(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CPA-FBRECCIA

IP Address192.168.1.16   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:12:46 2025  -  Fri Jun 13 23:22:49 2025 [Inactive since 0 sec]
MAC Address Network Interface Card (NIC)04:D9:F5:32:79:12 
OS NameOS: Windows [Windows XP Pro, Windows 2000 Pro] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent1.5 GBytes/7,285,695 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent4,647 Pkts
Multicast TrafficSent 1.0 MBytes/6,514 Pkts 
Data Sent Stats
0 %
 
Rem 100 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd11.7 GBytes/11,247,505 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 39.3 %
  
Rcvd 60.7 %
Sent vs. Rcvd Data
Sent 11.2 %
  
Rcvd 88.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
11 PM 1.6 MBytes0.6 %1.0 MBytes0.1 %
10 PM 4.1 MBytes1.4 %2.8 MBytes0.1 %
9 PM 4.4 MBytes1.5 %2.9 MBytes0.1 %
8 PM 4.0 MBytes1.4 %2.7 MBytes0.1 %
7 PM 4.1 MBytes1.4 %3.1 MBytes0.1 %
6 PM 4.7 MBytes1.6 %3.1 MBytes0.2 %
5 PM 4.3 MBytes1.5 %2.9 MBytes0.1 %
4 PM 4.4 MBytes1.5 %2.8 MBytes0.1 %
3 PM 6.0 MBytes2.1 %33.0 MBytes1.6 %
2 PM 5.5 MBytes1.9 %7.3 MBytes0.4 %
1 PM 7.2 MBytes2.5 %47.5 MBytes2.3 %
12 PM 18.1 MBytes6.1 %261.5 MBytes12.8 %
11 AM 11.4 MBytes3.9 %137.8 MBytes6.7 %
10 AM 71.5 MBytes24.3 %274.5 MBytes13.4 %
9 AM 15.6 MBytes5.3 %90.2 MBytes4.4 %
8 AM 11.0 MBytes3.7 %46.9 MBytes2.3 %
7 AM 25.6 MBytes8.7 %584.1 MBytes28.6 %
6 AM 30.1 MBytes10.2 %322.9 MBytes15.8 %
5 AM 30.3 MBytes10.3 %197.1 MBytes9.6 %
4 AM 7.0 MBytes2.4 %3.3 MBytes0.2 %
3 AM 5.9 MBytes2.0 %3.3 MBytes0.2 %
2 AM 5.8 MBytes2.0 %3.1 MBytes0.2 %
1 AM 5.8 MBytes2.0 %6.0 MBytes0.3 %
12 AM 5.6 MBytes1.9 %3.1 MBytes0.2 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted114,814 0 
Established55,415 [48 %] 47
Terminated197 0 

TCP FlagsPkts SentPkts Rcvd
SYN114,814 0 
RST|ACK9,646 910
RST0  3,683
NULL762 0 

AnomalyPkts Sent toPkts Rcvd from
Closed Empty TCP Conn.197 0 
ICMP Net Unreachable0  17

ARPPacket
Request Sent376
Reply Rcvd78 (20.7 %)
Reply Sent11,396

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP1.4 GBytes
93%

 

11.7 GBytes100
UDP91.7 MBytes
6%

 

12.3 MBytes 
ICMP80.1 KBytes  40.5 KBytes 
ICMPv60.1 KBytes  0.0 KBytes 
IPv60.1 KBytes  0.0 KBytes 
(R)ARP528.8 KBytes  313.7 KBytes 
IGMP0.4 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request7740
Echo Reply0113
Unreach017
Time Exceeded0273

 

Last Contacted Peers

Sent ToIP Address
waa-pa.clients6.google.com 142.251.129.106 
play.google.com 216.58.202.78 
peoplestack-pa.clients6.google.com 142.251.129.170 
ssl.gstatic.com 142.251.128.131 
00:24:8C:DE:84:31 Network Card  
business.facebook.com 31.13.94.19 
ss-prod-ue1-ns.aws.adobess.com 52.87.25.189 
mtalk.google.com 172.217.192.188 
Total Contacts400760
Received FromIP Address
waa-pa.clients6.google.com 142.251.129.106 
play.google.com 216.58.202.78 
ss-prod-ue1-ns.aws.adobess.com 52.87.25.189 
peoplestack-pa.clients6.google.com 142.251.129.170 
ssl.gstatic.com 142.251.128.131 
00:24:8C:DE:84:31 Network Card  
business.facebook.com 31.13.94.19 
mtalk.google.com 172.217.192.188 
Total Contacts356624

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS27,18940.0%39,23459.0%62,35099.0%4770.0%0.0 ms - 366986.4 sec2.7 ms - 196910.0 sec
HTTP00.0%00.0%18100.0%00.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain5361440/12.2 MBytes00:24:8C:DE:84:31 Network Card   
www806175/1.7 GBytesctldl.windowsupdate.com   
ntp1236/288time.windows.com 6/288time.windows.com
https4437015/10.5 GBytesss-prod-ue1-ns.aws.adobess.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

P2P Recently Exchanged Files

File Name
  1. <unknown file> Upload 

 

135 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562794040Fri Jun 13 23:11:41 2025Fri Jun 13 23:11:41 20250 sec11:08   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562804040Fri Jun 13 23:11:42 2025Fri Jun 13 23:11:42 20250 sec11:07   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562854040Fri Jun 13 23:12:52 2025Fri Jun 13 23:12:52 20250 sec9:57   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562864040Fri Jun 13 23:12:53 2025Fri Jun 13 23:12:53 20250 sec9:56   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562904040Fri Jun 13 23:14:41 2025Fri Jun 13 23:14:41 20250 sec8:08   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562924040Fri Jun 13 23:14:41 2025Fri Jun 13 23:14:41 20250 sec8:08   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562934040Fri Jun 13 23:15:46 2025Fri Jun 13 23:15:46 20250 sec7:03   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562954040Fri Jun 13 23:15:57 2025Fri Jun 13 23:15:57 20250 sec6:52   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562984040Fri Jun 13 23:17:02 2025Fri Jun 13 23:17:02 20250 sec5:47   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :562994040Fri Jun 13 23:17:09 2025Fri Jun 13 23:17:09 20250 sec5:40   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563024040Fri Jun 13 23:18:12 2025Fri Jun 13 23:18:12 20250 sec4:37   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563034040Fri Jun 13 23:18:41 2025Fri Jun 13 23:18:41 20250 sec4:08   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563064040Fri Jun 13 23:19:41 2025Fri Jun 13 23:19:41 20250 sec3:08   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563084040Fri Jun 13 23:19:51 2025Fri Jun 13 23:19:51 20250 sec2:58   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563134040Fri Jun 13 23:20:56 2025Fri Jun 13 23:20:56 20250 sec1:53   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563144040Fri Jun 13 23:20:58 2025Fri Jun 13 23:20:58 20250 sec1:51   ACK 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563164040Fri Jun 13 23:22:41 2025Fri Jun 13 23:22:41 20250 sec8 sec   ACK 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56317business.facebook.com  VoIP HTTP Server Low Risk :https5.0 KBytes5.3 KBytesFri Jun 13 23:22:41 2025Fri Jun 13 23:22:41 20250 sec8 sec   SYN ACK PUSH 
business.facebook.com  VoIP HTTP Server Low Risk :httpsCPA-FBRECCIA  VoIP Medium Risk P2P Server :563184040Fri Jun 13 23:22:41 2025Fri Jun 13 23:22:41 20250 sec8 sec   ACK 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56315array816.prod.do.dsp.mp.microsoft.com  HTTP Server :https1.8 KBytes3.4 KBytesFri Jun 13 23:21:37 2025Fri Jun 13 23:21:38 20251 sec1:11   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56251ssl.gstatic.com  HTTP Server :https28.4 KBytes36.7 KBytesFri Jun 13 23:05:28 2025Fri Jun 13 23:22:37 202517:0912 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56262ssl.gstatic.com  HTTP Server :https14.2 KBytes17.3 KBytesFri Jun 13 23:06:39 2025Fri Jun 13 23:22:47 202516:082 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56266prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https35.4 KBytes17.4 KBytesFri Jun 13 23:07:41 2025Fri Jun 13 23:22:26 202514:4523 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56259www.googleapis.com  HTTP Server :https11.0 KBytes10.5 KBytesFri Jun 13 23:06:22 2025Fri Jun 13 23:22:11 202515:4938 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56260www.googleapis.com  HTTP Server :https64.9 KBytes64.6 KBytesFri Jun 13 23:06:22 2025Fri Jun 13 23:22:44 202516:225 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56310hbrt.adobe.com  HTTP Server :https2080Fri Jun 13 23:19:59 2025Fri Jun 13 23:20:13 202514 sec2:36   SYN 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56307polka.typekit.com  HTTP Server :https2.9 KBytes5.3 KBytesFri Jun 13 23:19:48 2025Fri Jun 13 23:22:36 20252:4813 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56312accounts.google.com  HTTP Server Low Risk :https6.5 KBytes5.3 KBytesFri Jun 13 23:20:52 2025Fri Jun 13 23:22:22 20251:3027 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56252chat.google.com  HTTP Server :https455.4 KBytes168.3 KBytesFri Jun 13 23:05:29 2025Fri Jun 13 23:22:42 202517:137 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56253chat.google.com  HTTP Server :https304.1 KBytes93.5 KBytesFri Jun 13 23:05:29 2025Fri Jun 13 23:22:41 202517:128 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :62274mtalk.google.com  HTTP Server :https82.9 KBytes228.5 KBytesFri Jun 13 02:56:59 2025Fri Jun 13 23:22:47 202520:25:482 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :50870client.wns.windows.com  HTTP Server Low Risk :https146.1 KBytes172.6 KBytesFri Jun 13 10:06:09 2025Fri Jun 13 23:22:10 202513:16:0139 sec   SYN ACK PUSH 
CPA-FBRECCIA  VoIP Medium Risk P2P Server :56281ss-prod-ue1-ns.aws.adobess.com  HTTP Server :https23.0 KBytes27.9 KBytesFri Jun 13 23:12:31 2025Fri Jun 13 23:22:49 202510:180 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Fri Jun 13 23:22:49 2025 [ntop uptime: 4 days 19:10:03]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)