(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about 0.0.0.0

IP Address192.168.1.24   [unicast] [ Purge Asset ]
First/Last SeenMon Jul 14 04:55:44 2025  -  Wed Jul 16 14:38:11 2025 [Inactive since 3 sec]
MAC Address Network Interface Card (NIC)D8:5E:D3:A4:58:68 
OS NameOS: Windows [Windows 2000 Professional SP4] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent61.0 MBytes/328,662 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent581 Pkts
Multicast TrafficSent 1.0 MBytes/6,514 Pkts 
Data Sent Stats
Local 1.6 %
  
Rem 98.4 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd446.1 MBytes/454,391 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
Local 0.6 %
  
Rem 99.4 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 42.0 %
  
Rcvd 58.0 %
Sent vs. Rcvd Data
Sent 12.0 %
  
Rcvd 88.0 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] [Rcvd: port unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
2 PM 300.9 KBytes0.9 %594.4 KBytes0.3 %
1 PM 538.9 KBytes1.7 %1.2 MBytes0.6 %
12 PM 581.3 KBytes1.8 %1.4 MBytes0.7 %
11 AM 471.8 KBytes1.5 %1.1 MBytes0.5 %
10 AM 483.9 KBytes1.5 %1.0 MBytes0.5 %
9 AM 599.0 KBytes1.9 %1.6 MBytes0.8 %
8 AM 5.9 MBytes19.1 %20.1 MBytes9.9 %
7 AM 1.4 MBytes4.5 %4.6 MBytes2.3 %
6 AM 7.7 MBytes24.7 %54.5 MBytes26.7 %
5 AM 4.7 MBytes15.1 %36.3 MBytes17.8 %
4 AM 521.3 KBytes1.6 %1.1 MBytes0.5 %
3 AM 456.7 KBytes1.4 %700.3 KBytes0.3 %
2 AM 415.1 KBytes1.3 %637.9 KBytes0.3 %
1 AM 498.0 KBytes1.6 %1.9 MBytes0.9 %
12 AM 502.8 KBytes1.6 %920.4 KBytes0.4 %
11 PM 448.7 KBytes1.4 %978.5 KBytes0.5 %
10 PM 548.4 KBytes1.7 %1.6 MBytes0.8 %
9 PM 1.9 MBytes6.3 %65.9 MBytes32.3 %
8 PM 424.8 KBytes1.3 %817.7 KBytes0.4 %
7 PM 446.4 KBytes1.4 %801.7 KBytes0.4 %
6 PM 862.6 KBytes2.7 %1.2 MBytes0.6 %
5 PM 637.6 KBytes2.0 %3.5 MBytes1.7 %
4 PM 460.2 KBytes1.4 %903.0 KBytes0.4 %
3 PM 465.5 KBytes1.5 %822.3 KBytes0.4 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted19,614 0 
Established9,419 [48 %] 5
Terminated664 0 

TCP FlagsPkts SentPkts Rcvd
SYN19,614 0 
RST|ACK5,034 1,529
RST4 687
NULL159 0 

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port66 0 
Closed Empty TCP Conn.664 0 
ICMP Port Unreachable0  66

ARPPacket
Request Sent253
Reply Rcvd38 (15.0 %)
Reply Sent4,541

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP55.6 MBytes
91%

 

442.7 MBytes
99%

 

UDP5.3 MBytes
8%

 

3.3 MBytes 
ICMP0.0 KBytes  4.7 KBytes 
ICMPv60.1 KBytes  0.0 KBytes 
IPv60.1 KBytes  0.0 KBytes 
(R)ARP215.4 KBytes  125.2 KBytes 
IGMP0.3 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Unreach066

 

Last Contacted Peers

Sent ToIP Address
www.youtube.com 142.251.128.142 
mtalk.google.com 64.233.190.188 
00:24:8C:DE:84:31 Network Card  
safebrowsing.googleapis.com 172.217.28.10 
client.wns.windows.com 4.145.79.80 
224.0.0.251 224.0.0.251 
settings-win.data.microsoft.com 20.44.239.154 
settings-win.data.microsoft.com 13.71.55.58 
Total Contacts26855
Received FromIP Address
www.youtube.com 142.251.128.142 
safebrowsing.googleapis.com 172.217.28.10 
nos.ns1.ff.avast.com 35.230.116.55 
00:24:8C:DE:84:31 Network Card  
stream-production.avcdn.net 170.51.241.11 
200.69.128.1 200.69.128.1 
settings-win.data.microsoft.com 20.44.239.154 
settings-win.data.microsoft.com 13.71.55.58 
Total Contacts22668

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS8,39955.0%6,80044.0%11,82999.0%620.0%0.0 ms - 80726.6 sec2.5 ms - 576.8 ms
HTTP00.0%00.0%365100.0%00.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp2142/66300:24:8C:DE:84:31 Network Card   
domain5323912/3.3 MBytes00:24:8C:DE:84:31 Network Card   
bootps673/000:24:8C:DE:84:31 Network Card   
bootpc683/000:24:8C:DE:84:31 Network Card   
tftp693/7800:24:8C:DE:84:31 Network Card   
www8023882/109.3 MBytesstream-production.avcdn.net   
ntp12338/1.8 KBytestime.windows.com 14/672time.windows.com
netbios-ns1373/000:24:8C:DE:84:31 Network Card   
netbios-dgm1383/000:24:8C:DE:84:31 Network Card   
snmp1613/000:24:8C:DE:84:31 Network Card   
https44331709/351.8 MByteswww.youtube.com   
isakmp5003/000:24:8C:DE:84:31 Network Card   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

508 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
0.0.0.0  VoIP Medium Risk :54327client.wns.windows.com  HTTP Server Low Risk :https115.6 KBytes157.4 KBytesWed Jul 16 04:56:10 2025Wed Jul 16 14:37:17 20259:41:0757 sec   SYN ACK PUSH 
0.0.0.0  VoIP Medium Risk :49727nos.ns1.ff.avast.com  HTTP Server :https90.0 KBytes131.5 KBytesMon Jul 14 04:56:11 2025Wed Jul 16 14:36:00 20252 days 9:39:492:14   SYN ACK PUSH 
0.0.0.0  VoIP Medium Risk :58225play.google.com  HTTP Server Low Risk :https8.5 KBytes5.4 KBytesWed Jul 16 14:33:27 2025Wed Jul 16 14:38:11 20254:443 sec   SYN ACK PUSH 
0.0.0.0  VoIP Medium Risk :62102mtalk.google.com  HTTP Server :https21.2 KBytes32.0 KBytesWed Jul 16 09:08:18 2025Wed Jul 16 14:37:37 20255:29:1937 sec   SYN ACK PUSH 
0.0.0.0  VoIP Medium Risk :58226ncc.avast.com  HTTP Server :https1.2 KBytes2.9 KBytesWed Jul 16 14:36:20 2025Wed Jul 16 14:36:20 20250 sec1:54   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Wed Jul 16 14:38:14 2025 [ntop uptime: 2 days 10:25:38]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include only interface "eth0"