blob: 903014f48ad6bbb15ecf7e274cbb227a9726b632 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
|
DAEMON-EVENT: init
DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
new: [.....1] [ip4][..tcp] [..172.18.82.242][41986] -> [..172.18.82.243][...80]
detected: [.....1] [ip4][..tcp] [..172.18.82.242][41986] -> [..172.18.82.243][...80] [HTTP.WebSocket][Unknown][Web][Acceptable][something1.tld]
RISK: Obfuscated Traffic
new: [.....2] [ip4][..tcp] [..172.18.82.243][...80] -> [..172.18.82.242][51634] [MIDSTREAM]
detected: [.....2] [ip4][..tcp] [..172.18.82.243][...80] -> [..172.18.82.242][51634] [HTTP.WebSocket][Unknown][Web][Acceptable][]
RISK: HTTP Susp User-Agent
detection-update: [.....2] [ip4][..tcp] [..172.18.82.243][...80] -> [..172.18.82.242][51634] [HTTP.WebSocket][Unknown][Web][Acceptable][]
RISK: HTTP Susp User-Agent, Unidirectional Traffic
idle: [.....1] [ip4][..tcp] [..172.18.82.242][41986] -> [..172.18.82.243][...80] [HTTP.WebSocket][Unknown][Web][Acceptable][something1.tld]
RISK: Obfuscated Traffic
idle: [.....2] [ip4][..tcp] [..172.18.82.243][...80] -> [..172.18.82.242][51634] [HTTP.WebSocket][Unknown][Web][Acceptable]
RISK: HTTP Susp User-Agent, Unidirectional Traffic
DAEMON-EVENT: shutdown
|