(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about CPATRIBUNAL

IP Address192.168.1.27   [unicast] [ Purge Asset ]
First/Last SeenMon Jun 9 04:48:26 2025  -  Fri Jun 13 22:53:47 2025 [Inactive since 1 sec]
MAC Address Network Interface Card (NIC)70:71:BC:72:1F:5B 
OS NameOS: Windows [Windows XP Pro, Windows 2000 Pro] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent1.6 GBytes/8,042,808 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent165,847 Pkts
Multicast TrafficSent 1.3 MBytes/3,014 Pkts 
Data Sent Stats
Local 0.8 %
  
Rem 99.2 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd13.2 GBytes/13,509,767 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 37.3 %
  
Rcvd 62.7 %
Sent vs. Rcvd Data
Sent 10.9 %
  
Rcvd 89.1 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  4. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] [Rcvd: hostnet unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
10 PM 2.1 MBytes0.8 %1.5 MBytes0.1 %
9 PM 2.3 MBytes0.8 %1.1 MBytes0.1 %
8 PM 2.2 MBytes0.8 %1.1 MBytes0.1 %
7 PM 2.2 MBytes0.8 %1.0 MBytes0.1 %
6 PM 2.2 MBytes0.8 %1.0 MBytes0.1 %
5 PM 2.6 MBytes0.9 %11.6 MBytes0.6 %
4 PM 2.2 MBytes0.8 %1020.0 KBytes0.0 %
3 PM 8.1 MBytes2.9 %281.7 MBytes14.1 %
2 PM 2.2 MBytes0.8 %1.1 MBytes0.1 %
1 PM 2.2 MBytes0.8 %1.0 MBytes0.1 %
12 PM 6.6 MBytes2.4 %75.2 MBytes3.8 %
11 AM 13.3 MBytes4.8 %83.6 MBytes4.2 %
10 AM 22.9 MBytes8.3 %114.0 MBytes5.7 %
9 AM 30.0 MBytes10.8 %130.3 MBytes6.5 %
8 AM 16.3 MBytes5.9 %49.2 MBytes2.5 %
7 AM 33.8 MBytes12.2 %244.6 MBytes12.2 %
6 AM 45.3 MBytes16.4 %384.4 MBytes19.2 %
5 AM 59.5 MBytes21.4 %379.5 MBytes19.0 %
4 AM 5.5 MBytes2.0 %38.7 MBytes1.9 %
3 AM 2.3 MBytes0.8 %1.1 MBytes0.1 %
2 AM 2.3 MBytes0.8 %1.0 MBytes0.1 %
1 AM 2.3 MBytes0.8 %1.0 MBytes0.1 %
12 AM 6.7 MBytes2.4 %194.4 MBytes9.7 %
11 PM 2.2 MBytes0.8 %1.1 MBytes0.1 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted175,101 0 
Established86,811 [50 %] 77
Terminated458 0 

TCP FlagsPkts SentPkts Rcvd
SYN175,101 0 
RST|ACK15,825 962
RST0  1,995
NULL99 0 

AnomalyPkts Sent toPkts Rcvd from
Closed Empty TCP Conn.458 0 
ICMP Net Unreachable0  5

ARPPacket
Request Sent162,909
Reply Rcvd29 (0.0 %)
Reply Sent7,071

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP1.5 GBytes
95%

 

13.2 GBytes100
UDP71.7 MBytes
4%

 

19.7 MBytes 
ICMP3.3 KBytes  3.5 KBytes 
ICMPv60.2 KBytes  0.0 KBytes 
IPv60.2 KBytes  0.0 KBytes 
(R)ARP7.5 MBytes  194.1 KBytes 
IGMP0.8 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request320
Echo Reply010
Unreach05
Time Exceeded022

 

Last Contacted Peers

Sent ToIP Address
clientservices.googleapis.com 142.250.79.99 
waa-pa.clients6.google.com 142.251.129.106 
ssl.gstatic.com 142.251.128.131 
play.google.com 216.58.202.78 
safebrowsing.googleapis.com 142.251.128.42 
router7.teamviewer.com 188.172.244.142 
peoplestack-pa.clients6.google.com 142.250.79.138 
Total Contacts552127
Received FromIP Address
play.google.com 216.58.202.78 
mail.google.com 142.251.129.101 
00:24:8C:DE:84:31 Network Card  
clientservices.googleapis.com 142.250.79.99 
waa-pa.clients6.google.com 142.251.129.106 
ssl.gstatic.com 142.251.128.131 
safebrowsing.googleapis.com 142.251.128.42 
peoplestack-pa.clients6.google.com 142.250.79.138 
Total Contacts458087

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS51,15956.0%40,10743.0%88,98699.0%8920.0%0.0 ms - 187743.7 sec2.7 ms - 1.7 sec
HTTP00.0%00.0%1100.0%00.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain5350091/19.6 MBytes00:24:8C:DE:84:31 Network Card   
www8046218/1.4 GBytesctldl.windowsupdate.com   
snmp1612/84192.168.1.75   
https44364077/12.3 GBytesplay.google.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

P2P Recently Exchanged Files

File Name
  1. <unknown file> Upload Download 

 

131 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
CPATRIBUNAL  VoIP Medium Risk P2P Server :54435waa-pa.clients6.google.com  HTTP Server :https87.5 KBytes50.3 KBytesFri Jun 13 22:23:47 2025Fri Jun 13 22:53:41 202529:547 sec   SYN ACK PUSH 
CPATRIBUNAL  VoIP Medium Risk P2P Server :54475chat.google.com  HTTP Server :https25.2 KBytes9.1 KBytesFri Jun 13 22:53:30 2025Fri Jun 13 22:53:47 202517 sec1 sec   SYN ACK PUSH 
CPATRIBUNAL  VoIP Medium Risk P2P Server :57730mtalk.google.com  HTTP Server :https72.6 KBytes95.5 KBytesFri Jun 13 02:34:05 2025Fri Jun 13 22:53:07 202520:19:0241 sec   SYN ACK PUSH 
CPATRIBUNAL  VoIP Medium Risk P2P Server :52458router8.teamviewer.com  HTTP Server :https1008.7 KBytes988.3 KBytesWed Jun 11 06:52:50 2025Fri Jun 13 22:53:25 20252 days 16:00:3523 sec   SYN ACK PUSH 
CPATRIBUNAL  VoIP Medium Risk P2P Server :53993client.wns.windows.com  HTTP Server Low Risk :https8.2 KBytes11.4 KBytesFri Jun 13 17:26:48 2025Fri Jun 13 22:51:07 20255:24:192:41   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Fri Jun 13 22:53:48 2025 [ntop uptime: 4 days 18:41:02]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include all interfaces (merged)