(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CONSULTORIA

IP Address192.168.1.91   [unicast] [ Purge Asset ]
First/Last SeenWed Jul 16 05:58:38 2025  -  Wed Jul 16 13:29:34 2025 [Inactive since 12 sec]
MAC Address Network Interface Card (NIC)D8:43:AE:BB:DB:6C 
OS NameOS: Windows [Windows 2000 Professional SP4] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent19.5 MBytes/196,778 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent33 Pkts
Multicast TrafficSent 222.9 KBytes/1,381 Pkts 
Data Sent Stats
0 %
 
Rem 100 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd476.4 MBytes/350,443 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 36.0 %
  
Rcvd 64.0 %
Sent vs. Rcvd Data
Sent 3.9 %
  
Rcvd 96.1 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
1 PM 48.2 KBytes0.2 %58.9 KBytes0.0 %
12 PM 176.9 KBytes0.9 %356.9 KBytes0.1 %
11 AM 156.6 KBytes0.8 %267.7 KBytes0.1 %
10 AM 294.9 KBytes1.5 %7.1 MBytes1.5 %
9 AM 186.4 KBytes0.9 %2.3 MBytes0.5 %
8 AM 126.3 KBytes0.6 %281.3 KBytes0.1 %
7 AM 248.7 KBytes1.2 %320.0 KBytes0.1 %
6 AM 17.1 MBytes88.0 %448.6 MBytes94.2 %
5 AM 1.1 MBytes5.8 %17.2 MBytes3.6 %
4 AM 00.0 %00.0 %
3 AM 00.0 %00.0 %
2 AM 00.0 %00.0 %
1 AM 00.0 %00.0 %
12 AM 00.0 %00.0 %
11 PM 00.0 %00.0 %
10 PM 00.0 %00.0 %
9 PM 00.0 %00.0 %
8 PM 00.0 %00.0 %
7 PM 00.0 %00.0 %
6 PM 00.0 %00.0 %
5 PM 00.0 %00.0 %
4 PM 00.0 %00.0 %
3 PM 00.0 %00.0 %
2 PM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted3,133 0 
Established1,549 [49 %] 0 

TCP FlagsPkts SentPkts Rcvd
SYN3,133 0 
RST|ACK314 27
RST0  27

AnomalyPkts Sent toPkts Rcvd from
ICMP Net Unreachable0  131

ARPPacket
Request Sent103
Reply Rcvd84 (81.6 %)
Reply Sent574

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP17.6 MBytes
90%

 

476.1 MBytes100
UDP1.8 MBytes
9%

 

251.7 KBytes 
ICMP0.0 KBytes  13.8 KBytes 
(R)ARP30.4 KBytes  18.0 KBytes 
IGMP0.4 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Unreach0131

 

Last Contacted Peers

Sent ToIP Address
ecs.office.com 52.123.128.14 
224.0.0.251 224.0.0.251 
router16.teamviewer.com 34.151.192.21 
mtalk.google.com 142.251.0.188 
download.windowsupdate.com 109.61.38.38 
00:24:8C:DE:84:31 Network Card  
client.wns.windows.com 4.207.247.137 
nf.smartscreen.microsoft.com 20.201.52.37 
Total Contacts1941
Received FromIP Address
bigben-gi-1-1-10-3736-13-acr02.vta.embratel.net.br 200.241.211.30 
00:24:8C:DE:84:31 Network Card  
ecs.office.com 52.123.128.14 
download.windowsupdate.com 109.61.38.38 
mtalk.google.com 142.251.0.188 
client.wns.windows.com 4.207.247.137 
router16.teamviewer.com 34.151.192.21 
nf.smartscreen.microsoft.com 20.201.52.37 
Total Contacts1510

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS84551.0%80848.0%81195.0%364.0%0.0 ms - 1.6 sec3.7 ms - 3.7 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain531825/253.8 KBytes00:24:8C:DE:84:31 Network Card   
www8022039/298.2 MBytesdownload.windowsupdate.com   
ntp1234/192time.windows.com 4/192time.windows.com
https443875/165.0 MBytesmtalk.google.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

346 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CONSULTORIA Medium Risk :59874router16.teamviewer.com  HTTP Server :https188.6 KBytes208.7 KBytesWed Jul 16 05:58:44 2025Wed Jul 16 13:28:57 20257:30:1349 sec   SYN ACK PUSH 
CONSULTORIA Medium Risk :59857client.wns.windows.com  HTTP Server :https10.7 KBytes14.5 KBytesWed Jul 16 05:58:40 2025Wed Jul 16 13:28:29 20257:29:491:17   SYN ACK PUSH 
CONSULTORIA Medium Risk :61426mtalk.google.com  HTTP Server :https26.4 KBytes38.3 KBytesWed Jul 16 06:33:08 2025Wed Jul 16 13:29:29 20256:56:2117 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Wed Jul 16 13:29:46 2025 [ntop uptime: 2 days 9:17:10]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include only interface "eth0"