| Metric | Value |
|---|---|
| Total packets | 266 |
| Total streams | 18 |
| Total traffic | 629.68 KB |
| Internet hosts | 4 |
| Encrypted / Unencrypted | 0 / 266 |
| Undecodable | 0 |
| Bookmarks | 0 |
| TCP retransmissions / OOO | 0 / 0 |
| Stream length (avg / min / max) | 14.78 / 2 / 65 packets |
| Heatmap packet hits | 12 |
| Unique credentials | 1 (5b****************************32) |
| Capture window | 2026-07-29T15:50:53Z – 15:56:30Z |
Decoded protocols: DNS, HTTP, NTP, WebSocket
Transport: TCP, UDP
MIME types: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain
Data classifications (notable): 370× XA sysV pure executable (not stripped), ASCII text, Arhangel archive data, and 90+ DOS executable (COM) variants with start-instruction hashes (e.g. 0x8c07c25b 595911c6, 0xb80b314a 5d53e1ca).
Hosts (6): 10.0.1.23, 10.0.1.35, 8.8.8.8, 91.189.91.48, 47.96.29.236, 185.125.190.57
Ports (23): 53, 80, 123, 443, 4444, 33017, 35239, 36814, 38192, 39149, 39233, 39271, 41165, 42353, 42941, 43269, 43443, 44763, 44837, 46005, 46644, 51186, 51882
MAC vendors (3): Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch
Hostnames (7): 8.8.8.8 (dns.google), 91.189.91.48 (amyrose.canonical.com, `prod-ntp-4.ntp1.ps5.canonical.com
The 266-packet / 629.68 KB capture is dominated by traffic between two internal hosts (10.0.1.23 and 10.0.1.35) with a small footprint of external contact: NTP sync to a Canonical pool host, DNS to Google, and a couple of external hits geolocated to Hangzhou, China and Boston, United States. Zero packets are encrypted, but the dominant transport-layer activity is HTTP. Buried inside the HTTP payload is a high-entropy ZIP archive whose entries use ../ path-traversal filenames (shell-68d64, metasploit-68d64.php, cleanup-msf.php) — a textbook Metasploit-staging dropper pattern (a "ZIP slip"). The data-classification field further reports 90+ payloads heuristically labelled as DOS executable (COM) with start-instruction hashes, reinforcing that binary shellcode/executables are flowing across this link. A single masked credential (5b**************************32) is present in the keychain.
| Metric | Value |
|---|---|
| Total packets | 266 |
| Total streams | 18 |
| Total traffic | 629.68 KB |
| Internet hosts | 4 |
| Encrypted / Unencrypted | 0 / 266 |
| Undecodable | 0 |
| Bookmarks | 0 |
| Stream length (avg / min / max) | 14.78 / 2 / 65 packets |
| TCP retransmissions / OOO | 0 / 0 |
| Heatmap packet hits | 12 |
| Unique credentials | 1 (5b**************************32) |
Decoded protocols: DNS, HTTP, NTP, WebSocket
Network/Transport: TCP, UDP
MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain
| Host | Packets | Role |
|---|---|---|
| 10.0.1.23 | 266 | Local client (all packets traverse it) |
| 10.0.1.35 | 247 | Local peer — likely the server / upload target |
| 91.189.91.48 | 9 | Canonical NTP pool (prod-ntp-4.ntp*.ps5.canonical.com) |
| 47.96.29.236 | 6 | External, Hangzhou, China |
| 185.125.190.57 | 2 | External, Boston, United States |
Capture scope: 266 packets / 18 streams / 629.68 KB / 0 encrypted packets. All traffic is in the clear. 6 hosts are involved (4 internet-reachable), across 23 ports. Decoded protocols: DNS, HTTP, NTP, WebSocket. Top talkers are two internal hosts (10.0.1.23, 10.0.1.35) that account for essentially the entire packet volume. Geographic footprint is minimal: 6 heatmap hits to Hangzhou, China and 2 to Boston, United States. One masked credential is present (5b****32). Heatmap recorded 12 packet hits. There are no TCP retransmissions or out-of-order segments.
| Host | Role | Packets | Notes |
|---|---|---|---|
10.0.1.23 |
Internal client (Intel Corporate MAC) | 266 | Primary talker; drives virtually all observed flows |
10.0.1.35 |
Internal peer (Tenda Technology MAC) | 247 | Most traffic is bilateral with 10.0.1.23 |
91.189.91.48 |
Canonical NTP (prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com, amyrose.canonical.com) |
9 | NTP time sync |
47.96.29.236 |
External server (Hangzhou, China / Aliyun) | 6 | HTTP/Socket destination |
185.125.190.57 |
External server (Boston, US) | 2 | HTTP destination |
8.8.8.8 |
Google DNS (dns.google) |
0 packets attributed in Talker table but DNS queries present | Recursive resolver |
Per-protocol highlights
8.8.8.8 (dns.google).The capture is a small, fully unencrypted window of traffic — 266 packets across 18 streams totaling 629.68 KB. There are 0 encrypted packets, 0 undecodable packets, 0 TCP retransmissions, and 0 out-of-order segments, which makes the traffic trivially reconstructible. Stream length averages 14.78 packets (min 2, max 65), consistent with a handful of short client/server interactions rather than bulk transfers. No bookmarks were set; the analyst is working from a raw, unfiltered capture.
| Metric | Value |
|---|---|
| Total packets | 266 |
| Total streams | 18 |
| Total traffic | 629.68 KB |
| Encrypted / Unencrypted | 0 / 266 |
| Undecodable packets | 0 |
| TCP retransmissions | 0 |
| Out-of-order segments | 0 |
| Bookmarks | 0 |
| Avg / min / max stream length | 14.78 / 2 / 65 packets |
| Heatmap packet hits | 12 |
| Unique masked credentials | 1 (5b****************************32) |
Decoded protocols: DNS, HTTP, NTP, WebSocket (transport on TCP and UDP).
Hosts (6 total):
| Host | Role | Packets |
|---|---|---|
| 10.0.1.23 | Primary talker (likely local client/workstation) | 266 |
| 10.0.1.35 | Secondary local host (likely target/server) | 247 |
| 91.189.91.48 | External — Canonical NTP (amyrose.canonical.com, prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com) |
9 |
| 47.96.29.236 | External — Alibaba Cloud, Hangzhou, China | 6 |
| 185.125.190.57 | External — Boston, US | 2 |
| 8.8.8.8 | Google Public DNS (dns.google) |
(resolver) |
Geographic footprint is light and concentrated: Hangzhou, China (6 hits) and Boston, United States (2 hits).
Ports observed (23): 53, 80, 123, 443, 4444, 33017,
A 266-packet, 18-stream session totaling 629.68 KB of entirely unencrypted traffic (TCP/UDP). The transport mix is TCP, UDP, and decoded application protocols are DNS, HTTP, NTP, and WebSocket. There are no retransmissions, no out-of-order segments, and no undecodable packets — a clean capture window. Stream length averages 14.78 packets (min 2, max 65).
Top talkers are entirely intra-LAN, with one of them carrying every single packet in the trace:
| Host | Packets | Role |
|---|---|---|
| 10.0.1.23 | 266 | Web server / online-judge host |
| 10.0.1.35 | 247 | Attacker client (all HTTP/WS) |
| 91.189.91.48 | 9 | Ubuntu connectivity check (NTP+HTTP) |
| 47.96.29.236 | 6 | DNS resolver (Hangzhou geo) |
| 185.125.190.57 | 2 | Secondary DNS / Boston geo |
Six hosts participate overall, with MAC vendors **Intel Corporate, PCS Systemtechnik GmbH, and Tenda Technology Co
| Metric | Value |
|---|---|
| Total packets | 266 |
| Total streams | 18 |
| Total traffic | 629.68 KB |
| Internet hosts | 4 |
| Encrypted / Unencrypted | 0 / 266 |
| Undecodable packets | 0 |
| TCP retransmissions | 0 |
| Out-of-order segments | 0 |
| Bookmarks | 0 |
| Stream length (avg/min/max) | 14.78 / 2 / 65 packets |
| Heatmap packet hits | 12 |
| Unique credentials captured | 1 (5b****************************32) |
Protocols decoded: DNS, HTTP, NTP, WebSocket (over TCP and UDP).
Hosts (6): 10.0.1.23, 10.0.1.35, 185.125.190.57, 47.96.29.236, 8.8.8.8, 91.189.91.48.
Hostnames resolved (7): 185.125.190.57, 8.8.8.8 (dns.google), `
The capture contains 266 packets across 18 streams totaling 629.68 KB. All traffic is unencrypted (0 encrypted, 0 undecodable), and there are no TCP retransmissions or out-of-order segments. Average stream length is ~14.78 packets (min 2, max 65). Decoded protocols are limited to DNS, HTTP, NTP, and WebSocket over TCP/UDP.
The capture is dominated by a single internal client/server pair, with a small number of external probes:
| Host | Role | Packets |
|---|---|---|
| 10.0.1.23 | Local web/app server (HUSTOJ) | 266 |
| 10.0.1.35 | Internal client | 247 |
| 91.189.91.48 | Ubuntu NTP / connectivity check | 9 |
| 47.96.29.236 | External (Hangzhou, CN) | 6 |
| 185.125.190.57 | External (Boston, US) | 2 |
| 8.8.8.8 | Google DNS resolver | (referenced) |
MAC vendors observed: Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch. Geographic footprint is narrow: Hangzhou, China (6 hits) and Boston, United States (2 hits). MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain. The heatmap recorded 12 packet hits and the keychain surfaced 1 unique masked credential (5b****************************32).
The bulk of the capture is HTTP traffic between client 10.0.1.35 and web server 10.0.1.23 at http://10.0.1.23/, identified as the HUSTOJ online-judge platform (Chinese-language UI, "登录 - HUSTOJ" = "Login - HUSTOJ"). The HTML pages declare lang="cn", charset UTF-8, with an IE-edge meta tag and viewport initial-scale=0.5.
Stylesheet chain under template/syzoj/css/: style.css, tomorrow.css, semantic.min.css?v=0.1, katex.min.css, morris.min.css, FiraMono.css, latin.css, Exo.css?v=0.1. Inline CSS includes a @media (max-width: 991px) block toggling .mobile-only / .desktop-only, and a .padding rule with fro
This is a small, unencrypted capture: 266 packets across 18 streams, totaling 629.68 KB of clear-text traffic with 0 retransmissions and 0 out-of-order segments. All packets are decryptable; none are undecodable. The capture is fully passive/observational and short-lived (avg stream length 14.78 packets, min 2, max 65).
| Metric | Value |
|---|---|
| Total packets | 266 |
| Total streams | 18 |
| Total traffic | 629.68 KB |
| Encrypted packets | 0 |
| Unencrypted packets | 266 |
| Undecodable packets | 0 |
| Bookmarks | 0 |
| TCP retransmissions | 0 |
| Out-of-order segments | 0 |
| Stream length (avg / min / max) | 14.78 / 2 / 65 packets |
application/x-dosexec classifications (likely Content-Type sniffing artifacts on binary bodies rather than actual executables). Includes an XA sysV pure executable (not stripped) and an Arhangel archive data blob, plus the usual suite of DOS executable (COM) magic-byte variants.| Location | Hits |
|---|---|
| Hangzhou, China | 6 |
| Boston, United States | 2 |
Almost all traffic is between two LAN hosts, with small outbound probes to public services.
| Host | Packets | Role |
|---|---|---|
| 10.0.1.23 | 266 | Web server (HUSTOJ / syzoj) — full capture volume |
| 10.0.1.35 | 247 | Client workstation |
| 91.189.91.48 | 9 | Ubuntu NTP/connectivity check |
| 47.96.29.236 | 6 | External endpoint (Hangzhou) |
| 185.125.190.57 | 2 | External endpoint (Boston) |
application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain — 12 heatmap hits on the source/target.
1 unique credential was
Capture timestamp: 2026-07-29T15:50:53Z – 15:56:30Z Scope: 266 packets / 18 streams / 629.68 KB, entirely unencrypted, 0 retransmissions, 0 out-of-order.
A small, fully unencrypted pcap of 266 packets across 18 streams (629.68 KB) with zero retransmissions or out-of-order segments. Average stream length is 14.78 packets (min 2, max 65). All 266 packets decode cleanly (no encrypted, no undecodable traffic).
Decoded protocols: DNS, HTTP, NTP, WebSocket
Transport: TCP and UDP only
MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain
The Data Classifications panel is dominated by a long list of DOS executable (COM) signatures (70+ variants) and a single XA sysV pure executable not stripped, reflecting the binary payload distribution in the capture — most likely payload bodies served by the local web app.
Hosts (6):
| Host | Role / Notes |
|---|---|
| 10.0.1.23 | Local web server (client target) |
| 10.0.1.35 | Local client (admin workstation) |
| 8.8.8.8 | Google Public DNS (dns.google) |
| 91.189.91.48 | Canonical NTP / Ubuntu connectivity check (prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com, amyrose.canonical.com) |
| 47.96.29.236 | Public IPv4 in Hangzhou, China — ALISOFT allocation |
| 185.125.190.57 | Public IPv4 in Boston, US |
Ports (23 in use): 53, 80, 123, 443, 4444, 33017, 35239, 36814, 38192, 39149, 39233, 39271, 41165, 42353, 42941, 43269, 43443, 44763, 44837, 46005, 46644, 51186, 51882. The standout non-standard port is 4444 (commonly associated with Metasploit / reverse-shell handlers — worth a follow-up if any traffic actually lands there).
MAC vendors (3): Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch.
| Host | Packets |
|---|---|
| 10.0.1.23 | 266 |
| 10.0.1.35 | 247 |
| 91.189.91.48 | 9 |
| 47.96.29.236 | 6 |
| 185.125.190.57 | 2 |
Traffic is overwhelmingly intra-LAN between 10.0.1.35 ↔ 10.0.1.23; only a handful of packets traverse the public internet.
| Location | Hits |
|---|---|
| Hangzhou, China | 6 |
| Boston, United States | 2 |
5b****************************32 (32 hex chars → consistent with an MD