(C) 1998-2012 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about kp19-w7oag0218

IP Address10.29.119.54 [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenMon Apr 28 15:39:09 2025  -  Mon Apr 28 18:18:28 2025 [Inactive since 1 day 16:10:54]
Subnet10.29.119.0/24
MAC Address Network Interface Card (NIC)00:0A:48:21:02:18  [Albatron Technology]
OS NameOS: Windows [Windows 98 / 2000] 
NetBios NameKP19-W7OAG0218 (Server)
Host LocationLocal (inside specified/local subnet or known network list)
IP TTL (Time to Live)1:128 [~0 hop(s)]
Total Data Sent1.6 MBytes/15,298 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent108 Pkts
Multicast TrafficSent 16.8 KBytes/182 Pkts 
Data Sent Stats
Local 1.6 %
  
Rem 98.4 %
IP vs. Non-IP Sent
IP 99.2 %
  
Non-IP 0.8 %
Total Data Rcvd21.2 MBytes/17,909 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
0 %
 
Rem 100 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 46.1 %
  
Rcvd 53.9 %
Sent vs. Rcvd Data
Sent 6.9 %
  
Rcvd 93.1 %
Host TypeServer
Master Browser
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskUnexpected packets (e.g. traffic to closed port or connection reset):

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
6 PM 102.8 KBytes6.4 %111.0 KBytes0.5 %
5 PM 341.8 KBytes21.2 %416.7 KBytes1.9 %
4 PM 365.4 KBytes22.7 %793.6 KBytes3.7 %
3 PM 799.8 KBytes49.7 %19.9 MBytes93.9 %
Total
ProtocolData SentData Rcvd
TCP1.5 MBytes
97%

 

21.2 MBytes100
UDP34.9 KBytes
2%

 

11.2 KBytes 
ICMP0.1 KBytes  0.1 KBytes 
(R)ARP11.2 KBytes
1%

 

0.0 KBytes 
IGMP1.5 KBytes  0.0 KBytes 
Protocol Distribution
L7 ProtocolData SentData Rcvd
Unknown7.5 KBytes  0.0 KBytes 
Mail_POP1.5 MBytes
99%

 

21.2 MBytes100
Mail_SMTP7.7 KBytes  11.1 KBytes 
NTP0.1 KBytes  0.1 KBytes 
SSDP7.8 KBytes  0.0 KBytes 
IP Distribution

TypePkt SentPkt Rcvd
Echo Request20
Echo Reply02
Sent To# Contacts
ctldl.windowsupdate.com  HTTP Server

 

Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS00.0%98100.0%8086.0%1213.0%0.0 ms - 0.0 ms32.4 ms - 35.6 ms
HTTP00.0%32100.0%2887.0%412.0%0.0 ms - 0.0 ms1322.6 sec - 1322.6 sec

 

Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
domain53190/11.0 KBytessafe.dns.yandex.ru   
www80288/330.1 KBytes146.75.54.133   
ntp1232/9620.101.57.9   
https44320934/20.7 MBytes89.221.236.26   

 

Traffic on Other Port(s)

Client PortServer Port
     

 

Recently Used Ports

Client PortServer Port
     

 

Recent Sessions: Network Delay

Client Mode
Last TimeServiceLast Server ContactClient Delay [min/avg/max]
Mon Apr 28 16:09:05 2025 HTTP146.75.54.133 0.13/0.30/0.43 ms
  • Scenario: client <--> ntop <--> server
  • Client Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the client to reach ntop
  • Server Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the server to reach ntop
  • All times are majored during TCP 3-way handshake

ProtoClientServerData Sent/RcvdActive SinceDurationInactiveClient/Server Nw DelayL7 Proto
TCPkp19-w7oag0218 [NetBIOS] Medium Risk :49641webim.armgs.team  HTTP Server Low Risk :https43.0 KBytes53.4 KBytesMon Apr 28 17:40:33 202537:191 day 16:11:30  Mail_POP
TCPkp19-w7oag0218 [NetBIOS] Medium Risk :49659webim.armgs.team  HTTP Server Low Risk :https69.2 KBytes92.1 KBytesMon Apr 28 17:44:41 202533:441 day 16:10:57  Mail_POP
TCPkp19-w7oag0218 [NetBIOS] Medium Risk :49696calendarmsg.armgs.team  HTTP Server Low Risk :https49.0 KBytes56.7 KBytesMon Apr 28 17:50:56 202527:271 day 16:10:59  Mail_POP
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :49474224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:40 20250 sec1 day 16:11:42  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :49591224.0.0.252 Medium Risk :hostmon700Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :49870224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :50178224.0.0.252 Medium Risk :hostmon500Mon Apr 28 18:17:40 20250 sec1 day 16:11:42  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :55476239.255.255.250 Medium Risk :19009120Mon Apr 28 18:17:51 20256 sec1 day 16:11:25  SSDP
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :52855224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :54609224.0.0.252 Medium Risk :hostmon500Mon Apr 28 18:17:40 20250 sec1 day 16:11:42  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :55179224.0.0.252 Medium Risk :hostmon610Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :55693224.0.0.252 Medium Risk :hostmon610Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :57009224.0.0.252 Medium Risk :hostmon610Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :58109224.0.0.252 Medium Risk :hostmon610Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :58707224.0.0.252 Medium Risk :hostmon700Mon Apr 28 18:17:34 20250 sec1 day 16:11:48  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :59924224.0.0.252 Medium Risk :hostmon500Mon Apr 28 18:17:40 20250 sec1 day 16:11:42  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :61759224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :62054224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :62942224.0.0.252 Medium Risk :hostmon700Mon Apr 28 18:17:33 20250 sec1 day 16:11:49  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :62961224.0.0.252 Medium Risk :hostmon510Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :64092224.0.0.252 Medium Risk :hostmon610Mon Apr 28 18:17:36 20250 sec1 day 16:11:46  Unknown
UDPkp19-w7oag0218 [NetBIOS] Medium Risk :65439224.0.0.252 Medium Risk :hostmon500Mon Apr 28 18:17:40 20250 sec1 day 16:11:42  Unknown

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes