(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CPA-CFUCHILA

IP Address192.168.1.190   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:12:45 2025  -  Fri Jun 13 23:22:33 2025 [Inactive since 17 sec]
MAC Address Network Interface Card (NIC)2C:F0:5D:75:5E:DC 
OS NameOS: Windows [Windows 98 Second Edition] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:64 [~0 hop(s)]
Total Data Sent13.1 GBytes/17,515,513 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent1,883 Pkts
Multicast TrafficSent 460.5 KBytes/2,928 Pkts 
Data Sent Stats
Local 1.4 %
  
Rem 98.6 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd19.1 GBytes/19,393,973 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 47.5 %
  
Rcvd 52.5 %
Sent vs. Rcvd Data
Sent 40.6 %
  
Rcvd 59.4 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] [Rcvd: port unreac] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
11 PM 42.1 KBytes0.0 %44.1 KBytes0.0 %
10 PM 174.1 KBytes0.1 %361.0 KBytes0.0 %
9 PM 163.8 KBytes0.1 %219.4 KBytes0.0 %
8 PM 278.4 KBytes0.2 %538.6 KBytes0.0 %
7 PM 151.8 KBytes0.1 %309.9 KBytes0.0 %
6 PM 219.3 KBytes0.1 %390.9 KBytes0.0 %
5 PM 10.6 MBytes6.2 %34.0 MBytes0.7 %
4 PM 2.4 MBytes1.4 %5.2 MBytes0.1 %
3 PM 1.6 MBytes0.9 %1.2 MBytes0.0 %
2 PM 440.5 KBytes0.3 %629.0 KBytes0.0 %
1 PM 408.5 KBytes0.2 %465.4 KBytes0.0 %
12 PM 483.3 KBytes0.3 %609.5 KBytes0.0 %
11 AM 427.1 KBytes0.2 %1.0 MBytes0.0 %
10 AM 5.7 MBytes3.3 %16.3 MBytes0.3 %
9 AM 200.0 KBytes0.1 %310.6 KBytes0.0 %
8 AM 7.1 MBytes4.2 %42.7 MBytes0.9 %
7 AM 89.4 MBytes52.4 %4.0 GBytes84.7 %
6 AM 16.1 MBytes9.4 %329.2 MBytes6.9 %
5 AM 27.0 MBytes15.8 %241.9 MBytes5.0 %
4 AM 6.9 MBytes4.0 %58.0 MBytes1.2 %
3 AM 196.9 KBytes0.1 %1.0 MBytes0.0 %
2 AM 478.6 KBytes0.3 %308.9 KBytes0.0 %
1 AM 167.0 KBytes0.1 %281.2 KBytes0.0 %
12 AM 211.7 KBytes0.1 %796.2 KBytes0.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted65,627 0 
Established32,246 [49 %] 22
Terminated14 0 

TCP FlagsPkts SentPkts Rcvd
SYN65,627 0 
RST|ACK6,092 2,294
RST1 1,761
NULL406 0 

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port75 0 
Closed Empty TCP Conn.14 0 
ICMP Port Unreachable0  75
ICMP Net Unreachable0  5

ARPPacket
Request Sent2,238
Reply Rcvd2,062 (92.1 %)
Reply Sent7,356

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP13.1 GBytes100% 19.1 GBytes100
UDP29.8 MBytes  11.8 MBytes 
ICMP0.9 KBytes  12.0 KBytes 
ICMPv60.8 KBytes  0.0 KBytes 
IPv60.8 KBytes  0.0 KBytes 
(R)ARP431.0 KBytes  257.7 KBytes 
IGMP5.4 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request90
Echo Reply03
Unreach0107
Time Exceeded06

 

Last Contacted Peers

Sent ToIP Address
wns2-bl2p.wns.windows.com 172.172.255.216 
v10.events.data.microsoft.com 20.42.73.26 
router14.teamviewer.com 188.172.252.70 
easylist-downloads.adblockplus.org 88.221.0.42 
config.teams.microsoft.com 52.123.129.14 
00:24:8C:DE:84:31 Network Card  
ctldl.windowsupdate.com 151.101.218.172 
Total Contacts159477
Received FromIP Address
wns2-bl2p.wns.windows.com 172.172.255.216 
00:24:8C:DE:84:31 Network Card  
v10.events.data.microsoft.com 20.42.73.26 
easylist-downloads.adblockplus.org 23.50.112.225 
router14.teamviewer.com 188.172.252.70 
easylist-downloads.adblockplus.org 88.221.0.42 
config.teams.microsoft.com 52.123.129.14 
ctldl.windowsupdate.com 151.101.218.172 
Total Contacts144896

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS43,45493.0%2,8396.0%42,79598.0%6941.0%0.0 ms - 30.0 sec3.2 ms - 392.4 ms
HTTP00.0%00.0%1354.0%1145.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain5323771/11.9 MBytes00:24:8C:DE:84:31 Network Card   
www805557/13.9 GBytesctldl.windowsupdate.com   
ntp12320/960time.windows.com 20/960time.windows.com
netbios-ns13775/3.7 KBytes00:24:8C:DE:84:31 Network Card 75/3.7 KBytes00:24:8C:DE:84:31 Network Card
https44336881/16.0 GByteswns2-bl2p.wns.windows.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

136 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CPA-CFUCHILA  VoIP Medium Risk :49638ecs.office.com  HTTP Server :https1.5 KBytes7.7 KBytesFri Jun 13 23:22:16 2025Fri Jun 13 23:22:17 20251 sec33 sec   SYN ACK PUSH 
CPA-CFUCHILA  VoIP Medium Risk :49681router14.teamviewer.com  HTTP Server :https868.4 KBytes910.9 KBytesFri Jun 13 06:57:26 2025Fri Jun 13 23:22:07 202516:24:4143 sec   SYN ACK PUSH 
CPA-CFUCHILA  VoIP Medium Risk :49632easylist-downloads.adblockplus.org  HTTP Server :https3.6 KBytes1.8 KBytesFri Jun 13 23:15:31 2025Fri Jun 13 23:22:18 20256:4732 sec   SYN ACK PUSH 
CPA-CFUCHILA  VoIP Medium Risk :62890client.wns.windows.com  HTTP Server Low Risk :https15.9 KBytes21.0 KBytesFri Jun 13 08:55:00 2025Fri Jun 13 23:22:28 202514:27:2822 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Fri Jun 13 23:22:50 2025 [ntop uptime: 4 days 19:10:04]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)