(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about client.wns.windows.com

IP Address172.172.255.216 Flag for ISO 3166 code us (from p2c file) [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:56:33 2025  -  Sat Jun 14 00:38:10 2025 [Inactive since 3 sec]
Autonomous System1668
Domainwns.windows.com
Last MAC Address/Router Network Interface Card (NIC)/Router00:24:8C:DE:84:31 
Origin AS1668
Host LocationRemote (outside specified/local subnet)
IP TTL (Time to Live)107:114 [~21 hop(s)]
Total Data Sent8.7 MBytes/36,155 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent0 Pkts
Data Sent Stats
Local 100 %
 
Rem 0 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd6.8 MBytes/55,047 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
Local 100 %
 
Rem 0 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 39.6 %
  
Rcvd 60.4 %
Sent vs. Rcvd Data
Sent 56.0 %
  
Rcvd 44.0 %
Host TypeHTTP Server HTTP Server
Further Host Information[ Whois ] [ ]
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
12 AM 30.3 KBytes2.4 %22.6 KBytes2.2 %
11 PM 30.6 KBytes2.5 %27.3 KBytes2.7 %
10 PM 30.8 KBytes2.5 %27.4 KBytes2.7 %
9 PM 30.6 KBytes2.5 %27.3 KBytes2.7 %
8 PM 30.9 KBytes2.5 %27.4 KBytes2.7 %
7 PM 30.8 KBytes2.5 %27.5 KBytes2.7 %
6 PM 30.8 KBytes2.5 %27.5 KBytes2.7 %
5 PM 36.2 KBytes2.9 %31.4 KBytes3.1 %
4 PM 53.9 KBytes4.3 %40.9 KBytes4.0 %
3 PM 30.8 KBytes2.5 %27.4 KBytes2.7 %
2 PM 36.6 KBytes2.9 %32.9 KBytes3.2 %
1 PM 44.2 KBytes3.5 %40.2 KBytes3.9 %
12 PM 48.3 KBytes3.9 %44.6 KBytes4.4 %
11 AM 51.9 KBytes4.2 %47.0 KBytes4.6 %
10 AM 61.0 KBytes4.9 %54.2 KBytes5.3 %
9 AM 109.6 KBytes8.8 %85.9 KBytes8.4 %
8 AM 95.1 KBytes7.6 %70.5 KBytes6.9 %
7 AM 83.9 KBytes6.7 %65.4 KBytes6.4 %
6 AM 133.2 KBytes10.7 %97.8 KBytes9.6 %
5 AM 70.8 KBytes5.7 %50.1 KBytes4.9 %
4 AM 56.4 KBytes4.5 %41.8 KBytes4.1 %
3 AM 45.5 KBytes3.7 %36.9 KBytes3.6 %
2 AM 36.1 KBytes2.9 %31.8 KBytes3.1 %
1 AM 36.9 KBytes3.0 %32.6 KBytes3.2 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted0  1,590
Established0  792 [50 %]

TCP FlagsPkts SentPkts Rcvd
SYN0  1,590
RST|ACK51 46
RST2 29

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP8.7 MBytes100% 6.8 MBytes100
Protocol Distribution
IP Distribution

 

Last Contacted Peers

Sent ToIP Address
192.168.1.9 192.168.1.9 
70:71:BC:72:1F:5B Network Card  
D8:5E:D3:A4:56:93 Network Card  
D8:5E:D3:D8:79:24 Network Card  
192.168.1.190 192.168.1.190 
70:71:BC:31:71:72 Network Card  
04:D9:F5:32:79:12 Network Card  
0.0.0.0 :: 
Total Contacts4633
Received FromIP Address
192.168.1.9 192.168.1.9 
70:71:BC:72:1F:5B Network Card  
D8:5E:D3:A4:56:93 Network Card  
D8:5E:D3:D8:79:24 Network Card  
192.168.1.190 192.168.1.190 
70:71:BC:31:71:72 Network Card  
04:D9:F5:32:79:12 Network Card  
0.0.0.0 :: 
Total Contacts4596

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
https443  56631/10.6 MBytes04:D9:F5:32:79:12 Network Card

 

TCP/UDP Recently Used Ports

Client PortServer Port
     

 

125 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CPA-FBRECCIA  VoIP Medium Risk P2P Server :50870client.wns.windows.com  HTTP Server Low Risk :https159.7 KBytes188.4 KBytesFri Jun 13 10:06:09 2025Sat Jun 14 00:38:10 202514:32:013 sec   SYN ACK PUSH 
0.0.0.0 Medium Risk :52350client.wns.windows.com  HTTP Server Low Risk :https16.9 KBytes22.1 KBytesFri Jun 13 08:57:13 2025Sat Jun 14 00:35:00 202515:37:473:13   SYN ACK PUSH 
CPATRIBUNAL  VoIP Medium Risk P2P Server :53993client.wns.windows.com  HTTP Server Low Risk :https9.7 KBytes13.3 KBytesFri Jun 13 17:26:48 2025Sat Jun 14 00:37:28 20257:10:4045 sec   SYN ACK PUSH 
Archivos2 Medium Risk :61620client.wns.windows.com  HTTP Server Low Risk :https5.9 KBytes9.5 KBytesSat Jun 14 00:17:09 2025Sat Jun 14 00:38:10 202521:013 sec   SYN ACK PUSH 
CPA-CFUCHILA  VoIP Medium Risk :62890client.wns.windows.com  HTTP Server Low Risk :https17.1 KBytes22.3 KBytesFri Jun 13 08:55:00 2025Sat Jun 14 00:34:13 202515:39:134:00   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Sat Jun 14 00:38:13 2025 [ntop uptime: 4 days 20:25:27]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)