aboutsummaryrefslogtreecommitdiff
path: root/test/results/flow-info/exe_download.pcap.out
blob: 68b804d984ee63cab0dbeccf5ec3cb30eafb626d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
     DAEMON-EVENT: init
     DAEMON-EVENT: [Processed: 0 pkts][ZLib][compressions: 0|diff: 0 / 0]
     DAEMON-EVENT: [Flows][active: 0 / 0|skipped: 0|!detected: 0|guessed: 0|detection-updates: 0|updates: 0]
              new: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] 
         detected: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Web][Acceptable]
                   RISK: HTTP Suspicious User-Agent, HTTP Numeric IP Address
 detection-update: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Download][Acceptable]
                   RISK: Binary App Transfer, HTTP Suspicious User-Agent, HTTP Numeric IP Address
          analyse: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Download][Acceptable]
                   [min|max|avg|stddev|variance|entropy]
                   [IAT.........:     0.000|    0.320|    0.062|    0.115|13236.602|    0.000]
                   [PKTLEN......:    54.000| 1514.000|  868.500|  668.400|446708.300|    4.400]
                   [BINS(c->s)..: 10,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
                   [BINS(s->c)..: 2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,1,0,0,2,0,0,8,0,0,7,0,0]
                   [DIRECTIONS..: 0,1,0,0,1,1,1,0,1,1,0,1,1,1,0,1,1,1,0,0,1,1,1,1,0,1,0,1,1,1,1,0]
                   [IATS........: 319320,319527,656,1120,298136,10,298579,1555,147,1842,2428,2695,9,4969,246,28639,114,28917,100748,305805,34,11,94,205204,207,207,651,10,7,7,727,0]
                   [PKTLENS.....: 66,58,54,207,54,1514,1322,54,1418,1418,54,1418,1514,1302,54,1418,1418,1418,54,54,1514,1514,1226,1418,54,1418,54,1514,1514,1514,1130,54]
              end: [.....1] [ip4][..tcp] [....10.9.25.101][49165] -> [..144.91.69.195][...80] [HTTP][Download][Acceptable]
                   RISK: Binary App Transfer, HTTP Suspicious User-Agent, HTTP Numeric IP Address
     DAEMON-EVENT: shutdown