(C) 1998-2008 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about host

IP Address163.30.63.129 Flag for ISO 3166 code tw (from p2c file) [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenTue Nov 4 00:00:10 2025  -  Tue Nov 4 03:21:18 2025 [Inactive since 1 sec]
Autonomous System3462
Subnet163.30.63.128/25
Domaintw
MAC Address Network Interface Card (NIC)00:26:18:2C:75:E2 
Origin AS3462
Host LocationLocal (inside specified/local subnet or known network list)
Total Data Sent28/1 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent0 Pkts
Data Sent Stats
Local 100 %
 
Rem 0 %
IP vs. Non-IP Sent
0 %
 
Non-IP 100 %
Total Data Rcvd5.7 MBytes/41,879 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
0 %
 
Rcvd 100 %
Sent vs. Rcvd Data
0 %
 
Rcvd 100 %
Host TypePrinter Printer
VoIP Host VoIP
SMTP (Mail) Server Mail (SMTP)
POP Server 
FTP Server 
HTTP Server HTTP Server
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rejected] [Rcvd: rst] [Rcvd: port unreac] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
3 AM 28100.0 %607.9 KBytes10.4 %
2 AM 00.0 %2.3 MBytes40.7 %
1 AM 00.0 %1.5 MBytes25.5 %
12 AM 00.0 %1.3 MBytes23.3 %
11 PM 00.0 %00.0 %
10 PM 00.0 %00.0 %
9 PM 00.0 %00.0 %
8 PM 00.0 %00.0 %
7 PM 00.0 %00.0 %
6 PM 00.0 %00.0 %
5 PM 00.0 %00.0 %
4 PM 00.0 %00.0 %
3 PM 00.0 %00.0 %
2 PM 00.0 %00.0 %
1 PM 00.0 %00.0 %
12 PM 00.0 %00.0 %
11 AM 00.0 %00.0 %
10 AM 00.0 %00.0 %
9 AM 00.0 %00.0 %
8 AM 00.0 %00.0 %
7 AM 00.0 %00.0 %
6 AM 00.0 %00.0 %
5 AM 00.0 %00.0 %
4 AM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted0  5,989
Established0  3,344 [56 %]
Rejected0  1 [0 %]

TCP FlagsPkts SentPkts Rcvd
SYN0  5,989
RST|ACK0  52
RST0  1,496
NULL0  1

AnomalyPkts Sent toPkts Rcvd from
TCP Pkt Disgnostic Port0  6
Tiny Fragments0  6
ICMP Port Unreachable0  1

ARPPacket
Request Sent0
Reply Rcvd0 (0.0 %)
Reply Sent1

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP0.0 KBytes  4.7 MBytes
82%

 

UDP0.0 KBytes  857.6 KBytes
14%

 

ICMP0.0 KBytes  139.2 KBytes
2%

 

(R)ARP0.0 KBytes100% 0.0 KBytes 
Protocol Distribution
IP Distribution 

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request01,647
Unreach01

 

IP Fragments Distribution

ProtocolData SentData Rcvd
UDP0.0 KBytes  9.3 KBytes100
Fragment Distribution Received Fragment Distribution for 163.30.63.129-65535
IP Fragment Distribution Received IP Fragment Distribution for 163.30.63.129-65535

 

Last Contacted Peers

Sent ToIP Address
00:5D:73:14:1A:C1 Network Card  
Total Contacts1
Received FromIP Address
8.211.51.182 8.211.51.182 
194.180.49.219 194.180.49.219 
2.57.122.117 2.57.122.117 
daugherty.probe.onyphe.net 91.231.89.106 
159.65.159.93 159.65.159.93 
1.9.175.180 1.9.175.180 
114.119.154.186 114.119.154.186 
216.73.216.211 216.73.216.211 
Total Contacts5679

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp21  2/20scan-70-00.shadowserver.org
ssh22  13136/2.3 MBytes1.9.175.180
smtp25  6/58213.209.157.247
domain532611/743.7 KBytesns-cloud-b3.googledomains.com   
http80  1/91scan-68-08.shadowserver.org
pop3110  8/500138.197.189.46
submission587  3/14147.185.133.187

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveClient/Server Network DelayL7 ProtoNote
114.119.154.186 :20331host  VoIP Printer Mail (SMTP) HTTP Server Low Risk :30006600Tue Nov 4 03:21:15 2025Tue Nov 4 03:21:16 20251 sec3 sec    SYN ACK PUSH 
180.76.57.253 :54824host  VoIP Printer Mail (SMTP) HTTP Server Low Risk :ssh1640Tue Nov 4 03:17:19 2025Tue Nov 4 03:17:19 20250 sec4:00    SYN ACK 
1.9.175.180 :57502host  VoIP Printer Mail (SMTP) HTTP Server Low Risk :ssh1.4 KBytes0Tue Nov 4 03:21:13 2025Tue Nov 4 03:21:18 20255 sec1 sec    SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes