(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CPA-GAROFALO

IP Address192.168.1.15   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 05:18:33 2025  -  Sat Jun 14 00:16:15 2025 [Inactive since 1 sec]
MAC Address Network Interface Card (NIC)2C:F0:5D:99:7A:79 
OS NameOS: Windows [Windows XP Pro, Windows 2000 Pro] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent1.4 GBytes/8,184,834 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent10,887 Pkts
Multicast TrafficSent 1.1 MBytes/11,127 Pkts 
Data Sent Stats
Local 0.6 %
  
Rem 99.4 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd14.2 GBytes/13,643,543 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 37.5 %
  
Rcvd 62.5 %
Sent vs. Rcvd Data
Sent 9.2 %
  
Rcvd 90.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rejected] [Sent: udp to closed] [Rcvd: rst] [Sent: closed-empty] [Rcvd: port unreac] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
12 AM 1.5 MBytes0.7 %1.5 MBytes0.1 %
11 PM 4.4 MBytes2.0 %5.6 MBytes0.5 %
10 PM 5.0 MBytes2.3 %16.4 MBytes1.4 %
9 PM 4.6 MBytes2.1 %7.5 MBytes0.7 %
8 PM 5.0 MBytes2.3 %17.6 MBytes1.5 %
7 PM 4.5 MBytes2.1 %16.3 MBytes1.4 %
6 PM 4.7 MBytes2.2 %5.9 MBytes0.5 %
5 PM 4.7 MBytes2.2 %5.3 MBytes0.5 %
4 PM 4.8 MBytes2.2 %6.8 MBytes0.6 %
3 PM 4.9 MBytes2.2 %17.7 MBytes1.5 %
2 PM 5.0 MBytes2.3 %5.7 MBytes0.5 %
1 PM 5.3 MBytes2.5 %19.1 MBytes1.7 %
12 PM 43.2 MBytes19.9 %344.3 MBytes30.1 %
11 AM 15.9 MBytes7.3 %83.4 MBytes7.3 %
10 AM 16.0 MBytes7.4 %109.3 MBytes9.5 %
9 AM 20.0 MBytes9.2 %129.7 MBytes11.3 %
8 AM 8.8 MBytes4.0 %27.2 MBytes2.4 %
7 AM 14.2 MBytes6.6 %106.6 MBytes9.3 %
6 AM 17.7 MBytes8.1 %144.8 MBytes12.6 %
5 AM 7.9 MBytes3.7 %36.5 MBytes3.2 %
4 AM 4.7 MBytes2.2 %4.9 MBytes0.4 %
3 AM 4.8 MBytes2.2 %4.8 MBytes0.4 %
2 AM 4.8 MBytes2.2 %8.9 MBytes0.8 %
1 AM 4.8 MBytes2.2 %19.4 MBytes1.7 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted190,552 0 
Established93,375 [49 %] 76
Terminated1,816 0 
Rejected0 [0 %]  26

TCP FlagsPkts SentPkts Rcvd
SYN190,552 0 
RST|ACK31,408 4,133
RST29,743 6,153
NULL350 0 

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port104 10,364
Closed Empty TCP Conn.1,816 0 
ICMP Port Unreachable10,364 130
ICMP Net Unreachable0  11

ARPPacket
Request Sent206
Reply Rcvd98 (47.6 %)
Reply Sent11,029

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP1.3 GBytes
90%

 

14.1 GBytes100
UDP139.2 MBytes
9%

 

26.4 MBytes 
ICMP2.8 MBytes  45.9 KBytes 
ICMPv60.3 KBytes  0.0 KBytes 
IPv60.3 KBytes  0.0 KBytes 
(R)ARP504.7 KBytes  304.3 KBytes 
IGMP1.7 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request7130
Echo Reply0105
Unreach10,364141
Time Exceeded0245

 

Last Contacted Peers

Sent ToIP Address
play.google.com 142.251.129.46 
200.69.128.1 200.69.128.1 
espresso-pa.clients6.google.com 142.250.79.138 
mtalk.google.com 142.250.0.188 
mail-ads.google.com 142.251.129.165 
prod-dynamite-prod-02-us-signaler-pa.clients6.google.com 172.217.173.234 
media-eze1-1.cdn.whatsapp.net 31.13.94.52 
signaler-pa.clients6.google.com 216.58.202.74 
Total Contacts762717
Received FromIP Address
200.69.128.1 200.69.128.1 
espresso-pa.clients6.google.com 142.250.79.138 
mtalk.google.com 142.250.0.188 
mail-ads.google.com 142.251.129.165 
prod-dynamite-prod-02-us-signaler-pa.clients6.google.com 172.217.173.234 
media-eze1-1.cdn.whatsapp.net 31.13.94.52 
edge.microsoft.com 150.171.28.11 
signaler-pa.clients6.google.com 216.58.202.74 
Total Contacts679994

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS67,73254.0%56,26045.0%116,00898.0%1,2601.0%0.0 ms - 234212.7 sec2.6 ms - 138456.9 sec
HTTP00.0%00.0%795100.0%00.0%0.0 ms - 0.0 ms5396.6 sec - 349861.1 sec

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp2169/1.1 KBytes00:24:8C:DE:84:31 Network Card   
domain5339879/26.3 MBytes200.69.128.1   
bootps675/000:24:8C:DE:84:31 Network Card   
bootpc685/000:24:8C:DE:84:31 Network Card   
tftp695/13000:24:8C:DE:84:31 Network Card   
www8064137/871.0 MBytesncc.avast.com   
ntp12376/3.6 KBytestime.windows.com 12/576time.windows.com
netbios-ns1375/000:24:8C:DE:84:31 Network Card   
netbios-dgm1385/000:24:8C:DE:84:31 Network Card   
snmp1615/000:24:8C:DE:84:31 Network Card   
https44337253/13.6 GBytessignaler-pa.clients6.google.com   
isakmp5005/000:24:8C:DE:84:31 Network Card   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

P2P Recently Exchanged Files

File Name
  1. <unknown file> Upload 

 

436 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CPA-GAROFALO  VoIP Medium Risk P2P Server :65232polka.typekit.com  HTTP Server :https4.8 KBytes7.2 KBytesSat Jun 14 00:00:38 2025Sat Jun 14 00:16:06 202515:2810 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :50320web.whatsapp.com  HTTP Server Low Risk :https349.0 KBytes715.5 KBytesFri Jun 13 13:25:20 2025Sat Jun 14 00:16:13 202510:50:533 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :53303web.whatsapp.com  HTTP Server Low Risk :https284.2 KBytes365.2 KBytesFri Jun 13 13:27:25 2025Sat Jun 14 00:16:01 202510:48:3615 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :53710static.cdninstagram.com  HTTP Server Low Risk :https240.6 KBytes233.0 KBytesFri Jun 13 14:20:31 2025Sat Jun 14 00:16:05 20259:55:3411 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :54018static.cdninstagram.com  HTTP Server Low Risk :https226.1 KBytes220.6 KBytesFri Jun 13 15:07:17 2025Sat Jun 14 00:16:05 20259:08:4811 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65352prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https1.9 KBytes9.9 KBytesSat Jun 14 00:14:09 2025Sat Jun 14 00:15:40 20251:3136 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65327mail.google.com  HTTP Server :https21.0 KBytes12.0 KBytesSat Jun 14 00:10:24 2025Sat Jun 14 00:15:42 20255:1834 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65346prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https1.9 KBytes10.1 KBytesSat Jun 14 00:13:57 2025Sat Jun 14 00:16:12 20252:154 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65348prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https4.1 KBytes11.1 KBytesSat Jun 14 00:13:57 2025Sat Jun 14 00:16:12 20252:154 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65358accounts.google.com  HTTP Server :https6.5 KBytes4.9 KBytesSat Jun 14 00:15:37 2025Sat Jun 14 00:15:37 20250 sec39 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49708mtalk.google.com  HTTP Server :https82.5 KBytes193.9 KBytesFri Jun 13 02:02:03 2025Sat Jun 14 00:16:05 202522:14:0211 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65266ssl.gstatic.com  HTTP Server :https10.7 KBytes13.2 KBytesSat Jun 14 00:04:06 2025Sat Jun 14 00:16:12 202512:064 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65278ssl.gstatic.com  HTTP Server :https12.1 KBytes15.2 KBytesSat Jun 14 00:04:18 2025Sat Jun 14 00:16:11 202511:535 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65295ssl.gstatic.com  HTTP Server :https6.0 KBytes6.7 KBytesSat Jun 14 00:05:37 2025Sat Jun 14 00:15:42 202510:0534 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65340ssl.gstatic.com  HTTP Server :https4.3 KBytes4.7 KBytesSat Jun 14 00:12:42 2025Sat Jun 14 00:15:53 20253:1123 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65360ssl.gstatic.com  HTTP Server :https3.4 KBytes3.5 KBytesSat Jun 14 00:16:12 2025Sat Jun 14 00:16:12 20250 sec4 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65305play.google.com  HTTP Server :https95.8 KBytes33.9 KBytesSat Jun 14 00:06:57 2025Sat Jun 14 00:15:57 20259:0019 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65345googleads.g.doubleclick.net  HTTP Server :https2.4 KBytes5.1 KBytesSat Jun 14 00:13:51 2025Sat Jun 14 00:16:06 20252:1510 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65337play.google.com  HTTP Server :https6.4 KBytes9.7 KBytesSat Jun 14 00:12:27 2025Sat Jun 14 00:16:12 20253:454 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65354signaler-pa.clients6.google.com  HTTP Server :https1.9 KBytes9.9 KBytesSat Jun 14 00:14:33 2025Sat Jun 14 00:16:03 20251:3013 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65307waa-pa.clients6.google.com  HTTP Server :https28.7 KBytes19.6 KBytesSat Jun 14 00:06:57 2025Sat Jun 14 00:15:42 20258:4534 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65279addons-pa.clients6.google.com  HTTP Server :https6.6 KBytes14.5 KBytesSat Jun 14 00:04:22 2025Sat Jun 14 00:15:42 202511:2034 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65280addons-pa.clients6.google.com  HTTP Server :https50.5 KBytes33.8 KBytesSat Jun 14 00:04:22 2025Sat Jun 14 00:16:04 202511:4212 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65355waa-pa.clients6.google.com  HTTP Server :https5.8 KBytes11.1 KBytesSat Jun 14 00:14:57 2025Sat Jun 14 00:15:42 202545 sec34 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65347mail-ads.google.com  HTTP Server :https1.8 KBytes7.0 KBytesSat Jun 14 00:13:57 2025Sat Jun 14 00:16:12 20252:154 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65349mail-ads.google.com  HTTP Server :https5.6 KBytes69.2 KBytesSat Jun 14 00:13:57 2025Sat Jun 14 00:16:13 20252:163 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49880mtalk.google.com  HTTP Server :https76.3 KBytes100.7 KBytesFri Jun 13 02:26:37 2025Sat Jun 14 00:15:40 202521:49:0336 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :52311nos.ns1.ff.avast.com  HTTP Server :https101.9 KBytes148.0 KBytesWed Jun 11 06:53:12 2025Sat Jun 14 00:14:22 20252 days 17:21:101:54   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65335ss-prod-ue1-ns.aws.adobess.com  HTTP Server :https4.3 KBytes5.2 KBytesSat Jun 14 00:12:06 2025Sat Jun 14 00:14:47 20252:411:29   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :50411router3.teamviewer.com  HTTP Server :https965.9 KBytes933.2 KBytesWed Jun 11 10:27:48 2025Sat Jun 14 00:15:31 20252 days 13:47:4345 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65298prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https18.5 KBytes18.5 KBytesSat Jun 14 00:06:01 2025Sat Jun 14 00:16:12 202510:114 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49856mtalk.google.com  HTTP Server :https76.4 KBytes102.9 KBytesFri Jun 13 02:23:40 2025Sat Jun 14 00:16:12 202521:52:324 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65268chat.google.com  HTTP Server :https170.1 KBytes65.6 KBytesSat Jun 14 00:04:08 2025Sat Jun 14 00:16:11 202512:035 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65269chat.google.com  HTTP Server :https156.3 KBytes41.3 KBytesSat Jun 14 00:04:08 2025Sat Jun 14 00:16:08 202512:008 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65302signaler-pa.clients6.google.com  HTTP Server :https18.3 KBytes20.7 KBytesSat Jun 14 00:06:23 2025Sat Jun 14 00:16:15 20259:521 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :57338client.wns.windows.com  HTTP Server Low Risk :https160.1 KBytes188.6 KBytesFri Jun 13 09:36:20 2025Sat Jun 14 00:15:28 202514:39:0848 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :59413mtalk.google.com  HTTP Server :https78.7 KBytes104.1 KBytesFri Jun 13 01:43:59 2025Sat Jun 14 00:15:34 202522:31:3542 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :65338stream-production.avcdn.net  HTTP Server :https96810.4 KBytesSat Jun 14 00:12:41 2025Sat Jun 14 00:14:22 20251:411:54   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Sat Jun 14 00:16:16 2025 [ntop uptime: 4 days 20:03:30]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)