(C) 1998-2007 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about Tribunal01

IP Address192.168.1.27   [unicast] [ Purge Asset ]
First/Last SeenMon Jul 14 04:47:49 2025  -  Wed Jul 16 15:49:15 2025 [Inactive since 1 sec]
MAC Address Network Interface Card (NIC)D8:43:AE:BB:DE:41 
OS NameOS: Windows [Windows 2000 Professional SP4] 
Host LocationLocal (inside specified/local subnet)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent594.1 MBytes/3,122,689 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent12,030 Pkts
Multicast TrafficSent 2.4 MBytes/31,440 Pkts 
Data Sent Stats
Local 0.7 %
  
Rem 99.3 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd4.2 GBytes/4,735,182 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 39.7 %
  
Rcvd 60.3 %
Sent vs. Rcvd Data
Sent 12.2 %
  
Rcvd 87.8 %
Used Subnet Routers 00:24:8C:DE:84:31 Network Card
Host TypeVoIP Host VoIP
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Sent: closed-empty] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
3 PM 1.8 MBytes0.6 %1.2 MBytes0.1 %
2 PM 2.2 MBytes0.8 %1.4 MBytes0.1 %
1 PM 2.2 MBytes0.8 %3.3 MBytes0.2 %
12 PM 9.9 MBytes3.6 %77.3 MBytes3.7 %
11 AM 8.5 MBytes3.1 %94.3 MBytes4.5 %
10 AM 32.4 MBytes11.8 %238.4 MBytes11.3 %
9 AM 18.5 MBytes6.8 %215.7 MBytes10.2 %
8 AM 38.8 MBytes14.2 %284.8 MBytes13.4 %
7 AM 31.4 MBytes11.5 %289.6 MBytes13.7 %
6 AM 36.1 MBytes13.2 %543.2 MBytes25.7 %
5 AM 39.0 MBytes14.3 %222.8 MBytes10.5 %
4 AM 22.8 MBytes8.3 %109.7 MBytes5.2 %
3 AM 2.4 MBytes0.9 %1.3 MBytes0.1 %
2 AM 2.4 MBytes0.9 %1.3 MBytes0.1 %
1 AM 2.4 MBytes0.9 %3.4 MBytes0.2 %
12 AM 2.5 MBytes0.9 %1.3 MBytes0.1 %
11 PM 2.5 MBytes0.9 %1.5 MBytes0.1 %
10 PM 2.4 MBytes0.9 %1.3 MBytes0.1 %
9 PM 2.4 MBytes0.9 %3.4 MBytes0.2 %
8 PM 2.5 MBytes0.9 %1.4 MBytes0.1 %
7 PM 2.4 MBytes0.9 %1.4 MBytes0.1 %
6 PM 2.3 MBytes0.8 %1.2 MBytes0.1 %
5 PM 3.3 MBytes1.2 %15.9 MBytes0.8 %
4 PM 2.5 MBytes0.9 %2.1 MBytes0.1 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted49,390 0 
Established23,908 [48 %] 48
Terminated123 0 

TCP FlagsPkts SentPkts Rcvd
SYN49,390 0 
RST|ACK5,282 367
RST0  713

AnomalyPkts Sent toPkts Rcvd from
Closed Empty TCP Conn.123 0 

ARPPacket
Request Sent200
Reply Rcvd4 (2.0 %)
Reply Sent5,886

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP562.1 MBytes
94%

 

4.2 GBytes100
UDP31.8 MBytes
5%

 

9.7 MBytes 
ICMP1.3 KBytes  0.7 KBytes 
ICMPv60.1 KBytes  0.0 KBytes 
IPv60.1 KBytes  0.0 KBytes 
(R)ARP273.4 KBytes  161.1 KBytes 
IGMP0.4 KBytes  0.0 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request130
Echo Reply02
Time Exceeded05

 

Last Contacted Peers

Sent ToIP Address
google.com 172.217.28.14 
play.google.com 142.251.128.142 
jnn-pa.googleapis.com 142.251.134.202 
mtalk.google.com 64.233.190.188 
client.wns.windows.com 172.211.123.249 
router6.teamviewer.com 34.151.192.17 
chat.google.com 142.251.128.78 
00:24:8C:DE:84:31 Network Card  
Total Contacts265038
Received FromIP Address
google.com 172.217.28.14 
jnn-pa.googleapis.com 142.251.134.202 
clientservices.googleapis.com 142.251.128.99 
00:24:8C:DE:84:31 Network Card  
mtalk.google.com 64.233.190.188 
client.wns.windows.com 172.211.123.249 
router6.teamviewer.com 34.151.192.17 
chat.google.com 142.251.128.78 
Total Contacts229705

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS34,55066.0%17,10833.0%34,72799.0%730.0%0.0 ms - 1.6 sec3.4 ms - 219.7 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain535064/9.8 MBytes00:24:8C:DE:84:31 Network Card   
www8052441/249.5 MBytesocsp.digicert.com   
ntp12314/672time.windows.com 14/672time.windows.com
snmp1611/78192.168.1.75   
https44356442/4.1 GByteschat.google.com   

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

P2P Recently Exchanged Files

File Name
  1. <unknown file> Download 

 

335 Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveLatencyL7 ProtoNote
Tribunal01  VoIP Medium Risk P2P Server :52700client.wns.windows.com  HTTP Server Low Risk :https8.4 KBytes11.7 KBytesWed Jul 16 10:05:32 2025Wed Jul 16 15:49:11 20255:43:395 sec   SYN ACK PUSH 
Tribunal01  VoIP Medium Risk P2P Server :54531chat.google.com  HTTP Server Low Risk :https6.3 KBytes3.2 KBytesWed Jul 16 15:49:15 2025Wed Jul 16 15:49:15 20250 sec1 sec   SYN ACK PUSH 
Tribunal01  VoIP Medium Risk P2P Server :54475peoplestack-pa.clients6.google.com  HTTP Server :https115.6 KBytes64.1 KBytesWed Jul 16 15:19:19 2025Wed Jul 16 15:49:13 202529:543 sec   SYN ACK PUSH 
Tribunal01  VoIP Medium Risk P2P Server :54397mtalk.google.com  HTTP Server :https206.5 KBytes260.8 KBytesMon Jul 14 04:50:01 2025Wed Jul 16 15:49:09 20252 days 10:59:087 sec   SYN ACK PUSH 
Tribunal01  VoIP Medium Risk P2P Server :54162router6.teamviewer.com  HTTP Server :https1.1 MBytes1.1 MBytesMon Jul 14 04:48:06 2025Wed Jul 16 15:49:15 20252 days 11:01:091 sec   SYN ACK PUSH 
Tribunal01  VoIP Medium Risk P2P Server :54530google.com  HTTP Server :https3.8 KBytes3.6 KBytesWed Jul 16 15:49:15 2025Wed Jul 16 15:49:15 20250 sec1 sec   SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes  

Report created on Wed Jul 16 15:49:16 2025 [ntop uptime: 2 days 11:36:40]
Generated by ntop v.3.3 [x86_64-unknown-linux-gnu]
© 1998-2007 by Luca Deri, built: Aug 6 2008 09:54:10.
Listening on [eth0] for all packets (i.e. without a filtering expression)
Web reports include only interface "eth0"