1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432]
detected: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] [Nintendo][Unknown][Game][Fun]
new: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955]
detected: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955] [Nintendo][Unknown][Game][Fun]
new: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251]
detected: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251] [Nintendo][Unknown][Game][Fun]
new: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [MIDSTREAM]
detected: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [TLS][AmazonAWS][Web][Safe]
new: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335]
detected: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] [Nintendo][AmazonAWS][Game][Fun]
analyse: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] [Nintendo][Unknown][Game][Fun]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 1.730| 0.194| 0.332| 110172.324| 3.600]
[PKTLEN......: 88.000| 840.000| 153.000| 179.500| 32207.000| 4.500]
[BINS(c->s)..: 0,7,7,1,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,4,8,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,1,0,1,1,0,1,0,1,1,0,1,0,0,1,0,1,1,1,0,0,0,0,0,0,0,0,1,1,1,1]
[IATS(ms)....: 87.9,239.6,335.4,89.8,30.6,131.2,103.3,500.0,507.3,130.9,234.8,19.3,15.8,5.2,16.9,12.6,53.5,8.8,0.2,60.8,14.2,505.6,501.5,5.1,514.4,94.6,0.2,1729.7,0.1,52.6,0.1]
[PKTLENS.....: 88,88,184,216,104,88,136,104,88,104,136,120,104,104,104,840,104,840,88,88,104,88,88,88,88,88,104,104,104,104,104,104]
[ENTROPIES...: 6.1,6.1,6.8,6.9,6.2,6.1,6.7,6.2,6.1,6.3,6.6,6.4,6.2,6.2,6.2,6.3,6.3,5.9,5.8,5.9,6.2,5.9,6.1,6.2,6.0,6.0,6.1,6.1,6.0,6.2,6.2,6.2]
new: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343]
new: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53]
detected: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
detection-update: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
new: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443]
detected: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
new: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] [MIDSTREAM]
new: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334]
new: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025]
new: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335]
new: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53]
detected: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net]
detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net]
detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net]
detection-update: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net]
new: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343]
new: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53]
detected: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
detection-update: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
new: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443]
detected: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
detection-update: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
RISK: TLS (probably) Not Carrying HTTPS
analyse: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [TLS][AmazonAWS][Web][Safe]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 14.019| 1.263| 3.443| 11853821.379| 2.400]
[PKTLEN......: 52.000| 457.000| 120.200| 98.400| 9678.600| 4.600]
[BINS(c->s)..: 8,5,0,5,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 4,6,1,0,0,0,0,0,0,1,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,1,0,1,0,0,0,1,1,0,0,1,0,1,0,1,0,0,0,0,1,1,0,1,0,0,0,1,1,0,0,1]
[IATS(ms)....: 6.3,307.1,3508.7,3481.6,0.2,0.0,276.4,18.5,55.2,0.1,35.7,210.9,214.2,255.3,13944.5,14019.1,0.8,0.1,5.3,332.5,29.9,280.4,254.2,215.7,3.4,13.6,231.1,4.3,259.0,453.5,730.8]
[PKTLENS.....: 152,103,52,119,52,110,99,52,103,152,152,52,52,103,52,457,52,99,386,152,52,103,52,368,52,109,99,52,103,52,152,103]
[ENTROPIES...: 6.5,5.8,5.0,6.0,5.0,6.0,6.0,5.0,5.7,6.6,6.6,5.0,5.1,5.7,5.0,7.5,5.1,6.1,7.4,6.5,5.0,5.8,5.1,7.3,5.1,6.2,6.0,5.1,5.8,5.1,6.7,5.7]
new: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520]
detected: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] [Nintendo][Unknown][Game][Fun]
new: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114]
detected: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable]
new: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066]
detected: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] [Nintendo][Unknown][Game][Fun]
new: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769]
detected: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] [Nintendo][Unknown][Game][Fun]
new: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114]
detected: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable]
analyse: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] [Nintendo][Unknown][Game][Fun]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.754| 0.078| 0.153| 23284.658| 3.200]
[PKTLEN......: 88.000| 872.000| 154.000| 186.200| 34652.000| 4.500]
[BINS(c->s)..: 0,2,18,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,1,0,0,0,0,1,1,1,0,0,1,0,0,1,1,1]
[IATS(ms)....: 0.3,0.4,210.0,0.2,0.4,203.8,0.3,0.2,311.9,2.3,0.2,754.1,1.1,30.7,0.6,242.3,245.6,5.5,2.8,1.9,125.6,0.1,0.0,109.1,0.2,10.7,20.1,10.4,105.8,2.2,28.9]
[PKTLENS.....: 104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,88,104,104,104,104,872,88,872,104,104,88]
[ENTROPIES...: 6.0,6.2,6.0,6.0,6.0,6.0,6.0,6.1,6.0,6.0,6.1,6.1,6.1,6.2,6.0,6.1,6.6,5.9,6.1,6.1,6.7,6.1,6.2,6.3,6.0,6.1,5.6,5.9,5.6,6.1,6.2,5.9]
analyse: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] [Nintendo][Unknown][Game][Fun]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.758| 0.106| 0.188| 35487.695| 3.400]
[PKTLEN......: 88.000| 872.000| 207.000| 231.800| 53743.000| 4.400]
[BINS(c->s)..: 0,3,13,0,1,0,0,0,0,1,0,0,0,2,0,0,0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,2,6,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,1,1,0,0,1,1,0,0,1,1,1,0,0,0,0,0]
[IATS(ms)....: 0.7,2.7,200.8,0.2,0.4,313.8,0.2,0.3,757.9,0.1,245.9,0.2,38.4,0.2,116.7,3.0,25.9,110.5,1.2,79.7,8.0,87.9,10.1,91.9,20.1,506.4,607.1,9.7,10.2,12.9,36.7]
[PKTLENS.....: 104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,168,88,872,88,872,88,104,104,88,344,840,472,472]
[ENTROPIES...: 6.0,6.1,6.0,6.0,6.1,6.0,6.1,6.1,6.1,6.2,6.2,6.1,6.1,6.1,6.2,6.2,6.1,6.7,6.0,6.7,5.9,5.6,6.0,5.6,5.8,6.2,6.2,6.0,7.3,5.8,6.2,6.2]
analyse: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] [Nintendo][Unknown][Game][Fun]
min| max| avg| stddev| variance| entropy
[IAT.........: < 0.001| 0.649| 0.099| 0.184| 33766.533| 3.200]
[PKTLEN......: 88.000| 872.000| 153.500| 186.300| 34709.800| 4.400]
[BINS(c->s)..: 0,3,15,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[BINS(s->c)..: 0,2,8,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
[DIRECTIONS..: 0,0,0,0,0,0,0,0,0,1,1,0,0,0,0,1,0,0,0,0,1,1,1,1,1,1,0,0,1,1,1,0]
[IATS(ms)....: 0.3,0.4,313.5,0.3,0.3,284.3,0.1,0.4,629.4,5.2,43.7,5.3,61.4,0.1,131.6,65.4,7.9,0.2,0.8,31.1,0.4,67.6,2.9,0.5,7.5,105.9,5.7,103.3,9.8,549.4,649.3]
[PKTLENS.....: 104,104,104,104,104,104,104,104,104,104,104,104,104,104,104,168,88,104,104,168,104,104,88,104,104,872,88,872,88,104,104,88]
[ENTROPIES...: 6.1,6.1,6.1,6.0,6.2,6.2,6.2,6.2,6.1,6.0,6.1,6.1,6.1,6.1,6.1,6.7,6.0,6.1,6.2,6.8,6.2,6.2,5.9,6.2,6.2,5.5,5.9,5.6,6.0,6.2,6.1,6.0]
guessed: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343] [AmazonAWS][AmazonAWS][Cloud][Acceptable]
RISK: Susp Entropy, Unidirectional Traffic
idle: [.....6] [ip4][..udp] [.192.168.12.114][52119] -> [..52.10.205.177][34343]
idle: [....20] [ip4][..udp] [.192.168.12.114][55915] -> [..81.61.158.138][51769] [Nintendo][Unknown][Game][Fun]
end: [.....8] [ip4][..tcp] [.192.168.12.114][41517] -> [..54.192.27.217][..443] [TLS.Nintendo][AmazonAWS][Game][Fun]
RISK: TLS (probably) Not Carrying HTTPS
guessed: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343] [AmazonAWS][AmazonAWS][Cloud][Acceptable]
RISK: Susp Entropy, Unidirectional Traffic
idle: [....14] [ip4][..udp] [.192.168.12.114][55915] -> [..52.10.205.177][34343]
idle: [.....5] [ip4][..udp] [.192.168.12.114][52119] -> [...35.158.74.61][33335] [Nintendo][AmazonAWS][Game][Fun]
idle: [....15] [ip4][..udp] [.192.168.12.114][51035] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
idle: [.....7] [ip4][..udp] [.192.168.12.114][18874] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][e0d67c509fb203858ebcb2fe3f88c2aa.baas.nintendo.com]
idle: [.....4] [ip4][..tcp] [..54.187.10.185][..443] -> [.192.168.12.114][48328] [TLS][AmazonAWS][Web][Safe]
guessed: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334] [AmazonAWS][AmazonAWS][Cloud][Acceptable]
RISK: Unidirectional Traffic
idle: [....10] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33334]
guessed: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335] [AmazonAWS][AmazonAWS][Cloud][Acceptable]
RISK: Unidirectional Traffic
idle: [....12] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][33335]
idle: [....21] [ip4][.icmp] [...151.6.184.98] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable]
idle: [....18] [ip4][.icmp] [..151.6.184.100] -> [.192.168.12.114] [ICMP][Unknown][Network][Acceptable]
idle: [.....1] [ip4][..udp] [.192.168.12.114][52119] -> [....91.8.243.35][49432] [Nintendo][Unknown][Game][Fun]
guessed: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025] [AmazonAWS][AmazonAWS][Cloud][Acceptable]
idle: [....11] [ip4][..udp] [.192.168.12.114][55915] -> [...35.158.74.61][10025]
idle: [....19] [ip4][..udp] [.192.168.12.114][55915] -> [.93.237.131.235][56066] [Nintendo][Unknown][Game][Fun]
idle: [.....3] [ip4][..udp] [.192.168.12.114][52119] -> [..109.21.255.11][50251] [Nintendo][Unknown][Game][Fun]
idle: [.....2] [ip4][..udp] [.192.168.12.114][52119] -> [...134.3.248.25][56955] [Nintendo][Unknown][Game][Fun]
end: [....16] [ip4][..tcp] [.192.168.12.114][31329] -> [....54.192.27.8][..443] [TLS.Nintendo][AmazonAWS][Game][Fun]
RISK: TLS (probably) Not Carrying HTTPS
idle: [....17] [ip4][..udp] [.192.168.12.114][55915] -> [.185.118.169.65][27520] [Nintendo][Unknown][Game][Fun]
guessed: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443] [TLS][AmazonAWS][Web][Safe]
idle: [.....9] [ip4][..tcp] [.192.168.12.114][11534] -> [..54.146.242.74][..443]
idle: [....13] [ip4][..udp] [.192.168.12.114][10184] -> [...192.168.12.1][...53] [DNS.Nintendo][Unknown][Network][Fun][g2df33d01-lp1.p.srv.nintendo.net]
DAEMON-EVENT: shutdown
|