(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about Archivos2

IP Address192.168.1.9   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:12:46 2025  -  Sat Jun 14 00:11:02 2025 [Inactive since 8 sec]
MAC Address Network Interface Card (NIC)AC:22:0B:78:A5:3C 
OS NameOS: Windows [Windows XP] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:64 [~0 hop(s)]
Total Data Sent17.1 MBytes/101,212 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent1,146 Pkts
Multicast TrafficSent 121.6 KBytes/1,018 Pkts 
Data Sent Stats
Local 5.8 %
  
Rem 94.2 %
IP vs. Non-IP Sent
IP 96.1 %
  
Non-IP 3.9 %
Total Data Rcvd63.5 MBytes/108,246 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
Local 1.3 %
  
Rem 98.7 %
IP vs. Non-IP Rcvd
IP 99.4 %
  
Non-IP 0.6 %
Sent vs. Rcvd Pkts
Sent 48.3 %
  
Rcvd 51.7 %
Sent vs. Rcvd Data
Sent 21.2 %
  
Rcvd 78.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
12 AM 8.8 KBytes0.3 %32.9 KBytes0.1 %
11 PM 74.6 KBytes2.4 %80.9 KBytes0.2 %
10 PM 52.5 KBytes1.7 %76.9 KBytes0.2 %
9 PM 67.2 KBytes2.2 %73.9 KBytes0.2 %
8 PM 61.0 KBytes2.0 %78.7 KBytes0.2 %
7 PM 80.5 KBytes2.6 %108.9 KBytes0.3 %
6 PM 70.5 KBytes2.3 %75.3 KBytes0.2 %
5 PM 65.9 KBytes2.2 %74.9 KBytes0.2 %
4 PM 63.9 KBytes2.1 %94.9 KBytes0.3 %
3 PM 68.0 KBytes2.2 %102.6 KBytes0.3 %
2 PM 56.1 KBytes1.8 %60.3 KBytes0.2 %
1 PM 65.8 KBytes2.2 %74.0 KBytes0.2 %
12 PM 65.5 KBytes2.1 %77.7 KBytes0.2 %
11 AM 69.9 KBytes2.3 %92.8 KBytes0.3 %
10 AM 55.3 KBytes1.8 %54.9 KBytes0.2 %
9 AM 65.0 KBytes2.1 %77.9 KBytes0.2 %
8 AM 57.6 KBytes1.9 %62.1 KBytes0.2 %
7 AM 63.8 KBytes2.1 %69.0 KBytes0.2 %
6 AM 58.7 KBytes1.9 %54.7 KBytes0.2 %
5 AM 920.0 KBytes30.2 %15.9 MBytes46.0 %
4 AM 753.4 KBytes24.7 %17.0 MBytes49.3 %
3 AM 79.3 KBytes2.6 %119.7 KBytes0.3 %
2 AM 61.0 KBytes2.0 %54.9 KBytes0.2 %
1 AM 65.3 KBytes2.1 %74.8 KBytes0.2 %
Total

 

Packet Statistics

TCP FlagsPkts SentPkts Rcvd
RST|ACK7 165
RST1 23
NULL84 0 

AnomalyPkts Sent toPkts Rcvd from
ICMP Net Unreachable0  7

ARPPacket
Request Sent7,761
Reply Rcvd7,722 (99.5 %)
Reply Sent7,648

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP15.9 MBytes
92%

 

62.6 MBytes
98%

 

UDP532.5 KBytes
3%

 

504.1 KBytes 
ICMP0.0 KBytes  0.8 KBytes 
(R)ARP692.2 KBytes
3%

 

420.2 KBytes 
IGMP7.8 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Unreach07

 

Last Contacted Peers

Sent ToIP Address
client.teamviewer.com 191.235.228.33 
nustal05.advance.com.ar 200.0.243.10 
wns2-bl2p.wns.windows.com 172.172.255.216 
v10.vortex-win.data.microsoft.com 40.79.189.58 
time.windows.com 40.119.6.228 
router14.teamviewer.com 34.151.192.28 
00:24:8C:DE:84:31 Network Card  
Total Contacts2650
Received FromIP Address
9.au.download.windowsupdate.com 186.158.77.50 
client.teamviewer.com 191.235.228.33 
nustal05.advance.com.ar 200.0.243.10 
router14.teamviewer.com 34.151.192.28 
wns2-bl2p.wns.windows.com 172.172.255.216 
00:24:8C:DE:84:31 Network Card  
v10.vortex-win.data.microsoft.com 40.79.189.58 
time.windows.com 40.119.6.228 
Total Contacts1621

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS1,52270.0%62429.0%1,33489.0%16010.0%0.1 ms - 30.0 sec3.2 ms - 969.8 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain533639/499.6 KBytes00:24:8C:DE:84:31 Network Card   
www8037032/48.5 MBytes9.au.download.windowsupdate.com   
ntp123881/41.3 KBytestime.windows.com 881/41.3 KBytestime.windows.com
https443699/20.9 MBytesrouter14.teamviewer.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

761 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
Archivos2 Medium Risk :64894router13.teamviewer.com  HTTP Server :https1.2 MBytes1.2 MBytesWed Jun 11 06:52:46 2025Sat Jun 14 00:11:02 20252 days 17:18:168 sec   SYN ACK PUSH 
Archivos2 Medium Risk :61475client.wns.windows.com  HTTP Server Low Risk :https133.8 KBytes188.7 KBytesFri Jun 13 09:39:38 2025Sat Jun 14 00:10:41 202514:31:0329 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Sat Jun 14 00:11:10 2025 [ntop uptime: 4 days 19:58:24]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)