(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CPA-GAROFALO

IP Address192.168.1.15   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 05:18:33 2025  -  Fri Jun 13 22:45:00 2025 [Inactive since 0 sec]
MAC Address Network Interface Card (NIC)2C:F0:5D:99:7A:79 
OS NameOS: Windows [Windows XP Pro, Windows 2000 Pro] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent1.4 GBytes/8,156,376 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent10,816 Pkts
Multicast TrafficSent 1.1 MBytes/11,013 Pkts 
Data Sent Stats
Local 0.6 %
  
Rem 99.4 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd14.1 GBytes/13,605,579 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 37.5 %
  
Rcvd 62.5 %
Sent vs. Rcvd Data
Sent 9.2 %
  
Rcvd 90.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rejected] [Sent: udp to closed] [Rcvd: rst] [Sent: closed-empty] [Rcvd: port unreac] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
10 PM 3.5 MBytes1.6 %3.5 MBytes0.3 %
9 PM 4.6 MBytes2.1 %7.5 MBytes0.7 %
8 PM 5.0 MBytes2.3 %17.6 MBytes1.5 %
7 PM 4.5 MBytes2.1 %16.3 MBytes1.4 %
6 PM 4.7 MBytes2.1 %5.9 MBytes0.5 %
5 PM 4.7 MBytes2.1 %5.3 MBytes0.5 %
4 PM 4.8 MBytes2.2 %6.8 MBytes0.6 %
3 PM 4.9 MBytes2.2 %17.7 MBytes1.5 %
2 PM 5.0 MBytes2.3 %5.7 MBytes0.5 %
1 PM 5.3 MBytes2.4 %19.1 MBytes1.7 %
12 PM 43.2 MBytes19.6 %344.3 MBytes29.9 %
11 AM 15.9 MBytes7.2 %83.4 MBytes7.2 %
10 AM 16.0 MBytes7.3 %109.3 MBytes9.5 %
9 AM 20.0 MBytes9.1 %129.7 MBytes11.3 %
8 AM 8.8 MBytes4.0 %27.2 MBytes2.4 %
7 AM 14.2 MBytes6.5 %106.6 MBytes9.3 %
6 AM 17.7 MBytes8.0 %144.8 MBytes12.6 %
5 AM 7.9 MBytes3.6 %36.5 MBytes3.2 %
4 AM 4.7 MBytes2.2 %4.9 MBytes0.4 %
3 AM 4.8 MBytes2.2 %4.8 MBytes0.4 %
2 AM 4.8 MBytes2.2 %8.9 MBytes0.8 %
1 AM 4.8 MBytes2.2 %19.4 MBytes1.7 %
12 AM 5.0 MBytes2.3 %8.3 MBytes0.7 %
11 PM 4.9 MBytes2.2 %16.8 MBytes1.5 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted189,462 0 
Established92,830 [49 %] 76
Terminated1,816 0 
Rejected0 [0 %]  26

TCP FlagsPkts SentPkts Rcvd
SYN189,462 0 
RST|ACK31,172 4,114
RST29,708 6,145
NULL350 0 

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port104 10,258
Closed Empty TCP Conn.1,816 0 
ICMP Port Unreachable10,258 130
ICMP Net Unreachable0  11

ARPPacket
Request Sent206
Reply Rcvd98 (47.6 %)
Reply Sent10,878

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP1.3 GBytes
90%

 

14.1 GBytes100
UDP139.1 MBytes
9%

 

26.3 MBytes 
ICMP2.7 MBytes  45.9 KBytes 
ICMPv60.3 KBytes  0.0 KBytes 
IPv60.3 KBytes  0.0 KBytes 
(R)ARP497.9 KBytes  300.2 KBytes 
IGMP1.7 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request7130
Echo Reply0105
Unreach10,258141
Time Exceeded0245

 

Last Contacted Peers

Sent ToIP Address
239.255.255.250 239.255.255.250 
firefox.settings.services.mozilla.com 34.149.100.209 
peoplestack-pa.clients6.google.com 142.250.79.138 
incoming.telemetry.mozilla.org 34.120.208.123 
00:24:8C:DE:84:31 Network Card  
200.69.128.1 200.69.128.1 
edge-chat.instagram.com 31.13.94.51 
e3913.cd.akamaiedge.net 23.54.251.198 
Total Contacts757052
Received FromIP Address
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201 
e3913.cd.akamaiedge.net 23.54.251.198 
00:24:8C:DE:84:31 Network Card  
mail.google.com 142.250.79.133 
firefox.settings.services.mozilla.com 34.149.100.209 
peoplestack-pa.clients6.google.com 142.250.79.138 
incoming.telemetry.mozilla.org 34.120.208.123 
edge-chat.instagram.com 31.13.94.51 
Total Contacts674439

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS67,46754.0%55,78645.0%115,32598.0%1,2601.0%0.0 ms - 234212.7 sec2.6 ms - 138456.9 sec
HTTP00.0%00.0%786100.0%00.0%0.0 ms - 0.0 ms5396.6 sec - 349861.1 sec

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp2169/1.1 KBytes00:24:8C:DE:84:31 Network Card   
domain5338513/26.2 MBytes200.69.128.1   
bootps675/000:24:8C:DE:84:31 Network Card   
bootpc685/000:24:8C:DE:84:31 Network Card   
tftp695/13000:24:8C:DE:84:31 Network Card   
www8063962/870.9 MBytese3913.cd.akamaiedge.net   
ntp12376/3.6 KBytestime.windows.com 12/576time.windows.com
netbios-ns1375/000:24:8C:DE:84:31 Network Card   
netbios-dgm1385/000:24:8C:DE:84:31 Network Card   
snmp1615/000:24:8C:DE:84:31 Network Card   
https44364162/13.6 GBytesincoming.telemetry.mozilla.org   
isakmp5005/000:24:8C:DE:84:31 Network Card   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

P2P Recently Exchanged Files

File Name
  1. <unknown file> Upload 

 

182 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CPA-GAROFALO  VoIP Medium Risk P2P Server :64704polka.typekit.com  HTTP Server :https3.9 KBytes6.3 KBytesFri Jun 13 22:35:18 2025Fri Jun 13 22:44:56 20259:384 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :50320web.whatsapp.com  HTTP Server Low Risk :https312.0 KBytes671.7 KBytesFri Jun 13 13:25:20 2025Fri Jun 13 22:44:52 20259:19:328 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :53303web.whatsapp.com  HTTP Server Low Risk :https247.7 KBytes325.3 KBytesFri Jun 13 13:27:25 2025Fri Jun 13 22:44:53 20259:17:287 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :53710static.cdninstagram.com  HTTP Server Low Risk :https204.5 KBytes198.1 KBytesFri Jun 13 14:20:31 2025Fri Jun 13 22:45:00 20258:24:290 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :54018static.cdninstagram.com  HTTP Server Low Risk :https189.6 KBytes185.2 KBytesFri Jun 13 15:07:17 2025Fri Jun 13 22:45:00 20257:37:430 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64707waa-pa.clients6.google.com  HTTP Server :https5.9 KBytes13.8 KBytesFri Jun 13 22:35:48 2025Fri Jun 13 22:44:42 20258:5418 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64708waa-pa.clients6.google.com  HTTP Server :https46.5 KBytes30.9 KBytesFri Jun 13 22:35:48 2025Fri Jun 13 22:45:00 20259:120 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64736mail.google.com  HTTP Server :https10.3 KBytes7.8 KBytesFri Jun 13 22:40:14 2025Fri Jun 13 22:45:00 20254:460 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64768firefox.settings.services.mozilla.com  HTTP Server :https1.5 KBytes5.2 KBytesFri Jun 13 22:45:00 2025Fri Jun 13 22:45:00 20250 sec0 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49708mtalk.google.com  HTTP Server :https77.2 KBytes187.4 KBytesFri Jun 13 02:02:03 2025Fri Jun 13 22:44:33 202520:42:3027 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64713safebrowsing.googleapis.com  HTTP Server :https18.2 KBytes18.1 KBytesFri Jun 13 22:36:01 2025Fri Jun 13 22:44:51 20258:509 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64705ssl.gstatic.com  HTTP Server :https9.0 KBytes11.1 KBytesFri Jun 13 22:35:21 2025Fri Jun 13 22:44:47 20259:2613 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64696ssl.gstatic.com  HTTP Server :https11.0 KBytes13.4 KBytesFri Jun 13 22:34:23 2025Fri Jun 13 22:44:43 202510:2017 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64698ssl.gstatic.com  HTTP Server :https6.0 KBytes6.7 KBytesFri Jun 13 22:34:51 2025Fri Jun 13 22:44:56 202510:054 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64744ssl.gstatic.com  HTTP Server :https4.2 KBytes4.7 KBytesFri Jun 13 22:41:12 2025Fri Jun 13 22:44:22 20253:1038 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64737signaler-pa.clients6.google.com  HTTP Server :https2.9 KBytes10.9 KBytesFri Jun 13 22:40:16 2025Fri Jun 13 22:44:36 20254:2024 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64750ssl.gstatic.com  HTTP Server :https4.2 KBytes4.7 KBytesFri Jun 13 22:42:42 2025Fri Jun 13 22:44:22 20251:4038 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64757googleads.g.doubleclick.net  HTTP Server :https2.4 KBytes5.2 KBytesFri Jun 13 22:43:47 2025Fri Jun 13 22:44:33 202546 sec27 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64699play.google.com  HTTP Server :https84.8 KBytes34.1 KBytesFri Jun 13 22:34:56 2025Fri Jun 13 22:44:56 202510:004 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64748play.google.com  HTTP Server :https6.4 KBytes9.9 KBytesFri Jun 13 22:42:08 2025Fri Jun 13 22:44:41 20252:3319 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64701prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https24.4 KBytes18.2 KBytesFri Jun 13 22:34:56 2025Fri Jun 13 22:44:41 20259:4519 sec   SYN ACK PUSH 
mail.google.com  HTTP Server :httpsCPA-GAROFALO  VoIP Medium Risk P2P Server :64728800Fri Jun 13 22:42:33 2025Fri Jun 13 22:42:33 20250 sec2:27   ACK 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64715www.googleapis.com  HTTP Server :https24.4 KBytes22.1 KBytesFri Jun 13 22:36:10 2025Fri Jun 13 22:44:47 20258:3713 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49880mtalk.google.com  HTTP Server :https71.1 KBytes94.3 KBytesFri Jun 13 02:26:37 2025Fri Jun 13 22:44:54 202520:18:176 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :52311nos.ns1.ff.avast.com  HTTP Server :https99.6 KBytes144.6 KBytesWed Jun 11 06:53:12 2025Fri Jun 13 22:44:37 20252 days 15:51:2523 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :50411router3.teamviewer.com  HTTP Server :https941.2 KBytes909.6 KBytesWed Jun 11 10:27:48 2025Fri Jun 13 22:44:36 20252 days 12:16:4824 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64759prod-dynamite-prod-02-us-signaler-pa.clients6.google.com  HTTP Server :https1.9 KBytes9.9 KBytesFri Jun 13 22:44:10 2025Fri Jun 13 22:44:55 202545 sec5 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64766aus5.mozilla.org  HTTP Server :https1.3 KBytes5.1 KBytesFri Jun 13 22:44:59 2025Fri Jun 13 22:45:00 20251 sec0 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :49856mtalk.google.com  HTTP Server :https71.1 KBytes96.4 KBytesFri Jun 13 02:23:40 2025Fri Jun 13 22:44:41 202520:21:0119 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64669ss-prod-ue1-ns.aws.adobess.com  HTTP Server :https11.8 KBytes7.8 KBytesFri Jun 13 22:30:35 2025Fri Jun 13 22:43:57 202513:221:03   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64694chat.google.com  HTTP Server :https283.5 KBytes88.9 KBytesFri Jun 13 22:34:07 2025Fri Jun 13 22:45:00 202510:530 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64751espresso-pa.clients6.google.com  HTTP Server :https1.8 KBytes10.1 KBytesFri Jun 13 22:42:56 2025Fri Jun 13 22:44:27 20251:3133 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64752espresso-pa.clients6.google.com  HTTP Server :https4.2 KBytes11.2 KBytesFri Jun 13 22:42:56 2025Fri Jun 13 22:44:27 20251:3133 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64771incoming.telemetry.mozilla.org  HTTP Server :https8.8 KBytes4.5 KBytesFri Jun 13 22:45:00 2025Fri Jun 13 22:45:00 20250 sec0 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :57338client.wns.windows.com  HTTP Server Low Risk :https143.8 KBytes169.6 KBytesFri Jun 13 09:36:20 2025Fri Jun 13 22:44:28 202513:08:0832 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :59413mtalk.google.com  HTTP Server :https73.5 KBytes97.6 KBytesFri Jun 13 01:43:59 2025Fri Jun 13 22:44:48 202521:00:4912 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64761stream-production.avcdn.net  HTTP Server Low Risk :https7818.9 KBytesFri Jun 13 22:44:37 2025Fri Jun 13 22:44:37 20250 sec23 sec   SYN ACK PUSH 
CPA-GAROFALO  VoIP Medium Risk P2P Server :64767ocsp.digicert.com  HTTP Server :www1.1 KBytes2.3 KBytesFri Jun 13 22:44:59 2025Fri Jun 13 22:45:00 20251 sec0 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Fri Jun 13 22:45:00 2025 [ntop uptime: 4 days 18:32:15]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)