mirror of
https://github.com/vel21ripn/nDPI.git
synced 2026-04-28 15:09:47 +00:00
36 lines
2.1 KiB
Text
36 lines
2.1 KiB
Text
DPI Packets (TCP): 11 (11.00 pkts/flow)
|
|
Confidence DPI : 1 (flows)
|
|
Num dissector calls: 215 (215.00 diss/flow)
|
|
LRU cache ookla: 0/0/0 (insert/search/found)
|
|
LRU cache bittorrent: 0/0/0 (insert/search/found)
|
|
LRU cache stun: 0/0/0 (insert/search/found)
|
|
LRU cache tls_cert: 0/0/0 (insert/search/found)
|
|
LRU cache mining: 0/0/0 (insert/search/found)
|
|
LRU cache msteams: 0/0/0 (insert/search/found)
|
|
LRU cache fpc_dns: 0/1/0 (insert/search/found)
|
|
Automa host: 2/0 (search/found)
|
|
Automa domain: 1/0 (search/found)
|
|
Automa tls cert: 0/0 (search/found)
|
|
Automa risk mask: 1/0 (search/found)
|
|
Automa common alpns: 0/0 (search/found)
|
|
Patricia risk mask: 2/0 (search/found)
|
|
Patricia risk mask IPv6: 0/0 (search/found)
|
|
Patricia risk: 0/0 (search/found)
|
|
Patricia risk IPv6: 0/0 (search/found)
|
|
Patricia protocols: 2/0 (search/found)
|
|
Patricia protocols IPv6: 0/0 (search/found)
|
|
Hash malicious ja4: 0/0 (search/found)
|
|
Hash malicious sha1: 0/0 (search/found)
|
|
Hash TCP fingerprints: 1/0 (search/found)
|
|
Hash public domain suffix: 0/0 (search/found)
|
|
Hash ja4 custom protos: 0/0 (search/found)
|
|
Hash fp custom protos: 0/0 (search/found)
|
|
Hash url custom protos: 0/0 (search/found)
|
|
|
|
SMTP 95 23157 1
|
|
|
|
Acceptable 95 23157 1
|
|
|
|
Email 95 23157 1
|
|
|
|
1 TCP 194.7.248.153:2127 <-> 172.16.114.207:25 [proto: 3/SMTP][Stack: SMTP][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 0/Unknown, Confidence: Unknown][DPI packets: 11][cat: Email/3][Breed: Acceptable][51 pkts/19311 bytes <-> 44 pkts/3846 bytes][Goodput ratio: 86/37][0.23 sec][Hostname/SNI: pigeon.eyrie.af.mil][bytes ratio: 0.668 (Upload)][IAT c2s/s2c min/avg/max/stddev: 1/1 5/6 67/68 12/15][Pkt Len c2s/s2c min/avg/max/stddev: 60/60 379/87 1514/138 562/15][Risk: ** Malicious Fingerprint **][Risk Score: 100][Risk Info: Unusual TCP fingerprint (scanner detected?)][TCP Fingerprint: 2_64_512_6bbe28597824/Unknown][PLAIN TEXT (220 pigeon.eyrie.af.mil ESMTP S)][Plen Bins: 8,78,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,1,0,0,0,0,0,0,0,0,0,0,10,0,0]
|