nDPI/tests/cfgs/default/result/custom_fingerprint.pcap.out
2025-10-22 20:34:29 +02:00

41 lines
2.9 KiB
Text

DPI Packets (TCP): 6 (6.00 pkts/flow)
Confidence Match by custom rule: 1 (flows)
Num dissector calls: 1 (1.00 diss/flow)
LRU cache ookla: 0/0/0 (insert/search/found)
LRU cache bittorrent: 0/0/0 (insert/search/found)
LRU cache stun: 0/0/0 (insert/search/found)
LRU cache tls_cert: 0/0/0 (insert/search/found)
LRU cache mining: 0/0/0 (insert/search/found)
LRU cache msteams: 0/0/0 (insert/search/found)
LRU cache fpc_dns: 0/1/0 (insert/search/found)
Automa host: 1/1 (search/found)
Automa domain: 1/0 (search/found)
Automa tls cert: 0/0 (search/found)
Automa risk mask: 1/0 (search/found)
Automa common alpns: 2/2 (search/found)
Patricia risk mask: 2/0 (search/found)
Patricia risk mask IPv6: 0/0 (search/found)
Patricia risk: 0/0 (search/found)
Patricia risk IPv6: 0/0 (search/found)
Patricia protocols: 2/0 (search/found)
Patricia protocols IPv6: 0/0 (search/found)
Hash malicious ja4: 1/0 (search/found)
Hash malicious sha1: 1/0 (search/found)
Hash TCP fingerprints: 1/1 (search/found)
Hash public domain suffix: 0/0 (search/found)
Hash ja4 custom protos: 1/0 (search/found)
Hash fp custom protos: 1/1 (search/found)
Hash url custom protos: 0/0 (search/found)
CustomnDPIFPProto2 22 8476 1
Acceptable 22 8476 1
Chat 22 8476 1
JA Host Stats:
IP Address # JA4C
1 10.0.2.15 1
1 TCP 10.0.2.15:41400 <-> 204.14.73.14:443 [proto: 91.2062/TLS.CustomnDPIFPProto2][Stack: TLS.WhatsApp.CustomnDPIFPProto2][IP: 0/Unknown][ClearText][Confidence: Match by custom rule][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 6][cat: Chat/9][Breed: Acceptable][10 pkts/1672 bytes <-> 12 pkts/6804 bytes][Goodput ratio: 64/90][0.54 sec][Hostname/SNI: whatsapp.com][(Advertised) ALPNs: h2;http/1.1][bytes ratio: -0.605 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 47/25 118/118 54/46][Pkt Len c2s/s2c min/avg/max/stddev: 60/54 167/567 840/1514 231/665][Risk: ** TLS Cert Expired **** TLS Cert Validity Too Long **][Risk Score: 150][Risk Info: TLS Cert lasts 730 days / 29/Oct/2021 12:00:00 - 29/Oct/2023 23:59:59][nDPI Fingerprint: 2d3ea0b7f090060fa1b9f3783362f862][TCP Fingerprint: 2_64_64240_2e3cee914fc1/Linux][TLSv1.2][JA4: t12d1206h2_0cf722e5493e_4bc6cc91817c][ServerNames: *.whatsapp.com,whatsapp.com][JA3S: a704460bd0a887c62e4f462bf1bba96b][Issuer: C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA][Subject: C=US, ST=California, L=Santa Clara, O=WhatsApp, Inc., CN=*.whatsapp.com][Certificate SHA-1: 56:E9:E3:D8:DE:00:63:A7:53:D8:13:A5:46:4A:D2:EA:E9:79:EF:19][Firefox][Validity: 2021-10-29 12:00:00 - 2023-10-29 23:59:59][Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256][Plen Bins: 0,11,0,11,0,11,0,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,22,22,0,0]