Generated by PacketSnitch 2.4.2169 on 7/29/2026, 11:57:18 AM — packetsnitch.com

Capture Statistics

Metric Value
Total packets 266
Total streams 18
Total traffic 629.68 KB
Internet hosts 4
Encrypted / Unencrypted 0 / 266
Undecodable 0
Bookmarks 0
TCP retransmissions / OOO 0 / 0
Stream length (avg / min / max) 14.78 / 2 / 65 packets
Heatmap packet hits 12
Unique credentials 1 (5b****************************32)
Capture window 2026-07-29T15:50:53Z – 15:56:30Z

Decoded protocols: DNS, HTTP, NTP, WebSocket
Transport: TCP, UDP
MIME types: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain
Data classifications (notable): 370× XA sysV pure executable (not stripped), ASCII text, Arhangel archive data, and 90+ DOS executable (COM) variants with start-instruction hashes (e.g. 0x8c07c25b 595911c6, 0xb80b314a 5d53e1ca).

Hosts (6): 10.0.1.23, 10.0.1.35, 8.8.8.8, 91.189.91.48, 47.96.29.236, 185.125.190.57
Ports (23): 53, 80, 123, 443, 4444, 33017, 35239, 36814, 38192, 39149, 39233, 39271, 41165, 42353, 42941, 43269, 43443, 44763, 44837, 46005, 46644, 51186, 51882
MAC vendors (3): Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch
Hostnames (7): 8.8.8.8 (dns.google), 91.189.91.48 (amyrose.canonical.com, `prod-ntp-4.ntp1.ps5.canonical.com


PacketSnitch — Compacted Capture Analysis

Executive Snapshot

The 266-packet / 629.68 KB capture is dominated by traffic between two internal hosts (10.0.1.23 and 10.0.1.35) with a small footprint of external contact: NTP sync to a Canonical pool host, DNS to Google, and a couple of external hits geolocated to Hangzhou, China and Boston, United States. Zero packets are encrypted, but the dominant transport-layer activity is HTTP. Buried inside the HTTP payload is a high-entropy ZIP archive whose entries use ../ path-traversal filenames (shell-68d64, metasploit-68d64.php, cleanup-msf.php) — a textbook Metasploit-staging dropper pattern (a "ZIP slip"). The data-classification field further reports 90+ payloads heuristically labelled as DOS executable (COM) with start-instruction hashes, reinforcing that binary shellcode/executables are flowing across this link. A single masked credential (5b**************************32) is present in the keychain.

Capture-Level Statistics

Metric Value
Total packets 266
Total streams 18
Total traffic 629.68 KB
Internet hosts 4
Encrypted / Unencrypted 0 / 266
Undecodable 0
Bookmarks 0
Stream length (avg / min / max) 14.78 / 2 / 65 packets
TCP retransmissions / OOO 0 / 0
Heatmap packet hits 12
Unique credentials 1 (5b**************************32)

Decoded protocols: DNS, HTTP, NTP, WebSocket Network/Transport: TCP, UDP MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain

Top Talkers

Host Packets Role
10.0.1.23 266 Local client (all packets traverse it)
10.0.1.35 247 Local peer — likely the server / upload target
91.189.91.48 9 Canonical NTP pool (prod-ntp-4.ntp*.ps5.canonical.com)
47.96.29.236 6 External, Hangzhou, China
185.125.190.57 2 External, Boston, United States

PacketSnitch — Compacted Pcap Analysis

Capture scope: 266 packets / 18 streams / 629.68 KB / 0 encrypted packets. All traffic is in the clear. 6 hosts are involved (4 internet-reachable), across 23 ports. Decoded protocols: DNS, HTTP, NTP, WebSocket. Top talkers are two internal hosts (10.0.1.23, 10.0.1.35) that account for essentially the entire packet volume. Geographic footprint is minimal: 6 heatmap hits to Hangzhou, China and 2 to Boston, United States. One masked credential is present (5b****32). Heatmap recorded 12 packet hits. There are no TCP retransmissions or out-of-order segments.

1. Host & Protocol Topology

Host Role Packets Notes
10.0.1.23 Internal client (Intel Corporate MAC) 266 Primary talker; drives virtually all observed flows
10.0.1.35 Internal peer (Tenda Technology MAC) 247 Most traffic is bilateral with 10.0.1.23
91.189.91.48 Canonical NTP (prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com, amyrose.canonical.com) 9 NTP time sync
47.96.29.236 External server (Hangzhou, China / Aliyun) 6 HTTP/Socket destination
185.125.190.57 External server (Boston, US) 2 HTTP destination
8.8.8.8 Google DNS (dns.google) 0 packets attributed in Talker table but DNS queries present Recursive resolver

Per-protocol highlights


PacketSnitch — Compacted PCAP Analysis Summary

Capture Overview

The capture is a small, fully unencrypted window of traffic — 266 packets across 18 streams totaling 629.68 KB. There are 0 encrypted packets, 0 undecodable packets, 0 TCP retransmissions, and 0 out-of-order segments, which makes the traffic trivially reconstructible. Stream length averages 14.78 packets (min 2, max 65), consistent with a handful of short client/server interactions rather than bulk transfers. No bookmarks were set; the analyst is working from a raw, unfiltered capture.

Metric Value
Total packets 266
Total streams 18
Total traffic 629.68 KB
Encrypted / Unencrypted 0 / 266
Undecodable packets 0
TCP retransmissions 0
Out-of-order segments 0
Bookmarks 0
Avg / min / max stream length 14.78 / 2 / 65 packets
Heatmap packet hits 12
Unique masked credentials 1 (5b****************************32)

Protocols, Hosts, and Ports

Decoded protocols: DNS, HTTP, NTP, WebSocket (transport on TCP and UDP).

Hosts (6 total):

Host Role Packets
10.0.1.23 Primary talker (likely local client/workstation) 266
10.0.1.35 Secondary local host (likely target/server) 247
91.189.91.48 External — Canonical NTP (amyrose.canonical.com, prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com) 9
47.96.29.236 External — Alibaba Cloud, Hangzhou, China 6
185.125.190.57 External — Boston, US 2
8.8.8.8 Google Public DNS (dns.google) (resolver)

Geographic footprint is light and concentrated: Hangzhou, China (6 hits) and Boston, United States (2 hits).

Ports observed (23): 53, 80, 123, 443, 4444, 33017,


PacketSnitch — Compacted Capture Analysis

Capture at a Glance

A 266-packet, 18-stream session totaling 629.68 KB of entirely unencrypted traffic (TCP/UDP). The transport mix is TCP, UDP, and decoded application protocols are DNS, HTTP, NTP, and WebSocket. There are no retransmissions, no out-of-order segments, and no undecodable packets — a clean capture window. Stream length averages 14.78 packets (min 2, max 65).

Top talkers are entirely intra-LAN, with one of them carrying every single packet in the trace:

Host Packets Role
10.0.1.23 266 Web server / online-judge host
10.0.1.35 247 Attacker client (all HTTP/WS)
91.189.91.48 9 Ubuntu connectivity check (NTP+HTTP)
47.96.29.236 6 DNS resolver (Hangzhou geo)
185.125.190.57 2 Secondary DNS / Boston geo

Six hosts participate overall, with MAC vendors **Intel Corporate, PCS Systemtechnik GmbH, and Tenda Technology Co


PacketSnitch — Compacted Capture Summary

1. Capture-Level Overview

Metric Value
Total packets 266
Total streams 18
Total traffic 629.68 KB
Internet hosts 4
Encrypted / Unencrypted 0 / 266
Undecodable packets 0
TCP retransmissions 0
Out-of-order segments 0
Bookmarks 0
Stream length (avg/min/max) 14.78 / 2 / 65 packets
Heatmap packet hits 12
Unique credentials captured 1 (5b****************************32)

Protocols decoded: DNS, HTTP, NTP, WebSocket (over TCP and UDP).

Hosts (6): 10.0.1.23, 10.0.1.35, 185.125.190.57, 47.96.29.236, 8.8.8.8, 91.189.91.48.

Hostnames resolved (7): 185.125.190.57, 8.8.8.8 (dns.google), `


PacketSnitch — Capture Analysis Summary

Capture Profile

The capture contains 266 packets across 18 streams totaling 629.68 KB. All traffic is unencrypted (0 encrypted, 0 undecodable), and there are no TCP retransmissions or out-of-order segments. Average stream length is ~14.78 packets (min 2, max 65). Decoded protocols are limited to DNS, HTTP, NTP, and WebSocket over TCP/UDP.

The capture is dominated by a single internal client/server pair, with a small number of external probes:

Host Role Packets
10.0.1.23 Local web/app server (HUSTOJ) 266
10.0.1.35 Internal client 247
91.189.91.48 Ubuntu NTP / connectivity check 9
47.96.29.236 External (Hangzhou, CN) 6
185.125.190.57 External (Boston, US) 2
8.8.8.8 Google DNS resolver (referenced)

MAC vendors observed: Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch. Geographic footprint is narrow: Hangzhou, China (6 hits) and Boston, United States (2 hits). MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain. The heatmap recorded 12 packet hits and the keychain surfaced 1 unique masked credential (5b****************************32).

HUSTOJ Web Application Activity (10.0.1.23 ↔ 10.0.1.35)

The bulk of the capture is HTTP traffic between client 10.0.1.35 and web server 10.0.1.23 at http://10.0.1.23/, identified as the HUSTOJ online-judge platform (Chinese-language UI, "登录 - HUSTOJ" = "Login - HUSTOJ"). The HTML pages declare lang="cn", charset UTF-8, with an IE-edge meta tag and viewport initial-scale=0.5.

Assets referenced

Stylesheet chain under template/syzoj/css/: style.css, tomorrow.css, semantic.min.css?v=0.1, katex.min.css, morris.min.css, FiraMono.css, latin.css, Exo.css?v=0.1. Inline CSS includes a @media (max-width: 991px) block toggling .mobile-only / .desktop-only, and a .padding rule with fro


PacketSnitch — Session Capture Compaction

Capture Overview

This is a small, unencrypted capture: 266 packets across 18 streams, totaling 629.68 KB of clear-text traffic with 0 retransmissions and 0 out-of-order segments. All packets are decryptable; none are undecodable. The capture is fully passive/observational and short-lived (avg stream length 14.78 packets, min 2, max 65).

Metric Value
Total packets 266
Total streams 18
Total traffic 629.68 KB
Encrypted packets 0
Unencrypted packets 266
Undecodable packets 0
Bookmarks 0
TCP retransmissions 0
Out-of-order segments 0
Stream length (avg / min / max) 14.78 / 2 / 65 packets

Protocols

Geographic Footprint

Location Hits
Hangzhou, China 6
Boston, United States 2

Topology & Top Talkers

Almost all traffic is between two LAN hosts, with small outbound probes to public services.

Host Packets Role
10.0.1.23 266 Web server (HUSTOJ / syzoj) — full capture volume
10.0.1.35 247 Client workstation
91.189.91.48 9 Ubuntu NTP/connectivity check
47.96.29.236 6 External endpoint (Hangzhou)
185.125.190.57 2 External endpoint (Boston)

MIME Types Observed

application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain12 heatmap hits on the source/target.

Credential Capture

1 unique credential was


Capture Analysis Summary — HUSTOJ Web App Session

Capture timestamp: 2026-07-29T15:50:53Z – 15:56:30Z Scope: 266 packets / 18 streams / 629.68 KB, entirely unencrypted, 0 retransmissions, 0 out-of-order.

1. Capture-Level Snapshot


Network Capture Analysis — Consolidated Summary

Capture-Level Overview

A small, fully unencrypted pcap of 266 packets across 18 streams (629.68 KB) with zero retransmissions or out-of-order segments. Average stream length is 14.78 packets (min 2, max 65). All 266 packets decode cleanly (no encrypted, no undecodable traffic).

Decoded protocols: DNS, HTTP, NTP, WebSocket
Transport: TCP and UDP only
MIME types observed: application/javascript, application/octet-stream, application/x-dosexec, text/html, text/plain

The Data Classifications panel is dominated by a long list of DOS executable (COM) signatures (70+ variants) and a single XA sysV pure executable not stripped, reflecting the binary payload distribution in the capture — most likely payload bodies served by the local web app.

Hosts, Ports, and Vendors

Hosts (6):

Host Role / Notes
10.0.1.23 Local web server (client target)
10.0.1.35 Local client (admin workstation)
8.8.8.8 Google Public DNS (dns.google)
91.189.91.48 Canonical NTP / Ubuntu connectivity check (prod-ntp-4.ntp1.ps5.canonical.com, prod-ntp-4.ntp4.ps5.canonical.com, amyrose.canonical.com)
47.96.29.236 Public IPv4 in Hangzhou, China — ALISOFT allocation
185.125.190.57 Public IPv4 in Boston, US

Ports (23 in use): 53, 80, 123, 443, 4444, 33017, 35239, 36814, 38192, 39149, 39233, 39271, 41165, 42353, 42941, 43269, 43443, 44763, 44837, 46005, 46644, 51186, 51882. The standout non-standard port is 4444 (commonly associated with Metasploit / reverse-shell handlers — worth a follow-up if any traffic actually lands there).

MAC vendors (3): Intel Corporate, PCS Systemtechnik GmbH, Tenda Technology Co.,Ltd.Dongguan branch.

Top Talkers

Host Packets
10.0.1.23 266
10.0.1.35 247
91.189.91.48 9
47.96.29.236 6
185.125.190.57 2

Traffic is overwhelmingly intra-LAN between 10.0.1.35 ↔ 10.0.1.23; only a handful of packets traverse the public internet.

Geographic Footprint

Location Hits
Hangzhou, China 6
Boston, United States 2

Heatmap & Credentials