nDPI/tests/cfgs/default/result/mismatching_hostname.pcap.out
2025-10-22 20:34:29 +02:00

41 lines
2.5 KiB
Text

DPI Packets (TCP): 6 (6.00 pkts/flow)
Confidence DPI : 1 (flows)
Num dissector calls: 1 (1.00 diss/flow)
LRU cache ookla: 0/0/0 (insert/search/found)
LRU cache bittorrent: 0/0/0 (insert/search/found)
LRU cache stun: 0/0/0 (insert/search/found)
LRU cache tls_cert: 0/0/0 (insert/search/found)
LRU cache mining: 0/0/0 (insert/search/found)
LRU cache msteams: 0/0/0 (insert/search/found)
LRU cache fpc_dns: 0/1/0 (insert/search/found)
Automa host: 1/1 (search/found)
Automa domain: 1/0 (search/found)
Automa tls cert: 0/0 (search/found)
Automa risk mask: 0/0 (search/found)
Automa common alpns: 0/0 (search/found)
Patricia risk mask: 0/0 (search/found)
Patricia risk mask IPv6: 0/0 (search/found)
Patricia risk: 0/0 (search/found)
Patricia risk IPv6: 0/0 (search/found)
Patricia protocols: 2/0 (search/found)
Patricia protocols IPv6: 0/0 (search/found)
Hash malicious ja4: 1/0 (search/found)
Hash malicious sha1: 0/0 (search/found)
Hash TCP fingerprints: 1/1 (search/found)
Hash public domain suffix: 0/0 (search/found)
Hash ja4 custom protos: 1/0 (search/found)
Hash fp custom protos: 1/0 (search/found)
Hash url custom protos: 0/0 (search/found)
Facebook 100 39948 1
Fun 100 39948 1
SocialNetwork 100 39948 1
JA Host Stats:
IP Address # JA4C
1 192.168.2.7 1
1 TCP 192.168.2.7:35162 <-> 51.38.65.98:443 [proto: 91.119/TLS.Facebook][Stack: TLS.Facebook][IP: 0/Unknown][Encrypted][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 6][cat: SocialNetwork/6][Breed: Fun][45 pkts/9837 bytes <-> 55 pkts/30111 bytes][Goodput ratio: 70/88][2.40 sec][Hostname/SNI: facebook.com][TLS Supported Versions: TLSv1.3;TLSv1.2][bytes ratio: -0.508 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 58/44 643/679 107/108][Pkt Len c2s/s2c min/avg/max/stddev: 66/66 219/547 1104/1506 237/575][Risk: ** TLS (probably) Not Carrying HTTPS **** Mismatching Protocol with server IP address **][Risk Score: 110][Risk Info: nDPI protocol does not match the server IP address / No ALPN][nDPI Fingerprint: 95bafb19dedbfeb96601f7a5a2e778e7][TCP Fingerprint: 2_64_65535_d876f498b09e/Android][TLSv1.3][JA4: t13d171000_5b57614c22b0_86dd91ae2a36][JA3S: f4febc55ea12b31ae17cfb7e614afda8][Safari][Cipher: TLS_AES_128_GCM_SHA256][Plen Bins: 0,4,27,9,5,2,4,9,0,4,2,0,1,0,0,0,1,1,0,0,0,1,0,0,0,0,2,0,0,0,1,0,1,1,1,0,0,0,0,0,0,1,2,1,0,14,0,0]