aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/default/vnc.pcap.out
blob: 50653a0da88483a8cb6abe1f409a707ce33e513f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
     DAEMON-EVENT: init
     DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
              new: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900]
         detected: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                   RISK: Known Proto on Non Std Port, Desktop/File Sharing
          analyse: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                                         min|       max|       avg|    stddev|         variance|  entropy
                   [IAT.........: <    0.001|     0.545|     0.058|     0.113|        12857.595|    3.200]
                   [PKTLEN......:     40.000|    75.000|    56.600|    12.800|          163.200|    5.000]
                   [BINS(c->s)..: 12,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 13,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,0,1,0,0,1,0,0,1,0,1,1,1,1,0,0,0,1]
                   [IATS(ms)....: 0.5,38.8,49.9,50.3,38.8,37.1,157.8,7.0,164.5,0.7,37.5,0.2,0.0,36.4,0.0,37.3,1.2,0.0,0.2,0.7,0.0,0.7,0.5,199.0,310.3,0.0,0.1,545.3,0.7,22.3,59.5]
                   [PKTLENS.....: 52,52,46,52,52,48,46,40,59,46,69,74,74,62,46,75,40,74,72,40,68,72,40,63,40,70,68,72,46,46,67,40]
                   [ENTROPIES...: 4.6,4.9,4.6,5.0,5.1,5.0,4.8,4.7,5.3,4.6,5.6,5.6,5.9,5.4,4.6,5.8,4.7,5.8,5.7,4.7,5.7,5.7,4.6,5.6,4.7,5.6,5.6,5.5,4.5,4.5,5.6,4.7]
              new: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900]
         detected: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                   RISK: Known Proto on Non Std Port, Desktop/File Sharing
          analyse: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                                         min|       max|       avg|    stddev|         variance|  entropy
                   [IAT.........: <    0.001|     0.539|     0.054|     0.125|        15641.482|    3.000]
                   [PKTLEN......:     40.000|    75.000|    56.800|    12.600|          158.000|    5.000]
                   [BINS(c->s)..: 13,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 12,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [DIRECTIONS..: 0,1,0,1,0,1,0,1,0,1,1,0,0,1,0,1,0,0,1,0,0,1,0,0,0,1,1,1,1,0,0,0]
                   [IATS(ms)....: 0.1,37.5,48.7,49.6,38.3,36.9,46.4,48.5,45.7,1.7,45.5,0.2,37.4,0.5,0.4,36.8,3.0,39.9,0.8,0.2,0.8,0.8,0.2,0.0,1.0,501.8,0.0,0.7,538.8,0.0,97.7]
                   [PKTLENS.....: 52,52,46,52,52,48,46,40,46,40,59,46,69,74,74,62,46,75,40,74,72,40,68,72,63,40,70,68,72,46,46,67]
                   [ENTROPIES...: 4.5,4.9,4.7,5.0,5.2,5.0,4.7,4.7,4.6,4.7,5.2,4.7,5.6,5.7,5.7,5.5,4.6,5.7,4.7,5.8,5.7,4.6,5.5,5.6,5.4,4.6,5.6,5.5,5.5,4.5,4.6,5.6]
              end: [.....1] [ip4][..tcp] [..95.237.48.208][59791] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                   RISK: Known Proto on Non Std Port, Desktop/File Sharing
             idle: [.....2] [ip4][..tcp] [..95.237.48.208][51559] -> [..192.168.2.110][.6900] [VNC][Unknown][RemoteAccess][Acceptable]
                   RISK: Known Proto on Non Std Port, Desktop/File Sharing
     DAEMON-EVENT: shutdown