(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about 0.0.0.0

IP Address192.168.1.18   [unicast] [ Purge Asset ]
First/Last SeenFri Jun 13 04:48:41 2025  -  Sat Jun 14 00:19:42 2025 [Inactive since 9 sec]
MAC Address Network Interface Card (NIC)D8:5E:D3:A4:56:93 
OS NameOS: Windows [Windows 2000 Professional SP4] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent64.9 MBytes/709,841 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent1,723 Pkts
Multicast TrafficSent 678.1 KBytes/3,808 Pkts 
Data Sent Stats
Local 0.9 %
  
Rem 99.1 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd1.7 GBytes/1,274,515 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 35.8 %
  
Rcvd 64.2 %
Sent vs. Rcvd Data
Sent 3.6 %
  
Rcvd 96.4 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Sent: udp to closed] [Rcvd: rst] [Sent: closed-empty] [Rcvd: port unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
12 AM 77.8 KBytes0.1 %259.1 KBytes0.0 %
11 PM 310.0 KBytes0.5 %3.7 MBytes0.2 %
10 PM 177.2 KBytes0.3 %456.6 KBytes0.0 %
9 PM 167.4 KBytes0.3 %684.7 KBytes0.0 %
8 PM 192.4 KBytes0.3 %939.5 KBytes0.1 %
7 PM 182.7 KBytes0.3 %762.8 KBytes0.0 %
6 PM 418.9 KBytes0.6 %12.8 MBytes0.7 %
5 PM 372.7 KBytes0.6 %745.8 KBytes0.0 %
4 PM 205.6 KBytes0.3 %699.5 KBytes0.0 %
3 PM 162.0 KBytes0.2 %718.1 KBytes0.0 %
2 PM 203.9 KBytes0.3 %839.9 KBytes0.0 %
1 PM 159.1 KBytes0.2 %636.9 KBytes0.0 %
12 PM 229.3 KBytes0.3 %1.2 MBytes0.1 %
11 AM 157.8 KBytes0.2 %723.0 KBytes0.0 %
10 AM 165.4 KBytes0.2 %755.8 KBytes0.0 %
9 AM 174.6 KBytes0.3 %556.6 KBytes0.0 %
8 AM 268.5 KBytes0.4 %2.2 MBytes0.1 %
7 AM 3.5 MBytes5.4 %25.1 MBytes1.4 %
6 AM 8.5 MBytes13.0 %93.5 MBytes5.4 %
5 AM 36.5 MBytes56.2 %1.1 GBytes63.6 %
4 AM 12.9 MBytes19.9 %485.5 MBytes28.0 %
3 AM 00.0 %00.0 %
2 AM 00.0 %00.0 %
1 AM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted9,363 0 
Established4,541 [48 %] 5
Terminated245 0 

TCP FlagsPkts SentPkts Rcvd
SYN9,363 0 
RST|ACK1,772 490
RST998 268
NULL54 0 

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port21 390
Closed Empty TCP Conn.245 0 
ICMP Port Unreachable390 21

ARPPacket
Request Sent384
Reply Rcvd151 (39.3 %)
Reply Sent867

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP61.4 MBytes
94%

 

1.7 GBytes100
UDP3.3 MBytes
5%

 

1.1 MBytes 
ICMP128.3 KBytes  1.5 KBytes 
ICMPv60.1 KBytes  0.0 KBytes 
IPv60.1 KBytes  0.0 KBytes 
(R)ARP56.2 KBytes  27.8 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Unreach39021

 

Last Contacted Peers

Sent ToIP Address
settings-win.data.microsoft.com 20.49.150.241 
settings-win.data.microsoft.com 40.119.249.228 
ncc.avast.com 170.51.241.136 
nos.ns1.ff.avast.com 34.159.51.182 
00:24:8C:DE:84:31 Network Card  
200.69.128.1 200.69.128.1 
stream-production.avcdn.net 170.51.247.41 
Total Contacts11835
Received FromIP Address
200.69.128.1 200.69.128.1 
stream-production.avcdn.net 170.51.247.49 
00:24:8C:DE:84:31 Network Card  
settings-win.data.microsoft.com 20.49.150.241 
settings-win.data.microsoft.com 40.119.249.228 
ncc.avast.com 170.51.241.136 
nos.ns1.ff.avast.com 34.159.51.182 
stream-production.avcdn.net 170.51.247.41 
Total Contacts9946

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS2,49442.0%3,35457.0%3,93699.0%320.0%0.1 ms - 230322.1 sec2.7 ms - 540.4 ms
HTTP00.0%00.0%127100.0%00.0%0.0 ms - 0.0 ms403417.9 sec - 403417.9 sec

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp2114/22100:24:8C:DE:84:31 Network Card   
domain537954/1.1 MBytes200.69.128.1   
bootps671/000:24:8C:DE:84:31 Network Card   
bootpc681/000:24:8C:DE:84:31 Network Card   
tftp691/2600:24:8C:DE:84:31 Network Card   
www8028054/1.0 GBytesncc.avast.com   
ntp12328/1.3 KBytestime.windows.com 4/192time.windows.com
netbios-ns1371/000:24:8C:DE:84:31 Network Card   
netbios-dgm1381/000:24:8C:DE:84:31 Network Card   
snmp1611/000:24:8C:DE:84:31 Network Card   
https4437707/658.0 MBytesstream-production.avcdn.net   
isakmp5001/000:24:8C:DE:84:31 Network Card   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

136 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
0.0.0.0 Medium Risk :51585nos.ns1.ff.avast.com  HTTP Server :https25.8 KBytes39.8 KBytesFri Jun 13 04:48:49 2025Sat Jun 14 00:19:42 202519:30:539 sec   SYN ACK PUSH 
0.0.0.0 Medium Risk :52350client.wns.windows.com  HTTP Server Low Risk :https16.7 KBytes21.9 KBytesFri Jun 13 08:57:13 2025Sat Jun 14 00:18:39 202515:21:261:12   SYN ACK PUSH 
0.0.0.0 Medium Risk :55011ncc.avast.com  HTTP Server Low Risk :https1.2 KBytes2.6 KBytesSat Jun 14 00:19:42 2025Sat Jun 14 00:19:42 20250 sec9 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Sat Jun 14 00:19:51 2025 [ntop uptime: 4 days 20:07:05]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)