(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about 0.0.0.0

IP Address192.168.1.210   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:14:28 2025  -  Sat Jun 14 12:49:43 2025 [Inactive since 1 sec]
MAC Address Network Interface Card (NIC)00:10:18:AC:4A:C4 
Nw Board VendorBROADCOM CORPORATION 
OS NameOS: Windows [Windows XP] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:64 [~0 hop(s)]
Total Data Sent740.0 MBytes/11,401,902 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent29,128 Pkts
Multicast TrafficSent 4.9 KBytes/76 Pkts 
Data Sent Stats
Local 44.1 %
  
Rem 55.9 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd19.2 GBytes/17,972,434 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
Local 3.0 %
  
Rem 97.0 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 38.8 %
  
Rcvd 61.2 %
Sent vs. Rcvd Data
Sent 3.6 %
  
Rcvd 96.4 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
12 PM 4.2 MBytes3.8 %151.5 MBytes4.1 %
11 AM 4.4 MBytes4.0 %152.0 MBytes4.2 %
10 AM 4.5 MBytes4.0 %151.9 MBytes4.2 %
9 AM 4.4 MBytes3.9 %152.1 MBytes4.2 %
8 AM 4.4 MBytes4.0 %151.8 MBytes4.2 %
7 AM 4.6 MBytes4.1 %152.0 MBytes4.2 %
6 AM 4.5 MBytes4.1 %152.0 MBytes4.2 %
5 AM 4.4 MBytes3.9 %151.8 MBytes4.2 %
4 AM 4.6 MBytes4.1 %152.0 MBytes4.2 %
3 AM 4.3 MBytes3.9 %151.9 MBytes4.2 %
2 AM 4.6 MBytes4.1 %152.2 MBytes4.2 %
1 AM 4.6 MBytes4.1 %152.1 MBytes4.2 %
12 AM 4.7 MBytes4.2 %152.2 MBytes4.2 %
11 PM 4.7 MBytes4.2 %152.1 MBytes4.2 %
10 PM 4.5 MBytes4.0 %151.7 MBytes4.2 %
9 PM 4.4 MBytes4.0 %151.8 MBytes4.2 %
8 PM 4.6 MBytes4.1 %151.8 MBytes4.2 %
7 PM 4.6 MBytes4.1 %152.1 MBytes4.2 %
6 PM 4.8 MBytes4.3 %152.3 MBytes4.2 %
5 PM 4.9 MBytes4.4 %152.5 MBytes4.2 %
4 PM 5.0 MBytes4.5 %152.6 MBytes4.2 %
3 PM 5.4 MBytes4.8 %153.3 MBytes4.2 %
2 PM 5.3 MBytes4.8 %153.2 MBytes4.2 %
1 PM 5.1 MBytes4.6 %152.7 MBytes4.2 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted63,901 0 
Established31,936 [50 %] 1
Terminated2 0 

TCP FlagsPkts SentPkts Rcvd
SYN63,901 0 
RST|ACK31,573 11
RST0  158

AnomalyPkts Sent toPkts Rcvd from
Closed Empty TCP Conn.2 0 
ICMP Net Unreachable0  8

ARPPacket
Request Sent20,303
Reply Rcvd16,615 (81.8 %)
Reply Sent5,558

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP405.4 MBytes
54%

 

18.6 GBytes
96%

 

UDP333.4 MBytes
45%

 

603.9 MBytes
3%

 

ICMP0.0 KBytes  0.9 KBytes 
ICMPv60.1 KBytes  0.0 KBytes 
IPv60.1 KBytes  0.0 KBytes 
(R)ARP1.1 MBytes  606.3 KBytes 
IGMP0.6 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Unreach08

 

Last Contacted Peers

Sent ToIP Address
188.172.244.140 188.172.244.140 
autoupdate.wfbs.trendmicro.com 35.167.136.34 
00:24:8C:DE:84:31 Network Card  
e2903.dscb.akamaiedge.net 2.21.48.124 
housecall7-ssa-p.activeupdate.trendmicro.com 23.205.233.55 
time.windows.com 40.119.6.228 
200.0.243.10 200.0.243.10 
Total Contacts1695
Received FromIP Address
ns1.huaweicloud-dns.org 159.138.208.3 
autoupdate.wfbs.trendmicro.com 35.167.136.34 
e2903.dscb.akamaiedge.net 2.21.48.124 
housecall7-ssa-p.activeupdate.trendmicro.com 23.205.233.55 
00:24:8C:DE:84:31 Network Card  
188.172.244.140 188.172.244.140 
time.windows.com 40.119.6.228 
200.0.243.10 200.0.243.10 
Total Contacts1298

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS4,378,69997.0%114,7352.0%116,5242.0%4,375,67197.0%0.0 ms - 23.0 sec3.1 ms - 989.1 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain537197/575.0 MBytes00:24:8C:DE:84:31 Network Card   
www804756/12.6 MByteshousecall7-ssa-p.activeupdate.trendmicro.com   
ntp123258/12.1 KBytestime.windows.com 258/12.1 KBytestime.windows.com
https4439110/17.9 GBytes188.172.244.140   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

129 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
0.0.0.0  VoIP Medium Risk :58257router3.teamviewer.com  HTTP Server :https405.9 KBytes362.6 KBytesFri Jun 13 05:26:28 2025Sat Jun 14 12:48:55 20251 day 7:22:2749 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Sat Jun 14 12:49:44 2025 [ntop uptime: 5 days 8:36:58]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)