aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/EAQ.pcap.out
blob: 3c16af9bf8367169942f63aed547d8e762e663a6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
     DAEMON-EVENT: init
     DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
              new: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] 
         detected: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] [HTTP.Google][Web][Acceptable]
                   RISK: HTTP Suspicious User-Agent
              new: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] 
         detected: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] [HTTP.Google][Web][Acceptable]
                   RISK: HTTP Suspicious User-Agent
              new: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] 
              new: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] 
              new: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] 
              new: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] 
              new: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] 
              new: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] 
              new: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] 
              new: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] 
              new: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] 
              new: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] 
              new: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] 
              new: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] 
              new: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] 
              new: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] 
              new: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] 
              new: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] 
              new: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] 
              new: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] 
              new: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] 
              new: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] 
              new: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] 
              new: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] 
              new: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] 
              new: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] 
              new: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] 
              new: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] 
              new: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] 
              new: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] 
              new: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] 
         detected: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] [EAQ][Network][Acceptable]
         detected: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] [EAQ][Network][Acceptable]
         detected: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] [EAQ][Network][Acceptable]
         detected: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] [EAQ][Network][Acceptable]
         detected: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] [EAQ][Network][Acceptable]
         detected: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] [EAQ][Network][Acceptable]
         detected: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] [EAQ][Network][Acceptable]
         detected: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] [EAQ][Network][Acceptable]
           update: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] [EAQ][Network][Acceptable]
           update: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] [EAQ][Network][Acceptable]
           update: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] 
           update: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] 
           update: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] 
           update: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] [EAQ][Network][Acceptable]
           update: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] 
           update: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] 
           update: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] [EAQ][Network][Acceptable]
           update: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] [EAQ][Network][Acceptable]
           update: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] 
           update: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] [EAQ][Network][Acceptable]
           update: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] 
           update: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] 
           update: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] 
           update: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] 
           update: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] 
           update: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] [EAQ][Network][Acceptable]
           update: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] 
           update: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] 
           update: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] 
           update: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] [EAQ][Network][Acceptable]
           update: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] 
         detected: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] [EAQ][Network][Acceptable]
         detected: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] [EAQ][Network][Acceptable]
         detected: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] [EAQ][Network][Acceptable]
         detected: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] [EAQ][Network][Acceptable]
         detected: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] [EAQ][Network][Acceptable]
         detected: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] [EAQ][Network][Acceptable]
           update: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] 
           update: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] 
           update: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] 
           update: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] 
           update: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] 
           update: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] 
         detected: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] [EAQ][Network][Acceptable]
         detected: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] [EAQ][Network][Acceptable]
         detected: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] [EAQ][Network][Acceptable]
         detected: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] [EAQ][Network][Acceptable]
         detected: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] [EAQ][Network][Acceptable]
         detected: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] [EAQ][Network][Acceptable]
         detected: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] [EAQ][Network][Acceptable]
         detected: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] [EAQ][Network][Acceptable]
         detected: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] [EAQ][Network][Acceptable]
         detected: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] [EAQ][Network][Acceptable]
         detected: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] [EAQ][Network][Acceptable]
         detected: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] [EAQ][Network][Acceptable]
         detected: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] [EAQ][Network][Acceptable]
         detected: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] [EAQ][Network][Acceptable]
         detected: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] [EAQ][Network][Acceptable]
             idle: [....17] [ip4][..udp] [.......10.8.0.1][48563] -> [.200.194.141.67][.6000] [EAQ][Network][Acceptable]
             idle: [....19] [ip4][..udp] [.......10.8.0.1][52726] -> [.200.194.132.68][.6000] [EAQ][Network][Acceptable]
             idle: [.....4] [ip4][..udp] [.......10.8.0.1][48890] -> [200.185.125.226][.6000] [EAQ][Network][Acceptable]
             idle: [....14] [ip4][..udp] [.......10.8.0.1][48666] -> [.200.194.129.66][.6000] [EAQ][Network][Acceptable]
             idle: [.....7] [ip4][..udp] [.......10.8.0.1][42620] -> [.200.194.148.66][.6000] [EAQ][Network][Acceptable]
             idle: [....21] [ip4][..udp] [.......10.8.0.1][57004] -> [.200.194.133.67][.6000] [EAQ][Network][Acceptable]
             idle: [....23] [ip4][..udp] [.......10.8.0.1][36552] -> [.200.194.136.66][.6000] [EAQ][Network][Acceptable]
              end: [.....2] [ip4][..tcp] [.......10.8.0.1][40467] -> [.173.194.119.24][...80] [HTTP.Google][Web][Acceptable]
                   RISK: HTTP Suspicious User-Agent
             idle: [....26] [ip4][..udp] [.......10.8.0.1][59098] -> [.200.194.134.68][.6000] [EAQ][Network][Acceptable]
             idle: [....28] [ip4][..udp] [.......10.8.0.1][36577] -> [.200.194.149.68][.6000] [EAQ][Network][Acceptable]
             idle: [....22] [ip4][..udp] [.......10.8.0.1][53059] -> [.200.194.133.68][.6000] [EAQ][Network][Acceptable]
             idle: [.....9] [ip4][..udp] [.......10.8.0.1][34687] -> [.200.194.141.68][.6000] [EAQ][Network][Acceptable]
             idle: [....11] [ip4][..udp] [.......10.8.0.1][53354] -> [.200.194.137.66][.6000] [EAQ][Network][Acceptable]
             idle: [....25] [ip4][..udp] [.......10.8.0.1][47346] -> [.200.194.134.66][.6000] [EAQ][Network][Acceptable]
             idle: [....18] [ip4][..udp] [.......10.8.0.1][39185] -> [.200.194.132.67][.6000] [EAQ][Network][Acceptable]
             idle: [....10] [ip4][..udp] [.......10.8.0.1][39221] -> [.200.194.137.67][.6000] [EAQ][Network][Acceptable]
             idle: [.....5] [ip4][..udp] [.......10.8.0.1][51569] -> [.200.194.148.67][.6000] [EAQ][Network][Acceptable]
              end: [.....1] [ip4][..tcp] [.......10.8.0.1][53497] -> [.173.194.119.48][...80] [HTTP.Google][Web][Acceptable]
                   RISK: HTTP Suspicious User-Agent
             idle: [.....6] [ip4][..udp] [.......10.8.0.1][41438] -> [.200.194.141.66][.6000] [EAQ][Network][Acceptable]
             idle: [....12] [ip4][..udp] [.......10.8.0.1][59959] -> [.200.194.137.68][.6000] [EAQ][Network][Acceptable]
             idle: [....30] [ip4][..udp] [.......10.8.0.1][33356] -> [.200.194.149.66][.6000] [EAQ][Network][Acceptable]
             idle: [....15] [ip4][..udp] [.......10.8.0.1][47714] -> [.200.194.129.68][.6000] [EAQ][Network][Acceptable]
             idle: [....29] [ip4][..udp] [.......10.8.0.1][60013] -> [.200.194.136.67][.6000] [EAQ][Network][Acceptable]
             idle: [.....8] [ip4][..udp] [.......10.8.0.1][43641] -> [.200.194.148.68][.6000] [EAQ][Network][Acceptable]
             idle: [.....3] [ip4][..udp] [.......10.8.0.1][52257] -> [200.185.138.146][.6000] [EAQ][Network][Acceptable]
             idle: [....20] [ip4][..udp] [.......10.8.0.1][56128] -> [.200.194.133.66][.6000] [EAQ][Network][Acceptable]
             idle: [....24] [ip4][..udp] [.......10.8.0.1][43934] -> [.200.194.136.68][.6000] [EAQ][Network][Acceptable]
             idle: [....16] [ip4][..udp] [.......10.8.0.1][43979] -> [.200.194.132.66][.6000] [EAQ][Network][Acceptable]
             idle: [....27] [ip4][..udp] [.......10.8.0.1][50175] -> [.200.194.149.67][.6000] [EAQ][Network][Acceptable]
             idle: [....13] [ip4][..udp] [.......10.8.0.1][37985] -> [.200.194.129.67][.6000] [EAQ][Network][Acceptable]
             idle: [....31] [ip4][..udp] [.......10.8.0.1][40058] -> [.200.194.134.67][.6000] [EAQ][Network][Acceptable]
     DAEMON-EVENT: shutdown