(C) 1998-2008 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about host

IP Address163.30.63.129 Flag for ISO 3166 code tw (from p2c file) [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenTue Jul 2 00:00:10 2024  -  Tue Jul 2 20:16:01 2024 [Inactive since 1 sec]
Autonomous System3462
Subnet163.30.63.128/25
Domaintw
MAC Address Network Interface Card (NIC)00:26:18:2C:75:E2 
Origin AS3462
Host LocationLocal (inside specified/local subnet or known network list)
IP TTL (Time to Live)64:64 [~0 hop(s)]
Total Data Sent670/15 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent6 Pkts
Data Sent Stats
Local 50.1 %
  
Rem 49.9 %
IP vs. Non-IP Sent
IP 49.9 %
  
Non-IP 50.1 %
Total Data Rcvd35.2 MBytes/244,600 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
0 %
 
Rcvd 100 %
Sent vs. Rcvd Data
0 %
 
Rcvd 100 %
Used Subnet Routers 00:5D:73:14:1A:C1 Network Card
Host TypePrinter Printer
VoIP Host VoIP
SMTP (Mail) Server Mail (SMTP)
POP Server 
IMAP Server 
FTP Server 
HTTP Server HTTP Server
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Rcvd: rst] [Rcvd: port unreac] [Rcvd: admin prohib] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
8 PM 00.0 %655.1 KBytes1.8 %
7 PM 15022.4 %2.3 MBytes6.7 %
6 PM 00.0 %2.0 MBytes5.8 %
5 PM 568.4 %2.3 MBytes6.5 %
4 PM 00.0 %2.1 MBytes6.0 %
3 PM 00.0 %2.1 MBytes6.1 %
2 PM 568.4 %2.1 MBytes6.0 %
1 PM 00.0 %2.1 MBytes6.1 %
12 PM 00.0 %2.3 MBytes6.4 %
11 AM 568.4 %2.2 MBytes6.3 %
10 AM 11817.6 %2.3 MBytes6.7 %
9 AM 00.0 %2.2 MBytes6.2 %
8 AM 568.4 %2.9 MBytes8.2 %
7 AM 00.0 %2.3 MBytes6.4 %
6 AM 00.0 %2.1 MBytes5.9 %
5 AM 12218.2 %945.1 KBytes2.6 %
4 AM 00.0 %399.1 KBytes1.1 %
3 AM 00.0 %438.7 KBytes1.2 %
2 AM 568.4 %326.3 KBytes0.9 %
1 AM 00.0 %500.1 KBytes1.4 %
12 AM 00.0 %600.8 KBytes1.7 %
11 PM 00.0 %00.0 %
10 PM 00.0 %00.0 %
9 PM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted105 21,720
Established105 [100 %] 14,157 [65 %]

TCP FlagsPkts SentPkts Rcvd
SYN105 21,720
RST|ACK0  492
RST0  8,386
NULL0  9

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port31 0 
TCP Pkt Disgnostic Port0  3
Tiny Fragments0  76
ICMP Port Unreachable0  31
ICMP Administratively Prohibited0  20

ARPPacket
Request Sent6
Reply Rcvd6 (100.0 %)
Reply Sent6

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP0.3 KBytes
49%

 

30.2 MBytes
86%

 

UDP0.0 KBytes  4.8 MBytes
13%

 

ICMP0.0 KBytes  6.0 KBytes 
(R)ARP0.3 KBytes
50%

 

0.5 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request07
Unreach051
Time Exceeded02

 

IP Fragments Distribution

ProtocolData SentData Rcvd
UDP0.0 KBytes  169.0 KBytes100
Fragment Distribution Received Fragment Distribution for 163.30.63.129-65535
IP Fragment Distribution Received IP Fragment Distribution for 163.30.63.129-65535

 

Last Contacted Peers

Sent ToIP Address
163.30.63.147 163.30.63.147 
138.197.221.102 138.197.221.102 
Total Contacts3
Received FromIP Address
181.82.107.34.bc.googleusercontent.com 34.107.82.181 
u.arin.net 204.61.216.50 
ns-gce-public3.googledomains.com 216.239.36.102 
ns4-16-us-east-2.ec2-rdns.amazonaws.com 205.251.194.123 
ns3-24-us-east-2.ec2-rdns.amazonaws.com 205.251.199.23 
138.197.221.102 138.197.221.102 
ec2-3-15-192-152.us-east-2.compute.amazonaws.com 3.15.192.152 
ip-58-134.4vendeta.com 79.124.58.134 
Total Contacts18978

 

IP Service Stats: Server Role

 # Loc. Req. Rcvd# Rem. Req. Rcvd# Pos. Reply Sent# Neg. Reply SentLocal RndTripRem RndTrip
DNS24100.0%00.0%00.0%00.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
ftp21  7/96888.214.25.62
ssh22  16051/14.7 MBytes138.197.221.102
smtp25  88/1.4 KBytesstatic.194.35.154.94.client.virtualine.xyz
domain5313836/4.1 MBytesns3-24-us-east-2.ec2-rdns.amazonaws.com 27/1.3 KBytes206.168.34.217
http80  1/91scan-13k.shadowserver.org
pop3110  8/64900:5D:73:14:1A:C1 Network Card
smux199  6/366165.154.227.205
submission587  10/792azpdwsc33.stretchoid.com

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port
     

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

Active TCP/UDP Sessions

ClientServerData SentData RcvdActive SinceLast SeenDurationInactiveClient/Server Network DelayL7 ProtoNote
138.197.221.102 :56740host  VoIP Printer Mail (SMTP) HTTP Server Low Risk :ssh1.1 KBytes0Tue Jul 2 20:16:00 2024Tue Jul 2 20:16:01 20241 sec1 sec    SYN ACK PUSH 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes