nDPI/tests/cfgs/default/result/sites3.pcapng.out
Toni Uhlig 285496d0b9 Add (generic) MsgPack protocol dissector.
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
2025-12-08 17:50:20 +01:00

53 lines
6.3 KiB
Text

DPI Packets (TCP): 38 (7.60 pkts/flow)
Confidence DPI : 5 (flows)
Num dissector calls: 488 (97.60 diss/flow)
LRU cache ookla: 0/0/0 (insert/search/found)
LRU cache bittorrent: 0/0/0 (insert/search/found)
LRU cache stun: 0/0/0 (insert/search/found)
LRU cache tls_cert: 0/2/0 (insert/search/found)
LRU cache mining: 0/0/0 (insert/search/found)
LRU cache msteams: 0/0/0 (insert/search/found)
LRU cache fpc_dns: 0/5/0 (insert/search/found)
Automa host: 6/4 (search/found)
Automa domain: 5/0 (search/found)
Automa tls cert: 0/0 (search/found)
Automa risk mask: 3/0 (search/found)
Automa common alpns: 10/10 (search/found)
Patricia risk mask: 6/0 (search/found)
Patricia risk mask IPv6: 0/0 (search/found)
Patricia risk: 0/0 (search/found)
Patricia risk IPv6: 0/0 (search/found)
Patricia protocols: 7/3 (search/found)
Patricia protocols IPv6: 0/0 (search/found)
Hash malicious ja4: 5/0 (search/found)
Hash malicious sha1: 0/0 (search/found)
Hash TCP fingerprints: 5/5 (search/found)
Hash public domain suffix: 0/0 (search/found)
Hash ja4 custom protos: 5/0 (search/found)
Hash fp custom protos: 5/0 (search/found)
Hash url custom protos: 0/0 (search/found)
TLS 26 10480 1
Blacknut 65 36563 1
Boosteroid 70 53594 1
Rumble 15 3504 1
Espn 14 8798 1
Acceptable 26 10480 1
Fun 164 102459 4
Game 135 90157 2
Streaming 29 12302 2
AdultContent 26 10480 1
JA Host Stats:
IP Address # JA4C
1 192.168.1.126 2
2 192.168.43.159 2
1 TCP 192.168.43.159:19191 <-> 172.67.42.21:443 [proto: 91.108/TLS.Boosteroid][Stack: TLS.Boosteroid][IP: 220/Cloudflare][Encrypted][Confidence: DPI][FPC: 220/Cloudflare, Confidence: IP address][DPI packets: 9][cat: Game/8][Breed: Fun][18 pkts/5432 bytes <-> 52 pkts/48162 bytes][Goodput ratio: 82/94][5.65 sec][Hostname/SNI: cloud.boosteroid.com][(Advertised) ALPNs: h2;http/1.1][TLS Supported Versions: GREASE;TLSv1.3;TLSv1.2][bytes ratio: -0.797 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 392/58 2816/765 785/171][Pkt Len c2s/s2c min/avg/max/stddev: 54/54 302/926 1414/1414 445/606][nDPI Fingerprint: 609e548909eae5913f964632ede9a4a6][TCP Fingerprint: 2_128_64240_6bb88f5575fd/Windows][TLSv1.3][JA4: t13d1516h2_8daaf6152771_d8a2da3f94cd][JA3S: eb1d94daa7e0344597e756a1fb6e7054][ECH: version 0xfe0d][Chrome][Cipher: TLS_AES_128_GCM_SHA256][Plen Bins: 10,4,2,0,2,0,0,0,0,2,0,2,0,0,0,0,2,0,0,2,4,0,0,0,0,4,0,0,0,0,0,2,0,0,0,0,0,0,0,0,0,0,64,0,0,0,0,0]
2 TCP 192.168.43.159:19127 <-> 52.215.125.151:443 [proto: 91.107/TLS.Blacknut][Stack: TLS.Blacknut][IP: 461/AWS_EC2][Encrypted][Confidence: DPI][FPC: 461/AWS_EC2, Confidence: IP address][DPI packets: 8][cat: Game/8][Breed: Fun][24 pkts/13183 bytes <-> 41 pkts/23380 bytes][Goodput ratio: 90/90][12.69 sec][Hostname/SNI: www.blacknut.com][(Advertised) ALPNs: h2;http/1.1][TLS Supported Versions: GREASE;TLSv1.3;TLSv1.2][bytes ratio: -0.279 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 618/83 8607/293 2004/111][Pkt Len c2s/s2c min/avg/max/stddev: 54/54 549/570 1414/1414 588/605][nDPI Fingerprint: 296a44756a75786d601c2159dfcee868][TCP Fingerprint: 2_128_64240_6bb88f5575fd/Windows][TLSv1.3][JA4: t13d1517h2_8daaf6152771_b6f405a00624][JA3S: fcb2d4d0991292272fcb1e464eedfd43][ECH: version 0xfe0d][Chrome][Cipher: TLS_AES_128_GCM_SHA256][Plen Bins: 20,4,2,0,0,2,0,2,7,0,0,2,0,0,0,0,0,0,0,0,2,0,0,0,0,0,4,0,0,0,0,0,0,0,0,11,0,0,0,0,0,0,42,0,0,0,0,0]
3 TCP 192.168.1.126:44490 <-> 185.88.181.3:443 [proto: 91/TLS][Stack: TLS][IP: 0/Unknown][Encrypted][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 6][cat: AdultContent/34][Breed: Acceptable][15 pkts/3429 bytes <-> 11 pkts/7051 bytes][Goodput ratio: 72/90][2.88 sec][Hostname/SNI: xvideos.com][(Advertised) ALPNs: h2;http/1.1][TLS Supported Versions: TLSv1.3;TLSv1.2][bytes ratio: -0.346 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 238/3 2758/17 760/6][Pkt Len c2s/s2c min/avg/max/stddev: 54/66 229/641 1952/2962 476/841][nDPI Fingerprint: e25974c74b2da2d988b131ed95d469a7][TCP Fingerprint: 2_64_64240_2e3cee914fc1/Linux][TLSv1.3][JA4: t13d1715h2_5b57614c22b0_a54fffd0eb61][JA3S: 15af977ce25de452b96affa2addb1036][ECH: version 0xfe0d][Firefox][Cipher: TLS_AES_256_GCM_SHA384][Plen Bins: 18,0,9,0,0,0,0,0,18,0,0,0,0,0,9,0,0,0,9,0,0,0,0,0,0,0,0,0,0,0,0,0,9,0,0,0,0,9,0,0,0,0,0,0,0,0,0,18]
4 TCP 192.168.1.126:52752 <-> 3.124.173.63:443 [proto: 91.466/TLS.Espn][Stack: TLS.Espn][IP: 461/AWS_EC2][Encrypted][Confidence: DPI][FPC: 461/AWS_EC2, Confidence: IP address][DPI packets: 7][cat: Streaming/17][Breed: Fun][8 pkts/2605 bytes <-> 6 pkts/6193 bytes][Goodput ratio: 79/93][0.03 sec][Hostname/SNI: dcf.espn.com][(Advertised) ALPNs: h2;http/1.1][TLS Supported Versions: TLSv1.3;TLSv1.2][bytes ratio: -0.408 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 4/3 13/12 6/5][Pkt Len c2s/s2c min/avg/max/stddev: 66/66 326/1032 1963/2962 620/1087][nDPI Fingerprint: 61dca57aece72df86422af77a906753e][TCP Fingerprint: 2_64_64240_2e3cee914fc1/Linux][TLSv1.3][JA4: t13d1717h2_5b57614c22b0_3cbfd9057e0d][JA3S: 15af977ce25de452b96affa2addb1036][ECH: version 0xfe0d][Firefox][Cipher: TLS_AES_256_GCM_SHA384][Plen Bins: 0,0,33,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0,0,50]
5 TCP 192.168.43.159:19180 <-> 172.98.56.177:443 [proto: 91.446/TLS.Rumble][Stack: TLS.Rumble][IP: 0/Unknown][Encrypted][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 8][cat: Streaming/17][Breed: Fun][8 pkts/2519 bytes <-> 7 pkts/985 bytes][Goodput ratio: 82/60][8.16 sec][Hostname/SNI: wn0.rumble.com][(Advertised) ALPNs: h2;http/1.1][TLS Supported Versions: GREASE;TLSv1.3;TLSv1.2][bytes ratio: 0.438 (Upload)][IAT c2s/s2c min/avg/max/stddev: 0/0 1291/186 6654/414 2404/188][Pkt Len c2s/s2c min/avg/max/stddev: 54/54 315/141 1414/349 465/117][nDPI Fingerprint: 296a44756a75786d601c2159dfcee868][TCP Fingerprint: 2_128_64240_6bb88f5575fd/Windows][TLSv1.3][JA4: t13d1517h2_8daaf6152771_b6f405a00624][JA3S: fcb2d4d0991292272fcb1e464eedfd43][ECH: version 0xfe0d][Chrome][Cipher: TLS_AES_128_GCM_SHA256][Plen Bins: 0,16,16,0,0,0,0,16,0,16,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,0,0,0,0,0]