(C) 1998-2012 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about kp19zam-w

IP Address10.29.119.46 [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenMon Apr 28 15:34:42 2025  -  Mon Apr 28 18:18:20 2025 [Inactive since 1 day 9:45:17]
Subnet10.29.119.0/24
MAC Address Network Interface Card (NIC)90:2B:34:4F:52:6B  [GIGA-BYTE TECHNOLOGY CO.,LTD.]
OS NameOS: Windows [Windows 98 / 2000] 
NetBios NameKP19ZAM-W (Workstation)
Host LocationLocal (inside specified/local subnet or known network list)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent13.1 MBytes/71,829 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent375 Pkts
Multicast TrafficSent 43.0 KBytes/400 Pkts 
Data Sent Stats
Local 5.0 %
  
Rem 95.0 %
IP vs. Non-IP Sent
IP 95.3 %
  
Non-IP 4.7 %
Total Data Rcvd112.8 MBytes/95,802 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 42.8 %
  
Rcvd 57.2 %
Sent vs. Rcvd Data
Sent 10.4 %
  
Rcvd 89.6 %
Host TypeServer
Workstation
Master Browser
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskSuspicious activities: too many host contacts
  2. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):
  3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Sent: closed-empty] [Rcvd: port unreac] 

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
6 PM 1.2 MBytes8.9 %8.7 MBytes7.7 %
5 PM 5.4 MBytes40.7 %41.4 MBytes36.7 %
4 PM 6.0 MBytes45.8 %60.3 MBytes53.4 %
3 PM 614.8 KBytes4.6 %2.5 MBytes2.2 %
Total
TCP ConnectionsDirected toRcvd From
Attempted5,138 4
Established4,226 [82 %] 4 [100 %]
Terminated18 0 
SYN5,138 4
RST|ACK368 0 
NULL2,546 2,233
UDP Pkt to Closed Port30 0 
Closed Empty TCP Conn.18 0 
ICMP Port Unreachable0  30

ARPPackets
Request Sent0
Reply Rcvd0 (0.0 %)
Reply Sent242

ProtocolData SentData Rcvd
TCP12.1 MBytes
96%

 

112.0 MBytes
99%

 

UDP468.6 KBytes
4%

 

813.1 KBytes
1%

 

ICMP0.0 KBytes  17.3 KBytes 
(R)ARP10.9 KBytes  0.0 KBytes 
IGMP1.8 KBytes  0.0 KBytes 
Protocol Distribution
L7 ProtocolData SentData Rcvd
Unknown32.8 KBytes  32.3 KBytes 
Mail_POP12.9 MBytes
99%

 

112.6 MBytes100
Mail_SMTP100.5 KBytes
1%

 

166.8 KBytes 
MDNS0.5 KBytes  0.0 KBytes 
NTP0.1 KBytes  0.1 KBytes 
SSDP25.4 KBytes  0.0 KBytes 
IP Distribution

TypePkt SentPkt Rcvd
Unreach030
Sent To# Contacts
is-r...vip-sg.i.smailru.net  HTTP Server 2037 
is-r...vip-sg.i.smailru.net  HTTP Server 1708 
is-r...vip-sg.i.smailru.net  HTTP Server 1537 
lo-in-f188.1e100.net 980 
lo-in-f95.1e100.net  HTTP Server Medium Risk 878 
clients2.google.com  HTTP Server 712 
lm-in-f188.1e100.net 911 
lm-in-f95.1e100.net  HTTP Server Medium Risk 2022 
www.tns-counter.ru  HTTP Server 1537 
srv4-56-213-95.vk.com  HTTP Server 1040 
lk-in-f95.1e100.net  HTTP Server Medium Risk 980 
zv2.consultant.ru  HTTP Server 1251 
e.mail.ru  HTTP Server 1982 
ctldl.windowsupdate.com  HTTP Server 1036 
92.63.176.247  NTP Server Medium Risk 770 
portal.mail.ru  HTTP Server 771 
51.250.110.169  NTP Server Medium Risk 712 
medi...s-cdn1.p.smailru.net  HTTP Server 770 
top-fwz1.mail.ru  HTTP Server 1238 
ads.adfox.ru  HTTP Server Low Risk 770 
mail.yandex.ru  HTTP Server Low Risk 621 
lq-in-f188.1e100.net 770 
ctldl.windowsupdate.com  HTTP Server 1036 
lq-in-f94.1e100.net  HTTP Server Medium Risk 909 
srv151-185-240-87.vk.com  HTTP Server 770 
lu-in-f104.1e100.net  HTTP Server Medium Risk 1373 
dns.google  DNS HTTP Server Medium Risk 911 
62.128.101.35  HTTP Server 909 
62.128.100.47  HTTP Server Low Risk 1564 
62.128.100.49  HTTP Server Low Risk 477 
62.128.100.55  HTTP Server 621 
62.128.100.65  HTTP Server 477 
62.128.100.92  HTTP Server Low Risk 621 
detectportal.firefox.com  HTTP Server 2166 
lb-in-f136.1e100.net  HTTP Server 878 
lb-in-f93.1e100.net  HTTP Server 1040 
x1.c.lencr.org  HTTP Server 621 
lh-in-f95.1e100.net  HTTP Server Medium Risk 612 
ip58...147.odnoklassniki.ru  HTTP Server 1313 
ip1.147.odnoklassniki.ru  HTTP Server 477 
go.microsoft.com  HTTP Server 1835 
lj-in-f188.1e100.net  HTTP Server 878 
safe...wsing.googleapis.com  HTTP Server Medium Risk 1040 
li-in-f104.1e100.net  HTTP Server Medium Risk 998 
lg-in-f95.1e100.net  HTTP Server Medium Risk 911 
ec2-...ompute.amazonaws.com 621 
lf-in-f84.1e100.net  HTTP Server Medium Risk 771 
srv208-137-240-87.vk.com  HTTP Server 1238 
eb.cert.roskazna.ru  HTTP Server Low Risk 1564 
ip13...155.odnoklassniki.ru  HTTP Server 705 
ip4.155.odnoklassniki.ru  HTTP Server Low Risk 1251 
ip24...155.odnoklassniki.ru  HTTP Server 998 
srv67-132-240-87.vk.com  HTTP Server 712 
srv78-132-240-87.vk.com  HTTP Server 705 
ntp.ix.ru  NTP Server Medium Risk 705 
77.74.181.141  HTTP Server 477 
77.74.181.34  HTTP Server 2206 
195.90.182.235 1564 
nr-repo.roskazna.ru  HTTP Server 1152 
79.133.170.5  HTTP Server Low Risk 1609 
ya.ru  HTTP Server 1621 
e.mail.ru  HTTP Server 1152 
srv12-5-213-95.vk.com  HTTP Server 621 
93.158.134.39  HTTP Server 621 
bs.yandex.ru  HTTP Server 2212 
45.141.102.99  NTP Server Medium Risk 1814 
comm...l.edadeal.yandex.net  HTTP Server 1564 
player.mediavitrina.ru  HTTP Server 477 
beat.vitrinabeat.ru  HTTP Server 911 
31.200.249.235  HTTP Server 911 
31.200.249.234  HTTP Server 1708 
mskm...c.ntppool.yandex.net  NTP Server Medium Risk 1896 
nr.roskazna.ru  HTTP Server 770 
lr-in-f139.1e100.net  HTTP Server Medium Risk 477 
lr-in-f95.1e100.net  HTTP Server Medium Risk 771 
fina...vices.appex.bing.com  HTTP Server 1621 
suggest.dzen.ru  HTTP Server 771 
stat...-api.mediavitrina.ru  HTTP Server 612 
crl3.digicert.com  HTTP Server 1313 
fron....slb.maps.yandex.net 705 
mc.yandex.ru  HTTP Server 1152 
stor...e.browser.yandex.net  HTTP Server 1925 
brow...translate.yandex.net  HTTP Server 2166 
log.strm.yandex.ru  HTTP Server Low Risk 2842 
api.music.yandex.net  HTTP Server 2212 
mc.yandex.ru 2257 
srv6-237-186-93.vk.com  HTTP Server 477 
srv1-237-186-93.vk.com  HTTP Server 705 
avatars.mds.yandex.net  HTTP Server Low Risk 1036 
srv158-227.vkontakte.ru  HTTP Server 1040 
le-in-f188.1e100.net 878 
le-in-f139.1e100.net  HTTP Server Medium Risk 980 
le-in-f95.1e100.net  HTTP Server Medium Risk 477 
dzen.ru  HTTP Server Low Risk 770 
avatars.dzeninfra.ru  HTTP Server 909 
64.236.96.53 712 
!  HTTP Server 2192 
kp19-w7oag0218 [NetBIOS] Medium Risk 980 
kp19zam-w [NetBIOS] Medium Risk 1537 
10.29.119.35 Medium Risk 1251 
10.29.119.12 Medium Risk 770 
10.29.119.108 Medium Risk 1771 
10.29.119.69 Medium Risk 705 
ip11...185.odnoklassniki.ru  HTTP Server 1238 
bs.yandex.ru  HTTP Server 909 
core...capi.maps.yandex.net  HTTP Server 1040 
favicon.yandex.net  HTTP Server 712 
suggest.yandex.net  HTTP Server 1893 
frontend.vh.yandex.ru  HTTP Server 2257 
exte...ancer.yandex-team.ru  HTTP Server 878 
185.12.155.10  HTTP Server 2139 
bs.yandex.ru 1708 
91.232.93.95 1251 
195.209.109.24  HTTP Server 612 
91.232.93.62  HTTP Server 771 
178.185.137.130  HTTP Server 477 
5.255.230.28  HTTP Server 1893 
www.yandex.ru  HTTP Server Low Risk 1609 
"  HTTP Server 1036 
4.207.247.138  HTTP Server 770 
client.wns.windows.com  HTTP Server 770 
mq.dataservices.hp.com  HTTP Server 911 
noip-id.1c-connect.com  HTTP Server 770 
a2-1...amaitechnologies.com  HTTP Server Low Risk 771 
Received From# Contacts
is-r...vip-sg.i.smailru.net  HTTP Server 1882 
is-r...vip-sg.i.smailru.net  HTTP Server 580 
is-r...vip-sg.i.smailru.net  HTTP Server 1168 
lo-in-f188.1e100.net 1040 
lo-in-f95.1e100.net  HTTP Server Medium Risk 1124 
clients2.google.com  HTTP Server 1893 
lm-in-f188.1e100.net 580 
lm-in-f95.1e100.net  HTTP Server Medium Risk 621 
www.tns-counter.ru  HTTP Server 687 
srv4-56-213-95.vk.com  HTTP Server 1233 
lk-in-f95.1e100.net  HTTP Server Medium Risk 1454 
zv2.consultant.ru  HTTP Server 1695 
e.mail.ru  HTTP Server 1293 
ctldl.windowsupdate.com  HTTP Server 333 
92.63.176.247  NTP Server Medium Risk 1819 
portal.mail.ru  HTTP Server 1124 
51.250.110.169  NTP Server Medium Risk 1233 
medi...s-cdn1.p.smailru.net  HTTP Server 687 
top-fwz1.mail.ru  HTTP Server 2027 
ads.adfox.ru  HTTP Server Low Risk 1454 
mail.yandex.ru  HTTP Server Low Risk 2968 
lq-in-f188.1e100.net 389 
ctldl.windowsupdate.com  HTTP Server 687 
lq-in-f94.1e100.net  HTTP Server Medium Risk 629 
srv151-185-240-87.vk.com  HTTP Server 634 
lu-in-f104.1e100.net  HTTP Server Medium Risk 1819 
dns.google  DNS HTTP Server Medium Risk 539 
62.128.101.35  HTTP Server 580 
62.128.100.47  HTTP Server Low Risk 1124 
62.128.100.49  HTTP Server Low Risk 634 
62.128.100.55  HTTP Server 1459 
62.128.100.65  HTTP Server 629 
62.128.100.92  HTTP Server Low Risk 1819 
detectportal.firefox.com  HTTP Server 1052 
lb-in-f136.1e100.net  HTTP Server 333 
lb-in-f93.1e100.net  HTTP Server 712 
x1.c.lencr.org  HTTP Server 1087 
lh-in-f95.1e100.net  HTTP Server Medium Risk 684 
ip58...147.odnoklassniki.ru  HTTP Server 1259 
ip1.147.odnoklassniki.ru  HTTP Server 389 
go.microsoft.com  HTTP Server 1449 
lj-in-f188.1e100.net  HTTP Server 539 
safe...wsing.googleapis.com  HTTP Server Medium Risk 712 
li-in-f104.1e100.net  HTTP Server Medium Risk 1233 
lg-in-f95.1e100.net  HTTP Server Medium Risk 580 
ec2-...ompute.amazonaws.com 1933 
lf-in-f84.1e100.net  HTTP Server Medium Risk 684 
srv208-137-240-87.vk.com  HTTP Server 634 
eb.cert.roskazna.ru  HTTP Server Low Risk 712 
ip13...155.odnoklassniki.ru  HTTP Server 539 
ip4.155.odnoklassniki.ru  HTTP Server Low Risk 580 
ip24...155.odnoklassniki.ru  HTTP Server 634 
srv67-132-240-87.vk.com  HTTP Server 1293 
srv78-132-240-87.vk.com  HTTP Server 623 
ntp.ix.ru  NTP Server Medium Risk 1819 
77.74.181.141  HTTP Server 623 
77.74.181.34  HTTP Server 1293 
195.90.182.235 1259 
nr-repo.roskazna.ru  HTTP Server 1459 
79.133.170.5  HTTP Server Low Risk 2027 
ya.ru  HTTP Server 333 
e.mail.ru  HTTP Server 1790 
srv12-5-213-95.vk.com  HTTP Server 539 
93.158.134.39  HTTP Server 621 
bs.yandex.ru  HTTP Server 389 
45.141.102.99  NTP Server Medium Risk 1535 
comm...l.edadeal.yandex.net  HTTP Server 3495 
player.mediavitrina.ru  HTTP Server 333 
beat.vitrinabeat.ru  HTTP Server 333 
31.200.249.235  HTTP Server 621 
31.200.249.234  HTTP Server 1663 
mskm...c.ntppool.yandex.net  NTP Server Medium Risk 1168 
nr.roskazna.ru  HTTP Server 333 
lr-in-f139.1e100.net  HTTP Server Medium Risk 634 
lr-in-f95.1e100.net  HTTP Server Medium Risk 1695 
fina...vices.appex.bing.com  HTTP Server 2006 
suggest.dzen.ru  HTTP Server 1259 
stat...-api.mediavitrina.ru  HTTP Server 3069 
crl3.digicert.com  HTTP Server 1293 
fron....slb.maps.yandex.net 539 
mc.yandex.ru  HTTP Server 2130 
stor...e.browser.yandex.net  HTTP Server 687 
brow...translate.yandex.net  HTTP Server 333 
log.strm.yandex.ru  HTTP Server Low Risk 2649 
api.music.yandex.net  HTTP Server 1726 
mc.yandex.ru 1704 
srv6-237-186-93.vk.com  HTTP Server 389 
srv1-237-186-93.vk.com  HTTP Server 1124 
avatars.mds.yandex.net  HTTP Server Low Risk 621 
srv158-227.vkontakte.ru  HTTP Server 2027 
le-in-f188.1e100.net 580 
le-in-f139.1e100.net  HTTP Server Medium Risk 1449 
le-in-f95.1e100.net  HTTP Server Medium Risk 1882 
dzen.ru  HTTP Server Low Risk 629 
avatars.dzeninfra.ru  HTTP Server 687 
64.236.96.53 580 
!  HTTP Server 1168 
kp19-w7oag0218 [NetBIOS] Medium Risk 1087 
kp19zam-w [NetBIOS] Medium Risk 1427 
10.29.119.35 Medium Risk 2072 
10.29.119.12 Medium Risk 621 
10.29.119.108 Medium Risk 629 
10.29.119.69 Medium Risk 2130 
ip11...185.odnoklassniki.ru  HTTP Server 1052 
bs.yandex.ru  HTTP Server 684 
core...capi.maps.yandex.net  HTTP Server 1293 
favicon.yandex.net  HTTP Server 1933 
suggest.yandex.net  HTTP Server 623 
frontend.vh.yandex.ru  HTTP Server 684 
exte...ancer.yandex-team.ru  HTTP Server 1233 
185.12.155.10  HTTP Server 1052 
bs.yandex.ru 712 
91.232.93.95 1087 
195.209.109.24  HTTP Server 333 
91.232.93.62  HTTP Server 1233 
178.185.137.130  HTTP Server 1663 
5.255.230.28  HTTP Server 1168 
www.yandex.ru  HTTP Server Low Risk 1459 
"  HTTP Server 1868 
4.207.247.138  HTTP Server 1259 
client.wns.windows.com  HTTP Server 623 
mq.dataservices.hp.com  HTTP Server 1790 
noip-id.1c-connect.com  HTTP Server 1293 
a2-1...amaitechnologies.com  HTTP Server Low Risk 1040 
Virtual HostSentRcvd
api.browser.yandex.net2.2 KBytes 3.2 KBytes 
sdk-api.apptracer.ru4.0 KBytes 7.6 KBytes 
strm-mar-50.strm.yandex.net878 956 
strm-mar-107.strm.yandex.net878 957 
strm-mar-64.strm.yandex.net799 1.0 KBytes 
strm-mar-28.strm.yandex.net1.1 MBytes 37.1 KBytes 
webntp.yandex.ru248 1009 
sba.yandex.net600 1.9 KBytes 
ad.mail.ru546 1.0 KBytes 
api.browser.yandex.ru24.4 KBytes 236.3 KBytes 
NOTE: The above table is not updated in realtime but when connections are terminated.

 

Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS00.0%1,306100.0%1,25499.0%120.0%0.0 ms - 0.0 ms31.3 ms - 50.5 ms
HTTP00.0%17100.0%1100.0%00.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain532566/162.1 KBytessafe.dns.yandex.ru   
www80333/382.0 KBytes123....oogleusercontent.com   
ntp1232/9620.101.57.9 2/9620.101.57.9
https44342845/116.3 MBytesapi.browser.yandex.net   

 

Traffic on Other Port(s)

Client PortServer Port
     

 

Recently Used Ports

Client PortServer Port

 

Recent Sessions: Network Delay

Client Mode
Last TimeServiceLast Server ContactClient Delay [min/avg/max]
Mon Apr 28 18:11:28 2025 HTTPlt-in-f94.1e100.net 0.12/0.31/8.43 ms
  • Scenario: client <--> ntop <--> server
  • Client Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the client to reach ntop
  • Server Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the server to reach ntop
  • All times are majored during TCP 3-way handshake

ProtoClientServerData Sent/RcvdActive SinceDurationInactiveClient/Server Nw DelayL7 Proto
TCPkp19zam-w [NetBIOS] Medium Risk :50502api.browser.yandex.ru  HTTP Server Low Risk :https38.5 KBytes16.3 KBytesMon Apr 28 17:55:25 202522:501 day 9:45:220.26 ms15.85 msMail_POP
TCPkp19zam-w [NetBIOS] Medium Risk :49622lo-in-f188.1e100.net :52288.5 KBytes14.8 KBytesMon Apr 28 16:10:47 20252:07:311 day 9:45:190.24 ms12.54 msUnknown

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes