow_dst_packets_processed":21,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705591511972,"flow_dst_last_pkt_time":1722705591387622,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":100,"flow_dst_max_l4_payload_len":46,"flow_src_tot_l4_payload_len":196,"flow_dst_tot_l4_payload_len":218,"midstream":0,"thread_ts_usec":1722705591511972,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"data_analysis": {"iat": {"min":26,"avg":44847.8,"max":303035,"stddev":76201.7,"var":5806696960.0,"ent":3.5,"data": [102069,4840,6500,5499,5384,5348,5717,5375,5168,5616,5148,255594,100325,15640,143042,32722,143022,26,303035,27745,1278,5419,5419,5738,6677,5026,142895,27779,1244,5483,5509]},"pktlen": {"min":52,"avg":67.3,"max":152,"stddev":23.7,"var":562.8,"ent":4.9,"data": [60,52,61,61,61,61,61,61,61,61,61,59,64,88,58,80,80,52,152,98,52,59,59,59,59,59,59,52,148,52,52,52]},"bins": {"c_to_s": [9,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],"s_to_c": [19,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]},"directions": [0,1,1,1,1,1,1,1,1,1,1,1,0,1,1,0,0,0,0,1,1,1,1,1,1,1,1,0,0,0,0,0],"entropies": [5.300120831,5.233812809,5.399485111,5.467381954,5.434595108,5.401808262,5.500168800,5.401808262,5.455006599,5.377057552,5.233534813,5.055375576,5.207358360,5.946230888,5.336176872,5.165400982,5.130965233,5.231892586,6.316833973,5.691545963,5.156889915,5.259676456,5.280779839,5.403578281,5.333379745,5.369679928,5.299482346,5.193430901,6.433825016,5.140452385,5.193430901,5.270354271]}}
00946{"flow_event_id":6,"flow_event_name":"guessed","thread_id":0,"packet_id":122,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"info","flow_src_packets_processed":11,"flow_dst_packets_processed":21,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705591511972,"flow_dst_last_pkt_time":1722705591387622,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":100,"flow_dst_max_l4_payload_len":46,"flow_src_tot_l4_payload_len":196,"flow_dst_tot_l4_payload_len":218,"midstream":0,"thread_ts_usec":1722705591511972,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","ndpi": {"confidence": {"1":"Match by port"},"proto":"TLS","proto_id":"91","proto_by_ip":"Unknown","proto_by_ip_id":0,"encrypted":1,"breed":"Safe","category_id":5,"category":"Web"}}
01078{"flow_event_id":6,"flow_event_name":"guessed","thread_id":0,"packet_id":177,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":19,"flow_dst_packets_processed":11,"flow_first_seen":1722427401914491,"flow_src_last_pkt_time":1722427403179824,"flow_dst_last_pkt_time":1722427403133860,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":73,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":740,"flow_dst_max_l4_payload_len":1116,"flow_src_tot_l4_payload_len":2831,"flow_dst_tot_l4_payload_len":6507,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"149.102.238.108","src_port":47128,"dst_port":1214,"l4_proto":"udp","ndpi": {"flow_risk": {"35": {"risk":"Susp Entropy","severity":"Low","risk_score": {"total":210,"client":165,"server":45}}},"confidence": {"7":"Match by IP"},"proto":"NordVPN","proto_id":"426","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Acceptable","category_id":2,"category":"VPN"}}
00807{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":2,"flow_state":"info","flow_src_packets_processed":19,"flow_dst_packets_processed":11,"flow_first_seen":1722427401914491,"flow_src_last_pkt_time":1722427403179824,"flow_dst_last_pkt_time":1722427403133860,"flow_idle_time":200000000,"flow_src_min_l4_payload_len":73,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":740,"flow_dst_max_l4_payload_len":1116,"flow_src_tot_l4_payload_len":2831,"flow_dst_tot_l4_payload_len":6507,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"149.102.238.108","src_port":47128,"dst_port":1214,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":5}
01123{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"finished","flow_src_packets_processed":29,"flow_dst_packets_processed":31,"flow_first_seen":1722427237865123,"flow_src_last_pkt_time":1722427239577895,"flow_dst_last_pkt_time":1722427239598141,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1024,"flow_dst_max_l4_payload_len":1448,"flow_src_tot_l4_payload_len":5488,"flow_dst_tot_l4_payload_len":7758,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"192.168.12.156","dst_ip":"185.128.25.99","src_port":37976,"dst_port":465,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"flow_risk": {"51": {"risk":"Fully Encrypted Flow","severity":"Medium","risk_score": {"total":360,"client":240,"server":120}}},"confidence": {"1":"Match by port"},"proto":"SMTPS","proto_id":"29","proto_by_ip":"NordVPN","proto_by_ip_id":426,"encrypted":1,"breed":"Safe","category_id":3,"category":"Email"}}
00992{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":177,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","flow_id":3,"flow_state":"finished","flow_src_packets_processed":40,"flow_dst_packets_processed":47,"flow_first_seen":1722705590754656,"flow_src_last_pkt_time":1722705593900158,"flow_dst_last_pkt_time":1722705593880142,"flow_idle_time":7580000000,"flow_src_min_l4_payload_len":0,"flow_dst_min_l4_payload_len":0,"flow_src_max_l4_payload_len":1448,"flow_dst_max_l4_payload_len":1024,"flow_src_tot_l4_payload_len":6532,"flow_dst_tot_l4_payload_len":13095,"midstream":0,"thread_ts_usec":1722705593900158,"l3_proto":"ip4","src_ip":"107.161.86.131","dst_ip":"192.168.12.156","src_port":443,"dst_port":48072,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":5,"ndpi": {"confidence": {"1":"Match by port"},"proto":"TLS","proto_id":"91","proto_by_ip":"Unknown","proto_by_ip_id":0,"encrypted":1,"breed":"Safe","category_id":5,"category":"Web"}}
00813{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":177,"source":"cfgs\/default\/pcap\/openvpn_obfuscated.pcapng","alias":"nDPId-test","version":"1.7.0","ndpi_version":"4.11.0-4976-59ee1fe","packets-captured":177,"packets-processed":177,"pfring_active":false,"pfring_recv":0,"pfring_drop":0,"pfring_shunt":0,"total-skipped-flows":0,"total-l4-payload-len":42211,"total-not-detected-flows":0,"total-guessed-flows":3,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":3,"total-idle-flows":3,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"global-alloc-count":0,"global-free-count":0,"global-alloc-bytes":0,"global-free-bytes":0,"total-events-serialized":30,"global_ts_usec":1722705593900158}
~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~
~~ packets captured/processed: 177/177
~~ skipped flows.............: 0
~~ total layer4 data length..: 42211 bytes
~~ total detected protocols..: 0
~~ total active/idle flows...: 3/3
~~ total timeout flows.......: 1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ total memory allocated....: 6668215 bytes
~~ total memory freed........: 6668215 bytes
~~ total allocations/frees...: 114340/114340
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ json message min len.......: 558 chars
~~ json message max len.......: 2040 chars
~~ json message avg len.......: 1298 chars