(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about DESKTOP-SJRG11G

IP Address192.168.1.14   [unicast] [ Purge Asset ]
First/Last SeenFri Jun 13 12:37:01 2025  -  Fri Jun 13 23:06:22 2025 [Inactive since 12 sec]
MAC Address Network Interface Card (NIC)70:71:BC:72:1F:8B 
OS NameOS: Windows [Windows XP Professional, Build 2600] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:64 [~0 hop(s)]
Total Data Sent12.0 MBytes/40,877 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent869 Pkts
Multicast TrafficSent 18.9 KBytes/79 Pkts 
Data Sent Stats
Local 1.4 %
  
Rem 98.6 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd62.1 MBytes/59,252 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 40.8 %
  
Rcvd 59.2 %
Sent vs. Rcvd Data
Sent 16.2 %
  
Rcvd 83.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
11 PM 4.1 KBytes0.0 %7.9 KBytes0.0 %
10 PM 89.6 KBytes0.7 %137.3 KBytes0.2 %
9 PM 92.8 KBytes0.8 %152.2 KBytes0.2 %
8 PM 1.0 MBytes8.7 %34.3 MBytes55.3 %
7 PM 81.4 KBytes0.7 %125.6 KBytes0.2 %
6 PM 73.3 KBytes0.6 %120.1 KBytes0.2 %
5 PM 63.1 KBytes0.5 %146.8 KBytes0.2 %
4 PM 76.2 KBytes0.6 %136.9 KBytes0.2 %
3 PM 65.6 KBytes0.5 %133.2 KBytes0.2 %
2 PM 98.9 KBytes0.8 %217.3 KBytes0.3 %
1 PM 64.5 KBytes0.5 %129.1 KBytes0.2 %
12 PM 10.2 MBytes85.6 %26.5 MBytes42.6 %
11 AM 00.0 %00.0 %
10 AM 00.0 %00.0 %
9 AM 00.0 %00.0 %
8 AM 00.0 %00.0 %
7 AM 00.0 %00.0 %
6 AM 00.0 %00.0 %
5 AM 00.0 %00.0 %
4 AM 00.0 %00.0 %
3 AM 00.0 %00.0 %
2 AM 00.0 %00.0 %
1 AM 00.0 %00.0 %
12 AM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted1,356 0 
Established673 [50 %] 0 

TCP FlagsPkts SentPkts Rcvd
SYN1,356 0 
RST|ACK164 75
RST0  6

ARPPacket
Request Sent67
Reply Rcvd51 (76.1 %)
Reply Sent300

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP11.3 MBytes
94%

 

61.9 MBytes100
UDP665.9 KBytes
5%

 

214.8 KBytes 
ICMP8.6 KBytes  3.7 KBytes 
(R)ARP16.5 KBytes  9.4 KBytes 
IGMP0.3 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request830
Echo Reply011
Time Exceeded027

 

Last Contacted Peers

Sent ToIP Address
config.edge.skype.com 13.107.42.16 
00:24:8C:DE:84:31 Network Card  
crl.verisign.com 23.54.251.67 
array816.prod.do.dsp.mp.microsoft.com 52.137.125.63 
client.wns.windows.com 172.172.255.218 
ecs.office.com 52.123.129.14 
stream-production.avcdn.net 170.51.247.33 
Total Contacts1395
Received FromIP Address
v10.events.data.microsoft.com 20.189.173.28 
config.edge.skype.com 13.107.42.16 
00:24:8C:DE:84:31 Network Card  
crl.verisign.com 23.54.251.67 
array816.prod.do.dsp.mp.microsoft.com 52.137.125.63 
client.wns.windows.com 172.172.255.218 
ecs.office.com 52.123.129.14 
stream-production.avcdn.net 170.51.247.33 
Total Contacts1011

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS61875.0%19724.0%79699.0%20.0%0.0 ms - 766.0 ms2.9 ms - 465.2 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain531600/215.3 KBytes00:24:8C:DE:84:31 Network Card   
www8023862/32.5 MBytesstream-production.avcdn.net   
snmp16115/1.1 KBytes192.168.1.150   
https44336552/36.0 MBytesclient.wns.windows.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

138 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
DESKTOP-SJRG11G Medium Risk :52204client.wns.windows.com  HTTP Server Low Risk :https12.9 KBytes17.1 KBytesFri Jun 13 12:37:07 2025Fri Jun 13 23:03:14 202510:26:073:20   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Fri Jun 13 23:06:34 2025 [ntop uptime: 4 days 18:53:48]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)