(C) 1998-2008 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about host

IP Address163.30.63.129 Flag for ISO 3166 code tw (from p2c file) [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenThu Sep 18 00:00:13 2025  -  Thu Sep 18 10:56:41 2025 [Inactive since 1 sec]
Autonomous System3462
Subnet163.30.63.128/25
Domaintw
MAC Address Network Interface Card (NIC)00:26:18:2C:75:E2 
Origin AS3462
Host LocationLocal (inside specified/local subnet or known network list)
IP TTL (Time to Live)64:64 [~0 hop(s)]
Total Data Sent926/4 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent0 Pkts
Data Sent Stats
Local 9.1 %
  
Rem 90.9 %
IP vs. Non-IP Sent
IP 90.9 %
  
Non-IP 9.1 %
Total Data Rcvd18.8 MBytes/143,553 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
0 %
 
Rcvd 100 %
Sent vs. Rcvd Data
0 %
 
Rcvd 100 %
Used Subnet Routers 00:5D:73:14:1A:C1 Network Card
Host TypePrinter Printer
SMTP (Mail) Server Mail (SMTP)
POP Server 
IMAP Server 
FTP Server 
HTTP Server HTTP Server
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Rcvd: port unreac] [Rcvd: admin prohib] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
10 AM 87094.0 %2.3 MBytes12.2 %
9 AM 00.0 %2.2 MBytes11.6 %
8 AM 00.0 %3.6 MBytes18.9 %
7 AM 00.0 %2.5 MBytes13.5 %
6 AM 283.0 %1.8 MBytes9.6 %
5 AM 00.0 %1.2 MBytes6.6 %
4 AM 00.0 %873.0 KBytes4.5 %
3 AM 00.0 %1.3 MBytes6.7 %
2 AM 283.0 %960.0 KBytes5.0 %
1 AM 00.0 %1.0 MBytes5.4 %
12 AM 00.0 %1.1 MBytes6.0 %
11 PM 00.0 %00.0 %
10 PM 00.0 %00.0 %
9 PM 00.0 %00.0 %
8 PM 00.0 %00.0 %
7 PM 00.0 %00.0 %
6 PM 00.0 %00.0 %
5 PM 00.0 %00.0 %
4 PM 00.0 %00.0 %
3 PM 00.0 %00.0 %
2 PM 00.0 %00.0 %
1 PM 00.0 %00.0 %
12 PM 00.0 %00.0 %
11 AM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted21 19,692
Established21 [100 %] 13,609 [69 %]

TCP FlagsPkts SentPkts Rcvd
SYN21 19,692
RST|ACK0  1,008
RST0  4,441
NULL0  10

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port12 0 
TCP Pkt Disgnostic Port0  1
Tiny Fragments0  13
ICMP Port Unreachable0  12
ICMP Administratively Prohibited0  2

ARPPacket
Request Sent0
Reply Rcvd0 (0.0 %)
Reply Sent3

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP0.8 KBytes
90%

 

15.6 MBytes
83%

 

UDP0.0 KBytes  2.8 MBytes
14%

 

ICMP0.0 KBytes  378.7 KBytes
1%

 

(R)ARP0.1 KBytes
9%

 

0.1 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request04,333
Unreach014
Time Exceeded01

 

IP Fragments Distribution

ProtocolData SentData Rcvd
UDP0.0 KBytes  39.8 KBytes100
Fragment Distribution Received Fragment Distribution for 163.30.63.129-65535
IP Fragment Distribution Received IP Fragment Distribution for 163.30.63.129-65535

 

Last Contacted Peers

Sent ToIP Address
00:5D:73:14:1A:C1 Network Card  
1.58.109.6 1.58.109.6 
Total Contacts2
Received FromIP Address
110.10.130.46 110.10.130.46 
198.46.141.170 198.46.141.170 
43.174.251.117 43.174.251.117 
92.63.197.46 92.63.197.46 
23-94-171-218-host.colocrossing.com 23.94.171.218 
196.251.66.165 196.251.66.165 
1.58.109.6 1.58.109.6 
198-23-173-226-host.colocrossing.com 198.23.173.226 
Total Contacts15465

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp21  8/102ec2-54-221-189-140.compute-1.amazonaws.com
ssh22  36596/5.7 MBytes110.10.130.46
smtp25  550/4.8 KBytes178.16.53.142
domain538244/2.4 MBytesdns100.ovh.us 6/913azpdegwykt5n.stretchoid.com
pop3110  3/274ec2-23-22-135-42.compute-1.amazonaws.com
https443  1/245.187.35.27
submission587  3/250205.210.31.83

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveClient/Server Network DelayL7 ProtoNote
1.58.109.6 :35522host  Printer Mail (SMTP) HTTP Server Low Risk :ssh1.5 KBytes0Thu Sep 18 10:56:36 2025Thu Sep 18 10:56:41 20255 sec1 sec    SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes